Research · Medical device cybersecurity
Medical device cybersecurity standards: the 24 FDA records and what 11 regulators name
24 FDA recognition records cover 22 distinct standards with security or a vulnerability term in the title. Medical device cybersecurity standards are a set, not one rulebook. The PenTest Index found the same FDA warning on all 24: meeting one "may not satisfy all the cybersecurity requirements outlined in Section 524B," the U.S. device cybersecurity law. So which ones matter?
See the 24 records and their sources · Download the source CSV · Repeat the count
Key medical device cybersecurity standards statistics
- 24 FDA recognition records cover 22 distinct security standards. The FDA database has 24 records whose title names security, cybersecurity or a vulnerability term. That is 22 different standards, because one scoring system (CVSS) is listed in three versions. It is also 24 of the 1,738 records in FDA's database, or 1.4%. (The PenTest Index count of FDA's Recognized Consensus Standards database, October 9, 2026.) Source data.
- The same caution on all 24. All 24 selected recognition records carry an FDA note saying conformance "may not satisfy all the cybersecurity requirements outlined in Section 524B." In plain words, meeting the standard may not be enough to meet the law. (FDA database records; The PenTest Index count, October 9, 2026.) FDA record example.
- 8 of 22 list a replaced or withdrawn edition. For 8 of the 22 different security standards the FDA recognizes, the edition FDA lists has since been replaced or withdrawn by its publisher. (The PenTest Index comparison of FDA's database with IEC, ISO, UL and CLSI catalogs, October 9, 2026.) Edition sources.
- 0 standards named in the law. Section 524B of the Federal Food, Drug, and Cosmetic Act, the U.S. law on medical device cybersecurity, names no standard. It sets 4 requirements for "cyber devices" and has applied to covered FDA submissions for cyber devices since March 29, 2023. (Public Law 117-328, section 3305.) Law.
- 3 versions in 860 days. The FDA has issued 3 versions of its final premarket cybersecurity guidance in 860 days: September 27, 2023; June 27, 2025; and February 3, 2026. FDA calls the third a revision. The version before them stood for 3,282 days, about 9 years. (Federal Register; FDA.) Dated sources.
- No security standard above 8 of 11 regulators. None of the 25 security standards The PenTest Index checked is named by more than 8 of 11 medical device regulators. IEC 81001-5-1, AAMI TIR57 and CVSS each reach 8. All 11 name three general standards: ISO 14971, IEC 62304 and ISO 13485. ("Named" means the number or name appears in the documents searched, not that it is required. AAMI TIR57's eighth is Singapore's voluntary label scheme. The PenTest Index review, October 9, 2026.) Cell sources.
- Japan requires evidence for covered Class II, III and IV devices. Since April 1, 2024, applications for those devices must attach data showing conformance to JIS T 81001-5-1 "etc." The rule covers devices that use software and exchange data with other devices, networks or external media. Other standards, such as IEC 81001-5-1, may be used with an explanation. (Japan MHLW notification PSEHB/MDED No. 0331-8.) MHLW notification.
- 10 of 11 jurisdictions mention penetration testing in the official device-guidance sets reviewed. None of the 17 specified legal and regulatory texts contains the searched penetration-testing terms. The search covered English and local-language terms and included one Great Britain draft. A word search does not decide what testing the law requires. (The PenTest Index text search, October 9, 2026.) Text-search sources.
Which cybersecurity standards apply to medical devices?
No single standard covers medical device cybersecurity. Our short list has five standards covering four jobs (risk gets two): IEC 81001-5-1, ANSI/AAMI SW96, AAMI TIR57, AAMI TIR97 and UL 2900-2-1. All five are on the FDA's recognized list as of October 9, 2026.
"Recognized" means a maker can submit a signed statement that the device meets the recognized parts of that standard, within FDA's stated scope. That statement is called a declaration of conformity. In FDA's words, "conformance is voluntary, unless a standard is 'incorporated by reference' into regulation." Think of a teacher saying "you may show your work this way." You may. You don't have to.
| Job | Standard | FDA recognition no. | Named by (of 11 regulators) | List price (electronic/PDF) |
|---|---|---|---|---|
| Build software securely | IEC 81001-5-1:2021 | 13-122 | 8 | CHF 335 |
| Manage security risk (requirements) | ANSI/AAMI SW96:2023 | 13-131 | 3 | $298 |
| Manage security risk (guidance) | AAMI TIR57:2016/(R)2023 | 13-83 | 8* | $345 |
| Keep it secure after launch | AAMI TIR97:2019/(R)2023 | 13-112 | 6 | $298 |
| Test the product | UL 2900-2-1 (used with UL 2900-1) | 13-104 | 6 | $75 (UL 2900-1 adds $402) |
Source: FDA Recognized Consensus Standards database; publisher stores (IEC, AAMI, UL); The PenTest Index review of 11 regulators. All checked October 9, 2026. *AAMI TIR57's eighth regulator is Singapore's voluntary label scheme, not its regulator's own guidance.
The short list is our pick. The rule: security standards written for health care, recognized by the FDA, one per job, except risk, which gets a requirements standard (SW96) and a guidance report (TIR57).
Picture a connected insulin pump. IEC 81001-5-1 covers how the team writes and updates the pump's software. SW96 and TIR57 cover how the team finds and ranks what could go wrong. UL 2900-2-1 covers how a lab attacks the finished pump. TIR97 covers what happens when a flaw turns up three years after launch.
Three more standards show up on nearly every list: ISO 14971 (risk management), IEC 62304 (software life cycle) and ISO 13485 (quality management system). All 11 regulators we checked name all three. None of the three is a security standard, but security work plugs into them.
Standards finder
Pick your market, your job, or your device type, and the table below narrows to matching entries in our review. Every row shows the FDA recognition number, how many of the 11 regulators name it, and a note on its edition. The finder works on the same 31 rows as our download, and the full table stays readable without it.
Find matching standards
Filters narrow this review; they do not decide which rules or standards apply to a particular device.
Loading standards…
The PenTest Index. "Medical device cybersecurity standards: the 24 FDA records and what 11 regulators name." Updated October 9, 2026. https://thepentestindex.com/research/medical-device-cybersecurity-standards/
| Standard | Job | FDA recognition | Named by | Edition note | Electronic/PDF price | Penetration-testing evidence |
|---|
Source: standards.csv and regulators.csv. Each result retains its source and check date in the downloadable CSV.
| Standard | Job (our classification) | FDA recognition no. | Named by (of 11) | Edition or FDA note |
|---|---|---|---|---|
| ISO 14971 (risk management) † | Assess risk | 5-125 | 11 | — |
| IEC 62304 (software life cycle) † | Build | 13-79 | 11 | — |
| ISO 13485 (quality management system) † | Run the company | Not in FDA database | 11 | Not in FDA's database; binds through the Quality Management System Regulation (from 2026-02-02) |
| IEC 81001-5-1 (secure health software life cycle) | Build | 13-122 | 8 | Edition 1.0 remains current; IEC corrected its copy in December 2025 and includes Interpretation Sheet 1; FDA record does not mention that sheet |
| AAMI TIR57 (security risk management) | Assess risk | 13-83 | 8 | — |
| CVSS (vulnerability scoring) | After launch | 13-116; 13-142; 13-140 | 8 | Three versions listed; v3.0 accepted until 2026-12-20, v3.1 until 2028-07-02 |
| IEC 80001-1 (risk management for hospital IT networks) † | Run a hospital network | 13-38 | 8 | FDA lists Edition 1.0 (2010); IEC's current edition is 2.0 (2021-09-21) |
| ISO/IEC 29147 (vulnerability disclosure) | After launch | 13-77 | 7 | FDA lists the 2014 edition; ISO's current edition is 2018 |
| ANSI/NEMA HN 1 (MDS2 security disclosure form) | Tell buyers | 13-123 | 7 | — |
| AAMI TIR97 (postmarket security risk) | After launch | 13-112 | 6 | — |
| UL 2900-1 (security testing, general) | Test | 13-96 | 6 | FDA lists the 2017 first edition; UL's current edition is 2 (2023-12-13) |
| UL 2900-2-1 (security testing, healthcare systems) | Test | 13-104 | 6 | Used with UL 2900-1 |
| IEC TR 80001-2-2 (disclosing security needs and controls) | Tell buyers | 13-42 | 6 | Withdrawn by IEC 2025-10-01; replaced by IEC TS 81001-2-2:2025 |
| ISO/IEC 30111 (vulnerability handling) | After launch | 13-78 | 6 | FDA lists INCITS/ISO/IEC 30111:2013 (R2019); the current national adoption is INCITS/ISO/IEC 30111:2019 (2024), based on ISO/IEC 30111:2019 |
| NIST Cybersecurity Framework ‡ | Run the company | Not in FDA database | 6 | Not in FDA's database (NIST is not one of its standards organizations) |
| IEC 82304-1 (health software product safety) † | Build — Health software with no hardware | 13-97 | 5 | — |
| IEC TR 80001-2-8 (standards for security capabilities) | Tell buyers | 13-102 | 5 | Withdrawn by IEC 2025-10-01; replaced by IEC TS 81001-2-2:2025 |
| ISO/IEC 27001 (organization security management) | Run the company | Not in FDA database | 4 | Not in FDA's database |
| ANSI/AAMI SW96 (security risk management requirements) | Assess risk | 13-131 | 3 | — |
| IEC 62443-4-1 / ANSI/ISA-62443-4-1 (secure product development) | Build | 13-119 | 3 | FDA lists the U.S. edition, ANSI/ISA-62443-4-1-2018; the IEC edition is not in FDA's database |
| IEC TR 80001-2-9 (security assurance cases) | Tell buyers | 13-103 | 3 | Withdrawn by IEC 2025-09-05; no replacement named |
| IEC TR 60601-4-5 (security specifications for devices) | Build | Not in FDA database | 3 | Not in FDA's database; scope excludes in vitro diagnostic medical devices |
| IEC 62443-4-2 (security requirements for components) | Build | Not in FDA database | 2 | Not in FDA's database |
| IEC TS 62443-1-1 (industrial security terms and models) | Background | 13-60 | 1 | — |
| IEC 62443-2-1 (industrial security program) | Run the company | 13-61 | 1 | FDA lists the 2010 edition; IEC's current edition is 2.0 (2024-08) |
| IEC TR 62443-3-1 (industrial security technologies) | Background | 13-62 | 1 | — |
| IEEE 11073-40101 (vulnerability assessment, personal health devices) | Assess risk — Personal health or point-of-care device | 13-117 | 1 | Partial recognition: subclause 8.6 (Iteration) is not recognized |
| IEEE 11073-40102 (security capabilities, personal health devices) | Build — Personal health or point-of-care device | 13-118 | 1 | — |
| IEEE/UL 2621.2 (connected diabetes device security) | Build — Connected diabetes device | 13-128 | 1 | — |
| CLSI AUTO11 (IT security of lab instruments) | Build — Lab (IVD) instrument | 7-344 | 1 | FDA lists AUTO11-A2; CLSI's current edition is the 3rd (2024-09-27) |
| AAMI CR515 (security of machine-learning devices) | Assess risk — Machine-learning device | 13-153 | 1 | — |
Source: as linked in the table rows.
† Not a security standard. ‡ A framework, not a standard.
