Skip to main content
Leaving UL Solutions website
Within UL Solutions we provide a broad portfolio of offerings to all the medical device industries. This includes certification, Approved/Notified Body and consultancy services. In order to protect and prevent any conflict of interest, perception of conflict of interest and protection of both our brand and our customers brand, we have processes in place to identify and manage any potential conflicts of interest and maintain impartiality. UL Solutions is unable to provide consultancy services to EU MDD, MDR or IVDD Notified Body, UKCA MD Approved Body or MDSAP Customers.
  • Service

IEC 81001-5-1 Cybersecurity Compliance for Medical Devices

Support cybersecurity expectations for connected medical devices and global market access with services aligned to IEC 81001-5-1.

Two scientists in the lab viewing data on a laptop

Address cybersecurity expectations for connected medical devices and support global market access with IEC 81001-5-1 services from UL Solutions.

IEC 81001-5-1 services

UL Solutions offers a comprehensive service portfolio covering certification, testing, advisory, software, data insights, auditing and training. These services are designed to help global medical device manufacturers embed cybersecurity across the full product life cycle, from concept to decommissioning.

Medical devices are becoming increasingly connected, driven by digitalization, big data, AI and robotics. This connectivity introduces vulnerabilities that can affect both device performance, data security and patient safety. However, global regulators do not follow a single cybersecurity framework, which can add to complexity and additional cost for manufacturers placing products in multiple markets.

IEC 81001-5-1 is emerging as a reference framework for security activities in the medical device life cycle. When applied effectively, the standard can help manufacturers organize cybersecurity activities related to requirements across multiple medtech markets. The standard inherits its structure from IEC 62443 and IEC 62304, enabling medtech teams to work with familiar terminology and processes. It also introduces cybersecurity-specific tasks across the life cycle.

Our IEC 81001-5-1 services include support across the health software life cycle:

  • Advisory and governance – Quality management system (QMS), risk management, secure life cycle, threat modeling, and secure-by-design support.
  • Secure development – Security requirements, defense-in-depth architecture, and secure coding aligned to standards such as CERT secure coding guidance or MISRA guidelines.
  • Testing and verification – Vulnerability scanning, fuzzing, penetration testing, and software bill of materials (SBOM) and weakness analysis, with the independence the standard requires.
  • Certification – IEC 81001-5-1 certification via the IECEE CB Scheme or the UL Solutions Medical Cybersecurity Assurance Program (CAP). Medical CAP certification can also include UL 2900-2-1, the Standard for Software Cybersecurity for Network-Connectable Products, Part 2-1: Particular Requirements for Network Connectable Components of Healthcare and Wellness Systems, in a single certificate via the Medical CAP.
  • Post-market and training – Vulnerability management process review and refinement support, coordinated disclosure, security updates, and tailored training for engineering, quality, and regulatory teams.

Advantages of working with UL Solutions

  • Global coverage – IEC 81001-5-1 is referenced or used in several major markets, including the U.S., EU, U.K., Canada, Japan and China. UL Solutions can help manufacturers address market-specific cybersecurity expectations through a single, coordinated program.
  • Two standards, one certificate – Our Medical Cybersecurity Assurance Program (CAP) combines IEC 81001-5-1 (process-focused) and UL 2900-2-1 (testing-focused) — a U.S. Food and Drug Administration (FDA) consensus standard referenced in the IMDRF framework — in a single certificate, helping manufacturers reduce time and costs associated with compliance activities.
  • Familiar, integrated process – Built on IEC 62443 principles and the IEC 62304 structure, IEC 81001-5-1 aligns with ISO 13485, ISO 14971, IEC 62366 and EN 82304-1 to support a coordinated compliance approach. This structure may be familiar to medtech teams that already work with related medical device software, quality and risk management standards.
  • Beyond IEC 81001-5-1 – We also offer services that can help manufacturers address related cybersecurity frameworks and requirements — such as EU RED (EN 18031), EU CRA (prEN 40000), NIS2, and ISO 27001 — and support healthcare technologies that may not be regulated as medical devices themselves.
  • Independent, reproducible testing – UL Solutions offers medical and IoT cybersecurity testing capabilities in locations across North America, Europe and Asia, with testing independence considerations addressed according to IEC 81001-5-1 requirements.
  • Trusted testing, inspection and certification (TIC) leader – UL Solutions ranks No. 1 on brand strength out of 13 global TIC and adjacent category brands. UL Solutions also sits on more than 1,300+ standards panels and other technical committees, and ULTRUS® ComplianceWire® has delivered more than 835 million compliance trainings to healthcare and life sciences teams in 130+ countries.

