Interactive tool
Medical device cybersecurity standards mapper
Pick a device type and a use case. The tool maps your profile onto the chain that matters, FD&C Act Section 524B, ANSI/AAMI SW96:2023, IEC 81001-5-1, IEC 62304, and ISO 14971, and tells you what each one obligates for that specific profile.
Step 1 of 3. Nothing is sent anywhere; the map is generated in your browser.
1. What kind of device is it?
This sets the essential performance you inherit as harm criteria and the starting software safety class.
How to read the verdicts
| Verdict | What it means for your file |
|---|---|
| Required | Binding for this profile. Missing evidence is a deficiency or a legal gap. |
| Expected | Not law, but the bar reviewers measure you against. Deviating needs a written rationale. |
| Conditional | Applies only under the condition noted. Document the decision either way. |
| Not applicable | Out of scope for this profile. Record why so the file shows it was considered. |
Frequently asked questions
Common questions on which standards bind, which are expected, and how they connect.
Related tools and guides
- Section 524B Applicability Checker for the formal cyber device determination.
- SPDF Gap Checker to score your secure development framework against IEC 81001-5-1.
- The MedTech Cybersecurity Standards Decoder for the narrative version of this map.
- IEC 60601 and cybersecurity for why the 60601 family sets no security requirements.
- Section 524B requirements explained for the statutory detail behind step one.