Source: The PenTest Index review of FDA's Recognized Consensus Standards database, publisher catalogs and documents from 11 regulators, checked October 9, 2026. "Job" is our classification. "Named by" counts regulators whose documents name the standard; it does not mean required.
IEC 81001-5-1 vs IEC 62443-4-1
IEC 81001-5-1 takes its process rules from IEC 62443-4-1 and applies them to health software. Its own introduction says those requirements "have been derived from" IEC 62443-4-1. The FDA recognizes IEC 81001-5-1 and the U.S. edition of the other, ANSI/ISA-62443-4-1-2018.
| IEC 81001-5-1:2021 | IEC 62443-4-1:2018 | |
|---|---|---|
| Written for | Health software | Industrial control products |
| Pages | 114 | 54 |
| List price (electronic/PDF) | CHF 335 | CHF 335 (ANSI/ISA edition: $270) |
| FDA recognition | 13-122, entered December 19, 2022 | 13-119 (ANSI/ISA-62443-4-1-2018 only), entered June 7, 2021 |
| Testing clauses | 5.7.1 security requirements, 5.7.2 threat mitigation, 5.7.3 vulnerability, 5.7.4 penetration testing | 9.2 to 9.5 (SVV-1 to SVV-4): the same four kinds |
| Tester independence | 5.7.5 Managing conflicts of interest between testers and developers | 9.6 SVV-5: Independence of testers |
| Next edition | Edition 2 forecast August 2028 | Edition 2 forecast April 2028 |
Source: IEC Webstore, IEC 81001-5-1 and IEC 62443-4-1 (free contents previews); FDA records 13-122 and 13-119. Checked October 9, 2026.
One catch: IEC says meeting 81001-5-1 "is not necessarily a sufficient condition for conformance to IEC 62443-4-1." So a maker who sells into industrial markets too may need both.
Which cybersecurity standards does the FDA recognize?
As of October 9, 2026, the FDA has 24 recognition records whose title names security, cybersecurity or a vulnerability term. They are 22 different standards and 24 of the 1,738 records in FDA's database (1.4%). Using a recognized standard is a choice, not a duty, unless a regulation makes it one.
Not all 24 were written for medical devices. 14 of the 24 were written for health care. The other 10 come from other fields: 4 are for factory control systems, 3 are versions of one system for scoring security flaws (CVSS), 2 are for general IT, and 1 is for any connected product. (Our classification of the 24 FDA records.)
| # | FDA no. | Standard as FDA lists it — what it covers | FDA date of entry | Extent | Written for health care? | FDA's edition still the publisher's current one? | Named by (of 11) |
|---|---|---|---|---|---|---|---|
| 1 | 13-42 | IEC TR 80001-2-2:2012 — Telling buyers about device security needs, risks and controls | 2013-08-06 | Complete | Yes | No — Replaced by IEC TS 81001-2-2:2025; IEC withdrawal date 2025-10-01 | 6 |
| 2 | 13-60 | IEC TS 62443-1-1:2009 — Industrial network security: terms, concepts and models | 2013-08-06 | Complete | No | Yes | 1 |
| 3 | 13-61 | IEC 62443-2-1:2010 — Industrial control: setting up a security program | 2013-08-06 | Complete | No | No — IEC 62443-2-1:2024 (Edition 2.0, 2024-08) | 1 |
| 4 | 13-62 | IEC TR 62443-3-1:2009 — Industrial control: security technologies | 2013-08-06 | Complete | No | Yes | 1 |
| 5 | 13-77 | ISO/IEC 29147:2014 — Vulnerability disclosure | 2015-08-14 | Complete | No | No — ISO/IEC 29147:2018 (Edition 2, 2018-10) | 7 |
| 6 | 13-78 | INCITS/ISO/IEC 30111:2013 (R2019) — Vulnerability handling processes | 2015-08-14 | Complete | No | No — Current national adoption INCITS/ISO/IEC 30111:2019 (2024), based on ISO/IEC 30111:2019 (Edition 2) | 6 |
| 7 | 13-83 | AAMI TIR57:2016 — Security risk management for medical devices | 2016-06-27 | Complete | Yes | Yes | 8 |
| 8 | 13-96 | UL 2900-1, first edition (2017) — Security testing of network-connectable products: general requirements | 2017-08-21 | Complete | No | No — UL 2900-1 Edition 2, published 2023-12-13, last revised 2026-06-29 | 6 |
| 9 | 13-102 | IEC TR 80001-2-8:2016 — Standards for building security capabilities | 2017-12-04 | Complete | Yes | No — Replaced by IEC TS 81001-2-2:2025; IEC withdrawal date 2025-10-01 | 5 |
| 10 | 13-103 | IEC TR 80001-2-9:2017 — Security assurance cases | 2017-12-04 | Complete | Yes | No — Withdrawn by IEC 2025-09-05; no replacement named | 3 |
| 11 | 13-104 | UL 2900-2-1, first edition (2017) — Security testing of healthcare and wellness system components | 2018-06-07 | Complete | Yes | Yes | 6 |
| 12 | 13-112 | AAMI TIR97:2019 — Security risk management after launch (postmarket) | 2019-12-23 | Complete | Yes | Yes | 6 |
| 13 | 13-116 | FIRST CVSS v3.0 — Scoring how severe a vulnerability is | 2020-10-19 | Complete | No | No — Older CVSS version; FDA accepts declarations of conformity to it until 2026-12-20 | 8 |
| 14 | 13-117 | IEEE 11073-40101-2020 — Vulnerability assessment process for connected personal health devices | 2021-06-07 | Partial (excludes subclause 8.6, Iteration) | Yes | Yes | 1 |
| 15 | 13-118 | IEEE 11073-40102-2020 — Security capabilities for connected personal health devices | 2021-06-07 | Complete | Yes | Yes | 1 |
| 16 | 13-119 | ANSI/ISA-62443-4-1-2018 — Secure product development life cycle (industrial) | 2021-06-07 | Complete | No | Yes | 3 |
| 17 | 13-122 | IEC 81001-5-1:2021 — Secure life cycle for health software | 2022-12-19 | Complete | Yes | Yes | 8 |
| 18 | 13-123 | ANSI/NEMA HN 1-2019 — Manufacturer Disclosure Statement for Medical Device Security (MDS2 form) | 2022-12-19 | Complete | Yes | Yes | 7 |
| 19 | 13-128 | IEEE/UL 2621.2-2022 — Security of connected diabetes devices | 2022-12-19 | Complete | Yes | Yes | 1 |
| 20 | 13-131 | ANSI/AAMI SW96:2023 — Security risk management requirements for device makers | 2023-10-09 | Complete | Yes | Yes | 3 |
| 21 | 7-344 | CLSI AUTO11-A2 — IT security of lab (in vitro diagnostic) instruments and software | 2025-05-26 | Complete | Yes | No — CLSI AUTO11, 3rd edition (2024-09-27) | 1 |
| 22 | 13-142 | FIRST CVSS v3.1 — Scoring how severe a vulnerability is | 2025-05-26 | Complete | No | No — Older CVSS version; FDA accepts declarations of conformity to it until 2028-07-02 | 8 |
| 23 | 13-153 | AAMI CR515:2025 — Security of machine-learning devices | 2025-12-22 | Complete | Yes | Yes | 1 |
| 24 | 13-140 | FIRST CVSS v4.0 — Scoring how severe a vulnerability is | 2026-05-25 | Complete | No | Yes | 8 |
Source: FDA Recognized Consensus Standards database and record pages; IEC, ISO, UL, AAMI, CLSI, IEEE and FIRST catalogs. Checked October 9, 2026. "Health care?" is our classification. "Named by" counts the 11 regulators in Table 7, any edition. "Current" means the edition/version label, not every later revision, correction or interpretation.

How to check our count yourself
Anyone can repeat it in a few minutes. Search FDA's database for the keyword "524B". On October 9, 2026 it returned 31 records. Keep the ones whose title names security, cybersecurity or a vulnerability term: that leaves 24. Open any of them, and the note sits under "Rationale for Recognition."
The other 7 records in that search (13-33, 13-38, 13-44, 13-70, 13-82, 13-105 and 13-130) are not security standards by our title rule. Their exclusion does not mean they have no cybersecurity use.
Standards many guides list that aren't in FDA's database
Several standards that show up on vendor lists have no record in FDA's database. That is not the same as rejected: none of them is on FDA's short list of standards it declined to recognize.
| Standard | What FDA's database search returned |
|---|---|
| IEC TR 60601-4-5 | No record |
| IEC 62443-4-1 (the IEC edition) | No record. FDA lists the U.S. edition, ANSI/ISA-62443-4-1-2018 (13-119) |
| IEC 62443-4-2, 62443-3-3, 62443-3-2 | No record. Only parts 1-1, 2-1, 3-1 and ANSI/ISA 4-1 are listed |
| IEC TS 81001-2-2:2025 | No record. A keyword search for "81001" returns only 13-122 |
| ISO/IEC 27001 and 27002 | No record |
| ISO 27799 | No record |
| ISO/IEC 15408 (Common Criteria) | No record |
| IEEE 2621.1 and 2621.3 | No record. Only 2621.2 is listed |
| ISO 81001-1 | No record |
| ISO 13485 | No record. It binds through the Quality Management System Regulation instead |
| Any NIST publication | No record. NIST is not one of the 32 organizations in the database |
Source: FDA Recognized Consensus Standards database and Non-Recognized Standards table, checked October 9, 2026.
Does meeting a standard make a device compliant?
Meeting a recognized standard may not be enough to make a device compliant in the United States. FDA puts the same warning phrase on all 24 selected recognition records: conformance "may not satisfy all the cybersecurity requirements outlined in Section 524B." Section 524B itself names no standard.
Here is the note as FDA prints it on the records:
"Conformance to this standard may not satisfy all the cybersecurity requirements outlined in Section 524B of FD&C Act …"
Two of the 24 (AAMI TIR57 and ANSI/AAMI SW96) add an explanation of how security risk is judged: by how easily a flaw can be used (exploitability), not by the probability-of-harm model used for safety risk. A section 524B caution sits on 31 records in all: the 24 selected records plus 7 others. Record 13-130 uses different wording.
Other regulators say the same thing in their own words. Australia's TGA (Therapeutic Goods Administration) says "application of standards alone does not guarantee compliance to the Essential Principles," which are Australia's basic safety rules for devices. The EU's device experts group (MDCG) says the standards it lists "cannot provide a presumption of conformity, unless they are harmonised." In plain words: meeting a harmonised standard gives a presumption that the device meets the legal requirements that standard covers. It is not automatic proof of full compliance, and no dedicated cybersecurity standard is on the MDR list yet.
So a standard is a tool for showing your work. The legal test is the law.
What does the law require?
In the United States, section 524B of the Federal Food, Drug, and Cosmetic Act (FD&C Act) sets 4 requirements for "cyber devices" and names no standard. It has applied to covered submissions for cyber devices since March 29, 2023. A maker must provide:
- A plan to watch for, find and address vulnerabilities after launch in a reasonable time, including a process for coordinated vulnerability disclosure. A vulnerability is a weak spot an attacker could use.
- Processes that give reasonable assurance that the device and related systems are secure, with updates and patches.
- A software bill of materials (SBOM), which is a list of the software parts inside the device, including commercial, open-source and off-the-shelf software.
