Research · Medical device cybersecurity

Medical device cybersecurity standards: the 24 FDA records and what 11 regulators name

24 FDA recognition records cover 22 distinct standards with security or a vulnerability term in the title. Medical device cybersecurity standards are a set, not one rulebook. The PenTest Index found the same FDA warning on all 24: meeting one "may not satisfy all the cybersecurity requirements outlined in Section 524B," the U.S. device cybersecurity law. So which ones matter?

See the 24 records and their sources · Download the source CSV · Repeat the count

Key medical device cybersecurity standards statistics

  • 24 FDA recognition records cover 22 distinct security standards. The FDA database has 24 records whose title names security, cybersecurity or a vulnerability term. That is 22 different standards, because one scoring system (CVSS) is listed in three versions. It is also 24 of the 1,738 records in FDA's database, or 1.4%. (The PenTest Index count of FDA's Recognized Consensus Standards database, October 9, 2026.) Source data.
  • The same caution on all 24. All 24 selected recognition records carry an FDA note saying conformance "may not satisfy all the cybersecurity requirements outlined in Section 524B." In plain words, meeting the standard may not be enough to meet the law. (FDA database records; The PenTest Index count, October 9, 2026.) FDA record example.
  • 8 of 22 list a replaced or withdrawn edition. For 8 of the 22 different security standards the FDA recognizes, the edition FDA lists has since been replaced or withdrawn by its publisher. (The PenTest Index comparison of FDA's database with IEC, ISO, UL and CLSI catalogs, October 9, 2026.) Edition sources.
  • 0 standards named in the law. Section 524B of the Federal Food, Drug, and Cosmetic Act, the U.S. law on medical device cybersecurity, names no standard. It sets 4 requirements for "cyber devices" and has applied to covered FDA submissions for cyber devices since March 29, 2023. (Public Law 117-328, section 3305.) Law.
  • 3 versions in 860 days. The FDA has issued 3 versions of its final premarket cybersecurity guidance in 860 days: September 27, 2023; June 27, 2025; and February 3, 2026. FDA calls the third a revision. The version before them stood for 3,282 days, about 9 years. (Federal Register; FDA.) Dated sources.
  • No security standard above 8 of 11 regulators. None of the 25 security standards The PenTest Index checked is named by more than 8 of 11 medical device regulators. IEC 81001-5-1, AAMI TIR57 and CVSS each reach 8. All 11 name three general standards: ISO 14971, IEC 62304 and ISO 13485. ("Named" means the number or name appears in the documents searched, not that it is required. AAMI TIR57's eighth is Singapore's voluntary label scheme. The PenTest Index review, October 9, 2026.) Cell sources.
  • Japan requires evidence for covered Class II, III and IV devices. Since April 1, 2024, applications for those devices must attach data showing conformance to JIS T 81001-5-1 "etc." The rule covers devices that use software and exchange data with other devices, networks or external media. Other standards, such as IEC 81001-5-1, may be used with an explanation. (Japan MHLW notification PSEHB/MDED No. 0331-8.) MHLW notification.
  • 10 of 11 jurisdictions mention penetration testing in the official device-guidance sets reviewed. None of the 17 specified legal and regulatory texts contains the searched penetration-testing terms. The search covered English and local-language terms and included one Great Britain draft. A word search does not decide what testing the law requires. (The PenTest Index text search, October 9, 2026.) Text-search sources.

Which cybersecurity standards apply to medical devices?

No single standard covers medical device cybersecurity. Our short list has five standards covering four jobs (risk gets two): IEC 81001-5-1, ANSI/AAMI SW96, AAMI TIR57, AAMI TIR97 and UL 2900-2-1. All five are on the FDA's recognized list as of October 9, 2026.

"Recognized" means a maker can submit a signed statement that the device meets the recognized parts of that standard, within FDA's stated scope. That statement is called a declaration of conformity. In FDA's words, "conformance is voluntary, unless a standard is 'incorporated by reference' into regulation." Think of a teacher saying "you may show your work this way." You may. You don't have to.

Table 1. Our short list: five medical device cybersecurity standards
JobStandardFDA recognition no.Named by (of 11 regulators)List price (electronic/PDF)
Build software securelyIEC 81001-5-1:202113-1228CHF 335
Manage security risk (requirements)ANSI/AAMI SW96:202313-1313$298
Manage security risk (guidance)AAMI TIR57:2016/(R)202313-838*$345
Keep it secure after launchAAMI TIR97:2019/(R)202313-1126$298
Test the productUL 2900-2-1 (used with UL 2900-1)13-1046$75 (UL 2900-1 adds $402)

Source: FDA Recognized Consensus Standards database; publisher stores (IEC, AAMI, UL); The PenTest Index review of 11 regulators. All checked October 9, 2026. *AAMI TIR57's eighth regulator is Singapore's voluntary label scheme, not its regulator's own guidance.

The short list is our pick. The rule: security standards written for health care, recognized by the FDA, one per job, except risk, which gets a requirements standard (SW96) and a guidance report (TIR57).

Picture a connected insulin pump. IEC 81001-5-1 covers how the team writes and updates the pump's software. SW96 and TIR57 cover how the team finds and ranks what could go wrong. UL 2900-2-1 covers how a lab attacks the finished pump. TIR97 covers what happens when a flaw turns up three years after launch.

Three more standards show up on nearly every list: ISO 14971 (risk management), IEC 62304 (software life cycle) and ISO 13485 (quality management system). All 11 regulators we checked name all three. None of the three is a security standard, but security work plugs into them.

Standards finder

Pick your market, your job, or your device type, and the table below narrows to matching entries in our review. Every row shows the FDA recognition number, how many of the 11 regulators name it, and a note on its edition. The finder works on the same 31 rows as our download, and the full table stays readable without it.

Find matching standards

Filters narrow this review; they do not decide which rules or standards apply to a particular device.

Market (choose any number)
Limit results

Loading standards…

The PenTest Index. "Medical device cybersecurity standards: the 24 FDA records and what 11 regulators name." Updated October 9, 2026. https://thepentestindex.com/research/medical-device-cybersecurity-standards/

Filtered standards from the 31-entry review
StandardJobFDA recognitionNamed byEdition noteElectronic/PDF pricePenetration-testing evidence

Source: standards.csv and regulators.csv. Each result retains its source and check date in the downloadable CSV.

Table 2. Medical device cybersecurity standards: job, FDA status and how many of 11 regulators name each
StandardJob (our classification)FDA recognition no.Named by (of 11)Edition or FDA note
ISO 14971 (risk management) †Assess risk5-12511—
IEC 62304 (software life cycle) †Build13-7911—
ISO 13485 (quality management system) †Run the companyNot in FDA database11Not in FDA's database; binds through the Quality Management System Regulation (from 2026-02-02)
IEC 81001-5-1 (secure health software life cycle)Build13-1228Edition 1.0 remains current; IEC corrected its copy in December 2025 and includes Interpretation Sheet 1; FDA record does not mention that sheet
AAMI TIR57 (security risk management)Assess risk13-838—
CVSS (vulnerability scoring)After launch13-116; 13-142; 13-1408Three versions listed; v3.0 accepted until 2026-12-20, v3.1 until 2028-07-02
IEC 80001-1 (risk management for hospital IT networks) †Run a hospital network13-388FDA lists Edition 1.0 (2010); IEC's current edition is 2.0 (2021-09-21)
ISO/IEC 29147 (vulnerability disclosure)After launch13-777FDA lists the 2014 edition; ISO's current edition is 2018
ANSI/NEMA HN 1 (MDS2 security disclosure form)Tell buyers13-1237—
AAMI TIR97 (postmarket security risk)After launch13-1126—
UL 2900-1 (security testing, general)Test13-966FDA lists the 2017 first edition; UL's current edition is 2 (2023-12-13)
UL 2900-2-1 (security testing, healthcare systems)Test13-1046Used with UL 2900-1
IEC TR 80001-2-2 (disclosing security needs and controls)Tell buyers13-426Withdrawn by IEC 2025-10-01; replaced by IEC TS 81001-2-2:2025
ISO/IEC 30111 (vulnerability handling)After launch13-786FDA lists INCITS/ISO/IEC 30111:2013 (R2019); the current national adoption is INCITS/ISO/IEC 30111:2019 (2024), based on ISO/IEC 30111:2019
NIST Cybersecurity Framework ‡Run the companyNot in FDA database6Not in FDA's database (NIST is not one of its standards organizations)
IEC 82304-1 (health software product safety) †Build — Health software with no hardware13-975—
IEC TR 80001-2-8 (standards for security capabilities)Tell buyers13-1025Withdrawn by IEC 2025-10-01; replaced by IEC TS 81001-2-2:2025
ISO/IEC 27001 (organization security management)Run the companyNot in FDA database4Not in FDA's database
ANSI/AAMI SW96 (security risk management requirements)Assess risk13-1313—
IEC 62443-4-1 / ANSI/ISA-62443-4-1 (secure product development)Build13-1193FDA lists the U.S. edition, ANSI/ISA-62443-4-1-2018; the IEC edition is not in FDA's database
IEC TR 80001-2-9 (security assurance cases)Tell buyers13-1033Withdrawn by IEC 2025-09-05; no replacement named
IEC TR 60601-4-5 (security specifications for devices)BuildNot in FDA database3Not in FDA's database; scope excludes in vitro diagnostic medical devices
IEC 62443-4-2 (security requirements for components)BuildNot in FDA database2Not in FDA's database
IEC TS 62443-1-1 (industrial security terms and models)Background13-601—
IEC 62443-2-1 (industrial security program)Run the company13-611FDA lists the 2010 edition; IEC's current edition is 2.0 (2024-08)
IEC TR 62443-3-1 (industrial security technologies)Background13-621—
IEEE 11073-40101 (vulnerability assessment, personal health devices)Assess risk — Personal health or point-of-care device13-1171Partial recognition: subclause 8.6 (Iteration) is not recognized
IEEE 11073-40102 (security capabilities, personal health devices)Build — Personal health or point-of-care device13-1181—
IEEE/UL 2621.2 (connected diabetes device security)Build — Connected diabetes device13-1281—
CLSI AUTO11 (IT security of lab instruments)Build — Lab (IVD) instrument7-3441FDA lists AUTO11-A2; CLSI's current edition is the 3rd (2024-09-27)
AAMI CR515 (security of machine-learning devices)Assess risk — Machine-learning device13-1531—

Source: as linked in the table rows.

† Not a security standard. ‡ A framework, not a standard.

Source: The PenTest Index review of FDA's Recognized Consensus Standards database, publisher catalogs and documents from 11 regulators, checked October 9, 2026. "Job" is our classification. "Named by" counts regulators whose documents name the standard; it does not mean required.

