Regulations / Medical devices
Regulations by jurisdiction
Medical devices: what binds a connected product
A connected device that diagnoses or treats is a medical device, and its cybersecurity is part of regulatory approval in both the US and the EU. The process standard both recognise is IEC 81001-5-1.
| Framework | Applies when | Who demands it | In force | Penalties |
|---|---|---|---|---|
| FDA premarket cybersecurity | Cyber devices submitted for FDA clearance or approval in the US | Regulatory approval | Statutory since 29 Mar 2023 | Refusal to accept the submission |
| IEC 81001-5-1 | Health software and connected medical devices | Regulatory approval; recognised by FDA and cited under EU MDR | 2021 edition current | None directly; used as evidence in submissions |
FDA premarket cybersecurity
Section 524B of the FD&C Act: a cybersecurity plan, SBOM, and post-market vulnerability process in every submission; 2023 and 2025 guidance.
IEC 81001-5-1
Security lifecycle activities for health software: requirements, design, implementation, verification, release, maintenance.
Comparisons
- FDA 524B vs IEC 81001-5-1 — Section 524B is the US legal requirement for a cyber device submission; IEC 81001-5-1 is the process standard the FDA recognises as evidence that the requirement is met.
Check your own product
The IoT security scorecard and the requirements generator resolve these frameworks for your product archetype and markets. Educational reference, not legal advice.
← All jurisdictions