- Anything more the FDA requires by regulation.
For known unacceptable vulnerabilities, patches must follow a reasonably justified regular cycle. For critical vulnerabilities that could cause uncontrolled risks, the law calls for patches as soon as possible, outside that cycle. (Section 524B(b)(2).)
A "cyber device" meets 3 tests in the law: it includes software validated, installed or authorized by the sponsor; it can connect to the internet; and it has features validated, installed or authorized by the sponsor that could be open to cybersecurity threats. FDA counts Wi-Fi, cellular, Bluetooth and magnetic inductive links, plus hardware connectors capable of connecting to the internet, such as USB, ethernet and serial ports.
The law was signed December 29, 2022 (Public Law 117-328, section 3305). FDA said it would generally not refuse submissions on this ground before October 1, 2023. From that date, "FDA may RTA" (refuse to accept) submissions that lack the information.
FDA's guidance reaches further than the law's definition. It applies to "devices with cybersecurity considerations" and is "not limited to devices that are network-enabled," per the February 3, 2026 guidance.
One standard that FDA's cybersecurity guidance leans on does bind in the U.S., and it is not a security standard. The Quality Management System Regulation took effect February 2, 2026 and incorporates ISO 13485:2016. Even so, "The FDA will not require certificates of conformance to ISO 13485."
| Jurisdiction (regulator) | Binding rule | Main cybersecurity guidance | What it does with standards |
|---|---|---|---|
| United States (FDA) | FD&C Act section 524B (added by Pub. L. 117-328 sec. 3305; applies to submissions from 2023-03-29); Quality Management System Regulation (from 2026-02-02) | Cybersecurity in Medical Devices: QMS Considerations and Content of Premarket Submissions (2026-02-03); Postmarket Management of Cybersecurity in Medical Devices (2016-12-28) | Recognizes standards; using one is voluntary unless a regulation incorporates it. All 24 selected recognition records carry a section 524B caution |
| European Union (European Commission / MDCG) | Regulation (EU) 2017/745 (MDR) Annex I 17.2, 17.4, 18.8, 23.4(ab); Regulation (EU) 2017/746 (IVDR) Annex I 16.2, 16.4, 20.4.1(ah) | MDCG 2019-16 Rev.1 (July 2020) | None of the 70 harmonised MDR entries has security or software in its title (list consolidated 2026-06-17); the standards bodies' adoption deadline for an IEC 81001-5-1-based standard is 2028-05-27 |
| Japan (MHLW / PMDA) | Essential Principles Article 12(3) (from 2023-04-01; required for applications from 2024-04-01) | MHLW notification PSEHB/MDED No. 0331-8 (2023-03-31); manufacturer guide, 2nd edition | Applicants for covered controlled and specially-controlled devices (Class II, III, IV) 'must attach data showing conformance to JIS T 81001-5-1 etc.'; other standards 'such as IEC 81001-5-1' may be used with an explanation |
| Canada (Health Canada) | Medical Devices Regulations SOR/98-282 (do not use the words 'cyber' or 'security') | Pre-market Requirements for Medical Device Cybersecurity (effective 2019-06-26) | Names standards in guidance; the guidance predates IEC 81001-5-1 (2021) |
| Australia (TGA) | Essential Principle 12.1(5) uses the word 'cybersecurity' (from 2021-02-25) | Complying with medical device cyber security requirements | Standards use 'is not mandated by the TGA'; 'application of standards alone does not guarantee compliance to the Essential Principles' |
| Great Britain (MHRA) | Medical Devices Regulations 2002, as amended. Separate proposal: draft Medical Devices (Amendment) Regulations 2026, notified to the WTO 2026-05-08; not made | No penetration-testing mention in the MHRA documents searched. Government response (2026-10-06) promises further details on guidance work by spring 2027 | No security standard among the 25 checked is on the UK designated list |
| Brazil (ANVISA) | RDC 848/2024 and RDC 657/2022 contain cybersecurity wording and name no cybersecurity standard | Guia 38/2020 (ANVISA's adoption of IMDRF N60) | Names standards in guidance |
| China (NMPA / CMDE) | Regulations on the Supervision and Administration of Medical Devices; Measures for the Registration and Filing of Medical Devices | CMDE Guidelines for Registration Review of Medical Device Cybersecurity (2022 revision) | Lists standards as references (prints IEC 81001-5-1 as 'IEC 80001-5-1:2021') |
| South Korea (MFDS) | Digital Medical Products Act (first in force 2025-01-24; current Act No. 21525 effective 2026-10-08), Articles 13–14; MFDS Notification 2025-30 (effective 2025-04-29) | Cybersecurity approval and review guideline (2025-01-10); companion guide (2025-11-13); software-validation guideline 0095-02 (2026-07-28) | Guideline takes its requirements from IEC 62443-4-2 and IEC TR 60601-4-5; all must be met unless the maker shows why one cannot apply; the guideline says it has no legal force |
| Singapore (HSA) | Health Products (Medical Devices) Regulations 2010 | HSA GL-04-R4 (December 2025); voluntary Cybersecurity Labelling Scheme for Medical Devices (launched 2024-10-16) | Reference to IEC 81001-5-1 'is encouraged' |
| Saudi Arabia (SFDA) | Medical Devices Law and implementing regulation; MDS-REQ 1 v6, Requirements for Medical Devices Marketing Authorization | MDS-G38 and MDS-G37 (2019; still hosted by SFDA) | Recognised standards list MDS-G020 v3.0 includes IEC 81001-5-1:2021 |
Source: each regulator's law and guidance as listed in the Sources, checked October 9, 2026. Japanese, Korean, Chinese and Portuguese wording is our translation unless an official English version exists.
European Union
The EU has given official ("harmonised") status to 0 cybersecurity standards under its Medical Device Regulation (MDR). That is 0 of the 70 entries on its list as of June 17, 2026. The EU has asked the European standards bodies for a harmonised standard based on IEC 81001-5-1. The standards bodies' adoption deadline moved 4 years, from May 27, 2024 to May 27, 2028. This is not a device-maker compliance deadline or a promise that harmonisation will happen that day.
The MDR covers IT security in four clauses of Annex I (17.2, 17.4, 18.8 and 23.4(ab)). The words "cyber" and "penetration test" appear 0 times in it. Notified bodies are the groups that check devices for the EU market. In 2022, their association, Team-NB, called IEC 81001-5-1 "state of the art."
Japan
Japan added cybersecurity to its Essential Principles, the basic safety rules every device must meet (Article 12(3)), in 2023. This rule covers devices that use software and exchange data with other devices, networks or external media. For applications since April 1, 2024, makers of covered controlled and specially-controlled devices "must attach data showing conformance to JIS T 81001-5-1 etc." Those are Japan's Class II, III and IV devices. JIS T 81001-5-1 is identical to IEC 81001-5-1. Other international standards "such as IEC 81001-5-1" may be used if the applicant explains why. Covered Class I devices must also have their conformity checked, but the data need not be attached to their notification. (MHLW notification, sections 2(1) and 3(4).)
South Korea
South Korea has binding security duties alongside its non-binding explanatory guides. Its January 10, 2025 guideline takes its requirements from IEC 62443-4-2 and IEC TR 60601-4-5 and says all must be met unless the maker shows why one cannot apply. The same guideline says it has no legal force.
The Digital Medical Products Act, in its version effective October 8, 2026, requires ongoing work to fix vulnerabilities (Article 13) and compliance with the Ministry's security guidelines (Article 14). The binding MFDS Notification 2025-30, effective April 29, 2025, sets those security duties. Its Article 14 covers secure coding, secure design, security testing and vulnerability testing in development and validation.
Do the standards differ by country?
The standards regulators name do differ by country. Of 11 regulators checked on October 9, 2026, no two name the same set in the documents we searched. None of the 25 security standards we checked is named by more than 8 of the 11, while all 11 name three general standards: ISO 14971, IEC 62304 and ISO 13485.
Some standards travel less than you'd think. Eight of the security standards the FDA recognizes are named by none of the other 10 regulators in the documents we searched.
| Standard | US | EU | JP | CA | AU | UK | BR | CN | KR | SG | SA | Named by |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| ISO 14971 (risk management) † | ● | ● | ● | ● | ● | ● | ● | ● | ● | ● | ● | 11 of 11 |
| IEC 62304 (software life cycle) † | ● | ● | ● | ● | ● | ● | ● | ● | ● | ● | ● | 11 of 11 |
| ISO 13485 (quality management system) † | ● | ● | ● | ● | ● | ● | ● | ● | ● | ● | ● | 11 of 11 |
| IEC 81001-5-1 (secure health software life cycle) | ● | ● | ● | – | ● | – | – | ● | ● | ● | ● | 8 of 11 |
| AAMI TIR57 (security risk management) | ● | – | ● | ● | ● | – | ● | ● | ● | ● | – | 8 of 11 |
| CVSS (vulnerability scoring) | ● | ● | ● | – | ● | – | ● | ● | ● | ● | – | 8 of 11 |
| IEC 80001-1 (risk management for hospital IT networks) † | ● | ● | – | ● | ● | – | ● | ● | ● | – | ● | 8 of 11 |
| ISO/IEC 29147 (vulnerability disclosure) | ● | – | ● | – | ● | – | ● | ● | ● | ● | – | 7 of 11 |
| ANSI/NEMA HN 1 (MDS2 security disclosure form) | ● | ● | ● | – | ● | – | ● | ● | – | ● | – | 7 of 11 |
| AAMI TIR97 (postmarket security risk) | ● | – | ● | – | – | – | ● | ● | ● | ● | – | 6 of 11 |
| UL 2900-1 (security testing, general) | ● | – | – | ● | ● | – | ● | ● | – | ● | – | 6 of 11 |
| UL 2900-2-1 (security testing, healthcare systems) | ● | – | – | ● | ● | – | ● | ● | – | ● | – | 6 of 11 |
| IEC TR 80001-2-2 (disclosing security needs and controls) | ● | ● | ● | – | – | – | ● | ● | – | – | ● | 6 of 11 |
| ISO/IEC 30111 (vulnerability handling) | ● | – | ● | – | ● | – | ● | ● | ● | – | – | 6 of 11 |
| NIST Cybersecurity Framework ‡ | ● | – | ● | ● | ● | – | ● | – | ● | – | – | 6 of 11 |
| IEC 82304-1 (health software product safety) † | ● | ● | – | – | ● | – | – | – | ● | – | ● | 5 of 11 |
| IEC TR 80001-2-8 (standards for security capabilities) | ● | ● | – | – | – | – | ● | ● | – | – | ● | 5 of 11 |
| ISO/IEC 27001 (organization security management) | – | ● | – | – | – | – | – | ● | ● | ● | – | 4 of 11 |
| ANSI/AAMI SW96 (security risk management requirements) | ● | – | – | – | ● | – | – | – | ● | – | – | 3 of 11 |
| IEC 62443-4-1 / ANSI/ISA-62443-4-1 (secure product development) | ● | ● | – | – | – | – | – | – | ● | – | – | 3 of 11 |
| IEC TR 80001-2-9 (security assurance cases) | ● | – | – | – | – | – | – | ● | – | – | ● | 3 of 11 |
| IEC TR 60601-4-5 (security specifications for devices) | – | ● | – | – | – | – | – | ● | ● | – | – | 3 of 11 |
| IEC 62443-4-2 (security requirements for components) | – | ● | – | – | – | – | – | – | ● | – | – | 2 of 11 |
Source: The PenTest Index review of official documents from 11 regulators, checked October 9, 2026 (341 cells, each in the download with its source). ● = the standard's number or name appears in the documents we searched. It does not mean required. National adoptions count (for example JIS T 81001-5-1). A mention of a whole series (for example "the IEC 62443 series") is not counted for any one part. † Not a security standard. ‡ A framework, not a standard. US = FDA; EU = Commission and MDCG; JP = Japan; CA = Canada; AU = Australia; UK = Great Britain (England, Scotland and Wales); BR = Brazil; CN = China; KR = South Korea; SG = Singapore; SA = Saudi Arabia.