IEC 81001-5-1 vs IEC 62443-4-1

IEC 81001-5-1 takes its process rules from IEC 62443-4-1 and applies them to health software. Its own introduction says those requirements "have been derived from" IEC 62443-4-1. The FDA recognizes IEC 81001-5-1 and the U.S. edition of the other, ANSI/ISA-62443-4-1-2018.

Table 3. IEC 81001-5-1 compared with IEC 62443-4-1
IEC 81001-5-1:2021IEC 62443-4-1:2018
Written forHealth softwareIndustrial control products
Pages11454
List price (electronic/PDF)CHF 335CHF 335 (ANSI/ISA edition: $270)
FDA recognition13-122, entered December 19, 202213-119 (ANSI/ISA-62443-4-1-2018 only), entered June 7, 2021
Testing clauses5.7.1 security requirements, 5.7.2 threat mitigation, 5.7.3 vulnerability, 5.7.4 penetration testing9.2 to 9.5 (SVV-1 to SVV-4): the same four kinds
Tester independence5.7.5 Managing conflicts of interest between testers and developers9.6 SVV-5: Independence of testers
Next editionEdition 2 forecast August 2028Edition 2 forecast April 2028

Source: IEC Webstore, IEC 81001-5-1 and IEC 62443-4-1 (free contents previews); FDA records 13-122 and 13-119. Checked October 9, 2026.

One catch: IEC says meeting 81001-5-1 "is not necessarily a sufficient condition for conformance to IEC 62443-4-1." So a maker who sells into industrial markets too may need both.

Which cybersecurity standards does the FDA recognize?

As of October 9, 2026, the FDA has 24 recognition records whose title names security, cybersecurity or a vulnerability term. They are 22 different standards and 24 of the 1,738 records in FDA's database (1.4%). Using a recognized standard is a choice, not a duty, unless a regulation makes it one.

Not all 24 were written for medical devices. 14 of the 24 were written for health care. The other 10 come from other fields: 4 are for factory control systems, 3 are versions of one system for scoring security flaws (CVSS), 2 are for general IT, and 1 is for any connected product. (Our classification of the 24 FDA records.)

Table 4. The 24 FDA security recognition records (sorted by FDA date of entry)
#FDA no.Standard as FDA lists it — what it coversFDA date of entryExtentWritten for health care?FDA's edition still the publisher's current one?Named by (of 11)
113-42IEC TR 80001-2-2:2012 — Telling buyers about device security needs, risks and controls2013-08-06CompleteYesNo — Replaced by IEC TS 81001-2-2:2025; IEC withdrawal date 2025-10-016
213-60IEC TS 62443-1-1:2009 — Industrial network security: terms, concepts and models2013-08-06CompleteNoYes1
313-61IEC 62443-2-1:2010 — Industrial control: setting up a security program2013-08-06CompleteNoNo — IEC 62443-2-1:2024 (Edition 2.0, 2024-08)1
413-62IEC TR 62443-3-1:2009 — Industrial control: security technologies2013-08-06CompleteNoYes1
513-77ISO/IEC 29147:2014 — Vulnerability disclosure2015-08-14CompleteNoNo — ISO/IEC 29147:2018 (Edition 2, 2018-10)7
613-78INCITS/ISO/IEC 30111:2013 (R2019) — Vulnerability handling processes2015-08-14CompleteNoNo — Current national adoption INCITS/ISO/IEC 30111:2019 (2024), based on ISO/IEC 30111:2019 (Edition 2)6
713-83AAMI TIR57:2016 — Security risk management for medical devices2016-06-27CompleteYesYes8
813-96UL 2900-1, first edition (2017) — Security testing of network-connectable products: general requirements2017-08-21CompleteNoNo — UL 2900-1 Edition 2, published 2023-12-13, last revised 2026-06-296
913-102IEC TR 80001-2-8:2016 — Standards for building security capabilities2017-12-04CompleteYesNo — Replaced by IEC TS 81001-2-2:2025; IEC withdrawal date 2025-10-015
1013-103IEC TR 80001-2-9:2017 — Security assurance cases2017-12-04CompleteYesNo — Withdrawn by IEC 2025-09-05; no replacement named3
1113-104UL 2900-2-1, first edition (2017) — Security testing of healthcare and wellness system components2018-06-07CompleteYesYes6
1213-112AAMI TIR97:2019 — Security risk management after launch (postmarket)2019-12-23CompleteYesYes6
1313-116FIRST CVSS v3.0 — Scoring how severe a vulnerability is2020-10-19CompleteNoNo — Older CVSS version; FDA accepts declarations of conformity to it until 2026-12-208
1413-117IEEE 11073-40101-2020 — Vulnerability assessment process for connected personal health devices2021-06-07Partial (excludes subclause 8.6, Iteration)YesYes1
1513-118IEEE 11073-40102-2020 — Security capabilities for connected personal health devices2021-06-07CompleteYesYes1
1613-119ANSI/ISA-62443-4-1-2018 — Secure product development life cycle (industrial)2021-06-07CompleteNoYes3
1713-122IEC 81001-5-1:2021 — Secure life cycle for health software2022-12-19CompleteYesYes8
1813-123ANSI/NEMA HN 1-2019 — Manufacturer Disclosure Statement for Medical Device Security (MDS2 form)2022-12-19CompleteYesYes7
1913-128IEEE/UL 2621.2-2022 — Security of connected diabetes devices2022-12-19CompleteYesYes1
2013-131ANSI/AAMI SW96:2023 — Security risk management requirements for device makers2023-10-09CompleteYesYes3
217-344CLSI AUTO11-A2 — IT security of lab (in vitro diagnostic) instruments and software2025-05-26CompleteYesNo — CLSI AUTO11, 3rd edition (2024-09-27)1
2213-142FIRST CVSS v3.1 — Scoring how severe a vulnerability is2025-05-26CompleteNoNo — Older CVSS version; FDA accepts declarations of conformity to it until 2028-07-028
2313-153AAMI CR515:2025 — Security of machine-learning devices2025-12-22CompleteYesYes1
2413-140FIRST CVSS v4.0 — Scoring how severe a vulnerability is2026-05-25CompleteNoYes8

Source: FDA Recognized Consensus Standards database and record pages; IEC, ISO, UL, AAMI, CLSI, IEEE and FIRST catalogs. Checked October 9, 2026. "Health care?" is our classification. "Named by" counts the 11 regulators in Table 7, any edition. "Current" means the edition/version label, not every later revision, correction or interpretation.

Timeline of 24 FDA recognition records covering 22 distinct standards, by date of entry from 2013 to 2026. Fourteen list a current edition or version. Ten list a replaced or withdrawn edition, or an older CVSS version.
Source: The PenTest Index analysis of FDA’s Recognized Consensus Standards database and publisher catalogs. Checked October 9, 2026. Title rule: security (including cybersecurity) or a vulnerability term. 24 records cover 22 different standards. Edition/version comparison only. Later revisions, corrections and interpretation sheets are not assumed to be FDA-recognized. FDA recognition applies to the listed edition and extent; publisher replacement or withdrawal does not end FDA recognition.Download PNG

Download Chart 1 as SVG

How to check our count yourself

Anyone can repeat it in a few minutes. Search FDA's database for the keyword "524B". On October 9, 2026 it returned 31 records. Keep the ones whose title names security, cybersecurity or a vulnerability term: that leaves 24. Open any of them, and the note sits under "Rationale for Recognition."

The other 7 records in that search (13-33, 13-38, 13-44, 13-70, 13-82, 13-105 and 13-130) are not security standards by our title rule. Their exclusion does not mean they have no cybersecurity use.

Standards many guides list that aren't in FDA's database

Several standards that show up on vendor lists have no record in FDA's database. That is not the same as rejected: none of them is on FDA's short list of standards it declined to recognize.

Table 5. Often listed, but not in FDA's recognized database (October 9, 2026)
StandardWhat FDA's database search returned
IEC TR 60601-4-5No record
IEC 62443-4-1 (the IEC edition)No record. FDA lists the U.S. edition, ANSI/ISA-62443-4-1-2018 (13-119)
IEC 62443-4-2, 62443-3-3, 62443-3-2No record. Only parts 1-1, 2-1, 3-1 and ANSI/ISA 4-1 are listed
IEC TS 81001-2-2:2025No record. A keyword search for "81001" returns only 13-122
ISO/IEC 27001 and 27002No record
ISO 27799No record
ISO/IEC 15408 (Common Criteria)No record
IEEE 2621.1 and 2621.3No record. Only 2621.2 is listed
ISO 81001-1No record
ISO 13485No record. It binds through the Quality Management System Regulation instead
Any NIST publicationNo record. NIST is not one of the 32 organizations in the database

Source: FDA Recognized Consensus Standards database and Non-Recognized Standards table, checked October 9, 2026.

Does meeting a standard make a device compliant?

Meeting a recognized standard may not be enough to make a device compliant in the United States. FDA puts the same warning phrase on all 24 selected recognition records: conformance "may not satisfy all the cybersecurity requirements outlined in Section 524B." Section 524B itself names no standard.

Here is the note as FDA prints it on the records:

"Conformance to this standard may not satisfy all the cybersecurity requirements outlined in Section 524B of FD&C Act …"

Two of the 24 (AAMI TIR57 and ANSI/AAMI SW96) add an explanation of how security risk is judged: by how easily a flaw can be used (exploitability), not by the probability-of-harm model used for safety risk. A section 524B caution sits on 31 records in all: the 24 selected records plus 7 others. Record 13-130 uses different wording.

Other regulators say the same thing in their own words. Australia's TGA (Therapeutic Goods Administration) says "application of standards alone does not guarantee compliance to the Essential Principles," which are Australia's basic safety rules for devices. The EU's device experts group (MDCG) says the standards it lists "cannot provide a presumption of conformity, unless they are harmonised." In plain words: meeting a harmonised standard gives a presumption that the device meets the legal requirements that standard covers. It is not automatic proof of full compliance, and no dedicated cybersecurity standard is on the MDR list yet.

So a standard is a tool for showing your work. The legal test is the law.

What does the law require?

In the United States, section 524B of the Federal Food, Drug, and Cosmetic Act (FD&C Act) sets 4 requirements for "cyber devices" and names no standard. It has applied to covered submissions for cyber devices since March 29, 2023. A maker must provide:

  1. A plan to watch for, find and address vulnerabilities after launch in a reasonable time, including a process for coordinated vulnerability disclosure. A vulnerability is a weak spot an attacker could use.
  2. Processes that give reasonable assurance that the device and related systems are secure, with updates and patches.
  3. A software bill of materials (SBOM), which is a list of the software parts inside the device, including commercial, open-source and off-the-shelf software.
  4. Anything more the FDA requires by regulation.

For known unacceptable vulnerabilities, patches must follow a reasonably justified regular cycle. For critical vulnerabilities that could cause uncontrolled risks, the law calls for patches as soon as possible, outside that cycle. (Section 524B(b)(2).)

