IEC 81001-5-1 cybersecurity for European health software
Asteron helps healthtech teams build the security activities, responsibilities and evidence required across the software product lifecycle. IEC 81001-5-1 connects cybersecurity to product planning, development, verification, release, maintenance and vulnerability response. The service is designed for European health software companies, including teams selling medical software and connected products in the Netherlands, Germany and other regulated healthcare markets.
- Security integrated into the product lifecycle
- Cybersecurity risks and requirements connected
- Verification and vulnerability evidence prepared
- Existing Compliance Core reused where applicable
€8,900 from an existing Compliance Core · €23,900 as a first ISO 27001 + IEC 81001-5-1 project
What is IEC 81001-5-1?
IEC 81001-5-1 is an international standard for security activities throughout the lifecycle of health software. It defines processes, activities and tasks for developing and maintaining software with cybersecurity built into the lifecycle rather than added shortly before release.
The standard addresses both the security of the software product and the security of the processes used to create and maintain it. This includes planning, requirements, architecture, implementation, verification, vulnerability handling, updates and the responsibilities that connect these activities.
IEC 81001-5-1 is relevant beyond a single penetration test. A penetration test examines an agreed product scope at a point in time; IEC 81001-5-1 establishes how cybersecurity is managed repeatedly across versions and throughout the supported life of the product.
IEC 81001-5-1 is a secure product-lifecycle standard. It is not an organisational ISMS, a one-off security test or automatic proof of compliance with MDR, IVDR or another regulation.
Who needs IEC 81001-5-1?
The standard applies where health software requires structured, repeatable cybersecurity engineering across versions and supported operation.
Medical device software manufacturers
Manufacturers of software as a medical device or software forming part of a medical device need repeatable cybersecurity activities that align with product development, risk management and regulatory evidence.
IVD software teams
Software supporting in vitro diagnostic products may need lifecycle security evidence alongside IEC 62304, ISO 14971, ISO 13485 and the applicable IVDR pathway.
Health software and connected platforms
The standard is also relevant to health software and health IT systems that may not be regulated as standalone medical devices but still require controlled security engineering and maintenance.
European market expansion
Dutch hospitals, German healthcare customers, notified bodies and enterprise buyers may examine how a supplier manages product cybersecurity over time. IEC 81001-5-1 provides a recognised lifecycle structure, but the exact contractual or regulatory expectation must be confirmed for each product and market.
The decision to implement IEC 81001-5-1 should follow the product’s intended use, regulatory status, architecture, connectivity, risks and customer requirements. Do not assume that every healthtech product is legally required to implement the standard.
What the secure lifecycle covers
A compliant lifecycle must connect security decisions from initial planning through supported operation. Producing isolated policies or test reports is not enough if the activities are not integrated into the product-development process.
Security planning and governance
Define lifecycle responsibilities, required security activities, review points, tools, competence and the records needed to demonstrate that work was performed. Product, engineering, quality, security and regulatory responsibilities must connect rather than operate as separate programmes.
Product-security risk management
Identify security risks arising from the product architecture, intended environment, interfaces, users, data and foreseeable threats. Security risk decisions should connect with product requirements and, for medical devices, the wider safety and risk-management process.
Security requirements and architecture
Translate relevant risks into testable security requirements and architectural decisions. This may include authentication, authorisation, data protection, trust boundaries, secure communication, update mechanisms, logging and product-specific misuse cases.
Secure implementation and verification
Define implementation practices, reviews and verification activities appropriate to the software and risk. Automated tools may support the process, but the organisation still needs evidence that requirements were verified and material findings were resolved or accepted appropriately.
Vulnerability and issue management
Establish how vulnerabilities are received, assessed, prioritised, communicated and corrected. Responsibilities must extend beyond the initial release and include third-party components and reported product-security issues.
Maintenance, updates and end of support
Security must remain controlled as the product changes. Update decisions, supported versions, security fixes, customer communication and end-of-support planning should follow an agreed lifecycle rather than ad hoc engineering decisions.
The exact activities and evidence depend on the product, development model, regulatory pathway and existing processes. Asteron maps the standard into the team’s real delivery workflow rather than creating a parallel documentation system.