Named by FDA alone (8): IEC TS 62443-1-1, IEC 62443-2-1, IEC TR 62443-3-1, IEEE 11073-40101, IEEE 11073-40102, IEEE/UL 2621.2, CLSI AUTO11 and AAMI CR515.
How many of the 31 each regulator names: United States 28, China 18, South Korea 17, Australia 15, Brazil 15, European Union 14, Japan 12, Singapore 12, Saudi Arabia 9, Canada 8, Great Britain 3. Security standards only (of 25): United States 22, China 14, South Korea 11, Brazil 10, European Union 9, Australia 9, Singapore 9, Japan 8, Saudi Arabia 4, Canada 3, Great Britain 0.

Notes on the table:
- Singapore's marks for AAMI TIR57, ISO/IEC 29147 and the MDS2 form come from its voluntary Cybersecurity Labelling Scheme for Medical Devices, not from HSA's own guidance. Its marks for UL 2900 and ISO/IEC 27001 come from an HSA best-practice guide that "does not constitute regulatory guidance."
- The EU mark for IEC 81001-5-1 comes from the Commission's standardisation request. The standard is not harmonised.
- China's guideline prints IEC 81001-5-1 as "IEC 80001-5-1:2021," with the right title.
- China's YY/T 0664-2020 is a modified national adoption of IEC 62304:2015. The rule counts national adoptions, including modified ones. Its GB/T 22080-2016 reference, an adoption of ISO/IEC 27001:2013, was withdrawn on January 1, 2026. It still counts as a named reference in the 2022 guide, not as today's current edition.
- Japan and South Korea name ISO 13485, and South Korea names IEC 62304, IEC 82304-1 and IEC 80001-1, in quality system and software documents rather than cybersecurity documents.
- Saudi Arabia's marks for IEC 80001-1 and IEC TR 80001-2-2 rest on those numbers appearing inside the titles of other parts on its recognised list.
- Brazil's guide names "a família ISO 27000" (the ISO 27000 family), not ISO/IEC 27001 by number, so it gets no mark there.
- General cybersecurity laws are outside this matrix. One of them, the EU's NIS2 Directive, names ISO/IEC 29147 and ISO/IEC 30111 in recital 58. If it counted, ISO/IEC 29147 would reach 8 as well.
One standard, 11 regulators: where IEC 81001-5-1 stands
Picture a maker selling the same glucose monitor in Tokyo and Toronto. Japan expects proof of meeting JIS T 81001-5-1. Canada's guidance dates from 2019, two years before that standard existed, and does not name it.
| Regulator | Status of IEC 81001-5-1 |
|---|---|
| Japan | Applicants for covered controlled and specially-controlled devices (Class II, III and IV) "must attach data showing conformance to JIS T 81001-5-1 etc." since April 1, 2024. Other standards "such as IEC 81001-5-1" may be used with an explanation |
| United States | Recognized (13-122, entered December 19, 2022). Voluntary. FDA lists it among "Possible frameworks to consider" |
| Saudi Arabia | On SFDA's recognised standards list (MDS-G020 v3.0) |
| European Union | Not harmonised. The standards bodies' adoption deadline for a standard based on it is May 27, 2028; that is not a promised harmonisation date. Team-NB, the notified bodies' association, called it "state of the art" in 2022 |
| Singapore | Reference to it "is encouraged" (HSA GL-04-R4) |
| Australia | Named as best practice: "we have not endorsed these standards and applying them is not mandatory" |
| South Korea | Listed in the November 2025 companion guide. The main guideline is built on IEC 62443-4-2 and IEC TR 60601-4-5 |
| China | Listed in the references of the 2022 guideline, under a misprinted number |
| Canada, Great Britain, Brazil | Not named in the documents we searched. Canada's guidance (2019) and Brazil's guide (2020) are older than the standard (2021) |
Source: MHLW PSEHB/MDED No. 0331-8; FDA record 13-122 and February 3, 2026 guidance; SFDA MDS-G020; Commission C(2024) 3371; Team-NB position paper (October 5, 2022); HSA GL-04-R4; TGA software standards page; MFDS guides (January 10 and November 13, 2025); CMDE 2022 guideline. Checked October 9, 2026.
Is penetration testing required for medical devices?
FDA guidance says penetration test reports "should be provided" and lists 5 things each report should include. Across the official device-guidance sets we reviewed, 10 of 11 jurisdictions name penetration testing. None of the 17 specified legal and regulatory texts uses the searched penetration-testing phrase or local-language equivalent. That text-search result does not settle what testing a device needs to meet broader safety and security duties.
Penetration testing is a planned, authorized attack on a product to find its weak spots before someone else does.
The one jurisdiction without a mention in our searched guidance set is Great Britain. Saudi Arabia's two cybersecurity guides do not mention it, but a question in SFDA's software guide MDS-G23 does. That guide reprints documents from the International Medical Device Regulators Forum (IMDRF), a group of regulators that writes shared guidance. A mention is not a recommendation or a mandate.
| Where | Exact words | Strength |
|---|---|---|
| FDA guidance (February 3, 2026) | "Penetration test reports should be provided and include the following elements…" (5 elements) | Should |
| EU MDCG 2019-16 | "Methods can include security feature testing, fuzz testing, vulnerability scanning and penetration testing" | Can |
| German notified bodies (IG-NB, February 2025) | "Vulnerability scanning and penetration testing shall be done for all medical devices, unless duly justified." | Shall, unless justified. Not EU law or Commission guidance |
| Japan (manufacturer guide, 2nd edition) | For products with a large effect on patient safety, penetration testing is carried out in some cases (our translation) | May |
| Canada (2019) | "Structured Penetration Testing," in a table of tests "manufacturers may consider" | May |
| Australia (TGA) | "Consider implementing penetration testing initiatives (commensurate with risk level)" | Consider |
| Brazil (Guia 38/2020) | "por exemplo, teste de penetração" (for example, penetration testing) | Example |
| China (2022 guideline) | Listed with four other example activities (our translation) | Example |
| South Korea (November 2025 companion guide) | Security tests such as penetration testing, including fuzz testing, must be carried out and documented (our translation) | Named; the guide is not binding |
| Singapore (HSA GL-04-R4) | "Security testing can include: Penetration testing" | Can |
| Singapore label scheme, Level 3 | "required to pass independent third-party software binary analysis and penetration testing" | Required for the label; the scheme is voluntary |
| Saudi Arabia | Not in its two cybersecurity guides (2019). One question in software guide MDS-G23, a reprint of IMDRF documents: "…intrusion detection, penetration testing, vulnerability scanning…" | Mention in an official reprint; no testing direction in that question |
| Great Britain | No penetration-testing mention in the MHRA documents searched | None in this document set |
| 17 specified legal and regulatory texts, all 11 jurisdictions | No match for the searched penetration-testing phrase or local-language equivalent | A text-search result; not an exemption from broader testing duties |
Source: each document as listed in penetration-testing-wording.csv and the Sources, checked October 9, 2026.
What FDA asks to see in a penetration test report
FDA's guidance lists 4 kinds of security testing "among others": security requirements testing, threat mitigation testing, vulnerability testing and penetration testing. For the penetration test, FDA says the report should include 5 elements:
- Independence and technical expertise of testers
- Scope of testing
- Duration of testing
- Testing methods employed
- Test results, findings, and observations
The report is what a reviewer reads. So those five lines are worth sorting out before you hire anyone, not after.
| FDA report element | What to settle before testing starts |
|---|---|
| Independence and technical expertise of testers | Who will test, how they are separate from the developers, and what experience they have with devices like yours |
| Scope of testing | Which parts are in and out: device firmware, companion app, cloud services, interfaces (Bluetooth, USB, Wi-Fi), with exact versions |
| Duration of testing | Test dates and total days, written into the report |
| Testing methods employed | Which methods will be used and named in the report |
| Test results, findings, and observations | Report format, how findings are rated, and whether a retest after fixes is included |
Source: left column, FDA, Cybersecurity in Medical Devices (February 3, 2026), Section V.C. Right column: The PenTest Index buying checklist built on those elements; not an FDA form.
When you compare quotes, these same points decide whether two offers cover the same work.
Which standards name penetration testing?
Four entries in our finder have verified penetration-testing coverage. The free publisher contents show IEC 81001-5-1 clause 5.7.4 and IEC 62443-4-1 clause 9.5. UL's own explanation describes penetration testing for the UL 2900 standards, including UL 2900-1 and UL 2900-2-1. We did not verify their section numbers from UL. FDA's guidance names ANSI/UL 2900, ANSI/ISA 62443-4-1 and IEC 81001-5-1 and says they "may partially meet" its testing recommendations.
Does the tester have to be an outside company?
The tester does not always have to be an outside company. FDA asks the report to show who tested, for example "independent internal testers, external testers," and adds: "In some cases, it may be necessary to use third parties." Japan's January 2024 questions and answers say testing by a third-party body is not mandatory (our translation). Australia's TGA says testing "should be performed by a qualified party independent of the development team." Singapore's voluntary label requires independent third-party testing at Level 3.
How often should a device be tested?
FDA says that after release, cybersecurity testing "should be performed at regular intervals commensurate with the risk (e.g., annually)." "Annually" is an example, not a rule.
If you're getting ready to buy a penetration test for a device, Find My PenTest Match builds a free scope checklist you can copy or print. It asks for no contact details.
Are the FDA-recognized editions up to date?
Not every edition FDA lists is the newest one. For 8 of the 22 security standards the FDA recognizes, the publisher has since replaced or withdrawn the edition FDA lists. FDA accepts declarations of conformity to the editions in its database, so the listed edition still counts. A team buying a standard today must check both the edition and its status. Publishers can still sell a withdrawn report.
| FDA no. | Edition FDA lists | Publisher's status today |
|---|---|---|
| 13-42 | IEC TR 80001-2-2:2012 | Withdrawn October 1, 2025; replaced by IEC TS 81001-2-2:2025 |
| 13-102 | IEC TR 80001-2-8:2016 | Withdrawn October 1, 2025; replaced by IEC TS 81001-2-2:2025 |
| 13-103 | IEC TR 80001-2-9:2017 | Withdrawn September 5, 2025; no replacement named |
| 13-61 | IEC 62443-2-1:2010 | Replaced by IEC 62443-2-1:2024 (Edition 2.0, August 2024) |
| 13-77 | ISO/IEC 29147:2014 | Replaced by ISO/IEC 29147:2018 (Edition 2) |
| 13-78 | INCITS/ISO/IEC 30111:2013 (R2019) | Current national adoption: INCITS/ISO/IEC 30111:2019 (2024), based on ISO/IEC 30111:2019 (Edition 2) |
| 13-96 | UL 2900-1, first edition (2017) | Edition 2 published December 13, 2023; last revised June 29, 2026 |
| 7-344 | CLSI AUTO11-A2 | AUTO11, 3rd edition (September 27, 2024) |
Source: FDA record pages; IEC Webstore, ISO, UL Standards and CLSI catalogs. Checked October 9, 2026.
