Cybersecurity Standards that impact Medical Device Lifecycle

Most regulators have published cybersecurity guidance documents for manufacturers to follow and some countries have enacted laws. But manufacturers need to relay on published standards to align most activities in the medical device lifecycle as expected by regulators. Manufacturers must align with an ecosystem of international cybersecurity, software, risk management, and quality standards. This article provides a practical overview of the most relevant ISO, IEC, AAMI, and NIST standards that impact medical device cybersecurity, clearly indicating where they apply in the lifecycle.

StandardYearLifecycle CoveragePrimary FocusWhy It Matters for Medical Devices
IEC 81001-5-1 Principles for medical device security – Risk management2021Pre-market & Post-marketProduct cybersecurityFoundational cybersecurity standard for health software and software-containing medical devices; aligns security with safety and effectiveness
ANSI/AAMI SW962023Pre-market & Post-marketProduct cybersecurityProvides requirements on methods to perform security risk management for a medical device in the context of the safety risk management process required by ISO 14971. This document is intended to be used in conjunction with AAMI TIR57 and AAMI TIR97.
AAMI TIR572023Pre-market & Post-marketSecurity risk managementPractical guidance for implementing cybersecurity risk management tied to patient safety
AAMI TIR972023Post-marketOperational cybersecurityFocuses on vulnerability intake, remediation, patching, and customer communication
ISO 149712019Pre-market & Post-marketRisk managementCybersecurity risks must be evaluated as potential sources of hazardous situations impacting patient safety
ISO 134852016Organization-wideQuality management systemProvides the QMS framework that governs design controls, change management, and post-market processes. Adopted by FDA and other regulators
IEC 623042015Pre-market & MaintenanceSoftware lifecycleEnsures cybersecurity activities are embedded into software development and maintenance processes
IEC 82304-12016Pre-market & Post-marketHealth software safety & securityParticularly relevant for standalone software and SaMD products
NIST Cybersecurity Framework (CSF) 2.02024Organization-wide & Product lifecycleRisk-based cybersecurity frameworkWidely accepted by FDA and healthcare stakeholders; useful for structuring cybersecurity programs
NIST SP 800-532020Pre-market & Post-marketSecurity & privacy controlsComprehensive catalog of technical and administrative security controls
NIST SP 800-302012Pre-market & Post-marketRisk assessmentStructured threat and risk assessment methodology complementary to ISO 14971
NIST SP 800-612025Post-marketIncident responseBest practices for cybersecurity incident handling and response
ISO/IEC 270012022Organization-wideInformation security managementEstablishes governance and policies supporting secure development and operations
ISO/IEC 270022022Organization-wideSecurity controlsDetailed guidance for selecting and implementing information security controls
ISO/IEC 277992025ProvidersSecurity controlsProvides information security controls, including implementation guidance, for health organizations based on ISO/IEC 27002:2022.
ISO/IEC 291472018Post-marketVulnerability disclosureDefines principles for coordinated vulnerability disclosure programs
ISO/IEC 301112019Post-marketVulnerability handlingOperational processes for vulnerability analysis, remediation, and coordination