A "cyber device" meets 3 tests in the law: it includes software validated, installed or authorized by the sponsor; it can connect to the internet; and it has features validated, installed or authorized by the sponsor that could be open to cybersecurity threats. FDA counts Wi-Fi, cellular, Bluetooth and magnetic inductive links, plus hardware connectors capable of connecting to the internet, such as USB, ethernet and serial ports.

The law was signed December 29, 2022 (Public Law 117-328, section 3305). FDA said it would generally not refuse submissions on this ground before October 1, 2023. From that date, "FDA may RTA" (refuse to accept) submissions that lack the information.

FDA's guidance reaches further than the law's definition. It applies to "devices with cybersecurity considerations" and is "not limited to devices that are network-enabled," per the February 3, 2026 guidance.

One standard that FDA's cybersecurity guidance leans on does bind in the U.S., and it is not a security standard. The Quality Management System Regulation took effect February 2, 2026 and incorporates ISO 13485:2016. Even so, "The FDA will not require certificates of conformance to ISO 13485."

Table 6. What each of 11 regulators makes binding, and what it does with standards
Jurisdiction (regulator)Binding ruleMain cybersecurity guidanceWhat it does with standards
United States (FDA)FD&C Act section 524B (added by Pub. L. 117-328 sec. 3305; applies to submissions from 2023-03-29); Quality Management System Regulation (from 2026-02-02)Cybersecurity in Medical Devices: QMS Considerations and Content of Premarket Submissions (2026-02-03); Postmarket Management of Cybersecurity in Medical Devices (2016-12-28)Recognizes standards; using one is voluntary unless a regulation incorporates it. All 24 selected recognition records carry a section 524B caution
European Union (European Commission / MDCG)Regulation (EU) 2017/745 (MDR) Annex I 17.2, 17.4, 18.8, 23.4(ab); Regulation (EU) 2017/746 (IVDR) Annex I 16.2, 16.4, 20.4.1(ah)MDCG 2019-16 Rev.1 (July 2020)None of the 70 harmonised MDR entries has security or software in its title (list consolidated 2026-06-17); the standards bodies' adoption deadline for an IEC 81001-5-1-based standard is 2028-05-27
Japan (MHLW / PMDA)Essential Principles Article 12(3) (from 2023-04-01; required for applications from 2024-04-01)MHLW notification PSEHB/MDED No. 0331-8 (2023-03-31); manufacturer guide, 2nd editionApplicants for covered controlled and specially-controlled devices (Class II, III, IV) 'must attach data showing conformance to JIS T 81001-5-1 etc.'; other standards 'such as IEC 81001-5-1' may be used with an explanation
Canada (Health Canada)Medical Devices Regulations SOR/98-282 (do not use the words 'cyber' or 'security')Pre-market Requirements for Medical Device Cybersecurity (effective 2019-06-26)Names standards in guidance; the guidance predates IEC 81001-5-1 (2021)
Australia (TGA)Essential Principle 12.1(5) uses the word 'cybersecurity' (from 2021-02-25)Complying with medical device cyber security requirementsStandards use 'is not mandated by the TGA'; 'application of standards alone does not guarantee compliance to the Essential Principles'
Great Britain (MHRA)Medical Devices Regulations 2002, as amended. Separate proposal: draft Medical Devices (Amendment) Regulations 2026, notified to the WTO 2026-05-08; not madeNo penetration-testing mention in the MHRA documents searched. Government response (2026-10-06) promises further details on guidance work by spring 2027No security standard among the 25 checked is on the UK designated list
Brazil (ANVISA)RDC 848/2024 and RDC 657/2022 contain cybersecurity wording and name no cybersecurity standardGuia 38/2020 (ANVISA's adoption of IMDRF N60)Names standards in guidance
China (NMPA / CMDE)Regulations on the Supervision and Administration of Medical Devices; Measures for the Registration and Filing of Medical DevicesCMDE Guidelines for Registration Review of Medical Device Cybersecurity (2022 revision)Lists standards as references (prints IEC 81001-5-1 as 'IEC 80001-5-1:2021')
South Korea (MFDS)Digital Medical Products Act (first in force 2025-01-24; current Act No. 21525 effective 2026-10-08), Articles 13–14; MFDS Notification 2025-30 (effective 2025-04-29)Cybersecurity approval and review guideline (2025-01-10); companion guide (2025-11-13); software-validation guideline 0095-02 (2026-07-28)Guideline takes its requirements from IEC 62443-4-2 and IEC TR 60601-4-5; all must be met unless the maker shows why one cannot apply; the guideline says it has no legal force
Singapore (HSA)Health Products (Medical Devices) Regulations 2010HSA GL-04-R4 (December 2025); voluntary Cybersecurity Labelling Scheme for Medical Devices (launched 2024-10-16)Reference to IEC 81001-5-1 'is encouraged'
Saudi Arabia (SFDA)Medical Devices Law and implementing regulation; MDS-REQ 1 v6, Requirements for Medical Devices Marketing AuthorizationMDS-G38 and MDS-G37 (2019; still hosted by SFDA)Recognised standards list MDS-G020 v3.0 includes IEC 81001-5-1:2021

Source: each regulator's law and guidance as listed in the Sources, checked October 9, 2026. Japanese, Korean, Chinese and Portuguese wording is our translation unless an official English version exists.

European Union

The EU has given official ("harmonised") status to 0 cybersecurity standards under its Medical Device Regulation (MDR). That is 0 of the 70 entries on its list as of June 17, 2026. The EU has asked the European standards bodies for a harmonised standard based on IEC 81001-5-1. The standards bodies' adoption deadline moved 4 years, from May 27, 2024 to May 27, 2028. This is not a device-maker compliance deadline or a promise that harmonisation will happen that day.

The MDR covers IT security in four clauses of Annex I (17.2, 17.4, 18.8 and 23.4(ab)). The words "cyber" and "penetration test" appear 0 times in it. Notified bodies are the groups that check devices for the EU market. In 2022, their association, Team-NB, called IEC 81001-5-1 "state of the art."

Japan

Japan added cybersecurity to its Essential Principles, the basic safety rules every device must meet (Article 12(3)), in 2023. This rule covers devices that use software and exchange data with other devices, networks or external media. For applications since April 1, 2024, makers of covered controlled and specially-controlled devices "must attach data showing conformance to JIS T 81001-5-1 etc." Those are Japan's Class II, III and IV devices. JIS T 81001-5-1 is identical to IEC 81001-5-1. Other international standards "such as IEC 81001-5-1" may be used if the applicant explains why. Covered Class I devices must also have their conformity checked, but the data need not be attached to their notification. (MHLW notification, sections 2(1) and 3(4).)

South Korea

South Korea has binding security duties alongside its non-binding explanatory guides. Its January 10, 2025 guideline takes its requirements from IEC 62443-4-2 and IEC TR 60601-4-5 and says all must be met unless the maker shows why one cannot apply. The same guideline says it has no legal force.

The Digital Medical Products Act, in its version effective October 8, 2026, requires ongoing work to fix vulnerabilities (Article 13) and compliance with the Ministry's security guidelines (Article 14). The binding MFDS Notification 2025-30, effective April 29, 2025, sets those security duties. Its Article 14 covers secure coding, secure design, security testing and vulnerability testing in development and validation.

Do the standards differ by country?

The standards regulators name do differ by country. Of 11 regulators checked on October 9, 2026, no two name the same set in the documents we searched. None of the 25 security standards we checked is named by more than 8 of the 11, while all 11 name three general standards: ISO 14971, IEC 62304 and ISO 13485.

Some standards travel less than you'd think. Eight of the security standards the FDA recognizes are named by none of the other 10 regulators in the documents we searched.

Table 7. Which regulator names which standard (standards named by 2 or more of 11 regulators)
StandardUSEUJPCAAUUKBRCNKRSGSANamed by
ISO 14971 (risk management) †●●●●●●●●●●●11 of 11
IEC 62304 (software life cycle) †●●●●●●●●●●●11 of 11
ISO 13485 (quality management system) †●●●●●●●●●●●11 of 11
IEC 81001-5-1 (secure health software life cycle)●●●–●––●●●●8 of 11
AAMI TIR57 (security risk management)●–●●●–●●●●–8 of 11
CVSS (vulnerability scoring)●●●–●–●●●●–8 of 11
IEC 80001-1 (risk management for hospital IT networks) †●●–●●–●●●–●8 of 11
ISO/IEC 29147 (vulnerability disclosure)●–●–●–●●●●–7 of 11
ANSI/NEMA HN 1 (MDS2 security disclosure form)●●●–●–●●–●–7 of 11
AAMI TIR97 (postmarket security risk)●–●–––●●●●–6 of 11
UL 2900-1 (security testing, general)●––●●–●●–●–6 of 11
UL 2900-2-1 (security testing, healthcare systems)●––●●–●●–●–6 of 11
IEC TR 80001-2-2 (disclosing security needs and controls)●●●–––●●––●6 of 11
ISO/IEC 30111 (vulnerability handling)●–●–●–●●●––6 of 11
NIST Cybersecurity Framework ‡●–●●●–●–●––6 of 11
IEC 82304-1 (health software product safety) †●●––●–––●–●5 of 11
IEC TR 80001-2-8 (standards for security capabilities)●●––––●●––●5 of 11
ISO/IEC 27001 (organization security management)–●–––––●●●–4 of 11
ANSI/AAMI SW96 (security risk management requirements)●–––●–––●––3 of 11
IEC 62443-4-1 / ANSI/ISA-62443-4-1 (secure product development)●●––––––●––3 of 11
IEC TR 80001-2-9 (security assurance cases)●––––––●––●3 of 11
IEC TR 60601-4-5 (security specifications for devices)–●–––––●●––3 of 11
IEC 62443-4-2 (security requirements for components)–●––––––●––2 of 11

Source: The PenTest Index review of official documents from 11 regulators, checked October 9, 2026 (341 cells, each in the download with its source). ● = the standard's number or name appears in the documents we searched. It does not mean required. National adoptions count (for example JIS T 81001-5-1). A mention of a whole series (for example "the IEC 62443 series") is not counted for any one part. † Not a security standard. ‡ A framework, not a standard. US = FDA; EU = Commission and MDCG; JP = Japan; CA = Canada; AU = Australia; UK = Great Britain (England, Scotland and Wales); BR = Brazil; CN = China; KR = South Korea; SG = Singapore; SA = Saudi Arabia.

Named by FDA alone (8): IEC TS 62443-1-1, IEC 62443-2-1, IEC TR 62443-3-1, IEEE 11073-40101, IEEE 11073-40102, IEEE/UL 2621.2, CLSI AUTO11 and AAMI CR515.