That is about one in three (8 ÷ 22 = 36%). Counting records instead, it is 10 of 24, because FDA lists two older versions of CVSS that it is phasing out itself: it accepts declarations of conformity to CVSS v3.0 until December 20, 2026 and to v3.1 until July 2, 2028.
Three of the eight (IEC TR 80001-2-2, -2-8 and -2-9) are still cited in FDA's February 3, 2026 guidance. That was 125 and 151 days after IEC withdrew them.
Three more version notes that a standards list usually misses:
- IEC 81001-5-1 has a December 2025 correction. IEC's current copy is still Edition 1.0, marked "CORRECTED VERSION 2025-12," and includes Interpretation Sheet 1 (December 4, 2025; free from IEC). FDA's record 13-122 lists "Edition 1.0 2021-12" and does not mention the interpretation sheet.
- IEC 80001-1 is an edition gap outside the 24. FDA record 13-38 lists Edition 1.0 from 2010. IEC's current edition is 2.0, published September 21, 2021. Its title doesn't name security, so it isn't in our 24, but it carries the same 524B caution in its scope text.
- One recognition is partial. FDA record 13-117 for IEEE 11073-40101-2020 does not recognize subclause 8.6, "Iteration." FDA's record explains why, citing its own guidance, AAMI TIR57 and ISO 14971.
How often do the rules change?
FDA's guidance has changed often since 2023. The FDA has issued 3 versions of its final premarket cybersecurity guidance in 860 days: September 27, 2023; June 27, 2025; and February 3, 2026. FDA calls the third a revision, and the version before those three stood for almost 9 years.
| Date | Guidance | Version | Citation |
|---|---|---|---|
| January 14, 2005 | Cybersecurity for Networked Medical Devices Containing Off-the-Shelf Software | Final | Withdrawn September 25, 2025 |
| June 14, 2013 | Premarket cybersecurity | Draft | 78 FR 35940 |
| October 2, 2014 | Premarket cybersecurity | Final | 79 FR 59493 |
| January 22, 2016 | Postmarket cybersecurity | Draft | 81 FR 3803 |
| December 28, 2016 | Postmarket cybersecurity | Final (still current) | 81 FR 95617 |
| October 18, 2018 | Premarket cybersecurity | Draft | 83 FR 52835 |
| April 8, 2022 | Premarket cybersecurity (new title) | Draft; risk tiers removed | 87 FR 20873 |
| September 27, 2023 | Premarket cybersecurity | Final | 88 FR 66458 |
| March 13, 2024 | Select updates (section 524B) | Draft | 89 FR 18421 |
| June 27, 2025 | Premarket cybersecurity | Final; added Section VII on cyber devices | 90 FR 27634 |
| February 3, 2026 | Premarket cybersecurity | Final, revised. Current | FDA guidance history: Level 2 revision |
Source: Federal Register notices; FDA guidance pages. Checked October 9, 2026.
The February 2026 version was a "Level 2" update, FDA's term for a smaller revision that doesn't go out for public comment first. It was made to match the new quality system rule. It cites ISO 13485 clauses where earlier versions cited the old rule. The penetration-testing paragraph and its five report elements stayed the same across those three versions; only the punctuation after the testing heading changed.
Six facts that often get repeated wrong
| What gets repeated | What is true | Source |
|---|---|---|
| "FDA's 2023 guidance" is current | The current guidance is dated February 3, 2026. It is the third version of the final guidance since September 2023 | FDA guidance |
| "Section 524B took effect in October 2023" | It took effect March 29, 2023. October 1, 2023 is when FDA's grace period on refusing submissions ended | Pub. L. 117-328 §3305(d); 88 FR 19148 |
| "Tier 1 and Tier 2 devices" | FDA removed risk tiers in its April 8, 2022 draft | 87 FR 20873 |
| "Fix vulnerabilities within 90 days" / "disclose within 30 days" | Neither is in the statute. FDA's 2016 guidance says to act as soon as possible after learning of the flaw: within 30 days for customer notice, interim controls and a plan to fix it; within 60 days for a validated, distributed fix. Those are among the conditions for not enforcing a reporting rule | Pub. L. 117-328 §3305; FDA postmarket guidance, pp. 22–23 |
| "53% of devices have a critical vulnerability, says the FBI" | The vendor Cynerio published it in January 2022. The FBI repeated it | Cynerio release; FBI notice 20220912-001 |
| "IEC 81001-5-1 is harmonised in the EU" | It is not on the harmonised list. The standards bodies' adoption deadline for a standard based on it is May 27, 2028 | Decision (EU) 2021/1182, consolidated June 17, 2026; C(2024) 3371 |
Source: as linked in the table rows.
How much do the medical device cybersecurity standards cost?
The five standards on our short list cost $1,016 plus 335 Swiss francs (CHF 335) at individual electronic/PDF publisher list prices. That is an estimated $1,420 in all at the exchange rate below. One of them, UL 2900-2-1, is used with UL 2900-1, which adds $402. The regulators' own guidance is free.
| Standard | Pages | Price |
|---|---|---|
| IEC 81001-5-1:2021 | 114 | CHF 335 |
| ANSI/AAMI SW96:2023 | 61 | $298 |
| AAMI TIR57:2016/(R)2023 | 84 | $345 |
| AAMI TIR97:2019/(R)2023 | 56 | $298 |
| UL 2900-1 (Edition 2) | Not verified from UL | $402 |
| UL 2900-2-1 | Not verified from UL | $75 |
| ANSI/ISA-62443-4-1-2018 | 66 | $270 |
| IEC TR 60601-4-5:2021 | 51 | CHF 335 |
| IEC 80001-1:2021 | 75 | CHF 260 |
| ISO 14971:2019 | 36 | CHF 196 |
| IEC 62304:2006+AMD1:2015 | 170 | CHF 1,150 |
| ANSI/NEMA HN 1-2019 (MDS2 form) | 36 | $103 |
| Regulator guidance; CVSS; NIST Cybersecurity Framework | — | Free |
Source: publisher stores (IEC, AAMI, UL, ISA, ISO, NEMA), checked October 9, 2026. UL page counts were not verified from UL and are omitted. IEC prices shown are for the selected one-user PDF. AAMI prices are electronic listings; their single-user terms were not verified. ISO lists PDF plus ePub; ISA and NEMA list PDF. Prices exclude tax, fees, subscriptions, bundles and discounts.
The math: $298 + $345 + $298 + $75 = $1,016. CHF 335 at 0.8293 francs per dollar (Federal Reserve rate for October 2, 2026) is $403.96. Together that's an estimated $1,419.96. Adding UL 2900-1 at its separate $402 list price brings it to $1,821.96. These are individual list-price totals, not the lowest bundle prices. That's about the price of a good laptop, before anyone has read a page.
What do the numbers about device security really measure?
We traced six often-quoted numbers about medical device security. Five came from security vendors or from reports they co-wrote, not from regulators. The 53% figure is often credited to the FBI, but the vendor Cynerio published it in January 2022. For the sixth number, which is credited to the FDA, we found no FDA source.
| Figure as repeated | Source we traced it to | What to know |
|---|---|---|
| 53% of connected medical and other IoT devices in Cynerio's hospital data had a known critical vulnerability | Cynerio, January 19, 2022 | Data "collected from current Cynerio implementations": more than 10 million IoT and medical devices at more than 300 hospitals and other facilities. The FBI repeated it on September 12, 2022 |
| Claimed average: 6.2 vulnerabilities per medical device | Sensato blog post, February 7, 2018 | No sample or method published. Do not cite this as a reproducible device average |
| 993 vulnerabilities in 966 healthcare products, up 59% | Health-ISAC with Finite State and Securin, August 2023 | Public-disclosure review across 117 vendors, including hardware, operating systems and software. The report's 2022 comparison count was 624. (993 − 624) ÷ 624 rounds to 59%. |
| IoMT devices with known exploited vulnerabilities at 99% of the 351 organizations studied; in 9% of their IoMT devices | Claroty Team82, March 26, 2025 | The sample includes over 2.25 million IoMT (Internet of Medical Things) devices. Claroty does not say how the organizations were chosen. These are vulnerability figures, not attack rates |
| 22% in 2025 reported attacks directly affecting devices; 24% in 2026 reported attacks or exploited vulnerabilities involving devices | RunSafe Security releases: 605 healthcare executives (2025); 551 healthcare professionals (2026), in the US, UK and Germany | Survey self-reports. The releases use different event wording, so this is not a like-for-like trend. The 2026 introduction says attacks; its key findings also include exploited vulnerabilities |
| Unsupported claim: "FDA estimates 164 of every 1,000 devices remain vulnerable" | We found no supporting FDA source | A located repetition cites an incomplete supposed 2017 FDA guidance reference, with no data or method. Do not cite this as an FDA finding |
Source: repeated-statistics-traced.csv (links to the sources traced), checked October 9, 2026.
The U.S. cybersecurity agency, CISA, publishes security advisories about medical devices and the systems that support them. Advisories are disclosures of flaws, not attacks. CISA put out 24 medical device advisories whose ID carries the year 2025. That equals the 2020 count and is below the 2018 high of 31. The low since 2017 was 10, with a 2023 ID.
| Year in advisory ID | Advisories | Note |
|---|---|---|
| 2016 | 4 | Part year: first advisory 2016-03-29 |
| 2017 | 16 | — |
| 2018 | 31 | — |
| 2019 | 20 | — |
| 2020 | 24 | — |
| 2021 | 19 | — |
| 2022 | 15 | — |
| 2023 | 10 | CISA's release-year filter returns 11; this table uses the ID year |
| 2024 | 13 | — |
| 2025 | 24 | — |
| 2026 | 15 | To 2026-10-09 (latest ICSMA-26-253-02) |
| Total | 191 |
Source: The PenTest Index count of CISA ICS Medical Advisories (191 in all), checked October 9, 2026. We counted 188 unique ICSMA records in CISA's pinned CSAF repository and added 3 legacy advisories from CISA's website that are missing from the repository. Those 191 records match the live listing. Each advisory is counted once, by the year in its ID; all records are in the source CSV.

In December 2023, the U.S. Government Accountability Office wrote: "Although cyber incidents impacting medical devices have occurred, they are not common." That assessment predates the 2025 and 2026 surveys.
