← All resourcesCybersecurity Standards
Cybersecurity standards that impact the medical device lifecycle
Meeting regulatory expectations means aligning with an ecosystem of international cybersecurity, software, risk management, and quality standards — not just the regulations themselves. Here's the current landscape.
Coverage
Category
| Standard | Year | Coverage | Primary Focus | Description |
|---|---|---|---|---|
| IEC 81001-5-1 | 2021 | Full lifecycle | Product cybersecurity | Foundational standard for health software and software-containing devices. |
| ANSI/AAMI SW96 | 2023 | Full lifecycle | Security risk management | Security risk management methods aligned with ISO 14971. |
| AAMI TIR57 | 2023 | Full lifecycle | Security risk management | Practical guidance linking cybersecurity to patient safety. |
| AAMI TIR97 | 2023 | Post-market | Operational cybersecurity | Covers vulnerability intake, remediation, patching, and communication. |
| ISO 14971 | 2019 | Full lifecycle | Risk management | Cybersecurity risks evaluated as hazard sources. |
| ISO/TR 24971 | 2020 | Full lifecycle | Risk management guidance | Companion guidance document explaining how to apply ISO 14971 in practice. |
| ISO/IEC 23894 | 2023 | Full lifecycle | AI risk management | Adapts ISO 31000 risk management principles to AI-specific risks — robustness, bias, algorithmic transparency, human-AI interaction — relevant for risk assessment of AI-enabled devices. |
| ISO 31000 | 2018 | Organization | Risk management principles | Outlines a comprehensive approach to identifying, analyzing, evaluating, treating, monitoring and communicating risks across an organization — the parent framework ISO/IEC 23894 adapts specifically for AI. |
| ISO/TS 24971-2 | 2026 | Full lifecycle | AI/ML risk management guidance | Guidance on applying ISO 14971 to machine-learning-enabled devices — data management, bias, model drift, and continuous learning risks not addressed in ISO 14971 or ISO/TR 24971. Does not cover LLM or generative-AI-enabled devices. |
| AAMI TIR34971 | 2023 | Full lifecycle | AI/ML risk management guidance | The US/UK-origin guide (also published as BS/AAMI 34971) that ISO/TS 24971-2 was harmonized from — same ML-specific hazards: data bias, overtrust, and adaptive algorithms that change after deployment. |
| ISO/IEC 5259 (Parts 1-5) | 2024-2025 | Full lifecycle | AI/ML data quality | Defines data quality terminology, measurable characteristics, management requirements, and a governance framework for the training and validation data behind AI/ML models. |
| ISO/IEC 8183 | 2023 | Full lifecycle | AI data life cycle framework | Broader than the data-quality focus of ISO/IEC 5259 — governs AI data handling from acquisition through decommissioning across the full system life cycle. |
| IEC PAS 63621 | 2026 | Full lifecycle | AI/ML data management | Publicly Available Specification giving medical device manufacturers a data-lifecycle blueprint for AI/ML training data — suitability, quality, bias mitigation, versioning, and traceability — supporting MDR/IVDR data-governance expectations. |
| ISO 13485 | 2016 | Full lifecycle | Quality management system | Standard for quality management systems in the design and manufacture of medical devices. It outlines specific requirements that help organizations ensure their medical devices meet both customer and regulatory demands for safety and efficacy. |
| IEC 62304 | 2006+A1:2015 | Full lifecycle | Software lifecycle | Medical-device software lifecycle processes; provides a foundation for integrating cybersecurity into software development, not itself a security standard. |
| IEC 82304-1 | 2016 | Full lifecycle | Health software safety & security | Applies to the safety and security of health software products designed to operate on general computing platforms and intended to be placed on the market without dedicated hardware, and its primary focus is on the requirements for manufacturers. It covers the entire lifecycle including design, development, validation, installation, maintenance, and disposal of health software products. |