How many of the 31 each regulator names: United States 28, China 18, South Korea 17, Australia 15, Brazil 15, European Union 14, Japan 12, Singapore 12, Saudi Arabia 9, Canada 8, Great Britain 3. Security standards only (of 25): United States 22, China 14, South Korea 11, Brazil 10, European Union 9, Australia 9, Singapore 9, Japan 8, Saudi Arabia 4, Canada 3, Great Britain 0.

Grid showing which of 11 regulators name each of 23 standards and frameworks. ISO 14971, IEC 62304 and ISO 13485 are named by all 11. No security standard checked is named by more than 8; IEC 81001-5-1, AAMI TIR57 and CVSS are each named by 8.
Source: The PenTest Index review of specified official documents across 11 markets, checked October 9, 2026.Download PNG

Download Chart 2 as SVG

Notes on the table:

  • Singapore's marks for AAMI TIR57, ISO/IEC 29147 and the MDS2 form come from its voluntary Cybersecurity Labelling Scheme for Medical Devices, not from HSA's own guidance. Its marks for UL 2900 and ISO/IEC 27001 come from an HSA best-practice guide that "does not constitute regulatory guidance."
  • The EU mark for IEC 81001-5-1 comes from the Commission's standardisation request. The standard is not harmonised.
  • China's guideline prints IEC 81001-5-1 as "IEC 80001-5-1:2021," with the right title.
  • China's YY/T 0664-2020 is a modified national adoption of IEC 62304:2015. The rule counts national adoptions, including modified ones. Its GB/T 22080-2016 reference, an adoption of ISO/IEC 27001:2013, was withdrawn on January 1, 2026. It still counts as a named reference in the 2022 guide, not as today's current edition.
  • Japan and South Korea name ISO 13485, and South Korea names IEC 62304, IEC 82304-1 and IEC 80001-1, in quality system and software documents rather than cybersecurity documents.
  • Saudi Arabia's marks for IEC 80001-1 and IEC TR 80001-2-2 rest on those numbers appearing inside the titles of other parts on its recognised list.
  • Brazil's guide names "a família ISO 27000" (the ISO 27000 family), not ISO/IEC 27001 by number, so it gets no mark there.
  • General cybersecurity laws are outside this matrix. One of them, the EU's NIS2 Directive, names ISO/IEC 29147 and ISO/IEC 30111 in recital 58. If it counted, ISO/IEC 29147 would reach 8 as well.

One standard, 11 regulators: where IEC 81001-5-1 stands

Picture a maker selling the same glucose monitor in Tokyo and Toronto. Japan expects proof of meeting JIS T 81001-5-1. Canada's guidance dates from 2019, two years before that standard existed, and does not name it.

Table 8. IEC 81001-5-1 across 11 regulators (October 9, 2026)
RegulatorStatus of IEC 81001-5-1
JapanApplicants for covered controlled and specially-controlled devices (Class II, III and IV) "must attach data showing conformance to JIS T 81001-5-1 etc." since April 1, 2024. Other standards "such as IEC 81001-5-1" may be used with an explanation
United StatesRecognized (13-122, entered December 19, 2022). Voluntary. FDA lists it among "Possible frameworks to consider"
Saudi ArabiaOn SFDA's recognised standards list (MDS-G020 v3.0)
European UnionNot harmonised. The standards bodies' adoption deadline for a standard based on it is May 27, 2028; that is not a promised harmonisation date. Team-NB, the notified bodies' association, called it "state of the art" in 2022
SingaporeReference to it "is encouraged" (HSA GL-04-R4)
AustraliaNamed as best practice: "we have not endorsed these standards and applying them is not mandatory"
South KoreaListed in the November 2025 companion guide. The main guideline is built on IEC 62443-4-2 and IEC TR 60601-4-5
ChinaListed in the references of the 2022 guideline, under a misprinted number
Canada, Great Britain, BrazilNot named in the documents we searched. Canada's guidance (2019) and Brazil's guide (2020) are older than the standard (2021)

Source: MHLW PSEHB/MDED No. 0331-8; FDA record 13-122 and February 3, 2026 guidance; SFDA MDS-G020; Commission C(2024) 3371; Team-NB position paper (October 5, 2022); HSA GL-04-R4; TGA software standards page; MFDS guides (January 10 and November 13, 2025); CMDE 2022 guideline. Checked October 9, 2026.

Is penetration testing required for medical devices?

FDA guidance says penetration test reports "should be provided" and lists 5 things each report should include. Across the official device-guidance sets we reviewed, 10 of 11 jurisdictions name penetration testing. None of the 17 specified legal and regulatory texts uses the searched penetration-testing phrase or local-language equivalent. That text-search result does not settle what testing a device needs to meet broader safety and security duties.

Penetration testing is a planned, authorized attack on a product to find its weak spots before someone else does.

The one jurisdiction without a mention in our searched guidance set is Great Britain. Saudi Arabia's two cybersecurity guides do not mention it, but a question in SFDA's software guide MDS-G23 does. That guide reprints documents from the International Medical Device Regulators Forum (IMDRF), a group of regulators that writes shared guidance. A mention is not a recommendation or a mandate.

Table 9. Penetration testing: who says what
WhereExact wordsStrength
FDA guidance (February 3, 2026)"Penetration test reports should be provided and include the following elements…" (5 elements)Should
EU MDCG 2019-16"Methods can include security feature testing, fuzz testing, vulnerability scanning and penetration testing"Can
German notified bodies (IG-NB, February 2025)"Vulnerability scanning and penetration testing shall be done for all medical devices, unless duly justified."Shall, unless justified. Not EU law or Commission guidance
Japan (manufacturer guide, 2nd edition)For products with a large effect on patient safety, penetration testing is carried out in some cases (our translation)May
Canada (2019)"Structured Penetration Testing," in a table of tests "manufacturers may consider"May
Australia (TGA)"Consider implementing penetration testing initiatives (commensurate with risk level)"Consider
Brazil (Guia 38/2020)"por exemplo, teste de penetração" (for example, penetration testing)Example
China (2022 guideline)Listed with four other example activities (our translation)Example
South Korea (November 2025 companion guide)Security tests such as penetration testing, including fuzz testing, must be carried out and documented (our translation)Named; the guide is not binding
Singapore (HSA GL-04-R4)"Security testing can include: Penetration testing"Can
Singapore label scheme, Level 3"required to pass independent third-party software binary analysis and penetration testing"Required for the label; the scheme is voluntary
Saudi ArabiaNot in its two cybersecurity guides (2019). One question in software guide MDS-G23, a reprint of IMDRF documents: "…intrusion detection, penetration testing, vulnerability scanning…"Mention in an official reprint; no testing direction in that question
Great BritainNo penetration-testing mention in the MHRA documents searchedNone in this document set
17 specified legal and regulatory texts, all 11 jurisdictionsNo match for the searched penetration-testing phrase or local-language equivalentA text-search result; not an exemption from broader testing duties

Source: each document as listed in penetration-testing-wording.csv and the Sources, checked October 9, 2026.

What FDA asks to see in a penetration test report

FDA's guidance lists 4 kinds of security testing "among others": security requirements testing, threat mitigation testing, vulnerability testing and penetration testing. For the penetration test, FDA says the report should include 5 elements:

  1. Independence and technical expertise of testers
  2. Scope of testing
  3. Duration of testing
  4. Testing methods employed
  5. Test results, findings, and observations

The report is what a reviewer reads. So those five lines are worth sorting out before you hire anyone, not after.

Table 10. FDA's five report elements, and what to settle with a tester before you sign
FDA report elementWhat to settle before testing starts
Independence and technical expertise of testersWho will test, how they are separate from the developers, and what experience they have with devices like yours
Scope of testingWhich parts are in and out: device firmware, companion app, cloud services, interfaces (Bluetooth, USB, Wi-Fi), with exact versions
Duration of testingTest dates and total days, written into the report
Testing methods employedWhich methods will be used and named in the report
Test results, findings, and observationsReport format, how findings are rated, and whether a retest after fixes is included

Source: left column, FDA, Cybersecurity in Medical Devices (February 3, 2026), Section V.C. Right column: The PenTest Index buying checklist built on those elements; not an FDA form.

When you compare quotes, these same points decide whether two offers cover the same work.

Which standards name penetration testing?

Four entries in our finder have verified penetration-testing coverage. The free publisher contents show IEC 81001-5-1 clause 5.7.4 and IEC 62443-4-1 clause 9.5. UL's own explanation describes penetration testing for the UL 2900 standards, including UL 2900-1 and UL 2900-2-1. We did not verify their section numbers from UL. FDA's guidance names ANSI/UL 2900, ANSI/ISA 62443-4-1 and IEC 81001-5-1 and says they "may partially meet" its testing recommendations.

Does the tester have to be an outside company?

The tester does not always have to be an outside company. FDA asks the report to show who tested, for example "independent internal testers, external testers," and adds: "In some cases, it may be necessary to use third parties." Japan's January 2024 questions and answers say testing by a third-party body is not mandatory (our translation). Australia's TGA says testing "should be performed by a qualified party independent of the development team." Singapore's voluntary label requires independent third-party testing at Level 3.

How often should a device be tested?

FDA says that after release, cybersecurity testing "should be performed at regular intervals commensurate with the risk (e.g., annually)." "Annually" is an example, not a rule.

If you're getting ready to buy a penetration test for a device, Find My PenTest Match builds a free scope checklist you can copy or print. It asks for no contact details.

Are the FDA-recognized editions up to date?

Not every edition FDA lists is the newest one. For 8 of the 22 security standards the FDA recognizes, the publisher has since replaced or withdrawn the edition FDA lists. FDA accepts declarations of conformity to the editions in its database, so the listed edition still counts. A team buying a standard today must check both the edition and its status. Publishers can still sell a withdrawn report.

Source: FDA record pages; IEC Webstore, ISO, UL Standards and CLSI catalogs. Checked October 9, 2026.

That is about one in three (8 ÷ 22 = 36%). Counting records instead, it is 10 of 24, because FDA lists two older versions of CVSS that it is phasing out itself: it accepts declarations of conformity to CVSS v3.0 until December 20, 2026 and to v3.1 until July 2, 2028.

Three of the eight (IEC TR 80001-2-2, -2-8 and -2-9) are still cited in FDA's February 3, 2026 guidance. That was 125 and 151 days after IEC withdrew them.

Three more version notes that a standards list usually misses:

  • IEC 81001-5-1 has a December 2025 correction. IEC's current copy is still Edition 1.0, marked "CORRECTED VERSION 2025-12," and includes Interpretation Sheet 1 (December 4, 2025; free from IEC). FDA's record 13-122 lists "Edition 1.0 2021-12" and does not mention the interpretation sheet.
  • IEC 80001-1 is an edition gap outside the 24. FDA record 13-38 lists Edition 1.0 from 2010. IEC's current edition is 2.0, published September 21, 2021. Its title doesn't name security, so it isn't in our 24, but it carries the same 524B caution in its scope text.
  • One recognition is partial. FDA record 13-117 for IEEE 11073-40101-2020 does not recognize subclause 8.6, "Iteration." FDA's record explains why, citing its own guidance, AAMI TIR57 and ISO 14971.

