Standards Watch

Recent MD standards activity in IEC

10/9/20266 min read

Standards Watch: Software, Cybersecurity and AI Developments for Medical Device Manufacturers

Five projects to watch closely, plus an update on medical electrical safety and selected product-specific developments.

Information reviewed: 6 October 2026.

Several important standards projects are progressing together:

  • software lifecycle processes,

  • cybersecurity risk management,

  • AI testing,

  • AI-specific usability and

  • post-market surveillance of machine-learning devices.

For medical device and IVD manufacturers, these developments may affect

  • product design,

  • development processes,

  • risk management,

  • testing and

  • technical documentation.

Their relevance depends on the product and intended purpose. Lower regulatory classification does not, by itself, make them irrelevant.

These documents are drafts, and their contents may change before publication. My expectation is that many of the main themes will remain relevant, but the final wording and requirements are not yet confirmed. The summaries below describe the direction of the current work, not settled compliance obligations.

These projects do not amend the MDR or IVD and drafts do not confer presumption of conformity. Under these Regulations, that presumption depends on the applicable harmonised European standard being referenced in the Official Journal of the European Union and only covers the requirements addressed by that standard.

1. IEC 62304 Edition 2: Health software – Software life cycle processes

This would be my first priority for manufacturers developing medical device software or software-containing devices.

The current draft broadens the scope to health software and proposes replacing the three software safety classes with two software process rigour levels, I and II. These determine the applicable software lifecycle activities. They are separate from MDR and IVDR device classifications.

The revision also clarifies the relationship between software lifecycle activities and the quality and risk management processes applied to the product. The broader scope should therefore be understood alongside the manufacturer’s product-level responsibilities.

AI-enabled software remains relevant to the revision. The current draft includes planning for AI development and data management within software development planning, supported by an informative AI annex. The annex should not be interpreted as a complete framework for every aspect of the AI lifecycle.

Maintenance, re-release and retirement also receive attention.

Takeaway: Manufacturers should assess how existing software procedures and documentation would map to the proposed lifecycle and rigour model. Treat this as a process review, rather than assuming that updating terminology will be enough.

2. ISO 81001-5-2: Health software and health IT systems safety, effectiveness and security – Part 5-2: Security Risk Management for Manufacturers

This project develops a manufacturer-focused approach to security risk management across design, production and post-production activities.

Its main themes include identifying assets, threats and vulnerabilities:

  • Evaluating security risks,

  • Selecting and verifying controls and

  • Managing information and actions after release.

An important consideration is the connection between security risk management and safety risk management, while recognising that security consequences can extend beyond patient safety.

The project is particularly relevant alongside IEC 81001-5-1:2021, Health software and health IT systems safety, effectiveness and security – Part 5-1: Security – Activities in the product life cycle.

Takeaway: Manufacurers should review how threat modelling, security risk decisions, safety assessment, supply chain considerations and vulnerability handling connect within your existing processes. The interfaces between these activities deserve as much attention as the individual documents.

3. IEC 63450 Edition 1: Testing of Artificial Intelligence / Machine Learning-enabled Medical Devices

This project addresses testing of AI components in medical devices. It complements software testing and does not replace the complete device-development or clinical-evaluation process.

The current draft gives attention to test planning, representative data, separation of test data from training and tuning data, acceptance criteria, test records and re-testing after changes.

Its scope also includes considerations for continually learning models. These testing provisions should be assessed alongside the applicable regulatory requirements for device changes.

Clinical performance evaluation is outside the draft’s scope. Evidence from AI-component testing should therefore be considered as one part of the overall evidence needed for the device.

Takeaway: Examine whether the AI testing strategy provides credible, traceable evidence for the intended use. A single headline accuracy figure rarely explains the full picture.

4. IEC/IEEE 63685 Edition 1: Post-market surveillance of machine learning-enabled medical devices

This project addresses how post-market surveillance can account for the characteristics of machine-learning medical devices.

An important distinction is between locked and adaptive models. A locked model can experience declining real-world performance even when its software and model parameters remain unchanged. Input data, clinical practice, patient populations and operating environments can all change.

Adaptive models introduce additional considerations associated with model updates and the need to distinguish their effects from changes in data or the operating environment.

The draft considers monitoring proportionate to risk, performance criteria, relevant patient subgroups, data collection and human–AI interaction.

Takeaway: Manufacturers should consider post-market monitoring while developing the product. Access to suitable data, useful records and clear responsibilities should be planned before release.

5. IEC TS 62366-3 Edition 1: Medical devices – Part 3: Guidance for artificial intelligence-enabled medical devices

This proposed Technical Specification focuses on use-related safety when people interact with AI-enabled medical devices.

