IEC 81001-5-1:2021
IEC 81001-5-1 — Cybersecurity in Health Software
Security activities in the product lifecycle for health IT and medical device software
IEC 81001-5-1:2021 — IEC ↗IEC 62304 Software Safety Classifier
IEC 81001-5-1 applies to health software covered by IEC 62304. Classify your software first.
Article 1
What is IEC 81001-5-1 and who must comply?
Scope, applicability, and relationship to EU MDR GSPR 17 and NIS2.
Article 2
Security activities in the development lifecycle
From security planning to secure coding, testing, and release.
Article 3
Threat analysis and risk assessment (TARA)
How to identify threats, assess likelihood and impact, and define security controls.
Article 4
Vulnerability management and coordinated disclosure
Monitoring SOUP/OTS components, CVD process, and security advisories.
Article 5
Relationship to IEC 62443, ISO/IEC 27001, and EU MDR
How IEC 81001-5-1 fits into the broader regulatory and standards landscape.
Article 6
What does an auditor check for IEC 81001-5-1?
Key documentation, process evidence, and common nonconformities.