Cybersecurity Standards that impact Medical Device Lifecycle
Most regulators have published cybersecurity guidance documents for manufacturers to follow and some countries have enacted laws. But manufacturers need to relay on published standards to align most activities in the medical device lifecycle as expected by regulators. Manufacturers must align with an ecosystem of international cybersecurity, software, risk management, and quality standards. This article provides a practical overview of the most relevant ISO, IEC, AAMI, and NIST standards that impact medical device cybersecurity, clearly indicating where they apply in the lifecycle.
| Standard | Year | Lifecycle Coverage | Primary Focus | Why It Matters for Medical Devices |
|---|---|---|---|---|
| IEC 81001-5-1 Principles for medical device security – Risk management | 2021 | Pre-market & Post-market | Product cybersecurity | Foundational cybersecurity standard for health software and software-containing medical devices; aligns security with safety and effectiveness |
| ANSI/AAMI SW96 | 2023 | Pre-market & Post-market | Product cybersecurity | Provides requirements on methods to perform security risk management for a medical device in the context of the safety risk management process required by ISO 14971. This document is intended to be used in conjunction with AAMI TIR57 and AAMI TIR97. |
| AAMI TIR57 | 2023 | Pre-market & Post-market | Security risk management | Practical guidance for implementing cybersecurity risk management tied to patient safety |
| AAMI TIR97 | 2023 | Post-market | Operational cybersecurity | Focuses on vulnerability intake, remediation, patching, and customer communication |
| ISO 14971 | 2019 | Pre-market & Post-market | Risk management | Cybersecurity risks must be evaluated as potential sources of hazardous situations impacting patient safety |
| ISO 13485 | 2016 | Organization-wide | Quality management system | Provides the QMS framework that governs design controls, change management, and post-market processes. Adopted by FDA and other regulators |
| IEC 62304 | 2015 | Pre-market & Maintenance | Software lifecycle | Ensures cybersecurity activities are embedded into software development and maintenance processes |
| IEC 82304-1 | 2016 | Pre-market & Post-market | Health software safety & security | Particularly relevant for standalone software and SaMD products |
| NIST Cybersecurity Framework (CSF) 2.0 | 2024 | Organization-wide & Product lifecycle | Risk-based cybersecurity framework | Widely accepted by FDA and healthcare stakeholders; useful for structuring cybersecurity programs |
| NIST SP 800-53 | 2020 | Pre-market & Post-market | Security & privacy controls | Comprehensive catalog of technical and administrative security controls |
| NIST SP 800-30 | 2012 | Pre-market & Post-market | Risk assessment | Structured threat and risk assessment methodology complementary to ISO 14971 |
| NIST SP 800-61 | 2025 | Post-market | Incident response | Best practices for cybersecurity incident handling and response |
| ISO/IEC 27001 | 2022 | Organization-wide | Information security management | Establishes governance and policies supporting secure development and operations |
| ISO/IEC 27002 | 2022 | Organization-wide | Security controls | Detailed guidance for selecting and implementing information security controls |
| ISO/IEC 27799 | 2025 | Providers | Security controls | Provides information security controls, including implementation guidance, for health organizations based on ISO/IEC 27002:2022. |
| ISO/IEC 29147 | 2018 | Post-market | Vulnerability disclosure | Defines principles for coordinated vulnerability disclosure programs |
| ISO/IEC 30111 | 2019 | Post-market | Vulnerability handling | Operational processes for vulnerability analysis, remediation, and coordination |
