Compare / FDA 524B vs IEC 81001-5-1

Regulation comparison

FDA 524B vs IEC 81001-5-1

Section 524B is the US legal requirement for a cyber device submission; IEC 81001-5-1 is the process standard the FDA recognises as evidence that the requirement is met. One says what must be in the file, the other says how to run a lifecycle that produces it.

FDA premarket cybersecurityIEC 81001-5-1
Applies whenCyber devices submitted for FDA clearance or approval in the USHealth software and connected medical devices
Who demands itRegulatory approvalRegulatory approval; recognised by FDA and cited under EU MDR
What it isStatute plus guidanceStandard
ScopeSection 524B of the FD&C Act: a cybersecurity plan, SBOM, and post-market vulnerability process in every submission; 2023 and 2025 guidanceSecurity lifecycle activities for health software: requirements, design, implementation, verification, release, maintenance
In forceStatutory since 29 Mar 20232021 edition current
PenaltiesRefusal to accept the submissionNone directly; used as evidence in submissions
Authoritative textFDA 524B text ↗IEC 81001-5-1 text ↗

What a product team should do

Run the IEC 81001-5-1 lifecycle from the first design review and the 524B submission writes itself: cybersecurity plan, SBOM, post-market process. The same file serves EU MDR submissions.

Check your own product

The IoT security scorecard grades a product against these frameworks in 19 questions, and the requirements generator turns the applicable ones into PRD-ready requirements. Both cite the same provisions this page does. The full map is on the regulatory landscape reference.

Sources: FDA premarket cybersecurity (official text) and IEC 81001-5-1 (official text). Educational reference, not legal advice. See Chapter 18 and Chapter 19 of Tangibles.

← All comparisons

© 2026 Yoel Frischoff / TheRoad. All rights reserved. · About the Book · Press · Teaching · Glossary · References · Privacy · Terms · Accessibility