Why this matters now
The rules are moving on several fronts at once. FDA revised its premarket guidance on February 3, 2026. FDA's window for declarations of conformity to CVSS v3.0 closes on December 20, 2026, 72 days after our check. The EU and the UK both have new rules pending.
| Change | Date shown | Source |
|---|---|---|
| End of FDA's window for declarations of conformity to CVSS v3.0 | December 20, 2026 | FDA record 13-116 |
| Great Britain: draft device regulations and planned MHRA cybersecurity guidance | Draft notified May 8, 2026. Government says further details of the cybersecurity guidance work will be shared by Spring 2027 | WTO draft; MHRA notice (May 11, 2026); UK government response (October 6, 2026), recommendation 10 |
| EU proposal: report actively exploited vulnerabilities and severe incidents within 30 days of awareness; existing serious-incident duties still apply | Proposed December 16, 2025; awaiting committee decision at this check | COM(2025) 1023, proposed Article 87a; Parliament procedure 2025/0404(COD) |
| Australia: Essential Principles reform | "implementation anticipated in 2027" | TGA consultation page (updated September 22, 2026) |
| ISO 81001-5-2, security risk management for manufacturers | Committee draft; no publication date stated on the reviewed ISO record | ISO/CD 81001-5-2 project record |
| Standards-body adoption of a standard based on IEC 81001-5-1 for the EU request | Adoption deadline May 27, 2028; not a guaranteed harmonisation date | C(2024) 3371, Annex I, Table 2, entry 50 |
| IEC 62443-4-1 Edition 2 | Forecast April 2028 | IEC project page |
| IEC 81001-5-1 Edition 2 | Forecast August 2028 | IEC project page |
| IEC 62304 Edition 2 | Forecast October 2028 | IEC project page |
| IMDRF: baseline cybersecurity controls and testing | Work item approved September 2025; no draft linked on the working-group page at this check | IMDRF 28th Session Outcome Statement; current working-group page |
Source: as listed in each row; forecast dates move. Checked October 9, 2026.
How we built this
We checked the sources on October 9, 2026. The download records the source and check date for each result.
- FDA's database. We ran five keyword searches ("security," "cybersecurity," "cyber," "vulnerability," "threat"), which returned 97 different records. We then downloaded all 1,738 records and selected titles containing "security" (including "cybersecurity") or a vulnerability term. The case-insensitive rule
security|vulnerabilitreturns 24. The same title rule on the 31 results for "524B" returns the same 24. We opened all 24 detail pages and checked the title, entry date, recognition scope and warning. The download includes the full 1,738-row denominator and the 31-record check. - 11 jurisdictions. We searched the specified official guidance, software documents, standards lists and voluntary-scheme documents recorded in the source manifest. We checked 31 standards and frameworks against these sets: 341 cells. National adoptions count where their identity was verified. A whole-series mention does not count for a specific part. The long CSV gives the document, source, match or absence and note for every cell. The sets differ by jurisdiction; this is a document comparison, not a ranking of legal strictness.
- 17 legal and regulatory texts. We searched the full specified versions for penetration-testing terms or local-language equivalents, with the exact terms and sources in the download. This includes the current Great Britain regulations, one Great Britain draft and the Korean notification named in Table 6. The Brazilian resolutions are their original published texts, and the Saudi requirements are the specified v6 text. This is not a search of every later amendment. A zero word count does not establish that testing is unnecessary under broader duties.
- Publisher catalogs and previews. We checked editions, withdrawals, formats, page counts and prices on primary publisher pages. For penetration-testing coverage, the two IEC/ISA rows have public contents clauses; the two UL rows have an official publisher explanation. We did not buy or review the complete paid standards.
- Guidance versions. We read the current FDA PDF and archived official 2023 and 2025 PDFs. We compared the penetration-testing paragraph and five report elements, not the whole testing section. The comparison file records those exact passages and source hashes.
- CISA. We counted 188 unique ICSMA advisory IDs in the pinned official CSAF repository and checked all 188 files against their Git blob hashes. We added three legacy medical advisories from CISA's own website that the repository omits. The 191-row source file reproduces every annual total by the year in the ID.
- Repeated statistics. We traced the six claims to the original reports or releases we could read. We recomputed the Health-ISAC increase from its published counts. The vendors do not publish the underlying observations or survey responses needed to recalculate their percentages. Sensato's average and the alleged FDA estimate are labeled unusable as supported device statistics.
- Final checks. We recalculated our own totals, derived percentages, date gaps, price sums, matrix subsets and chart values from the delivered files. We checked that the finder rules, tables, chart specs and datasets agree. The calculation snapshot and reproduction script record those checks.
For how The PenTest Index checks sources and dates across the site, see How It Works.
What this data does and does not show
This data shows what official documents say on one date. It does not show how reviewers apply them, and it doesn't decide which rules apply to a specific product.
- "24" is our count by our rule: security, cybersecurity or a vulnerability term in the title. FDA publishes no such count.
- The 24 records are 22 different standards. FDA accepts declarations of conformity to CVSS v3.0 only until December 20, 2026.
- FDA's caution sits on 31 records in all, not only the 24.
- "Named" does not mean "required." A mention of a whole series is not counted for any one part.
- We did not search the same kinds of document for every regulator. A regulator may name a standard somewhere we did not look.
- General cybersecurity laws, such as the EU's NIS2 Directive, are outside the country matrix.
- For paid standards we read public publisher catalog text and available previews, not the full paid text. UL coverage rests on its own explanation; unverified UL section numbers and page counts are omitted.
- Japanese, Korean, Chinese and Portuguese documents were read in the original. English wording for them is our translation unless an official English version exists.
- The legal search covers 17 specified legal and regulatory texts, including one Great Britain draft. The Brazilian resolutions are their original published texts; the Saudi requirements are the specified v6 text. The search is not a complete, consolidated inventory of all current rules or later amendments.
- Prices are individual electronic/PDF publisher list prices on the check date. Formats and verified user terms are listed in the price CSV. The USD conversion is an estimate at the stated exchange rate.
- The CISA count goes by the year in each advisory ID. 2016 and 2026 are part years. An advisory is not a count of attacks, unique vulnerabilities or affected devices.
- Third-party percentages are reported results, not estimates of the whole medical-device market. Their raw observations and survey responses are not public. The RunSafe releases were read; their full reports and questionnaires were not accessed.
- "Current edition" compares edition or version labels. It does not say FDA recognizes every later revision, correction or interpretation in the publisher's current file.
How to cite this page
The PenTest Index. "Medical device cybersecurity standards: the 24 FDA records and what 11 regulators name." Updated October 9, 2026. https://thepentestindex.com/research/medical-device-cybersecurity-standards/
You may reuse The PenTest Index's original compilation, counts and charts with credit to The PenTest Index by name; no link is required. Third-party titles, clause names, quotes and source material keep their own rights, attribution and terms. This permission covers only our contribution.
Download the data
Download all files: medical-device-cybersecurity-standards-data.zip (17 CSV files, a read-me and reproducible calculations). No form, no email. Every row carries its source and check date. The files contain our compilation, not copies of any standard.
fda-recognized-security-standards.csv — The 24 security standard records the FDA recognizes (24 rows).
standards.csv — The 31 standards and frameworks behind the Standards finder (31 rows).
regulator-standard-matrix-wide.csv — 31 standards by 11 regulators, one row per standard (31 rows; 341 cells).
regulator-standard-matrix.csv — The same 341 cells in long form, one row per cell, with the documents searched for each regulator (341 rows).
regulators.csv — The 11 regulators: binding rule, guidance, what each does with standards, penetration testing wording (11 rows).
penetration-testing-wording.csv — Penetration testing wording in guidance, plus the 17 legal and regulatory texts searched (32 rows).
fda-cybersecurity-guidance-timeline.csv — FDA's main premarket and postmarket cybersecurity guidance since 2005 (11 rows).
cisa-medical-advisories-by-year.csv — CISA ICS medical advisories by year in the advisory ID (11 rows).
repeated-statistics-traced.csv — Six often-repeated statistics traced to their sources (6 rows).
Source files for reproducing the counts
- fda-recognized-all-records.csv — 1,738 data rows.
- fda-524b-record-evidence.csv — 31 data rows.
- cisa-medical-advisory-records.csv — 191 data rows.
- publisher-price-evidence.csv — 14 data rows.
- eu-mdr-harmonised-entries.csv — 70 data rows.
- exchange-rate-used.csv — 1 data row.
- regulator-source-manifest.csv — 67 data rows.
- penetration-testing-search-evidence.csv — 17 data rows.
The data ZIP also includes calculation-snapshot.json, the FDA paragraph comparison, the pinned CISA snapshot, the legal-search method, reproduce.py and rebuild_charts.py. These files reproduce the stated selection rules and arithmetic; they do not contain full paid standards.
Questions people ask
What is the FDA's cybersecurity guidance for medical devices in 2026?
The FDA's current premarket guidance is "Cybersecurity in Medical Devices: Quality Management System Considerations and Content of Premarket Submissions," dated February 3, 2026. It revises the June 27, 2025 version. A separate guidance from December 28, 2016 covers devices already on the market.
What is a cyber device per FDA?
A cyber device meets 3 tests in section 524B. It includes software validated, installed or authorized by the sponsor; it can connect to the internet; and it has features validated, installed or authorized by the sponsor that could be open to cybersecurity threats. FDA includes USB and other hardware ports when they can connect to the internet; Bluetooth and Wi-Fi are also listed.
Does the FDA recognize cybersecurity standards?
The FDA does recognize cybersecurity standards. As of October 9, 2026, its database has 24 recognition records covering 22 distinct standards with security, cybersecurity or a vulnerability term in the title, by our count. They include IEC 81001-5-1, ANSI/AAMI SW96, AAMI TIR57, AAMI TIR97 and UL 2900-2-1. Each carries an FDA note that meeting it may not satisfy section 524B.
Does the FDA require cybersecurity details in medical device submissions?
The law has required cybersecurity details in covered submissions for cyber devices since March 29, 2023. It sets 4 requirements: a plan to address vulnerabilities and coordinate disclosure; processes that give reasonable assurance of security, with updates and patches; a software bill of materials; and anything more FDA requires by regulation.
What is FDA 510(k) penetration testing?
A 510(k) is one kind of FDA submission. Penetration testing is one of 4 kinds of security testing FDA's guidance lists "among others." FDA says the test report should cover 5 things: how independent and skilled the testers were, the scope, how long testing took, the methods, and the findings.
What is the difference between ISO 13485 and ISO 14971?
ISO 13485 is the quality management system standard. ISO 14971 is the risk management standard. Neither is a cybersecurity standard. All 11 regulators we checked name both.
Is IEC 81001-5-1 required by the FDA?
The FDA does not require IEC 81001-5-1. It has recognized it since December 19, 2022 (record 13-122), and using it is voluntary. FDA's guidance lists it among "Possible frameworks to consider." Japan is where we found a rule to attach proof of meeting its Japanese twin, JIS T 81001-5-1, for covered Class II, III and IV devices that use software and exchange data with other devices, networks or external media.
What is AAMI TIR57?
AAMI TIR57 is a technical report on security risk management for medical devices. The FDA has recognized it since June 27, 2016 (record 13-83). It is named by 8 of the 11 regulators we checked, counting Singapore's voluntary label scheme.
Is IEC 81001-5-1 harmonised under the EU MDR?
IEC 81001-5-1 is not harmonised under the EU's Medical Device Regulation. It is not among the 70 entries on the EU's harmonised list as of June 17, 2026. The standards bodies' adoption deadline for a standard based on it is May 27, 2028; that is not a promised harmonisation date.
Is ISO 27001 enough for a medical device?
ISO/IEC 27001 is not enough by itself for a medical device. It covers how a company manages information security, not how a product is built. It is not in FDA's recognized database, and 4 of the 11 regulators we checked name it.
