Blue Goat CyberBlue Goat CyberSMMedical Device Cybersecurity
    K
    Part ofThreat Modeling·Postmarket Cybersecurity
    Guide · Standards

    AAMI TIR57 vs TIR97: Medical Device Risk Management Guide

    Compare AAMI TIR57 vs TIR97. Learn how these cybersecurity risk management standards differ and how to apply them for FDA premarket and postmarket compliance.

    Hero illustration for the Standards article: AAMI TIR57 vs TIR97: Medical Device Risk Management Guide
    On this page
    Christian Espinosa, Founder & CEO at Blue Goat Cyber

    By Christian Espinosa, MBA, CISSP

    Founder & CEO · Blue Goat Cyber

    Key Takeaways

    • ANSI/AAMI SW96:2023 is now the current security risk management standard the FDA points to for premarket submissions; TIR57 is its historical predecessor and is being phased out of that role.
    • AAMI TIR97 is not a premarket alternative to SW96. It addresses postmarket security risk management, covering vulnerability monitoring, triage, and updates after a device ships.
    • Teams still find TIR57 useful as a readable explanation of security risk management concepts, but submissions built solely around it are increasingly likely to draw a deficiency asking for SW96 alignment.
    • SW96 and TIR97 are complementary, not competing: SW96 governs the premarket risk management process, TIR97 governs what happens once the device is in the field.
    • The practical move for most manufacturers is a single security risk management file that maps explicitly to SW96 for premarket activities and to TIR97 for the postmarket plan, rather than picking one document to satisfy both.
    TL;DR

    TIR57 and TIR97 answer different questions and were never meant to compete. TIR57 was AAMI's original security risk management guidance and has been superseded for premarket work by ANSI/AAMI SW96:2023, the standard the FDA's current guidance actually points to. TIR97 covers postmarket security risk management: what happens after the device ships. Most manufacturers need SW96 for premarket and TIR97 for postmarket, not TIR57 for either.

    Manufacturers frequently ask us to compare TIR57 and TIR97 as if they were two versions of the same standard, competing for the same slot in a submission. They are not. TIR57 was written to guide premarket security risk management and has, in practical terms, been superseded in that role by ANSI/AAMI SW96:2023. TIR97 was written to guide postmarket security risk management, a job neither TIR57 nor SW96 fully covers. Understanding that division, rather than treating this as a head-to-head standard comparison, is what actually prevents a deficiency.

    TIR57's historical role

    AAMI TIR57, "Principles for medical device security - Risk management," was published in 2016 and for several years functioned as the closest thing the industry had to a dedicated cybersecurity risk management framework built on top of ISO 14971. It introduced device manufacturers to security-specific concepts that ISO 14971's safety-oriented risk process did not natively cover: threat modeling, adversarial risk (as opposed to random failure risk), and the idea that a security risk assessment needs to account for an intelligent, motivated attacker rather than a probability distribution of component failures.

    TIR57 remains a useful, well-written explanation of those concepts, and many risk management procedures still cite it for definitions and rationale. What has changed is its standing as the document a submission should be built around. As the FDA's premarket cybersecurity expectations matured, especially with Section 524B and the enforcement of refuse-to-accept criteria for cyber devices, the agency's current guidance points to ANSI/AAMI SW96:2023 as the recognized consensus standard for premarket security risk management, not TIR57. A submission that leans entirely on TIR57 in 2026, without any reference to SW96, is increasingly likely to draw a question asking why the current standard was not used.

    ANSI/AAMI SW96:2023: the current premarket standard

    ANSI/AAMI SW96:2023, "Medical device security risk management," is the standard that formally succeeds TIR57's premarket role. It was developed specifically to align with the FDA's expectations under the February 3, 2026 premarket cybersecurity guidance and with the broader Secure Product Development Framework (SPDF) concept the agency expects manufacturers to demonstrate.