How often do the rules change?

FDA's guidance has changed often since 2023. The FDA has issued 3 versions of its final premarket cybersecurity guidance in 860 days: September 27, 2023; June 27, 2025; and February 3, 2026. FDA calls the third a revision, and the version before those three stood for almost 9 years.

Table 12. FDA's main premarket and postmarket cybersecurity guidance since 2005
DateGuidanceVersionCitation
January 14, 2005Cybersecurity for Networked Medical Devices Containing Off-the-Shelf SoftwareFinalWithdrawn September 25, 2025
June 14, 2013Premarket cybersecurityDraft78 FR 35940
October 2, 2014Premarket cybersecurityFinal79 FR 59493
January 22, 2016Postmarket cybersecurityDraft81 FR 3803
December 28, 2016Postmarket cybersecurityFinal (still current)81 FR 95617
October 18, 2018Premarket cybersecurityDraft83 FR 52835
April 8, 2022Premarket cybersecurity (new title)Draft; risk tiers removed87 FR 20873
September 27, 2023Premarket cybersecurityFinal88 FR 66458
March 13, 2024Select updates (section 524B)Draft89 FR 18421
June 27, 2025Premarket cybersecurityFinal; added Section VII on cyber devices90 FR 27634
February 3, 2026Premarket cybersecurityFinal, revised. CurrentFDA guidance history: Level 2 revision

Source: Federal Register notices; FDA guidance pages. Checked October 9, 2026.

The February 2026 version was a "Level 2" update, FDA's term for a smaller revision that doesn't go out for public comment first. It was made to match the new quality system rule. It cites ISO 13485 clauses where earlier versions cited the old rule. The penetration-testing paragraph and its five report elements stayed the same across those three versions; only the punctuation after the testing heading changed.

Six facts that often get repeated wrong

Six facts that often get repeated wrong
What gets repeatedWhat is trueSource
"FDA's 2023 guidance" is currentThe current guidance is dated February 3, 2026. It is the third version of the final guidance since September 2023FDA guidance
"Section 524B took effect in October 2023"It took effect March 29, 2023. October 1, 2023 is when FDA's grace period on refusing submissions endedPub. L. 117-328 §3305(d); 88 FR 19148
"Tier 1 and Tier 2 devices"FDA removed risk tiers in its April 8, 2022 draft87 FR 20873
"Fix vulnerabilities within 90 days" / "disclose within 30 days"Neither is in the statute. FDA's 2016 guidance says to act as soon as possible after learning of the flaw: within 30 days for customer notice, interim controls and a plan to fix it; within 60 days for a validated, distributed fix. Those are among the conditions for not enforcing a reporting rulePub. L. 117-328 §3305; FDA postmarket guidance, pp. 22–23
"53% of devices have a critical vulnerability, says the FBI"The vendor Cynerio published it in January 2022. The FBI repeated itCynerio release; FBI notice 20220912-001
"IEC 81001-5-1 is harmonised in the EU"It is not on the harmonised list. The standards bodies' adoption deadline for a standard based on it is May 27, 2028Decision (EU) 2021/1182, consolidated June 17, 2026; C(2024) 3371

Source: as linked in the table rows.

How much do the medical device cybersecurity standards cost?

The five standards on our short list cost $1,016 plus 335 Swiss francs (CHF 335) at individual electronic/PDF publisher list prices. That is an estimated $1,420 in all at the exchange rate below. One of them, UL 2900-2-1, is used with UL 2900-1, which adds $402. The regulators' own guidance is free.

Table 13. What the standards cost (individual electronic/PDF list prices, October 9, 2026)
StandardPagesPrice
IEC 81001-5-1:2021114CHF 335
ANSI/AAMI SW96:202361$298
AAMI TIR57:2016/(R)202384$345
AAMI TIR97:2019/(R)202356$298
UL 2900-1 (Edition 2)Not verified from UL$402
UL 2900-2-1Not verified from UL$75
ANSI/ISA-62443-4-1-201866$270
IEC TR 60601-4-5:202151CHF 335
IEC 80001-1:202175CHF 260
ISO 14971:201936CHF 196
IEC 62304:2006+AMD1:2015170CHF 1,150
ANSI/NEMA HN 1-2019 (MDS2 form)36$103
Regulator guidance; CVSS; NIST Cybersecurity Framework—Free

Source: publisher stores (IEC, AAMI, UL, ISA, ISO, NEMA), checked October 9, 2026. UL page counts were not verified from UL and are omitted. IEC prices shown are for the selected one-user PDF. AAMI prices are electronic listings; their single-user terms were not verified. ISO lists PDF plus ePub; ISA and NEMA list PDF. Prices exclude tax, fees, subscriptions, bundles and discounts.

The math: $298 + $345 + $298 + $75 = $1,016. CHF 335 at 0.8293 francs per dollar (Federal Reserve rate for October 2, 2026) is $403.96. Together that's an estimated $1,419.96. Adding UL 2900-1 at its separate $402 list price brings it to $1,821.96. These are individual list-price totals, not the lowest bundle prices. That's about the price of a good laptop, before anyone has read a page.

What do the numbers about device security really measure?

We traced six often-quoted numbers about medical device security. Five came from security vendors or from reports they co-wrote, not from regulators. The 53% figure is often credited to the FBI, but the vendor Cynerio published it in January 2022. For the sixth number, which is credited to the FDA, we found no FDA source.

Table 14. Six repeated statistics, traced to their sources
Figure as repeatedSource we traced it toWhat to know
53% of connected medical and other IoT devices in Cynerio's hospital data had a known critical vulnerabilityCynerio, January 19, 2022Data "collected from current Cynerio implementations": more than 10 million IoT and medical devices at more than 300 hospitals and other facilities. The FBI repeated it on September 12, 2022
Claimed average: 6.2 vulnerabilities per medical deviceSensato blog post, February 7, 2018No sample or method published. Do not cite this as a reproducible device average
993 vulnerabilities in 966 healthcare products, up 59%Health-ISAC with Finite State and Securin, August 2023Public-disclosure review across 117 vendors, including hardware, operating systems and software. The report's 2022 comparison count was 624. (993 − 624) ÷ 624 rounds to 59%.
IoMT devices with known exploited vulnerabilities at 99% of the 351 organizations studied; in 9% of their IoMT devicesClaroty Team82, March 26, 2025The sample includes over 2.25 million IoMT (Internet of Medical Things) devices. Claroty does not say how the organizations were chosen. These are vulnerability figures, not attack rates
22% in 2025 reported attacks directly affecting devices; 24% in 2026 reported attacks or exploited vulnerabilities involving devicesRunSafe Security releases: 605 healthcare executives (2025); 551 healthcare professionals (2026), in the US, UK and GermanySurvey self-reports. The releases use different event wording, so this is not a like-for-like trend. The 2026 introduction says attacks; its key findings also include exploited vulnerabilities
Unsupported claim: "FDA estimates 164 of every 1,000 devices remain vulnerable"We found no supporting FDA sourceA located repetition cites an incomplete supposed 2017 FDA guidance reference, with no data or method. Do not cite this as an FDA finding

Source: repeated-statistics-traced.csv (links to the sources traced), checked October 9, 2026.

The U.S. cybersecurity agency, CISA, publishes security advisories about medical devices and the systems that support them. Advisories are disclosures of flaws, not attacks. CISA put out 24 medical device advisories whose ID carries the year 2025. That equals the 2020 count and is below the 2018 high of 31. The low since 2017 was 10, with a 2023 ID.

Table 15. CISA medical device advisories (ICS Medical Advisories) by year in the advisory ID
Year in advisory IDAdvisoriesNote
20164Part year: first advisory 2016-03-29
201716—
201831—
201920—
202024—
202119—
202215—
202310CISA's release-year filter returns 11; this table uses the ID year
202413—
202524—
202615To 2026-10-09 (latest ICSMA-26-253-02)
Total191

Source: The PenTest Index count of CISA ICS Medical Advisories (191 in all), checked October 9, 2026. We counted 188 unique ICSMA records in CISA's pinned CSAF repository and added 3 legacy advisories from CISA's website that are missing from the repository. Those 191 records match the live listing. Each advisory is counted once, by the year in its ID; all records are in the source CSV.

Bar chart of CISA medical device security advisories by the year in each advisory ID, 2016 to 2026. The count peaked at 31 with a 2018 ID, fell to 10 with a 2023 ID and was 24 with a 2025 ID.
Source: The PenTest Index count of CISA ICS Medical Advisories by advisory ID year, checked October 9, 2026. Includes medical devices and systems that support them. 191 advisories in total. Advisories are disclosures, not attacks.Download PNG

Download Chart 3 as SVG

In December 2023, the U.S. Government Accountability Office wrote: "Although cyber incidents impacting medical devices have occurred, they are not common." That assessment predates the 2025 and 2026 surveys.

Why this matters now

The rules are moving on several fronts at once. FDA revised its premarket guidance on February 3, 2026. FDA's window for declarations of conformity to CVSS v3.0 closes on December 20, 2026, 72 days after our check. The EU and the UK both have new rules pending.

Table 16. What's coming (dates shown by each body on October 9, 2026)
ChangeDate shownSource
End of FDA's window for declarations of conformity to CVSS v3.0December 20, 2026FDA record 13-116
Great Britain: draft device regulations and planned MHRA cybersecurity guidanceDraft notified May 8, 2026. Government says further details of the cybersecurity guidance work will be shared by Spring 2027WTO draft; MHRA notice (May 11, 2026); UK government response (October 6, 2026), recommendation 10
EU proposal: report actively exploited vulnerabilities and severe incidents within 30 days of awareness; existing serious-incident duties still applyProposed December 16, 2025; awaiting committee decision at this checkCOM(2025) 1023, proposed Article 87a; Parliament procedure 2025/0404(COD)
Australia: Essential Principles reform"implementation anticipated in 2027"TGA consultation page (updated September 22, 2026)
ISO 81001-5-2, security risk management for manufacturersCommittee draft; no publication date stated on the reviewed ISO recordISO/CD 81001-5-2 project record
Standards-body adoption of a standard based on IEC 81001-5-1 for the EU requestAdoption deadline May 27, 2028; not a guaranteed harmonisation dateC(2024) 3371, Annex I, Table 2, entry 50
IEC 62443-4-1 Edition 2Forecast April 2028IEC project page
IEC 81001-5-1 Edition 2Forecast August 2028IEC project page
IEC 62304 Edition 2Forecast October 2028IEC project page
IMDRF: baseline cybersecurity controls and testingWork item approved September 2025; no draft linked on the working-group page at this checkIMDRF 28th Session Outcome Statement; current working-group page

Source: as listed in each row; forecast dates move. Checked October 9, 2026.

