Compare / FDA 524B vs IEC 81001-5-1
Regulation comparison
FDA 524B vs IEC 81001-5-1
Section 524B is the US legal requirement for a cyber device submission; IEC 81001-5-1 is the process standard the FDA recognises as evidence that the requirement is met. One says what must be in the file, the other says how to run a lifecycle that produces it.
| FDA premarket cybersecurity | IEC 81001-5-1 | |
|---|---|---|
| Applies when | Cyber devices submitted for FDA clearance or approval in the US | Health software and connected medical devices |
| Who demands it | Regulatory approval | Regulatory approval; recognised by FDA and cited under EU MDR |
| What it is | Statute plus guidance | Standard |
| Scope | Section 524B of the FD&C Act: a cybersecurity plan, SBOM, and post-market vulnerability process in every submission; 2023 and 2025 guidance | Security lifecycle activities for health software: requirements, design, implementation, verification, release, maintenance |
| In force | Statutory since 29 Mar 2023 | 2021 edition current |
| Penalties | Refusal to accept the submission | None directly; used as evidence in submissions |
| Authoritative text | FDA 524B text ↗ | IEC 81001-5-1 text ↗ |
What a product team should do
Run the IEC 81001-5-1 lifecycle from the first design review and the 524B submission writes itself: cybersecurity plan, SBOM, post-market process. The same file serves EU MDR submissions.
Check your own product
The IoT security scorecard grades a product against these frameworks in 19 questions, and the requirements generator turns the applicable ones into PRD-ready requirements. Both cite the same provisions this page does. The full map is on the regulatory landscape reference.
Sources: FDA premarket cybersecurity (official text) and IEC 81001-5-1 (official text). Educational reference, not legal advice. See Chapter 18 and Chapter 19 of Tangibles.
← All comparisons