Standards library
20 governed knowledge sources in 8 families under release FR-2026.1.
Sources
20
8 families
Effective
18
of 20 sources
Licensed
7
entitlement-gated
Not effective
2
draft or superseded
FDA guidance supersession
- KS-0002June 2025 (passed)
- KS-0001February 2026 (current)
- FR-2026.2impact assessed (pending)
Source families
Open a family for its governed sources.
- Use
- Premarket documentation, secure product development, vulnerability/patch plan, SBOM, labeling
- Control
- Controlled current release; prior releases superseded
FDA · Cybersecurity in Medical Devices: Quality Management System Considerations and Content of Premarket Submissions
KS-0001Final, February 2026Effectiveeffective 17 Feb 2026
FDA · Cybersecurity in Medical Devices: Quality Management System Considerations and Content of Premarket Submissions
KS-0002Final, June 2025Supersededeffective 27 Jun 2025
- Use
- Total product lifecycle and legacy-device cybersecurity
- Control
- Normative profile mapping by market
IMDRF · N60 — Principles and Practices for Medical Device Cybersecurity
KS-0003N60 (2020)Effectiveeffective 15 Jan 2026
IMDRF · N70 — Principles and Practices for the Cybersecurity of Legacy Medical Devices
KS-0004N70 (2023)Effectiveeffective 15 Jan 2026
- Use
- Cybersecurity under MDR/IVDR
- Control
- Guidance mapping
MDCG · MDCG 2019-16 — Guidance on Cybersecurity for Medical Devices
KS-0005Rev.1 (2020)Effectiveeffective 15 Jan 2026
- Use
- Safety-aware security risk and post-market risk management
- Control
- Licensed summaries and mappings
ISO · ISO 14971 — Application of risk management to medical devices
KS-00062019 + A11:2021Effectiveeffective 15 Jan 2026
AAMI · TIR57 — Principles for medical device security: Risk management
KS-00072016 (R2023)Effectiveeffective 15 Jan 2026
AAMI · TIR97 — Principles for medical device security: Postmarket risk management
KS-00082019 (R2023)Effectiveeffective 15 Jan 2026
- Use
- Health software security and software/product development lifecycle
- Control
- Licensed summaries and mappings
IEC · IEC 81001-5-1 — Health software and health IT systems safety, effectiveness and security
KS-00092021Effectiveeffective 15 Jan 2026
IEC · IEC 62304 — Medical device software lifecycle processes
KS-00102006 + A1:2015Effectiveeffective 15 Jan 2026
IEC · IEC 62443-4-1 — Secure product development lifecycle requirements
KS-00112018Effectiveeffective 15 Jan 2026
- Use
- Secure development practices and common vocabulary
- Control
- Final version normative; drafts tracked separately
NIST · SP 800-218 — Secure Software Development Framework (SSDF)
KS-0012Version 1.1Effectiveeffective 15 Jan 2026
NIST · SP 800-218A — SSDF profile for generative AI system development
KS-0013DraftIn revieweffective 04 May 2026
- Use
- Governance and control crosswalks
- Control
- Profile-dependent
NIST · Cybersecurity Framework (CSF)
KS-00142.0Effectiveeffective 15 Jan 2026
ISO/IEC · ISO/IEC 27001 — Information security management systems
KS-00152022Effectiveeffective 15 Jan 2026
NIST · SP 800-53 — Security and Privacy Controls
KS-0016Rev. 5Effectiveeffective 15 Jan 2026
- Use
- Threat enrichment, weakness references, and severity context
- Control
- Informative; not a substitute for patient-safety risk
MITRE · ATT&CK knowledge base
KS-0017v16Effectiveeffective 15 Jan 2026
OWASP · OWASP Top 10 and Application Security Verification Standard
KS-0018Top 10 (2021) / ASVS 4.0.3Effectiveeffective 15 Jan 2026
MITRE · CWE — Common Weakness Enumeration
KS-0019v4.15Effectiveeffective 15 Jan 2026
FIRST · CVSS — Common Vulnerability Scoring System
KS-0020v4.0Effectiveeffective 15 Jan 2026