IEC

International Electrotechnical Commission

InternationalInternationalStandards body

Consensus standards for medical electrical equipment (60601), device software life cycles (62304), and usability engineering (62366).

What this page does not claim

SPEQ curates and cross-references these bodies. It is not affiliated with, accredited by, or endorsed by any of them, and a count of decoded standards is a measure of SPEQ’s coverage, not of a body’s importance.

WHAT IEC COVERS

The International Electrotechnical Commission publishes standards for electrical, electronic, and related technologies. In the regulated space its standards govern medical electrical equipment safety, medical device software lifecycles, and usability engineering.

WHAT IEC PUBLISHES

  1. 01IEC 62304 — medical device software lifecycle processes, with safety classes A/B/C
  2. 02IEC 60601 series — safety and essential performance of medical electrical equipment
  3. 03IEC 62366-1 — usability engineering for medical devices
  4. 04IEC 61010 — safety for laboratory equipment
  5. 05IEC 80001 — risk management for IT networks incorporating medical devices

HOW ITS REQUIREMENTS BITE

Like ISO, IEC does not regulate. Its standards are applied through conformity assessment and become effectively binding when regulators reference them — IEC 60601 for electrical safety and IEC 62304 for software lifecycle are expected in device submissions in both the US and EU.

What practitioners get wrong

  • IEC 62304 safety classes A/B/C determine how much lifecycle rigour a software item needs — and the class is argued from what happens if the software fails, not from how complex it is.
  • IEC 62304 covers the software lifecycle; ISO 14971 covers the risk management that feeds it — you need both, and the classification depends on the 14971 analysis.
  • IEC 60601 has particular standards for specific device types layered on top of the general standard; meeting only the general standard is a common submission gap.
  • Usability engineering under IEC 62366-1 is frequently underdone, yet use-related hazards are a leading source of device incidents.
  • Software of unknown provenance — third-party libraries and OTS components — must be identified and risk-assessed, not silently inherited.

WHERE IT SITS INTERNATIONALLY

IEC works jointly with ISO in several areas, and its standards are widely harmonised under EU MDR and recognised by FDA as consensus standards. In practice a device software submission is built from an interlocking set — ISO 13485 for the quality system, ISO 14971 for risk, IEC 62304 for the lifecycle, and IEC 62366-1 for use — and a gap in any one of them shows up as a deficiency in the others.

IEC STANDARDS SPEQ DECODES · 9

DISCIPLINES IN IEC’S REMIT

TOPIC EXPLAINERS CITING IEC STANDARDS
Medical Device Quality System (ISO 13485 / QMSR)
ISO 13485, the FDA QMSR harmonisation with 21 CFR 820, device risk management (ISO 14971), and software (IEC 62304).
Software as a Medical Device (SaMD)
Software that is itself a medical device — the IMDRF definition, IEC 62304 lifecycle, ISO 14971 risk, EU MDR Rule 11, and how AI/ML changes the picture.
Human Factors and Usability Engineering (IEC 62366-1)
The engineering discipline, and the standard behind it, for designing medical devices so that intended users can operate them safely and effectively.
Medical Device Cybersecurity
The engineering and regulatory discipline for securing connected medical devices against cyber threats across their design, submission, and post-market lifecycle.
OT & ICS Security in Regulated Manufacturing
Securing the PLCs, DCS, SCADA and historians that run regulated production — where availability outranks confidentiality and a patch is a change.
Software Supply-Chain Security & SBOM
Third-party components, software bills of materials, vulnerability intake, and supplier assurance for the software a regulated organisation did not write.
Identity & Access Management in GxP Systems
Unique identity, authority checks, segregation of duties, privileged access and periodic review — the controls that make a GxP record attributable.
Cyber Incident Response for Regulated Records
What happens to GxP records, batch disposition and reporting clocks when a security incident lands — and why containment is only half the response.
Asset Inventory & Attack Surface
Every other control depends on knowing what exists — and in regulated manufacturing the forgotten assets are the ones connected to production.
Network, Cloud & Endpoint Security for GxP Systems
Segmentation as the control that stops an ordinary compromise becoming a production outage — plus cloud responsibility and endpoints that cannot be touched.
Vulnerability & Patch Management Under Change Control
Most compromises exploit something known and unpatched — and in validated environments the window between disclosure and remediation is structurally wider.
Business Continuity & Recovery
Ransomware made recovery the primary control — and in regulated manufacturing a system that is running again is not yet back in a validated state.
Security Awareness & Human Factors in GxP
People are the most-attacked control and the fastest detector — and which one dominates depends entirely on whether reporting a mistake is safe.
Automation Strategy & Architecture
Architecture decides what can be changed independently later — which is why obsolete control systems stay in service past the point of support.
Alarm Management & Safety Instrumented Systems
An alarm asks a person to act; a safety instrumented function acts itself. Collapsing the two removes the independence the risk assessment assumed.
Automation Lifecycle & Support
Control systems outlive the projects that install them and the people who configured them — support arrangements made at handover decide year eight.
Control System Assurance
Where a small configuration change has a direct physical consequence — and can be made by someone whose role is not framed as regulated.
Formulation & Product Design
Design fixes most of the risk and most of the cost before manufacturing begins — and operations carries what design left behind.
Human Performance & Work Design
Human error is an outcome, not a cause — treating it as a cause ends the investigation where the useful information starts.
Process Safety in Pharmaceutical Operations
The leading indicators are ordinary — deferred maintenance, bypassed interlocks, changes assessed for product and not for hazard.

IEC: frequently asked questions

Reference answers on International Electrotechnical Commission’s mandate, what it publishes, and how its requirements acquire force.

What does the IEC standardise?

The International Electrotechnical Commission publishes standards for electrical, electronic, and related technologies. In the regulated space its standards govern medical electrical equipment safety (IEC 60601), medical device software lifecycles (IEC 62304), and usability engineering (IEC 62366-1).

What are IEC 62304 safety classes?

IEC 62304 assigns software items safety classes A, B, or C, which determine how much lifecycle rigour is needed. The class is argued from what happens if the software fails, not from how complex it is, and it depends on the ISO 14971 risk analysis that feeds it.

How do IEC standards become binding?

Like ISO, IEC does not regulate; its standards become effectively binding when regulators reference them. IEC 60601 and IEC 62304 are expected in device submissions in both the US and EU. A submission is built from an interlocking set — ISO 13485, ISO 14971, IEC 62304, and IEC 62366-1.