Relationship to IEC 62443, ISO/IEC 27001, and EU MDR

IEC 81001-5-1:2021 · Standards landscape and regulatory context

Key point

IEC 81001-5-1 is a product security standard — it governs what the manufacturer builds into the software. It does not replace IEC 62443 (which addresses operational technology and network security), ISO/IEC 27001 (which addresses the organisation's information security management system), or EU MDR compliance. These standards operate at different layers and must all be addressed in a comprehensive cybersecurity programme.

IEC 62443 — Industrial automation and OT security

IEC 62443 is the international series of standards for security of industrial automation and control systems (IACS) — commonly referred to as operational technology (OT) security. While IEC 81001-5-1 addresses the security of the health software product itself, IEC 62443 addresses the security of the infrastructure in which that product is deployed: the hospital network, the medical device integration platform, the clinical workstations, and the communication protocols.

IEC 62443-4-1 (Product development requirements) is the most directly relevant part for health software manufacturers, as it defines security development lifecycle requirements for embedded and networked products. It was used as a key reference in the development of IEC 81001-5-1. Manufacturers who comply with IEC 81001-5-1 will find significant overlap with IEC 62443-4-1, but the two are not equivalent — IEC 62443-4-1 has a broader scope including firmware and hardware-level security considerations.

ISO/IEC 27001 — Information Security Management System

ISO/IEC 27001 is the standard for Information Security Management Systems (ISMS). It addresses the organisational practices and controls that protect the confidentiality, integrity, and availability of information assets — including the development environment, source code repositories, build pipelines, and deployment infrastructure.

ISO/IEC 27001 certification does not confer conformance with IEC 81001-5-1, and vice versa. However, an ISMS conforming to ISO/IEC 27001 provides an essential foundation: it ensures that the development environment itself is secure, that access to source code and build systems is controlled, that personnel are trained on security practices, and that security incidents in the development environment are detected and managed.

Many notified bodies and regulators expect health software manufacturers to have ISMS processes in place, even if formal ISO/IEC 27001 certification is not required. The overlap with IEC 81001-5-1 is most significant in the areas of secure development environment, access management, and personnel security.

EU MDR — GSPR 17 cybersecurity requirements

EU MDR 2017/745 Annex I GSPR 17 is the primary regulatory hook for cybersecurity in medical device software. GSPR 17.1 requires that devices designed to be connected to other devices or to IT infrastructure be designed and manufactured to operate safely given the foreseeable risks of such connectivity. GSPR 17.4 explicitly requires manufacturers to establish minimum IT security requirements for customers.

EN IEC 81001-5-1 was listed in the Official Journal of the European Union as a harmonised standard under MDR in 2023. Compliance with EN IEC 81001-5-1 creates a presumption of conformity with the cybersecurity-related GSPRs. Manufacturers who comply with the standard and document that compliance in their Technical Documentation should be able to demonstrate GSPR 17 conformance to their notified body.

NIS2 Directive (EU) 2022/2555

The NIS2 Directive creates cybersecurity obligations for "essential entities" in critical sectors, including healthcare. Hospitals, healthcare networks, and manufacturers of critical medical devices above certain size thresholds may be subject to NIS2 requirements. NIS2 obligations include: implementing risk management measures; reporting significant incidents to the national CSIRT within 24 hours; supply chain security management; and cybersecurity training for management.

FDA 2023 Cybersecurity Guidance

The FDA's "Cybersecurity in Medical Devices: Quality System Considerations and Content of Premarket Submissions" (September 2023) is the US regulatory framework for medical device cybersecurity. It requires: a Security Risk Management Report per product; an SBOM; a Vulnerability Management Plan; a Security Architecture Document; and evidence of cybersecurity testing. The FDA guidance aligns closely with IEC 81001-5-1 in its lifecycle approach and documentation expectations.

Standards comparison

StandardPrimary focusApplies toRelationship to IEC 81001-5-1
IEC 81001-5-1:2021Security of the health software product lifecycleHealth software manufacturersPrimary standard — this article's subject
IEC 62443-4-1:2018Secure product development lifecycle for IACSOT/ICS product manufacturersSignificant overlap; IEC 81001-5-1 adapted from this standard for health context
ISO/IEC 27001:2022Organisational ISMSAny organisation handling informationComplementary — secures the development organisation itself
EU MDR Annex I GSPR 17Regulatory requirement for medical device cybersecurityMedical device manufacturers placing on EU marketIEC 81001-5-1 is the harmonised standard addressing GSPR 17
NIS2 Directive 2022/2555Cybersecurity for critical infrastructure operatorsEssential and important entities in healthcare sectorIEC 81001-5-1 contributes to NIS2 compliance for device manufacturers
FDA Cybersecurity Guidance 2023Premarket cybersecurity requirements for US marketMedical device manufacturers for FDA clearance/approvalBroadly aligned; SBOM and security risk management requirements overlap
IMDRF N60 (2020)International cybersecurity principles for medical devicesGlobal regulatory harmonisationIEC 81001-5-1 implements IMDRF N60 principles in normative form

Practical implementation guidance

Health software manufacturers targeting both the EU and US markets should treat IEC 81001-5-1 as the primary technical standard for product security, supplemented by ISO/IEC 27001 for organisational security management. The SBOM, Security Risk Management Report, and CVD process are common requirements across EU MDR, FDA guidance, and IEC 81001-5-1, making these the highest-priority deliverables for any manufacturer without an existing cybersecurity programme.