Does a device with no network connection still need cybersecurity work?
A device with no network connection can still fall under FDA's cybersecurity guidance. The guidance applies to "devices with cybersecurity considerations" and is "not limited to devices that are network-enabled." The law's stricter "cyber device" rules apply only to devices that meet its 3 tests.
Does the FDA require an ISO 13485 certificate?
The FDA does not require an ISO 13485 certificate. Since February 2, 2026, its Quality Management System Regulation incorporates ISO 13485:2016, but FDA says it "will not require certificates of conformance to ISO 13485."
Sources
Every source was checked on October 9, 2026.
-
FDA, Recognized Consensus Standards: Medical Devices (database; "Page Last Updated: 09/28/2026"). https://www.accessdata.fda.gov/scripts/cdrh/cfdocs/cfStandards/search.cfm. Checked October 9, 2026.
-
FDA database, keyword search "524B" (31 results). https://www.accessdata.fda.gov/scripts/cdrh/cfdocs/cfStandards/results.cfm?title=524B. Checked October 9, 2026.
-
FDA record 13-122, IEC 81001-5-1. https://www.accessdata.fda.gov/scripts/cdrh/cfdocs/cfStandards/detail.cfm?standard__identification_no=43889. Checked October 9, 2026.
-
FDA record 13-117, IEEE 11073-40101-2020 (partial recognition). https://www.accessdata.fda.gov/scripts/cdrh/cfdocs/cfStandards/detail.cfm?standard__identification_no=42310. Checked October 9, 2026.
-
FDA record 13-116, CVSS v3.0 (transition note). https://www.accessdata.fda.gov/scripts/cdrh/cfdocs/cfStandards/detail.cfm?standard__identification_no=46348. Checked October 9, 2026.
-
FDA record 13-142, CVSS v3.1 (transition note). https://www.accessdata.fda.gov/scripts/cdrh/cfdocs/cfStandards/detail.cfm?standard__identification_no=47095. Checked October 9, 2026.
-
FDA record 13-38, IEC 80001-1 Edition 1.0. https://www.accessdata.fda.gov/scripts/cdrh/cfdocs/cfStandards/detail.cfm?standard__identification_no=37083. Checked October 9, 2026.
-
FDA record 5-125, ISO 14971:2019. https://www.accessdata.fda.gov/scripts/cdrh/cfdocs/cfStandards/detail.cfm?standard__identification_no=41349. Checked October 9, 2026.
-
FDA record 13-79, IEC 62304 Edition 1.1. https://www.accessdata.fda.gov/scripts/cdrh/cfdocs/cfStandards/detail.cfm?standard__identification_no=38829. Checked October 9, 2026.
-
FDA, Non-Recognized Standards table. https://www.accessdata.fda.gov/scripts/cdrh/cfdocs/cfStandards/nr_results.cfm. Checked October 9, 2026.
-
FDA, Division of Standards and Conformity Assessment (what recognition means). https://www.fda.gov/medical-devices/premarket-submissions-selecting-and-preparing-correct-submission/division-standards-and-conformity-assessment. Checked October 9, 2026.
-
Federal Register, FDA Recognition List Number 066, 91 FR 54715 (August 24, 2026). https://www.govinfo.gov/content/pkg/FR-2026-08-24/html/2026-17229.htm. Checked October 9, 2026.
-
Public Law 117-328, section 3305 (FD&C Act section 524B; 21 U.S.C. 360n-2). https://www.govinfo.gov/content/pkg/PLAW-117publ328/html/PLAW-117publ328.htm. Checked October 9, 2026.
-
FDA, Cybersecurity in Medical Devices: Quality Management System Considerations and Content of Premarket Submissions (February 3, 2026), guidance page. https://www.fda.gov/regulatory-information/search-fda-guidance-documents/cybersecurity-medical-devices-quality-management-system-considerations-and-content-premarket. Checked October 9, 2026.
-
FDA, same guidance, PDF (Sections II, V.C, VII; footnotes 48 and 52). https://www.fda.gov/media/119933/download. Checked October 9, 2026.
-
FDA, Postmarket Management of Cybersecurity in Medical Devices (December 28, 2016). https://www.fda.gov/media/95862/download. Checked October 9, 2026.
-
FDA, Quality Management System Regulation: Frequently Asked Questions. https://www.fda.gov/medical-devices/quality-management-system-regulation-qmsr/quality-management-system-regulation-frequently-asked-questions. Checked October 9, 2026.
-
FDA, Withdrawn or Expired Guidance. https://www.fda.gov/medical-devices/guidance-documents-medical-devices-and-radiation-emitting-products/withdrawn-or-expired-guidance. Checked October 9, 2026.
-
Federal Register, FDA guidance notices: 78 FR 35940; 79 FR 59493; 81 FR 3803; 81 FR 95617; 83 FR 52835; 87 FR 20873; 88 FR 19148; 88 FR 66458; 89 FR 18421; 90 FR 27634 (links in fda-cybersecurity-guidance-timeline.csv). https://www.federalregister.gov/citation/88-FR-19148. Checked October 9, 2026.
-
Regulation (EU) 2017/745 (MDR), consolidated July 19, 2026. https://op.europa.eu/o/opportal-service/download-handler?identifier=e56fc708-95ab-11f1-9262-01aa75ed71a1&format=pdfa2a&language=en&productionSystem=cellar&part=. Checked October 9, 2026.
-
Regulation (EU) 2017/746 (IVDR), consolidated January 10, 2025. https://op.europa.eu/o/opportal-service/download-handler?identifier=bb7d3f94-cd06-11ef-be2a-01aa75ed71a1&format=pdfa2a&language=en&productionSystem=cellar&part=. Checked October 9, 2026.
-
Commission Implementing Decision (EU) 2021/1182, consolidated June 17, 2026 (harmonised standards under the MDR). https://op.europa.eu/o/opportal-service/download-handler?identifier=a74b24b7-74b8-11f1-bf5e-01aa75ed71a1&format=pdfa2a&language=en&productionSystem=cellar&part=. Checked October 9, 2026.
-
European Commission, standardisation request M/575 and amendment C(2024) 3371. https://ec.europa.eu/growth/tools-databases/enorm/mandate/575_en. Checked October 9, 2026.
-
MDCG 2019-16 Rev.1, Guidance on Cybersecurity for medical devices. https://health.ec.europa.eu/document/download/b23b362f-8a56-434c-922a-5b3ca4d0a7a1_en?filename=md_cybersecurity_en.pdf. Checked October 9, 2026.
-
IG-NB, Questionnaire "Cybersecurity for Medical Devices - Audit", version 2 (February 25, 2025). https://www.ig-nb.de/fileadmin/user_upload/ig-nb/2025_Questionnaire_Cybersecurity_for_Medical_Devices_-Audit-_Version_2.pdf. Checked October 9, 2026.
-
Team-NB, Position Paper on Cyber Security (October 5, 2022). https://www.team-nb.org/wp-content/uploads/members/M2022/Team-NB-PositionPaper-CyberSecurity-V1-20221005.pdf. Checked October 9, 2026.
-
European Commission, COM(2025) 1023 (December 16, 2025). https://www.europarl.europa.eu/RegData/docs_autres_institutions/commission_europeenne/com/2025/1023/COM_COM%282025%291023_EN.pdf. Checked October 9, 2026.
-
Directive (EU) 2022/2555 (NIS2), recital 58. https://eur-lex.europa.eu/legal-content/EN/ALL/?uri=CELEX:32022L2555. Checked October 9, 2026.
-
Japan MHLW, Notification PSEHB/MDED No. 0331-8 (March 31, 2023), provisional English translation. https://www.mhlw.go.jp/content/11120000/001203128.pdf. Checked October 9, 2026.
-
Japan MHLW, medical device cybersecurity page (manufacturer guide; Q&A of January 31, 2024). https://www.mhlw.go.jp/stf/seisakunitsuite/bunya/0000179749_00009.html. Checked October 9, 2026.
-
PMDA, Basic concept for medical device regulation in Japan (device classes). https://www.std.pmda.go.jp/scripts/stdDB_en/refetc/stdDB_refetc_sum_absbttm.cgi?absdisp=1. Checked October 9, 2026.
-
Japanese Standards Association, JIS T 81001-5-1:2023 record. https://webdesk.jsa.or.jp/books/W11M0090/index/?bunsyo_id=JIS+T+81001-5-1%3A2023. Checked October 9, 2026.
-
Health Canada, Pre-market Requirements for Medical Device Cybersecurity (2019). https://www.canada.ca/en/health-canada/services/drugs-health-products/medical-devices/application-information/guidance-documents/cybersecurity/document.html. Checked October 9, 2026.
-
Canada, Medical Devices Regulations (SOR/98-282). https://laws-lois.justice.gc.ca/eng/regulations/SOR-98-282/FullText.html. Checked October 9, 2026.
-
Australia TGA, Complying with medical device cyber security requirements. https://www.tga.gov.au/resources/guidance/complying-medical-device-cyber-security-requirements. Checked October 9, 2026.
-
Australia TGA, Standards for software-based medical devices. https://www.tga.gov.au/products/medical-devices/software-and-artificial-intelligence-ai/overview/standards-software-based-medical-devices. Checked October 9, 2026.
-
Australia TGA, Essential Principles consultation (results updated September 22, 2026). https://consultations.tga.gov.au/tga/aus-essential-principles-aligning-eu-regulation/. Checked October 9, 2026.
-
UK, Designated standards: medical devices. https://www.gov.uk/government/publications/designated-standards-medical-devices. Checked October 9, 2026.
-
UK, draft Medical Devices (Amendment) Regulations 2026, WTO notification. https://members.wto.org/crnattachments/2026/TBT/GBR/26_02425_00_e.pdf. Checked October 9, 2026.
-
UK government response on the regulation of AI in healthcare (October 6, 2026). https://www.gov.uk/government/publications/government-response-to-the-national-commissions-recommendations-on-the-regulation-of-ai-in-healthcare. Checked October 9, 2026.
-
Brazil ANVISA, Guia 38/2020. https://www.gov.br/anvisa/pt-br/assuntos/noticias-anvisa/2020/saiba-mais-sobre-ciberseguranca-em-dispositivos-medicos/guia-38.pdf/@@display-file/file. Checked October 9, 2026.
-
Brazil ANVISA, RDC 848/2024. https://www.in.gov.br/en/web/dou/-/resolucao-da-diretoria-colegiada-rdc-n-848-de-6-de-marco-de-2024-547032236. Checked October 9, 2026.
-
China CMDE, Guidelines for Registration Review of Medical Device Cybersecurity (2022 revision). https://www.cmde.org.cn/flfg/zdyz/zdyzwbk/20220309085900737.html. Checked October 9, 2026.
-
South Korea MFDS, cybersecurity approval and review guideline (January 10, 2025). https://www.mfds.go.kr/brd/m_1060/view.do?seq=15625. Checked October 9, 2026.
-
South Korea MFDS, companion guide (November 13, 2025). https://www.mfds.go.kr/brd/m_1060/view.do?seq=15757. Checked October 9, 2026.
-
Singapore HSA, GL-04-R4 Regulatory Guidelines for Software Medical Devices (December 2025). https://isomer-user-content.by.gov.sg/409/26808a93-6a7a-4551-8c66-13046c6124c5/gl-04-r4-regulatory-guidelines-for-software-medical-devices---a-life-cycle-approach-(2025-dec)-pub.pdf. Checked October 9, 2026.