It considers how users understand AI-generated information, its limitations and uncertainty, and how the interface supports appropriate trust and action. Misunderstanding, over-reliance and inadequate communication can all affect safe use.

The proposed guidance complements the usability engineering framework. Its scope is limited to AI-related usability considerations. It does not replace AI performance validation or provide a complete AI compliance framewor

Takeaway: Manufacturers should include the interpretation of AI outputs in usability assessment. Safe interaction involves more than navigating screens and finding the correct button.

6. IEC 60601-1 Edition 4: Medical electrical equipment – Part 1: General requirements for basic safety and essential performance

Status update: The fourth edition is progressing through individual fragments.

Fragment 1. General requirements
Fragment 2: Physical environment hazard
Fragment 3: User interface hazards
Fragment 4: Materials hazards
Fragment 9: Optical radiation hazards
Fragment 10: Ionizing radiation hazards
Fragment 11: Electromagnetic exposure hazards

Only fragments currently visible are listed above.

The contents and implications of the fourth edition is addressed in a separate blog.

7. Important, but more product-specific

The following projects have a narrower product focus. For a manufacturer whose device falls within their scope, they can be just as important as the broader projects above.

  • IEC 60601-2-54 ED3: Medical electrical equipment – Part 2-54: Particular requirements for the basic safety and essential performance of X-ray equipment for radiography and radioscopy

  • IEC 60976 ED3: Medical electrical equipment – Medical electron accelerators – Functional performance characteristics

  • ISO 81060-7 ED1: Non-invasive sphygmomanometers – Part 7: Clinical performance verification of intermittent or repeated intermittent cuffless measurement type

  • ISO 27427 ED1: Anaesthetic and respiratory equipment – Nebulizing systems and components

Other recent standard contents still in draft status

  • IEC 60601-2-24 ED3: Medical electrical equipment – Part 2-24: Particular requirements for the basic safety and essential performance of infusion pumps and controllers

  • IEC 60601-2-18 ED4: Medical electrical equipment – Part 2-18: Particular requirements for the basic safety and essential performance of endoscopic equipment

  • IEC 80601-2-77 ED2: Medical electrical equipment – Part 2-77: Particular requirements for the basic safety and essential performance of robotically assisted surgical equipment

  • IEC 80601-2-78 ED2: Medical electrical equipment – Part 2-78: Particular requirements for basic safety and essential performance of medical robots for rehabilitation, assessment, compensation or alleviation

  • IEC 80601-2-86 ED1: Medical electrical equipment – Part 2-86: Particular requirements for the basic safety and essential performance of electrocardiographs, including diagnostic equipment, monitoring equipment, ambulatory equipment, electrodes, cables and leadwires

  • IEC 60601-2-36 ED3: Medical electrical equipment – Part 2-36: Particular requirements for the basic safety and essential performance of equipment for extracorporeally induced lithotripsy

  • IEC 62083/AMD1 ED3: Amendment 1 – Medical device software – Requirements for the safety of radiotherapy treatment planning systems

  • IEC 60601-2-92 ED1: Medical electrical equipment – Part 2-92: Particular requirements for the basic safety and essential performance of magnetic resonance guided radiotherapy equipment for use with external beam equipment

  • IEC 60731 ED4: Medical electrical equipment – Dosimeters with ionization chambers or solid-state detectors as used in radiotherapy

Prepare for upcoming standards

Karkinen Consulting has access to the relevant draft standards and can help you assess what the proposed requirements and changes could mean for your device or device family. Together, we can discuss potential implications for product design, development processes, risk management, testing and technical documentation.

There is no need to wait for publication before starting this discussion.

If your products and processes have been developed against an earlier edition, understanding the proposed changes now can help you identify potential gaps, plan resources and avoid unnecessary rework. Waiting until publication can leave less time to assess the changes and prepare their implementation.

My recommendation is to record relevant projects in the company’s Regulatory Requirements Register and not include draft standards there. Identify the potentially affected products and processes, assign an owner and review developments at the next milestone.

Note that publication alone does not automatically make a new edition mandatory for every manufacturer. The standard should have published first in the EU harmonsed standards list. The same applies to FDA recognized standards list. However, a published standard may be considered to represent State-Of-The-Art and thus should be carefully investigated.

Do not wait for the final publication to start understanding what may change.

Contact Karkinen Consulting to discuss which developments matter for your products and how to prepare.

Quality and Regulatory Consulting

Expert services in medical device regulation and quality compliance.

contact information

Karkinen Consulting Oy, Helsinki, Finland
Business ID: 3103786-9
info@karkinen.com

NATO NCAGE code A10CG

© 2026. All rights reserved.