ISO 27001

ISO 27001 is an international standard that specifies the requirements for an information security management system (ISMS): a structured set of policies, processes, and controls an organization uses to manage the confidentiality, integrity, and availability of its information. Published by ISO and IEC, it is certifiable and applies to any organization, including medical device companies and their suppliers.


What is ISO 27001?

ISO 27001, formally ISO/IEC 27001, defines how an organization establishes, operates, monitors, and improves an information security management system. The current edition is ISO/IEC 27001:2022, with Amendment 1:2024 adding requirements to consider climate change as part of the organizational context.

The standard pairs a management-system core (clauses 4 to 10, covering context, leadership, planning, support, operation, performance evaluation, and improvement) with a catalog of security controls in Annex A. It is risk-based: an organization decides which controls to apply by assessing its information security risks, and then records those decisions in a Statement of Applicability.


Why ISO 27001 matters in medical device development

Medical device work generates sensitive information that carries real safety and commercial weight: design history files, software source code for a medical device, manufacturing records, clinical and patient data, and supplier intellectual property. A breach can expose patient data, corrupt design records, or interrupt production.

Regulators and customers increasingly expect formal information security. The EU Medical Device Regulation (EU MDR 2017/745) sets cybersecurity expectations for connected devices, and FDA premarket guidance asks manufacturers to manage cybersecurity across the product lifecycle. An ISO 27001 certificate does not replace product-level cybersecurity work, but it demonstrates that the organization handling design, code, and patient data runs a disciplined ISMS. For OEMs selecting a contract partner, that certificate often shortens supplier due diligence and reduces audit findings tied to data handling.


How ISO 27001 works

The standard follows a plan-do-check-act cycle built around managed risk. The core requirements break down into a few stages:

  • Define scope and context: identify what information and systems the ISMS covers, plus internal and external factors, now including climate-related issues under Amendment 1:2024.
  • Assess and treat risk: identify information security risks, evaluate them, and select controls to reduce them to an acceptable level.
  • Select controls and document a Statement of Applicability: justify which Annex A controls apply and which do not. The 2022 edition reorganized Annex A into 93 controls across four themes (organizational, people, physical, technological).
  • Operate and monitor: run the controls, log security events, and measure effectiveness against objectives.
  • Audit and improve: conduct internal audits, hold management reviews, and correct nonconformities through corrective action.

Certification is granted by an accredited certification body after a two-stage audit, followed by periodic surveillance audits and recertification, typically on a three-year cycle. In a medical device setting, the ISMS usually runs alongside the ISO 13485 quality management system, and the two share evidence such as document control, training records, and supplier oversight.


Common challenges and best practices

The most common mistake is treating ISO 27001 as a cybersecurity product standard. It is not. ISO 27001 governs the organization’s information security, while device cybersecurity is addressed through standards and frameworks such as IEC 81001-5-1, AAMI TIR57, and IEC 62443, as well as the software lifecycle controls in IEC 62304. Teams that conflate the two leave gaps in their regulatory submissions.

Other common problems: scoping the ISMS too broadly and drowning in controls, writing a Statement of Applicability that nobody maintains, and collecting evidence only just before an audit. Good practice keeps scope tight and defensible, ties each control to a real risk, and integrates ISMS records with the existing ISO 13485 QMS so security and quality evidence are managed once, not twice. Aligning the risk approach with ISO 14971 thinking helps engineering and security teams speak a shared language.


How SJML helps with ISO 27001

Syrma Johari MedTech operates as an end-to-end medical device CDMO and is certified to recognized medical device quality and information security standards, including ISO 13485 and ISO 27001. That means design data, source code, manufacturing records, and client intellectual property are handled within a managed information security system rather than on an ad hoc basis. SJML’s QARA practice also supports device-level cybersecurity work, including IEC 81001-5-1 cybersecurity risk assessment and IEC 62304 software lifecycle activities, ensuring that organizational and product security are addressed together.

Talk to SJML’s QARA team →


Frequently asked questions

Is ISO 27001 the same as medical device cybersecurity?

No. ISO 27001 certifies an organization’s information security management system, covering how a company protects its data and systems. Medical device cybersecurity addresses the security of the device itself and is governed by standards such as IEC 81001-5-1 and IEC 62304, as well as FDA and EU MDR requirements. The two are complementary, not interchangeable.

What is the current version of ISO 27001?

The current edition is ISO/IEC 27001:2022, the third edition, with Amendment 1:2024 adding climate change considerations to the organizational context. The earlier 2013 edition is withdrawn, and the transition period for certified organizations closed at the end of October 2025, so all valid certifications now reference the 2022 edition.

Does a medical device manufacturer need ISO 27001?

It is not a legal requirement for placing a device on the market, but it is increasingly expected. OEMs and regulators want assurance that design data, patient information, and software are protected. Manufacturers handling connected devices, software as a medical device, or large volumes of clinical data often pursue certification to satisfy customer due diligence and reduce data-related audit risk.

How does ISO 27001 relate to ISO 13485?

ISO 27001 and ISO 13485 are separate standards with a shared management-system structure. ISO 13485 governs the quality management system for medical devices; ISO 27001 governs information security. Many companies run both together because they reuse common elements such as document control, internal audits, training records, corrective action, and supplier management, which lowers the cost of maintaining each.

Related terms

ISO 13485

IEC 62304

IEC 81001-5-1

Medical Device Cybersecurity

ISO 14971


Table of Contents

Free EU MDR Technical Documentation Compliance Checklist

Understand documentation gaps and use our single-window worksheet to prepare for Notified Body review.

Related Glossaries

Ask Sygma AI

AI-Powered Assistant

SJ Assistant