Relevance for the Netherlands and Germany
Netherlands
Dutch hospitals and healthcare organisations may expect suppliers to demonstrate secure development, product maintenance and vulnerability handling in addition to organisational controls such as ISO 27001 or NEN 7510.
IEC 81001-5-1 can provide the product-lifecycle layer, while NEN 7510 addresses the Dutch healthcare information-security context. One does not replace the other.
Germany
German medical-software and DiGA teams may need structured cybersecurity evidence for the product, backend services and supported lifecycle. IEC 81001-5-1 can support that evidence alongside the applicable BSI, BfArM, MDR, IEC 62304 and ISO 14971 requirements.
The exact German assessment route depends on the product and intended market claim. IEC 81001-5-1 is not automatic DiGA approval or MDR conformity.
For companies operating across Europe, Asteron builds one reusable organisational and product-security foundation, then adds explicit country and product extensions where required.
How Asteron implements IEC 81001-5-1
Confirm the product and regulatory context
Asteron reviews intended use, software architecture, product classification, development model, supported environments and target markets.
We identify which organisational, quality and software-lifecycle processes already exist.
Map the existing lifecycle
Current security, engineering, quality and regulatory activities are mapped against IEC 81001-5-1.
Valid processes and evidence are reused; missing ownership, activities or records are documented.
Design the integrated secure lifecycle
Asteron defines the agreed security planning, risk, requirements, architecture, verification, vulnerability and maintenance activities.
Responsibilities and evidence are connected to the team’s actual product workflow and release cadence.
Implement and evidence the processes
Templates, records and working practices are introduced through practical workshops.
Existing product artefacts are updated where included, and client implementation actions are tracked with owners and deadlines.
Verify readiness
Asteron reviews the implemented lifecycle and evidence, supports internal review and prepares the team for the intended customer, auditor, notified-body or conformity-assessment discussion.
The external assessment decision remains with the independent reviewing organisation.
What Asteron delivers
The engagement creates an operable secure lifecycle and the supporting evidence needed for the agreed product scope. Deliverables may include:
- – IEC 81001-5-1 applicability and scope record
- – Mapping of existing lifecycle processes
- – Product-security management plan
- – Security roles and responsibilities
- – Security risk-management workflow
- – Security requirements and traceability structure
- – Architecture and security-review approach
- – Secure implementation and review practices
- – Security verification and testing strategy
- – Vulnerability intake and remediation process
- – Third-party component and dependency workflow
- – Security update and maintenance process
- – End-of-support security planning
- – Readiness review and prioritised action plan
The final deliverable set depends on the product, regulatory pathway and reusable processes already in place. It does not imply that every engagement includes preparation of the entire medical-device technical documentation file.
Two ways to implement IEC 81001-5-1
The price depends on the product, architecture, existing processes, regulatory pathway and how much of an existing Compliance Core can be reused.
For companies that already have a current Asteron Compliance Core. Organisational governance, risk, evidence and recurring processes are reused, reducing duplicate implementation work.
The project adds the health-software lifecycle security activities and evidence required for the agreed product scope.
This combines the first ISO 27001 Compliance Core with IEC 81001-5-1 implementation. It is intended for companies that need both an organisation-wide information-security system and a secure health-software lifecycle.
Prices reflect the approved starting point for the applicable company-size assumptions on the Pricing page. Larger, multi-product or more complex regulatory scopes are assessed individually.
If the engagement also requires ISO 13485, ISO 14971, IEC 62304 and coordinated MDR or IVDR work, see the Medical Device Track from €30,000.
Prices exclude VAT where applicable.
External assessment and certification boundaries
Asteron implements the processes, prepares the evidence and supports the team during the agreed assessment. Asteron does not act as the independent certification body, notified body or regulatory authority.
IEC 81001-5-1 does not always result in a separate accredited certificate. Evidence may instead be examined by a customer, notified body, certification body or another independent assessor as part of a wider product or management-system assessment.
Any external assessment, notified-body or certification-body fees remain separate and are contracted and paid directly by the client to the independent organisation.