How we built this

We checked the sources on October 9, 2026. The download records the source and check date for each result.

  • FDA's database. We ran five keyword searches ("security," "cybersecurity," "cyber," "vulnerability," "threat"), which returned 97 different records. We then downloaded all 1,738 records and selected titles containing "security" (including "cybersecurity") or a vulnerability term. The case-insensitive rule security|vulnerabilit returns 24. The same title rule on the 31 results for "524B" returns the same 24. We opened all 24 detail pages and checked the title, entry date, recognition scope and warning. The download includes the full 1,738-row denominator and the 31-record check.
  • 11 jurisdictions. We searched the specified official guidance, software documents, standards lists and voluntary-scheme documents recorded in the source manifest. We checked 31 standards and frameworks against these sets: 341 cells. National adoptions count where their identity was verified. A whole-series mention does not count for a specific part. The long CSV gives the document, source, match or absence and note for every cell. The sets differ by jurisdiction; this is a document comparison, not a ranking of legal strictness.
  • 17 legal and regulatory texts. We searched the full specified versions for penetration-testing terms or local-language equivalents, with the exact terms and sources in the download. This includes the current Great Britain regulations, one Great Britain draft and the Korean notification named in Table 6. The Brazilian resolutions are their original published texts, and the Saudi requirements are the specified v6 text. This is not a search of every later amendment. A zero word count does not establish that testing is unnecessary under broader duties.
  • Publisher catalogs and previews. We checked editions, withdrawals, formats, page counts and prices on primary publisher pages. For penetration-testing coverage, the two IEC/ISA rows have public contents clauses; the two UL rows have an official publisher explanation. We did not buy or review the complete paid standards.
  • Guidance versions. We read the current FDA PDF and archived official 2023 and 2025 PDFs. We compared the penetration-testing paragraph and five report elements, not the whole testing section. The comparison file records those exact passages and source hashes.
  • CISA. We counted 188 unique ICSMA advisory IDs in the pinned official CSAF repository and checked all 188 files against their Git blob hashes. We added three legacy medical advisories from CISA's own website that the repository omits. The 191-row source file reproduces every annual total by the year in the ID.
  • Repeated statistics. We traced the six claims to the original reports or releases we could read. We recomputed the Health-ISAC increase from its published counts. The vendors do not publish the underlying observations or survey responses needed to recalculate their percentages. Sensato's average and the alleged FDA estimate are labeled unusable as supported device statistics.
  • Final checks. We recalculated our own totals, derived percentages, date gaps, price sums, matrix subsets and chart values from the delivered files. We checked that the finder rules, tables, chart specs and datasets agree. The calculation snapshot and reproduction script record those checks.

For how The PenTest Index checks sources and dates across the site, see How It Works.

What this data does and does not show

This data shows what official documents say on one date. It does not show how reviewers apply them, and it doesn't decide which rules apply to a specific product.

  • "24" is our count by our rule: security, cybersecurity or a vulnerability term in the title. FDA publishes no such count.
  • The 24 records are 22 different standards. FDA accepts declarations of conformity to CVSS v3.0 only until December 20, 2026.
  • FDA's caution sits on 31 records in all, not only the 24.
  • "Named" does not mean "required." A mention of a whole series is not counted for any one part.
  • We did not search the same kinds of document for every regulator. A regulator may name a standard somewhere we did not look.
  • General cybersecurity laws, such as the EU's NIS2 Directive, are outside the country matrix.
  • For paid standards we read public publisher catalog text and available previews, not the full paid text. UL coverage rests on its own explanation; unverified UL section numbers and page counts are omitted.
  • Japanese, Korean, Chinese and Portuguese documents were read in the original. English wording for them is our translation unless an official English version exists.
  • The legal search covers 17 specified legal and regulatory texts, including one Great Britain draft. The Brazilian resolutions are their original published texts; the Saudi requirements are the specified v6 text. The search is not a complete, consolidated inventory of all current rules or later amendments.
  • Prices are individual electronic/PDF publisher list prices on the check date. Formats and verified user terms are listed in the price CSV. The USD conversion is an estimate at the stated exchange rate.
  • The CISA count goes by the year in each advisory ID. 2016 and 2026 are part years. An advisory is not a count of attacks, unique vulnerabilities or affected devices.
  • Third-party percentages are reported results, not estimates of the whole medical-device market. Their raw observations and survey responses are not public. The RunSafe releases were read; their full reports and questionnaires were not accessed.
  • "Current edition" compares edition or version labels. It does not say FDA recognizes every later revision, correction or interpretation in the publisher's current file.

How to cite this page

The PenTest Index. "Medical device cybersecurity standards: the 24 FDA records and what 11 regulators name." Updated October 9, 2026. https://thepentestindex.com/research/medical-device-cybersecurity-standards/

You may reuse The PenTest Index's original compilation, counts and charts with credit to The PenTest Index by name; no link is required. Third-party titles, clause names, quotes and source material keep their own rights, attribution and terms. This permission covers only our contribution.

Download the data

Download all files: medical-device-cybersecurity-standards-data.zip (17 CSV files, a read-me and reproducible calculations). No form, no email. Every row carries its source and check date. The files contain our compilation, not copies of any standard.

fda-recognized-security-standards.csv — The 24 security standard records the FDA recognizes (24 rows).

standards.csv — The 31 standards and frameworks behind the Standards finder (31 rows).

regulator-standard-matrix-wide.csv — 31 standards by 11 regulators, one row per standard (31 rows; 341 cells).

regulator-standard-matrix.csv — The same 341 cells in long form, one row per cell, with the documents searched for each regulator (341 rows).

regulators.csv — The 11 regulators: binding rule, guidance, what each does with standards, penetration testing wording (11 rows).

penetration-testing-wording.csv — Penetration testing wording in guidance, plus the 17 legal and regulatory texts searched (32 rows).

fda-cybersecurity-guidance-timeline.csv — FDA's main premarket and postmarket cybersecurity guidance since 2005 (11 rows).

cisa-medical-advisories-by-year.csv — CISA ICS medical advisories by year in the advisory ID (11 rows).

repeated-statistics-traced.csv — Six often-repeated statistics traced to their sources (6 rows).

Source files for reproducing the counts

The data ZIP also includes calculation-snapshot.json, the FDA paragraph comparison, the pinned CISA snapshot, the legal-search method, reproduce.py and rebuild_charts.py. These files reproduce the stated selection rules and arithmetic; they do not contain full paid standards.

Questions people ask

What is the FDA's cybersecurity guidance for medical devices in 2026?

The FDA's current premarket guidance is "Cybersecurity in Medical Devices: Quality Management System Considerations and Content of Premarket Submissions," dated February 3, 2026. It revises the June 27, 2025 version. A separate guidance from December 28, 2016 covers devices already on the market.

What is a cyber device per FDA?

A cyber device meets 3 tests in section 524B. It includes software validated, installed or authorized by the sponsor; it can connect to the internet; and it has features validated, installed or authorized by the sponsor that could be open to cybersecurity threats. FDA includes USB and other hardware ports when they can connect to the internet; Bluetooth and Wi-Fi are also listed.

Does the FDA recognize cybersecurity standards?

The FDA does recognize cybersecurity standards. As of October 9, 2026, its database has 24 recognition records covering 22 distinct standards with security, cybersecurity or a vulnerability term in the title, by our count. They include IEC 81001-5-1, ANSI/AAMI SW96, AAMI TIR57, AAMI TIR97 and UL 2900-2-1. Each carries an FDA note that meeting it may not satisfy section 524B.

Does the FDA require cybersecurity details in medical device submissions?

The law has required cybersecurity details in covered submissions for cyber devices since March 29, 2023. It sets 4 requirements: a plan to address vulnerabilities and coordinate disclosure; processes that give reasonable assurance of security, with updates and patches; a software bill of materials; and anything more FDA requires by regulation.

What is FDA 510(k) penetration testing?

A 510(k) is one kind of FDA submission. Penetration testing is one of 4 kinds of security testing FDA's guidance lists "among others." FDA says the test report should cover 5 things: how independent and skilled the testers were, the scope, how long testing took, the methods, and the findings.

What is the difference between ISO 13485 and ISO 14971?

ISO 13485 is the quality management system standard. ISO 14971 is the risk management standard. Neither is a cybersecurity standard. All 11 regulators we checked name both.

Is IEC 81001-5-1 required by the FDA?

The FDA does not require IEC 81001-5-1. It has recognized it since December 19, 2022 (record 13-122), and using it is voluntary. FDA's guidance lists it among "Possible frameworks to consider." Japan is where we found a rule to attach proof of meeting its Japanese twin, JIS T 81001-5-1, for covered Class II, III and IV devices that use software and exchange data with other devices, networks or external media.

What is AAMI TIR57?

AAMI TIR57 is a technical report on security risk management for medical devices. The FDA has recognized it since June 27, 2016 (record 13-83). It is named by 8 of the 11 regulators we checked, counting Singapore's voluntary label scheme.

Is IEC 81001-5-1 harmonised under the EU MDR?

IEC 81001-5-1 is not harmonised under the EU's Medical Device Regulation. It is not among the 70 entries on the EU's harmonised list as of June 17, 2026. The standards bodies' adoption deadline for a standard based on it is May 27, 2028; that is not a promised harmonisation date.

Is ISO 27001 enough for a medical device?

ISO/IEC 27001 is not enough by itself for a medical device. It covers how a company manages information security, not how a product is built. It is not in FDA's recognized database, and 4 of the 11 regulators we checked name it.

Does a device with no network connection still need cybersecurity work?

A device with no network connection can still fall under FDA's cybersecurity guidance. The guidance applies to "devices with cybersecurity considerations" and is "not limited to devices that are network-enabled." The law's stricter "cyber device" rules apply only to devices that meet its 3 tests.

Does the FDA require an ISO 13485 certificate?

The FDA does not require an ISO 13485 certificate. Since February 2, 2026, its Quality Management System Regulation incorporates ISO 13485:2016, but FDA says it "will not require certificates of conformance to ISO 13485."

Sources

Every source was checked on October 9, 2026.

  1. FDA, Recognized Consensus Standards: Medical Devices (database; "Page Last Updated: 09/28/2026"). https://www.accessdata.fda.gov/scripts/cdrh/cfdocs/cfStandards/search.cfm. Checked October 9, 2026.

  2. FDA database, keyword search "524B" (31 results). https://www.accessdata.fda.gov/scripts/cdrh/cfdocs/cfStandards/results.cfm?title=524B. Checked October 9, 2026.

  3. FDA record 13-122, IEC 81001-5-1. https://www.accessdata.fda.gov/scripts/cdrh/cfdocs/cfStandards/detail.cfm?standard__identification_no=43889. Checked October 9, 2026.

