Regulations / Medical devices

Regulations by jurisdiction

Medical devices: what binds a connected product

A connected device that diagnoses or treats is a medical device, and its cybersecurity is part of regulatory approval in both the US and the EU. The process standard both recognise is IEC 81001-5-1.

FrameworkApplies whenWho demands itIn forcePenalties
FDA premarket cybersecurityCyber devices submitted for FDA clearance or approval in the USRegulatory approvalStatutory since 29 Mar 2023Refusal to accept the submission
IEC 81001-5-1Health software and connected medical devicesRegulatory approval; recognised by FDA and cited under EU MDR2021 edition currentNone directly; used as evidence in submissions

FDA premarket cybersecurity

Section 524B of the FD&C Act: a cybersecurity plan, SBOM, and post-market vulnerability process in every submission; 2023 and 2025 guidance.

IEC 81001-5-1

Security lifecycle activities for health software: requirements, design, implementation, verification, release, maintenance.

Comparisons

Check your own product

The IoT security scorecard and the requirements generator resolve these frameworks for your product archetype and markets. Educational reference, not legal advice.

← All jurisdictions

© 2026 Yoel Frischoff / TheRoad. All rights reserved. · About the Book · Press · Teaching · Glossary · References · Privacy · Terms · Accessibility