| NIST CSF 2.0 | 2024 | Organization & product | Risk-based framework | Offers a taxonomy of high-level cybersecurity outcomes that can be used by any organization to better understand, assess, prioritize, and communicate its cybersecurity efforts. Accepted by FDA and healthcare stakeholders. |
| NIST AI RMF 1.0 | 2023 | Organization & product | AI risk-based framework | Voluntary framework for managing AI risk and promoting trustworthy, responsible AI — the AI sibling to NIST CSF 2.0, relevant for AI-enabled device risk governance. |
| NIST SP 800-53 | 2020 | Full lifecycle | Security & privacy controls | Provides a catalog of security and privacy controls for information systems and organizations. |
| NIST SP 800-30 | 2012 | Full lifecycle | Risk assessment | Guide for Conducting Risk Assessments. Complements ISO 14971 methodology. |
| NIST SP 800-61 | 2025 | Post-market | Incident response | Revision 3 reframes it as a CSF 2.0 community profile for incident response, superseding the original Incident Handling Guide. |
| NIST SP 800-218 (SSDF) | 2022 | Pre-market | Secure software development | Secure Software Development Framework — practices referenced by FDA guidance for aligning a Secure Product Development Framework (SPDF). |
| NIST SP 800-40 Rev. 4 | 2022 | Post-market | Patch management | Enterprise patch management planning, referenced for postmarket vulnerability remediation timelines and patching capability. |
| ISO/IEC 27001 | 2022 | Organization | Information security management | Governance and secure development policies. |
| ISO/IEC 27002 | 2022 | Organization | Security controls | Implementation guidance for controls. |
| ISO/IEC 27005 | 2022 | Organization | Information security risk management | Companion guidance to ISO/IEC 27001 for identifying, assessing, and treating information security risks — the enterprise-ISMS counterpart to ISO 14971 for device safety risk. |
| ISO/IEC 42001 | 2023 | Organization | AI management system | Certifiable AI governance framework — the AI counterpart to ISO/IEC 27001, covering how an organization manages AI risk, oversight, and lifecycle controls. |
| ISO 27799 | 2025 | Providers | Security controls | Health organization-specific guidance, based on ISO/IEC 27002. |
| ISO/IEC 29147 | 2018 | Post-market | Vulnerability disclosure | Coordinated disclosure principles. |
| ISO/IEC 30111 | 2019 | Post-market | Vulnerability handling | Operational processes for remediation. |
| ANSI/NEMA HN 1 (MDS2) | 2019 | Procurement | Security disclosure | Standardized form manufacturers complete to disclose a device's security control features to healthcare delivery organizations. |
| IEC TS 81001-2-2 | 2025 | Full lifecycle | Health software security disclosure | Guidance for implementing, disclosing, and communicating health software and medical device security needs, risks, and controls between manufacturers and healthcare delivery organizations, applied across the software lifecycle — supersedes IEC TR 80001-2-2:2012 and IEC TR 80001-2-8:2016, complements the MDS2 disclosure form above. |
| ANSI/CAN/UL 2900-2-1 | 2023 | Full lifecycle | Product cybersecurity testing | Particular requirements for network-connectable components of healthcare and wellness systems, building on the UL 2900-1 general requirements. |
| IEEE 2621.2 / UL 2621-2 | 2022 | Full lifecycle | Connected diabetes device | Defines the security functional requirements (protection profile) for connected diabetes devices — insulin pumps, continuous glucose monitors, and their companion controllers/apps — covering authentication, encryption, and secure communication between paired devices. Part 2 of the multi-part IEEE/UL 2621 series; Part 1 covers the security evaluation program and Part 3 covers mobile-device use in diabetes control. |
| IEC 62443-4-1 | 2018 | Pre-market | Secure product development lifecycle | Secure development lifecycle (SDL) requirements for products used in industrial automation and control systems — requirements definition, secure design, secure implementation, verification/validation, defect and patch management, and end-of-life; relevant to connected medical device components built to IACS-adjacent expectations. |
Need help mapping standards to your program?
We'll help you decide which standards matter most for your device and markets.