  4. FDA record 13-117, IEEE 11073-40101-2020 (partial recognition). https://www.accessdata.fda.gov/scripts/cdrh/cfdocs/cfStandards/detail.cfm?standard__identification_no=42310. Checked October 9, 2026.

  5. FDA record 13-116, CVSS v3.0 (transition note). https://www.accessdata.fda.gov/scripts/cdrh/cfdocs/cfStandards/detail.cfm?standard__identification_no=46348. Checked October 9, 2026.

  6. FDA record 13-142, CVSS v3.1 (transition note). https://www.accessdata.fda.gov/scripts/cdrh/cfdocs/cfStandards/detail.cfm?standard__identification_no=47095. Checked October 9, 2026.

  7. FDA record 13-38, IEC 80001-1 Edition 1.0. https://www.accessdata.fda.gov/scripts/cdrh/cfdocs/cfStandards/detail.cfm?standard__identification_no=37083. Checked October 9, 2026.

  8. FDA record 5-125, ISO 14971:2019. https://www.accessdata.fda.gov/scripts/cdrh/cfdocs/cfStandards/detail.cfm?standard__identification_no=41349. Checked October 9, 2026.

  9. FDA record 13-79, IEC 62304 Edition 1.1. https://www.accessdata.fda.gov/scripts/cdrh/cfdocs/cfStandards/detail.cfm?standard__identification_no=38829. Checked October 9, 2026.

  10. FDA, Non-Recognized Standards table. https://www.accessdata.fda.gov/scripts/cdrh/cfdocs/cfStandards/nr_results.cfm. Checked October 9, 2026.

  11. FDA, Division of Standards and Conformity Assessment (what recognition means). https://www.fda.gov/medical-devices/premarket-submissions-selecting-and-preparing-correct-submission/division-standards-and-conformity-assessment. Checked October 9, 2026.

  12. Federal Register, FDA Recognition List Number 066, 91 FR 54715 (August 24, 2026). https://www.govinfo.gov/content/pkg/FR-2026-08-24/html/2026-17229.htm. Checked October 9, 2026.

  13. Public Law 117-328, section 3305 (FD&C Act section 524B; 21 U.S.C. 360n-2). https://www.govinfo.gov/content/pkg/PLAW-117publ328/html/PLAW-117publ328.htm. Checked October 9, 2026.

  14. FDA, Cybersecurity in Medical Devices: Quality Management System Considerations and Content of Premarket Submissions (February 3, 2026), guidance page. https://www.fda.gov/regulatory-information/search-fda-guidance-documents/cybersecurity-medical-devices-quality-management-system-considerations-and-content-premarket. Checked October 9, 2026.

  15. FDA, same guidance, PDF (Sections II, V.C, VII; footnotes 48 and 52). https://www.fda.gov/media/119933/download. Checked October 9, 2026.

  16. FDA, Postmarket Management of Cybersecurity in Medical Devices (December 28, 2016). https://www.fda.gov/media/95862/download. Checked October 9, 2026.

  17. FDA, Quality Management System Regulation: Frequently Asked Questions. https://www.fda.gov/medical-devices/quality-management-system-regulation-qmsr/quality-management-system-regulation-frequently-asked-questions. Checked October 9, 2026.

  18. FDA, Withdrawn or Expired Guidance. https://www.fda.gov/medical-devices/guidance-documents-medical-devices-and-radiation-emitting-products/withdrawn-or-expired-guidance. Checked October 9, 2026.

  19. Federal Register, FDA guidance notices: 78 FR 35940; 79 FR 59493; 81 FR 3803; 81 FR 95617; 83 FR 52835; 87 FR 20873; 88 FR 19148; 88 FR 66458; 89 FR 18421; 90 FR 27634 (links in fda-cybersecurity-guidance-timeline.csv). https://www.federalregister.gov/citation/88-FR-19148. Checked October 9, 2026.

  20. Regulation (EU) 2017/745 (MDR), consolidated July 19, 2026. https://op.europa.eu/o/opportal-service/download-handler?identifier=e56fc708-95ab-11f1-9262-01aa75ed71a1&format=pdfa2a&language=en&productionSystem=cellar&part=. Checked October 9, 2026.

  21. Regulation (EU) 2017/746 (IVDR), consolidated January 10, 2025. https://op.europa.eu/o/opportal-service/download-handler?identifier=bb7d3f94-cd06-11ef-be2a-01aa75ed71a1&format=pdfa2a&language=en&productionSystem=cellar&part=. Checked October 9, 2026.

  22. Commission Implementing Decision (EU) 2021/1182, consolidated June 17, 2026 (harmonised standards under the MDR). https://op.europa.eu/o/opportal-service/download-handler?identifier=a74b24b7-74b8-11f1-bf5e-01aa75ed71a1&format=pdfa2a&language=en&productionSystem=cellar&part=. Checked October 9, 2026.

  23. European Commission, standardisation request M/575 and amendment C(2024) 3371. https://ec.europa.eu/growth/tools-databases/enorm/mandate/575_en. Checked October 9, 2026.

  24. MDCG 2019-16 Rev.1, Guidance on Cybersecurity for medical devices. https://health.ec.europa.eu/document/download/b23b362f-8a56-434c-922a-5b3ca4d0a7a1_en?filename=md_cybersecurity_en.pdf. Checked October 9, 2026.

  25. IG-NB, Questionnaire "Cybersecurity for Medical Devices - Audit", version 2 (February 25, 2025). https://www.ig-nb.de/fileadmin/user_upload/ig-nb/2025_Questionnaire_Cybersecurity_for_Medical_Devices_-Audit-_Version_2.pdf. Checked October 9, 2026.

  26. Team-NB, Position Paper on Cyber Security (October 5, 2022). https://www.team-nb.org/wp-content/uploads/members/M2022/Team-NB-PositionPaper-CyberSecurity-V1-20221005.pdf. Checked October 9, 2026.

  27. European Commission, COM(2025) 1023 (December 16, 2025). https://www.europarl.europa.eu/RegData/docs_autres_institutions/commission_europeenne/com/2025/1023/COM_COM%282025%291023_EN.pdf. Checked October 9, 2026.

  28. Directive (EU) 2022/2555 (NIS2), recital 58. https://eur-lex.europa.eu/legal-content/EN/ALL/?uri=CELEX:32022L2555. Checked October 9, 2026.

  29. Japan MHLW, Notification PSEHB/MDED No. 0331-8 (March 31, 2023), provisional English translation. https://www.mhlw.go.jp/content/11120000/001203128.pdf. Checked October 9, 2026.

  30. Japan MHLW, medical device cybersecurity page (manufacturer guide; Q&A of January 31, 2024). https://www.mhlw.go.jp/stf/seisakunitsuite/bunya/0000179749_00009.html. Checked October 9, 2026.

  31. PMDA, Basic concept for medical device regulation in Japan (device classes). https://www.std.pmda.go.jp/scripts/stdDB_en/refetc/stdDB_refetc_sum_absbttm.cgi?absdisp=1. Checked October 9, 2026.

  32. Japanese Standards Association, JIS T 81001-5-1:2023 record. https://webdesk.jsa.or.jp/books/W11M0090/index/?bunsyo_id=JIS+T+81001-5-1%3A2023. Checked October 9, 2026.

  33. Health Canada, Pre-market Requirements for Medical Device Cybersecurity (2019). https://www.canada.ca/en/health-canada/services/drugs-health-products/medical-devices/application-information/guidance-documents/cybersecurity/document.html. Checked October 9, 2026.

  34. Canada, Medical Devices Regulations (SOR/98-282). https://laws-lois.justice.gc.ca/eng/regulations/SOR-98-282/FullText.html. Checked October 9, 2026.

  35. Australia TGA, Complying with medical device cyber security requirements. https://www.tga.gov.au/resources/guidance/complying-medical-device-cyber-security-requirements. Checked October 9, 2026.

  36. Australia TGA, Standards for software-based medical devices. https://www.tga.gov.au/products/medical-devices/software-and-artificial-intelligence-ai/overview/standards-software-based-medical-devices. Checked October 9, 2026.

  37. Australia TGA, Essential Principles consultation (results updated September 22, 2026). https://consultations.tga.gov.au/tga/aus-essential-principles-aligning-eu-regulation/. Checked October 9, 2026.

  38. UK, Designated standards: medical devices. https://www.gov.uk/government/publications/designated-standards-medical-devices. Checked October 9, 2026.

  39. UK, draft Medical Devices (Amendment) Regulations 2026, WTO notification. https://members.wto.org/crnattachments/2026/TBT/GBR/26_02425_00_e.pdf. Checked October 9, 2026.

  40. UK government response on the regulation of AI in healthcare (October 6, 2026). https://www.gov.uk/government/publications/government-response-to-the-national-commissions-recommendations-on-the-regulation-of-ai-in-healthcare. Checked October 9, 2026.

  41. Brazil ANVISA, Guia 38/2020. https://www.gov.br/anvisa/pt-br/assuntos/noticias-anvisa/2020/saiba-mais-sobre-ciberseguranca-em-dispositivos-medicos/guia-38.pdf/@@display-file/file. Checked October 9, 2026.

  42. Brazil ANVISA, RDC 848/2024. https://www.in.gov.br/en/web/dou/-/resolucao-da-diretoria-colegiada-rdc-n-848-de-6-de-marco-de-2024-547032236. Checked October 9, 2026.

  43. China CMDE, Guidelines for Registration Review of Medical Device Cybersecurity (2022 revision). https://www.cmde.org.cn/flfg/zdyz/zdyzwbk/20220309085900737.html. Checked October 9, 2026.

  44. South Korea MFDS, cybersecurity approval and review guideline (January 10, 2025). https://www.mfds.go.kr/brd/m_1060/view.do?seq=15625. Checked October 9, 2026.

  45. South Korea MFDS, companion guide (November 13, 2025). https://www.mfds.go.kr/brd/m_1060/view.do?seq=15757. Checked October 9, 2026.

  46. Singapore HSA, GL-04-R4 Regulatory Guidelines for Software Medical Devices (December 2025). https://isomer-user-content.by.gov.sg/409/26808a93-6a7a-4551-8c66-13046c6124c5/gl-04-r4-regulatory-guidelines-for-software-medical-devices---a-life-cycle-approach-(2025-dec)-pub.pdf. Checked October 9, 2026.

  47. Singapore CSA, Cybersecurity Labelling Scheme for Medical Devices. https://www.csa.gov.sg/our-programmes/certification-and-labelling-schemes/cls-md/about/. Checked October 9, 2026.

  48. Saudi SFDA, MDS-G38 (cybersecurity guidance, 2019). https://sfda.gov.sa/sites/default/files/2019-10/MDS-G38.pdf. Checked October 9, 2026.