-
Singapore CSA, Cybersecurity Labelling Scheme for Medical Devices. https://www.csa.gov.sg/our-programmes/certification-and-labelling-schemes/cls-md/about/. Checked October 9, 2026.
-
Saudi SFDA, MDS-G38 (cybersecurity guidance, 2019). https://sfda.gov.sa/sites/default/files/2019-10/MDS-G38.pdf. Checked October 9, 2026.
-
Saudi SFDA, MDS-G020 v3.0 recognised standards. https://www.sfda.gov.sa/en/guide/15903. Checked October 9, 2026.
-
Saudi SFDA, MDS-G23 (software guidance reprinting IMDRF documents). https://www.sfda.gov.sa/sites/default/files/2020-03/MDS_G23.pdf. Checked October 9, 2026.
-
IMDRF, Principles and Practices for Medical Device Cybersecurity (N60). https://www.imdrf.org/documents/principles-and-practices-medical-device-cybersecurity. Checked October 9, 2026.
-
IMDRF, Outcome Statement of the 28th Session (September 2025). https://www.imdrf.org/sites/default/files/2025-09/Japan%20Sapporo%20Outcome%20Statement%20%2828th%20Session%29.pdf. Checked October 9, 2026.
-
IEC Webstore, IEC 81001-5-1:2021 (corrected version 2025-12). https://webstore.iec.ch/en/publication/63293. Checked October 9, 2026.
-
IEC Webstore, IEC 81001-5-1:2021/ISH1:2025. https://webstore.iec.ch/en/publication/108664. Checked October 9, 2026.
-
IEC Webstore, IEC 62443-4-1:2018. https://webstore.iec.ch/en/publication/33615. Checked October 9, 2026.
-
IEC Webstore, IEC 80001-1:2021 (Edition 2.0). https://webstore.iec.ch/en/publication/34263. Checked October 9, 2026.
-
IEC Webstore, IEC TR 80001-2-2:2012 (withdrawn). https://webstore.iec.ch/en/publication/7484. Checked October 9, 2026.
-
IEC Webstore, IEC TR 80001-2-8:2016 (withdrawn). https://webstore.iec.ch/en/publication/24908. Checked October 9, 2026.
-
IEC Webstore, IEC TR 80001-2-9:2017 (withdrawn). https://webstore.iec.ch/en/publication/31953. Checked October 9, 2026.
-
IEC Webstore, IEC TS 81001-2-2:2025. https://webstore.iec.ch/en/publication/78673. Checked October 9, 2026.
-
ISO, ISO/IEC 29147:2018. https://www.iso.org/standard/72311.html. Checked October 9, 2026.
-
ISO, ISO/IEC 30111:2019. https://www.iso.org/standard/69725.html. Checked October 9, 2026.
-
ISO, ISO 14971:2019. https://www.iso.org/standard/72704.html. Checked October 9, 2026.
-
AAMI, ANSI/AAMI SW96:2023 (list price). https://array.aami.org/doi/full/10.2345/9781570208621.ch1. Checked October 9, 2026.
-
AAMI, AAMI TIR57:2016/(R)2023 (list price). https://array.aami.org/doi/full/10.2345/9781570206122.ch1. Checked October 9, 2026.
-
AAMI, AAMI TIR97:2019/(R)2023 (list price). https://array.aami.org/doi/full/10.2345/9781570207259.ch1. Checked October 9, 2026.
-
UL Standards & Engagement, UL 2900-1 Edition 2. https://www.shopulstandards.com/ProductDetail.aspx?productId=UL2900-1_2_S_20231213. Checked October 9, 2026.
-
UL Standards & Engagement, UL 2900-2-1 Edition 1. https://www.shopulstandards.com/ProductDetail.aspx?productId=UL2900-2-1_1_S_20170901. Checked October 9, 2026.
-
ISA, ANSI/ISA-62443-4-1-2018. https://www.isa.org/products/ansi-isa-62443-4-1-2018-security-for-industrial-au. Checked October 9, 2026.
-
NEMA, ANSI/NEMA HN 1-2019 (MDS2). https://www.makeitelectric.store/us/view-details/manufacturer-disclosure-statement-for-medical-device-security. Checked October 9, 2026.
-
CLSI, AUTO11. https://clsi.org/shop/standards/auto11/. Checked October 9, 2026.
-
FIRST, Common Vulnerability Scoring System. https://www.first.org/cvss/. Checked October 9, 2026.
-
Federal Reserve, H.10 Foreign Exchange Rates (release of October 5, 2026). https://www.federalreserve.gov/releases/h10/current/. Checked October 9, 2026.
-
CISA, ICS Medical Advisories. https://www.cisa.gov/news-events/ics-advisories?f%5B0%5D=ics_advisory_type%3A96. Checked October 9, 2026.
-
CISA, CSAF advisory repository. https://github.com/cisagov/CSAF. Checked October 9, 2026.
-
Cynerio, research release of January 19, 2022 (archived). https://web.archive.org/web/20230207111704/https://www.cynerio.com/blog/cynerio-research-finds-critical-medical-device-risks-continue-to-threaten-hospital-security-and-patient-safety. Checked October 9, 2026.
-
FBI, Private Industry Notification 20220912-001. https://www.ic3.gov/CSA/2022/220912.pdf. Checked October 9, 2026.
-
Health-ISAC, Finite State and Securin, 2023 State of Cybersecurity for Medical Devices and Healthcare Systems. https://health-isac.org/2023-state-of-cybersecurity-for-medical-devices-and-healthcare-systems/. Checked October 9, 2026.
-
Claroty, Team82 healthcare research release (March 26, 2025). https://claroty.com/press-releases/new-research-from-clarotys-team82-highlights-riskiest-medical-device-exposures-in-healthcare-environments. Checked October 9, 2026.
-
RunSafe Security, Medical Device Cybersecurity Index 2026 release. https://runsafesecurity.com/press-releases/medical-device-cybersecurity-index-2026/. Checked October 9, 2026.
-
U.S. Government Accountability Office, GAO-24-106683 (December 21, 2023). https://www.gao.gov/assets/gao-24-106683.pdf. Checked October 9, 2026.
-
European Commission, harmonised-standards scope and current publications. https://health.ec.europa.eu/medical-devices-topics-interest/harmonised-standards_en. Checked October 9, 2026.
-
European Commission, original M/575 request C(2021)2406. https://ec.europa.eu/transparency/documents-register/api/files/C%282021%292406_1/de00000001031154. Checked October 9, 2026.
-
European Commission, M/575 amendment C(2024)3371. https://ec.europa.eu/transparency/documents-register/api/files/C%282024%293371_1/de00000001064396?rendition=false. Checked October 9, 2026.
-
European Parliament, current procedure 2025/0404(COD). https://oeil.europarl.europa.eu/oeil/en/procedure-file?reference=2025%2F0404%28COD%29. Checked October 9, 2026.
-
ISO, ISO/CD 81001-5-2 project record. https://www.iso.org/standard/90129.html. Checked October 9, 2026.
-
IMDRF, current Medical Devices Cybersecurity Working Group. https://www.imdrf.org/working-groups/medical-devices-cybersecurity-working-group. Checked October 9, 2026.
-
UL, official penetration-testing explanation. https://www.ul.com/insights/medical-device-cybersecurity-standards-and-services. Checked October 9, 2026.
-
UL, Medical Device Cybersecurity Q&A. https://www.ul.com/resources/medical-device-cybersecurity-qa. Checked October 9, 2026.
-
UL, UL 2900-2-1 Secure PDF list price. https://www.shopulstandards.com/PurchaseProduct.aspx?UniqueKey=33295. Checked October 9, 2026.
-
UL, UL 2900-1 Secure PDF list price. https://www.shopulstandards.com/PurchaseProduct.aspx?UniqueKey=45541. Checked October 9, 2026.
-
INCITS/ANSI, current national adoption ISO/IEC 30111:2019 (2024). https://webstore.ansi.org/standards/incits/incitsisoiec3011120192024. Checked October 9, 2026.
-
Health-ISAC, full 2023 report. https://health-isac.org/wp-content/uploads/11883-StateMedSecurityReport_v6.pdf. Checked October 9, 2026.
-
Claroty, full 2025 healthcare report. https://web-assets.claroty.com/resource-downloads/state-of-cps-security-healthcare-2025.pdf. Checked October 9, 2026.
-
Sensato, February 7, 2018 claim source. https://www.sensato.co/post/endless-terrifying-possibilities-call-for-a-good-medical-device-cop. Checked October 9, 2026.
-
RunSafe, 2025 release. https://runsafesecurity.com/press-releases/2025-medical-device-cybersecurity-index/. Checked October 9, 2026.
-
FDA, archived September 2023 PDF. https://web.archive.org/web/20230926162534id_/https://www.fda.gov/media/119933/download. Checked October 9, 2026.
-
FDA, archived June 2025 PDF. https://web.archive.org/web/20250627223421id_/https://www.fda.gov/media/119933/download. Checked October 9, 2026.
-
UK, Medical Devices Regulations 2002 (SI 2002/618), revised text. https://www.legislation.gov.uk/uksi/2002/618/data.xht?view=snippet&wrap=true. Checked October 9, 2026.
-
South Korea, Digital Medical Products Act, Act No. 21525, effective October 8, 2026. https://www.law.go.kr/LSW/lsInfoR.do?lsiSeq=285333&efYd=20261008&chrClsCd=010202. Checked October 9, 2026.
-
South Korea MFDS, Notification 2025-30, effective April 29, 2025. https://www.law.go.kr/LSW/admRulLsInfoR.do?admRulSeq=2100000258410. Checked October 9, 2026.
-
South Korea MFDS, software-validation guideline 0095-02, July 28, 2026, PDF page 192. https://www.mfds.go.kr/brd/m_1060/down.do?brd_id=data0011&seq=15895&data_tp=A&file_seq=2. Checked October 9, 2026.
-
Saudi SFDA, MDS-REQ1 v6, Requirements for Medical Devices Marketing Authorization. https://www.sfda.gov.sa/sites/default/files/2021-12/REQ1En_0.pdf. Checked October 9, 2026.
-
China SAMR, primary mapping for YY/T 0664-2020 to IEC 62304:2015 (modified adoption). https://std.samr.gov.cn/dcpspTools/gbPlan/download?path=%2Fzxd%2F2021002339%2F20_%E6%A0%87%E5%87%86%E8%B5%B7%E8%8D%89%2F20_WD_2021002339_%E6%89%8B%E6%9C%AF%E6%A4%8D%E5%85%A5%E7%89%A9+%E6%9C%89%E6%BA%90%E6%A4%8D%E5%85%A5%E5%BC%8F%E5%8C%BB%E7%96%97%E5%99%A8%E6%A2%B0+%E7%AC%AC1%E9%83%A8%E5%88%86.pdf. Checked October 9, 2026.
-
China SAMR, GB/T 22080-2016 adoption and withdrawal record. https://std.samr.gov.cn/gb/search/gbDetailedCNF?id=71F772D812CCD3A7E05397BE0A0AB82A. Checked October 9, 2026.
The PenTest Index Research is the research and reference section of thepentestindex.com.