Medtech Makers

Cybersecurity for Medtech Software: A Look at IEC 81001-5-1—A Medtech Makers Q&A

As more healthcare stakeholders become better educated on the need for cybersecurity, these standards become more important for developers.

Released By Eurofins Electrical & Electronics

By Sean Fenske, Editor-in-Chief

As the number of cyber attacks on healthcare facilities and the devices within continues to increase, the importance of cybersecurity becomes more pronounced. As such, regulatory agencies and standards organizations are putting out information, guidance, recommendations, and rules for its implementation. As such, medical device developers need to be well-informed on what they need to do to remain ahead of challenges.

One such standard is IEC 81001-5-1 which covers healthcare software. Regardless of how it is used—as part of a device or software as a medical device—the standard applies. Therefore, medtech manufacturers need to be aware of what this standard contains, how it could apply to them, and the ways in which they can verify compliance with it.

Fortunately, two representatives from Eurofins Electrical & Electronic Testing NA LLC took time to address a number of questions about this standard in the following Q&A. Junming Wang, Medical Chief, and Christopher Wyman, Director of Consumer Products, at the organization responded to inquires around what IEC 81001-5-1 covers, its impact, its relationship with regulatory agencies, and other relevant topics.

Sean Fenske: First, can you please explain what IEC 81001-5-1 is and what it covers?

Junming Wang: IEC 81001-5-1 is a process standard, specific to the necessary cybersecurity activities to be implemented during the health software development lifecycle. Health software consists of software as part of a medical device, software as a medical device, software as part of hardware specifically intended for health use, and a software-only product for other health use.

Fenske: What’s the direct impact of IEC 81001-5-1 on medical device manufacturers? What’s most important to them?

Christopher Wyman: The challenge for manufacturers is to start integrating cybersecurity into the software development lifecycle. Manufacturers must have a plan to add security controls at the start of development, document objective evidence of compliance, and construct a vulnerability assessment consisting of penetration testing.

Fenske: Are regulatory agencies following this standard? Is IEC 81001-5-1 relevant to FDA or MDR?

Wang: On Jun 27, 2025, FDA issued its final guidance “Cybersecurity in Medical Devices: Quality System Considerations and Content of Premarket Submissions,” in which the agency calls out IEC 81001-5-1 as “possible frameworks to consider”.

MDCG 2019-16 is the guidance for cybersecurity for medical devices, and EN 81001-5-1 was published in 2022. This standard is derived as an enhancement from IEC 62443-4-1:2018, “Security for industrial automation and control systems – Part 4-1: Secure product development lifecycle requirements.”

Wyman: The IEC 81001-5-1 framework has been recognized by most markets and medical regulatory agencies globally, including the U.S. FDA, EU Notified Bodies, and Japan PMDA. The standard is fast-moving toward complete harmonization within the next two years.

Fenske: How are software updates handled with IEC 81001-5-1? Does this standard address the launch of a device, or does it remain relevant throughout its lifetime?

Wang: IEC 81001-5-1 addresses the process throughout the service life of health software, including new design and modifications of the product on the market. Software updates are managed by regulations, not the standard. This standard addresses new medical devices, legacy medical devices, and post-market surveillance of these devices; how does the manufacturer maintain cyber compliance with threat modeling throughout the lifetime of the device?

Fenske: Can you speak more to how this standard impacts devices already on the market? How does the standard impact the cybersecurity of these devices?

Wyman: As Junming mentioned, the IEC 81001-5-1 standard impacts legacy devices on the market, not just new systems in product development. The regulators have introduced a transitional compliance framework. This transitional assessment differs from the full development lifecycle, which allows manufacturers to demonstrate secure maintenance activities. Manufacturers must assess the existing device, mitigate against the new requirements, and implement security controls to avoid any redesign of the system or software architecture. This allows manufacturers to remain on the market and continue distribution while coming online with the requirement risk assessment, which, in most cases, predates the new cybersecurity framework.

Fenske: What are the most important considerations for manufacturers developing new devices with regard to IEC 81001-5-1? What must they determine or identify before starting?

Wyman: Manufacturers should align the current risk management process within their quality management system (QMS). They should purchase a copy of the standard, read through the 64 specific requirements, and determine which apply or are already common in the software development lifecycle. All manufacturers need to provide objective evidence that is not self-validated with a vulnerability assessment and penetration testing, and also implement threat modeling. Manufacturers should start reviewing existing policies, procedures, and documentation of the process. Basically, they need to approach it the same way they would deal with current cybersecurity threats and provide post-market surveillance.

Fenske: Do you have any additional comments you’d like to share based on any of the topics we discussed or something you’d like to tell medical device manufacturers?

Wyman: The Eurofins Medical and Cybersecurity teams are working in a collaborative effort to provide evaluation services against IEC 81001-5-1. This process is no different from how the risk management file (RMF) checklists and documentation are required for medical base, collateral, and particular standard requirements. If manufacturers have issues meeting the cyber evaluation and report requirements, Eurofins Cybersecurity can seamlessly support the vulnerability assessment, penetration testing, and threat modeling analysis.

Click here to learn more about Eurofins Electrical & Electronic Testing NA LLC >>>>>

Request more information from Eurofins Electrical & Electronics

Keep Up With Our Content. Subscribe To Medical Product Outsourcing Newsletters