  49. Saudi SFDA, MDS-G020 v3.0 recognised standards. https://www.sfda.gov.sa/en/guide/15903. Checked October 9, 2026.

  50. Saudi SFDA, MDS-G23 (software guidance reprinting IMDRF documents). https://www.sfda.gov.sa/sites/default/files/2020-03/MDS_G23.pdf. Checked October 9, 2026.

  51. IMDRF, Principles and Practices for Medical Device Cybersecurity (N60). https://www.imdrf.org/documents/principles-and-practices-medical-device-cybersecurity. Checked October 9, 2026.

  52. IMDRF, Outcome Statement of the 28th Session (September 2025). https://www.imdrf.org/sites/default/files/2025-09/Japan%20Sapporo%20Outcome%20Statement%20%2828th%20Session%29.pdf. Checked October 9, 2026.

  53. IEC Webstore, IEC 81001-5-1:2021 (corrected version 2025-12). https://webstore.iec.ch/en/publication/63293. Checked October 9, 2026.

  54. IEC Webstore, IEC 81001-5-1:2021/ISH1:2025. https://webstore.iec.ch/en/publication/108664. Checked October 9, 2026.

  55. IEC Webstore, IEC 62443-4-1:2018. https://webstore.iec.ch/en/publication/33615. Checked October 9, 2026.

  56. IEC Webstore, IEC 80001-1:2021 (Edition 2.0). https://webstore.iec.ch/en/publication/34263. Checked October 9, 2026.

  57. IEC Webstore, IEC TR 80001-2-2:2012 (withdrawn). https://webstore.iec.ch/en/publication/7484. Checked October 9, 2026.

  58. IEC Webstore, IEC TR 80001-2-8:2016 (withdrawn). https://webstore.iec.ch/en/publication/24908. Checked October 9, 2026.

  59. IEC Webstore, IEC TR 80001-2-9:2017 (withdrawn). https://webstore.iec.ch/en/publication/31953. Checked October 9, 2026.

  60. IEC Webstore, IEC TS 81001-2-2:2025. https://webstore.iec.ch/en/publication/78673. Checked October 9, 2026.

  61. ISO, ISO/IEC 29147:2018. https://www.iso.org/standard/72311.html. Checked October 9, 2026.

  62. ISO, ISO/IEC 30111:2019. https://www.iso.org/standard/69725.html. Checked October 9, 2026.

  63. ISO, ISO 14971:2019. https://www.iso.org/standard/72704.html. Checked October 9, 2026.

  64. AAMI, ANSI/AAMI SW96:2023 (list price). https://array.aami.org/doi/full/10.2345/9781570208621.ch1. Checked October 9, 2026.

  65. AAMI, AAMI TIR57:2016/(R)2023 (list price). https://array.aami.org/doi/full/10.2345/9781570206122.ch1. Checked October 9, 2026.

  66. AAMI, AAMI TIR97:2019/(R)2023 (list price). https://array.aami.org/doi/full/10.2345/9781570207259.ch1. Checked October 9, 2026.

  67. UL Standards & Engagement, UL 2900-1 Edition 2. https://www.shopulstandards.com/ProductDetail.aspx?productId=UL2900-1_2_S_20231213. Checked October 9, 2026.

  68. UL Standards & Engagement, UL 2900-2-1 Edition 1. https://www.shopulstandards.com/ProductDetail.aspx?productId=UL2900-2-1_1_S_20170901. Checked October 9, 2026.

  69. ISA, ANSI/ISA-62443-4-1-2018. https://www.isa.org/products/ansi-isa-62443-4-1-2018-security-for-industrial-au. Checked October 9, 2026.

  70. NEMA, ANSI/NEMA HN 1-2019 (MDS2). https://www.makeitelectric.store/us/view-details/manufacturer-disclosure-statement-for-medical-device-security. Checked October 9, 2026.

  71. CLSI, AUTO11. https://clsi.org/shop/standards/auto11/. Checked October 9, 2026.

  72. FIRST, Common Vulnerability Scoring System. https://www.first.org/cvss/. Checked October 9, 2026.

  73. Federal Reserve, H.10 Foreign Exchange Rates (release of October 5, 2026). https://www.federalreserve.gov/releases/h10/current/. Checked October 9, 2026.

  74. CISA, ICS Medical Advisories. https://www.cisa.gov/news-events/ics-advisories?f%5B0%5D=ics_advisory_type%3A96. Checked October 9, 2026.

  75. CISA, CSAF advisory repository. https://github.com/cisagov/CSAF. Checked October 9, 2026.

  76. Cynerio, research release of January 19, 2022 (archived). https://web.archive.org/web/20230207111704/https://www.cynerio.com/blog/cynerio-research-finds-critical-medical-device-risks-continue-to-threaten-hospital-security-and-patient-safety. Checked October 9, 2026.

  77. FBI, Private Industry Notification 20220912-001. https://www.ic3.gov/CSA/2022/220912.pdf. Checked October 9, 2026.

  78. Health-ISAC, Finite State and Securin, 2023 State of Cybersecurity for Medical Devices and Healthcare Systems. https://health-isac.org/2023-state-of-cybersecurity-for-medical-devices-and-healthcare-systems/. Checked October 9, 2026.

  79. Claroty, Team82 healthcare research release (March 26, 2025). https://claroty.com/press-releases/new-research-from-clarotys-team82-highlights-riskiest-medical-device-exposures-in-healthcare-environments. Checked October 9, 2026.

  80. RunSafe Security, Medical Device Cybersecurity Index 2026 release. https://runsafesecurity.com/press-releases/medical-device-cybersecurity-index-2026/. Checked October 9, 2026.

  81. U.S. Government Accountability Office, GAO-24-106683 (December 21, 2023). https://www.gao.gov/assets/gao-24-106683.pdf. Checked October 9, 2026.

  82. European Commission, harmonised-standards scope and current publications. https://health.ec.europa.eu/medical-devices-topics-interest/harmonised-standards_en. Checked October 9, 2026.

  83. European Commission, original M/575 request C(2021)2406. https://ec.europa.eu/transparency/documents-register/api/files/C%282021%292406_1/de00000001031154. Checked October 9, 2026.

  84. European Commission, M/575 amendment C(2024)3371. https://ec.europa.eu/transparency/documents-register/api/files/C%282024%293371_1/de00000001064396?rendition=false. Checked October 9, 2026.

  85. European Parliament, current procedure 2025/0404(COD). https://oeil.europarl.europa.eu/oeil/en/procedure-file?reference=2025%2F0404%28COD%29. Checked October 9, 2026.

  86. ISO, ISO/CD 81001-5-2 project record. https://www.iso.org/standard/90129.html. Checked October 9, 2026.

  87. IMDRF, current Medical Devices Cybersecurity Working Group. https://www.imdrf.org/working-groups/medical-devices-cybersecurity-working-group. Checked October 9, 2026.

  88. UL, official penetration-testing explanation. https://www.ul.com/insights/medical-device-cybersecurity-standards-and-services. Checked October 9, 2026.

  89. UL, Medical Device Cybersecurity Q&A. https://www.ul.com/resources/medical-device-cybersecurity-qa. Checked October 9, 2026.

  90. UL, UL 2900-2-1 Secure PDF list price. https://www.shopulstandards.com/PurchaseProduct.aspx?UniqueKey=33295. Checked October 9, 2026.

  91. UL, UL 2900-1 Secure PDF list price. https://www.shopulstandards.com/PurchaseProduct.aspx?UniqueKey=45541. Checked October 9, 2026.

  92. INCITS/ANSI, current national adoption ISO/IEC 30111:2019 (2024). https://webstore.ansi.org/standards/incits/incitsisoiec3011120192024. Checked October 9, 2026.

  93. Health-ISAC, full 2023 report. https://health-isac.org/wp-content/uploads/11883-StateMedSecurityReport_v6.pdf. Checked October 9, 2026.

  94. Claroty, full 2025 healthcare report. https://web-assets.claroty.com/resource-downloads/state-of-cps-security-healthcare-2025.pdf. Checked October 9, 2026.

  95. Sensato, February 7, 2018 claim source. https://www.sensato.co/post/endless-terrifying-possibilities-call-for-a-good-medical-device-cop. Checked October 9, 2026.

  96. RunSafe, 2025 release. https://runsafesecurity.com/press-releases/2025-medical-device-cybersecurity-index/. Checked October 9, 2026.

  97. FDA, archived September 2023 PDF. https://web.archive.org/web/20230926162534id_/https://www.fda.gov/media/119933/download. Checked October 9, 2026.

  98. FDA, archived June 2025 PDF. https://web.archive.org/web/20250627223421id_/https://www.fda.gov/media/119933/download. Checked October 9, 2026.

  99. UK, Medical Devices Regulations 2002 (SI 2002/618), revised text. https://www.legislation.gov.uk/uksi/2002/618/data.xht?view=snippet&wrap=true. Checked October 9, 2026.

  100. South Korea, Digital Medical Products Act, Act No. 21525, effective October 8, 2026. https://www.law.go.kr/LSW/lsInfoR.do?lsiSeq=285333&efYd=20261008&chrClsCd=010202. Checked October 9, 2026.

  101. South Korea MFDS, Notification 2025-30, effective April 29, 2025. https://www.law.go.kr/LSW/admRulLsInfoR.do?admRulSeq=2100000258410. Checked October 9, 2026.

  102. South Korea MFDS, software-validation guideline 0095-02, July 28, 2026, PDF page 192. https://www.mfds.go.kr/brd/m_1060/down.do?brd_id=data0011&seq=15895&data_tp=A&file_seq=2. Checked October 9, 2026.

  103. Saudi SFDA, MDS-REQ1 v6, Requirements for Medical Devices Marketing Authorization. https://www.sfda.gov.sa/sites/default/files/2021-12/REQ1En_0.pdf. Checked October 9, 2026.

  104. China SAMR, primary mapping for YY/T 0664-2020 to IEC 62304:2015 (modified adoption). https://std.samr.gov.cn/dcpspTools/gbPlan/download?path=%2Fzxd%2F2021002339%2F20_%E6%A0%87%E5%87%86%E8%B5%B7%E8%8D%89%2F20_WD_2021002339_%E6%89%8B%E6%9C%AF%E6%A4%8D%E5%85%A5%E7%89%A9+%E6%9C%89%E6%BA%90%E6%A4%8D%E5%85%A5%E5%BC%8F%E5%8C%BB%E7%96%97%E5%99%A8%E6%A2%B0+%E7%AC%AC1%E9%83%A8%E5%88%86.pdf. Checked October 9, 2026.

  105. China SAMR, GB/T 22080-2016 adoption and withdrawal record. https://std.samr.gov.cn/gb/search/gbDetailedCNF?id=71F772D812CCD3A7E05397BE0A0AB82A. Checked October 9, 2026.

The PenTest Index Research is the research and reference section of thepentestindex.com.