| Part B: Supplementary Information Sheet (SIS) |
|
FR Recognition List Number
|
059
|
Date of Entry 12/19/2022
|
|
FR Recognition Number
|
13-122
|
| Standard | |
IEC 81001-5-1 Edition 1.0 2021-12 Health software and health IT systems safety, effectiveness and security - Part 5-1: Security - Activities in the product life cycle
|
|
Scope/Abstract| This document defines the LIFE CYCLE requirements for development and maintenance of HEALTH SOFTWARE needed to support conformance to IEC 62443-4-1 - taking the specific needs for HEALTH SOFTWARE into account. The set of PROCESSES, ACTIVITIES, and TASKS described in this document establishes a common framework for secure HEALTH SOFTWARE LIFE CYCLE PROCESSES. |
|
| Extent of Recognition
|
Rationale for Recognition
This standard is relevant to medical devices and is recognized on its scientific and technical merit and/or because it supports existing regulatory policies.
NOTE: Conformance to this standard may not satisfy all the cybersecurity requirements outlined in Section 524B of FD&C Act or the recommendations in the (1) listed below (Relevant FDA Guidance). Manufacturers should consider the information contained within these resources in their assessment of cybersecurity for their device. |
|
Relevant FDA Guidance and/or Supportive Publications*
1. Cybersecurity in Medical Devices: Quality Management System Considerations and Content of Premarket Submissions, Guidance for Industry and Food and Drug Administration Staff, issued February 2026.
2. Design Considerations and Pre-market Submission Recommendations for Interoperable Medical Devices, Guidance for Industry and Food and Drug Administration Staff, issued September 2017.
3. Off-The-Shelf Software Use in Medical Devices, Guidance for Industry and Food and Drug Administration Staff, issued August 2023.
4. Medical Device Data Systems, Medical Image Storage Devices, and Medical Image Communications Devices, Guidance for Industry and Food and Drug Administration Staff, issued September 2022.
5. Postmarket Management of Cybersecurity in Medical Devices - Guidance for Industry and Food and Drug Administration Staff, issued December 2016.
Appropriate Use of Voluntary Consensus Standards in Premarket Submissions for Medical Devices - Guidance for Industry and Food and Drug Administration Staff, issued September 2018. |
|
| FDA Technical Contact
|
| Standards Development Organization
|
| FDA Specialty Task Group (STG)
|
| *These are provided as examples and others may be applicable. |