    SW96 formalizes what TIR57 introduced conceptually: a structured security risk management process that runs alongside ISO 14971 safety risk management, covers threat modeling, vulnerability assessment, and security control selection, and produces the traceable evidence a reviewer expects to find in a security risk management file. Where TIR57 explained the reasoning behind adversarial risk assessment, SW96 operationalizes it into a process manufacturers can point to as their premarket security risk management methodology, and it is the standard current FDA guidance recognizes for that purpose.

    AAMI TIR97: the postmarket standard

    AAMI TIR97, "Principles for medical device security - Postmarket risk management for device manufacturers," fills a gap that neither TIR57 nor SW96 was designed to address: what a manufacturer does with security risk management once the device is in the field. TIR97 covers:

    • Establishing an ongoing vulnerability monitoring process, including SBOM-driven CVE matching.
    • Triaging newly discovered vulnerabilities against the device's deployed configuration, the same discipline behind a VEX statement.
    • Determining when a vulnerability warrants a patch, a compensating control, or a documented decision not to act.
    • Coordinating with a coordinated vulnerability disclosure program to receive and process externally reported vulnerabilities.
    • Communicating with users, providers, and regulators when postmarket risk changes materially.

    None of this is premarket work. A manufacturer that has a rigorous SW96-based premarket security risk management file but no TIR97-aligned postmarket process has covered half the lifecycle. Section 524B's postmarket vulnerability management plan requirement is essentially asking for the process TIR97 describes, whether or not the submission cites TIR97 by name.

    Head-to-head: what each document is actually for

    Dimension AAMI TIR57 (historical) ANSI/AAMI SW96:2023 (current premarket) AAMI TIR97 (postmarket)
    Lifecycle phase Premarket (superseded in this role) Premarket Postmarket
    Current FDA recognition Referenced historically; not the current cited standard Current standard referenced in FDA's February 2026 guidance Recognized guidance for postmarket vulnerability management
    Core content Introduces adversarial risk concepts on top of ISO 14971 Formal premarket security risk management process and documentation Vulnerability monitoring, triage, patching decisions, disclosure coordination
    Relationship to ISO 14971 Extends ISO 14971 conceptually for security Runs as a parallel, integrated process alongside ISO 14971 Assumes a premarket risk baseline already exists; manages change to it over time
    Typical submission use Legacy citation; increasingly questioned if used alone Cited as the premarket security risk management methodology Cited as the basis for the postmarket vulnerability management plan
    Relationship to SBOM/VEX Not addressed Establishes risk categories that inform what needs monitoring Directly governs how SBOM and VEX outputs are triaged over time

    Why manufacturers still get this wrong

    The confusion is understandable. TIR57 and TIR97 share a naming convention and a publisher, and both use "risk management" in their titles, which invites the assumption that TIR97 is simply an updated TIR57. It is not an update to TIR57 at all; it is a postmarket-specific standard that was published to cover a lifecycle phase TIR57 never addressed. Meanwhile, SW96 actually is the premarket successor manufacturers should be citing, but because it has a different name and numbering convention (SW96, not a TIR number), teams searching for "the new TIR57" sometimes miss it entirely and end up citing TIR57 well past its useful life in a submission.

    What this means for your security risk management file

    The practical answer for most manufacturers is not to choose between TIR57, SW96, and TIR97. It is to build one security risk management file that:

    1. Uses ANSI/AAMI SW96:2023 as the premarket methodology, documenting threat modeling, security risk assessment, and control selection in the terms and structure SW96 defines.
    2. References TIR57 only for background and rationale, if at all, and does not present it as the current standard your process is built on.
    3. Uses AAMI TIR97 as the postmarket methodology, documenting your vulnerability monitoring cadence, triage process, and patch/notify decision criteria in a way that satisfies the Section 524B postmarket vulnerability management plan requirement.
    4. Keeps ISO 14971 as the governing safety risk framework, with SW96 and TIR97 integrated into it rather than run as disconnected parallel processes. See our companion guide on ISO 14971 vs. AAMI TIR57 hazard analysis for how the safety and security risk processes intersect.
    5. Traces every premarket risk decision forward into the postmarket plan, so a residual risk accepted at clearance has a defined postmarket monitoring trigger if new information changes that risk calculus.