Indicative ISO 27001 external certification-audit ranges
- – €4,500–6,000 for organisations with 10–50 employees
- – €6,000–9,000 for organisations with 51–150 employees
The certification body confirms its own final scope and price. These ranges do not cover notified-body medical-device assessment fees.
Payment terms for fixed-scope certification projects
- – 40% at signing
- – 40% when audit-ready
- – 20% after certification
For non-certification IEC 81001-5-1 engagements, milestones follow the individual proposal rather than a certification milestone.
What remains separate
Unless explicitly included, the following remain separate:
- – Medical-device or IVD classification decisions
- – Formal legal or regulatory opinions
- – Full ISO 13485, ISO 14971 or IEC 62304 implementation
- – MDR or IVDR technical-documentation delivery
- – Source-code remediation by the client’s engineering team
- – Penetration testing
- – Continuous Vulnerability Management
- – Independent notified-body or certification assessment
- – Product hosting or infrastructure implementation
Asteron can coordinate related work through the Medical Device Track, but these activities are not automatically included in the €8,900 framework extension.
Shared responsibilities
Asteron
Asteron maps the standard, designs the agreed lifecycle processes, prepares the included documentation and evidence structure, facilitates workshops and coordinates readiness activities.
Your team
The client provides product, architecture, development and regulatory information; assigns product and engineering owners; approves risk decisions; and implements technical changes allocated to its teams.
Management and the legal manufacturer remain accountable for product and regulatory decisions.
Frequently asked questions
What is IEC 81001-5-1?
It is an international standard defining security activities and tasks across the development and maintenance lifecycle of health software.
Is IEC 81001-5-1 only for medical devices?
No. It addresses health software and health IT systems more broadly, although it is particularly relevant to medical device and IVD software requiring structured cybersecurity evidence.
Is IEC 81001-5-1 a cybersecurity checklist?
No. It is a lifecycle process standard. It requires security activities, responsibilities and evidence to be integrated into development and maintenance.
How is it different from ISO 27001?
ISO 27001 governs information security across the organisation. IEC 81001-5-1 focuses on cybersecurity activities throughout the health-software product lifecycle.
How does it relate to IEC 62304?
IEC 62304 structures medical device software lifecycle processes. IEC 81001-5-1 adds dedicated security activities that should be integrated with those processes.
Does IEC 81001-5-1 guarantee MDR or IVDR compliance?
No. It may support cybersecurity evidence, but regulatory compliance depends on the product, classification, applicable legislation and complete conformity-assessment route.
Is the standard relevant in the Netherlands?
Yes. It can support healthtech suppliers that need to demonstrate controlled product-security processes to Dutch hospitals and healthcare customers. It does not replace NEN 7510.
Is it relevant for German healthtech and DiGA companies?
It can be relevant to the secure product lifecycle, but German DiGA and medical-device requirements must be assessed separately. The standard alone does not create DiGA approval.
Can an existing ISO 27001 system be reused?
Yes, when it is current and sufficiently aligned. Organisational governance, risk and evidence processes can reduce duplicate IEC 81001-5-1 implementation work.
How much does implementation cost?
The approved starting price is €8,900 from an existing Compliance Core or €23,900 for the combined first ISO 27001 and IEC 81001-5-1 project.
Does the price include penetration testing?
No. Security verification planning may be part of the lifecycle, but execution of a penetration test is a separately scoped technical service.
Does Asteron issue an IEC 81001-5-1 certificate?
No. Asteron implements the processes and prepares evidence. Any independent assessment or certification decision remains with the relevant external organisation.
Official references
- – IEC — IEC 81001-5-1:2021
- – European Commission — MDCG cybersecurity guidance for medical devices
- – IMDRF — Principles and Practices for Medical Device Cybersecurity
- – IEC — IEC 62304 medical device software lifecycle processes
- – ISO — ISO 14971 medical device risk management
Last reviewed: July 2026
Asteron is not endorsed by or partnered with IEC, ISO, IMDRF, the European Commission or any notified body.
Related services and frameworks
Build cybersecurity into the product lifecycle
Share the product architecture, development model, regulatory pathway and existing management systems. Asteron will determine what can be reused and define the right IEC 81001-5-1 implementation scope.