FAQ

Q: Who does IEC 81001-5-1 apply to?  
A: IEC 81001-5-1 applies to organizations that develop health software, including software embedded in medical devices, standalone software as a medical device (SaMD) and other health IT systems. The standard addresses cybersecurity activities across the full product life cycle and within the software's intended environment of use.

Q: Is IEC 81001-5-1 conformance mandatory?  
A: It depends on the market. In Japan, conformity is a mandatory requirement for market approval. In the EU and U.K., IEC 81001-5-1 is regarded as a state-of-the-art standard for addressing MDR/IVDR cybersecurity requirements and is listed for future harmonization under EU MDR, with a target date of May 27, 2028. In the U.S. and Canada, regulators consider it a consensus standard that can support cybersecurity submissions and compliance activities. In China, it serves as a primary reference standard for Class II and Class III device evaluations.

Q: How does IEC 81001-5-1 relate to IEC 62304? 
A: IEC 81001-5-1 inherits its structure from IEC 62304, so the process and terminology may be familiar to medtech teams that already work with IEC 62304. The standard complements IEC 62304 by adding tasks specific to cybersecurity — at the development stage (secure requirements, defense-in-depth architecture, detailed design, secure coding) and at the testing stage (software, integration, and verification testing).

Q: How does IEC 81001-5-1 fit alongside ISO 13485, ISO 14971, and IEC 62304?  
A: Together, these standards form an integrated compliance framework under EU MDR Annex I: ISO 13485 covers quality management, ISO 14971 covers risk management, IEC 62304 covers software life cycle, and IEC 81001-5-1 addresses cybersecurity requirements within that life cycle. Together, these standards can support a coordinated approach to safety, usability and security.

Q: Does IEC 81001-5-1 cover testing?  
A: Yes. But from the perspective of requiring the presence of testing activities including Static Application Software Testing / Dynamic Application Software Testing (SAST / DAST), which can include vulnerability scanning, fuzzing, and penetration testing, where the independence of testing can support objectivity in the testing process.

Q: How does IEC 81001-5-1 relate to UL 2900-2-1?  
A: They complement each other. IEC 81001-5-1 primarily addresses security activities across the health software life cycle. UL 2900-2-1 covers both process and testable product requirements, including documentation and process assessment, software testing (known vulnerability, malware and weakness analysis) and product testing (security controls verification, fuzzing and penetration testing). The Medical Cybersecurity Assurance Program (CAP) enables manufacturers to demonstrate compliance with both standards through a single certification approach, based on the technical overlap between them. The IECEE CB Scheme allows demonstration of compliance to IEC 81001-5-1.

Q: Can one program address both U.S. FDA and EU MDR requirements?  
A: A coordinated program can help address overlapping FDA and EU MDR cybersecurity expectations across areas including quality management, risk management, software development life cycle (SDLC), threat modeling, cryptography, vulnerability management and testing, but manufacturers should confirm market-specific submission requirements. A program combining IEC 81001-5-1 process requirements with UL 2900-2-1 testing requirements can help address the documentation, process and testing expectations of both jurisdictions.

Q: What are the most common cybersecurity compliance failures we see?  
A: Two recurring misconceptions stand out. First, manufacturers sometimes assume that nonwireless ports (e.g., USB) or ports intended only for engineering or maintenance use fall outside the scope of cybersecurity requirements. Regulators may consider multiple types of connectivity, including internet-facing or internal, wireless or wired, user-facing or engineer-facing. Second, some manufacturers misinterpret the EU MDR's "state-of-the-art" requirement. It does not imply that no testing is needed. In practice, the term points to current, generally accepted good practice, which manufacturers can help demonstrate through testing aligned with applicable standards such as UL 2900-2-1.

Q: What does the standard expect after release?  
A: The standard requires structured security update processes including risk-based prioritization, vulnerability assessment, supplier and dependency updates, update communication and traceability. It also requires continuous security risk management including threat model maintenance, post-release monitoring and coordinated vulnerability disclosure.

Q: Where can UL Solutions deliver these services?  
A: Globally, across the U.S., United Kingdom, Germany, Italy, Poland, Greater China, Japan, South Korea and Singapore.

X

Get connected with our sales team

Thanks for your interest in our products and services. Let's collect some information so we can connect you with the right person.

Please wait…