    How Blue Goat Cyber approaches this

    We build security risk management files that cite ANSI/AAMI SW96:2023 as the premarket methodology and AAMI TIR97 as the postmarket methodology, rather than defaulting to whatever standard a legacy template happened to reference. For manufacturers still running a TIR57-based process, we assess how much of the existing analysis is salvageable and re-map it to SW96's structure rather than starting over, which is usually faster than a full rebuild. On the postmarket side, we tie the TIR97-aligned vulnerability management process directly into SBOM and VEX tooling so the monitoring commitment in your submission narrative reflects a system that is actually running, not a policy statement. This work is delivered through FDA Premarket Cybersecurity Services for the premarket side and FDA Postmarket Cybersecurity Services for the ongoing postmarket program.

    Where this fits in the cluster

    FAQ

    Is AAMI TIR57 still valid for FDA submissions?

    TIR57 has not been formally withdrawn, and it remains a reasonable reference for the concepts behind security risk management. However, it is no longer the standard the FDA's current guidance points to for premarket security risk management; that role now belongs to ANSI/AAMI SW96:2023. Submissions built solely around TIR57 in 2026 are more likely to draw a reviewer question asking for alignment with the current standard than submissions that cite SW96 directly.

    What is the difference between AAMI TIR57 and SW96?

    TIR57 introduced adversarial security risk management concepts as an extension of ISO 14971. SW96 is the formal standard that succeeds TIR57 in the premarket role, structuring those same concepts into a documented process and evidence set that aligns with current FDA premarket cybersecurity expectations. They cover similar territory conceptually; SW96 is the version manufacturers should be citing as their active methodology today.

    What is the difference between SW96 and TIR97?

    SW96 governs premarket security risk management: threat modeling, risk assessment, and control selection before a device is cleared. TIR97 governs postmarket security risk management: vulnerability monitoring, triage, patch decisions, and disclosure coordination after the device is in the field. They are not competing standards; a complete security risk management program uses both, for different phases of the same device lifecycle.

    Do I need both SW96 and TIR97 for FDA compliance?

    Most cyber devices need both in substance, even if a submission does not cite every standard by name. The February 3, 2026 premarket guidance expects a premarket security risk management process, which SW96 structures, and a postmarket vulnerability management plan under Section 524B, which TIR97 structures. Citing both standards explicitly in your submission narrative gives reviewers a recognized framework to check your process against rather than making them evaluate a bespoke approach from scratch.

    Should I rewrite my TIR57-based risk management file from scratch to use SW96?

    Usually not entirely. Most TIR57-based threat models and risk assessments contain analysis that is still valid; what typically needs to change is the structure, terminology, and evidence mapping so the file reads as SW96-aligned rather than TIR57-aligned. A gap assessment against SW96's specific process steps is the faster path, reserving a full rebuild for cases where the underlying analysis itself is thin or outdated.

    Sources & primary references

    Sources & references

    Primary sources cited in this article. Links open in a new tab.

    1. February 3, 2026 premarket cybersecurity guidance- U.S. FDA
    2. ANSI/AAMI SW96:2023, Medical device security risk management- AAMI
    3. ISO 14971:2019, Medical devices - Application of risk management to medical devices- ISO
    Related. Threat Modeling

    Continue exploring this topic

    Pillar
    Threat Modeling
    Article
    FMEA vs Threat Modeling for Medical Devices
    Article
    CAPA and Medical Device Cybersecurity
    Guide
    STRIDE for Medical Devices
    Related 524B & eSTAR resources

    Keep going: the 524B and eSTAR working set

    Start with the walkthrough hub, then drill into the statute, the eSTAR field map, SBOM monitoring, postmarket planning, and deficiency response. Use these as the playbook behind every cyber device submission.

    Hub
    FDA Section 524B & eSTAR Cybersecurity Walkthrough

    Start here: the hub that ties the statute, the February 2026 guidance, and the eSTAR fields together in the order a submission team works through them.

    Ready when you are

    Get FDA cleared without the cybersecurity headaches.

    30-minute strategy session. No cost, no commitment - just answers from people who've shipped 250+ FDA submissions.