Glossary Updates12 new terms added to the glossaries · October 2, 2026, 22:44 CEST
AI TechDocKnowledge

Glossary · ISO and IEC standards for MedTech and pharma

IEC 81001-5-1

Also known as: IEC 81001-5-1:2021, EN IEC 81001-5-1, Health software security lifecycle

IEC 81001-5-1 is the international standard for security activities in the product life cycle of health software, including medical device software. It adds security requirements to the software development and maintenance processes, such as threat modeling, secure design and coding, security testing, vulnerability handling and security updates.

  • Standards
  • MDR
  • IVDR

In one sentence

IEC 81001-5-1:2021 defines security activities across the health software life cycle, from threat modeling to vulnerability handling and updates.

Example

A manufacturer of a networked insulin pump extends its IEC 62304 processes with threat modeling, a software bill of materials, penetration testing before release and a documented process for handling vulnerability reports from researchers.

How it applies

  • Legal hook: The GSPR in Annex I MDR and IVDR require software to be developed according to the state of the art, including information security, and set minimum IT security requirements. MDCG 2019-16 on cybersecurity describes how manufacturers can address them; see MDCG guidance.
  • Structure: The standard follows the process structure of IEC 62304 and adds security activities to each phase, so both can be run as one life cycle.
  • Activities: Security requirements, threat modeling, secure design, secure coding, security verification and testing, management of third-party components, security risk management, and post-release vulnerability handling and updates.
  • Security and safety: Security risks can lead to safety risks. The security risk assessment and the ISO 14971 risk analysis must be linked, but they are not the same analysis.
  • Technical documentation: Threat model, security requirements, test results, the list of software components and the vulnerability handling procedure are part of the software evidence; the instructions for use need the security information the operator must know.

IEC 81001-5-1 vs. IEC 62443

IEC 62443 is the series for industrial automation and control systems. IEC 81001-5-1 is based on the secure development lifecycle of IEC 62443-4-1 but adapted to health software and to the process structure of IEC 62304. A medical device manufacturer cites IEC 81001-5-1; a supplier of industrial components cites IEC 62443-4-1.

Compared with the Cyber Resilience Act

Products covered by the MDR or IVDR are excluded from the Cyber Resilience Act. Their cybersecurity is regulated through the device regulations, and IEC 81001-5-1 is one of the standards used to show it.

By knowledge.aitechdoc.world · Published September 25, 2026 · Last reviewed

Source: IEC 81001-5-1:2021, Health software and health IT systems safety, effectiveness and security — Part 5-1: Security — Activities in the product life cycle

Definitions follow the cited standards and specifications. Where a source is a copyrighted publication, such as an ISO, IEC or EN standard, the definition is a close paraphrase, not a verbatim quotation, so as not to infringe copyright. We recommend reading the original publication. The sections “How it applies” are editorial commentary by AI TechDoc Knowledge and are not part of any standard.

Seen a mistake? Send us a note!