---
title: "AAMI TIR57 - Principles for medical device security, risk ma"
description: "AAMI · The bridge between ISO 14971 (safety risk) and IEC 80001 / IEC 62443 (security risk). FDA names it as a recognised consensus standard."
lang: en
json-ld: |
  [
    {
      "@context": "https://schema.org",
      "@type": "WebSite",
      "name": "The Medical Device Cybersecurity Crosswalk",
      "alternateName": "MDC Crosswalk",
      "url": "https://mdccrosswalk.com/",
      "description": "Compare FDA, EU MDR, MHRA, PMDA, NMPA, TGA, MFDS and Health Canada medical device cybersecurity requirements across 29 jurisdictions."
    },
    {
      "@context": "https://schema.org",
      "@type": "Organization",
      "name": "MDC Crosswalk",
      "url": "https://mdccrosswalk.com/",
      "logo": "https://mdccrosswalk.com/favicon.png",
      "sameAs": [
        "https://bluegoatcyber.com"
      ],
      "description": "An editorial reference comparing global medical-device cybersecurity regulations. Maintained by Blue Goat Cyber."
    },
    {
      "@context": "https://schema.org",
      "@type": "Article",
      "headline": "AAMI TIR57 - Principles for medical device security, risk management",
      "description": "The bridge between ISO 14971 (safety risk) and IEC 80001 / IEC 62443 (security risk). FDA names it as a recognised consensus standard.",
      "author": {
        "@type": "Organization",
        "name": "MDC Crosswalk"
      },
      "publisher": {
        "@type": "Organization",
        "name": "MDC Crosswalk"
      },
      "image": "https://mdccrosswalk.lovable.app/favicon.png",
      "datePublished": "2026-05-28",
      "dateModified": "2026-05-28",
      "about": "AAMI",
      "mainEntityOfPage": "https://mdccrosswalk.lovable.app/frameworks/aami-tir57"
    },
    {
      "@context": "https://schema.org",
      "@type": "BreadcrumbList",
      "itemListElement": [
        {
          "@type": "ListItem",
          "position": 1,
          "name": "Home",
          "item": "https://mdccrosswalk.lovable.app/"
        },
        {
          "@type": "ListItem",
          "position": 2,
          "name": "Frameworks"
        },
        {
          "@type": "ListItem",
          "position": 3,
          "name": "AAMI TIR57"
        }
      ]
    }
  ]
---

[

The Crosswalk



](/)

[Overview](/)[Playbook](/playbook)CompareReference

[New Per-page social previews and this changelog ](/changelog "Per-page social previews and this changelog") Search⌘K

1.  [Home ](/)
2.  Frameworks 
3.  AAMI TIR57 

AAMI

# AAMI TIR57

[Source](https://www.aami.org/)

Principles for medical device security, risk management

Last updated · July 25, 2026 

Share Copy link X LinkedIn Email

## What it is

The bridge between ISO 14971 (safety risk) and IEC 80001 / IEC 62443 (security risk). FDA names it as a recognised consensus standard.

## Why it matters

If you reference TIR57 in your risk management plan, the FDA accepts the structure with little debate. Increasingly cited in SFDA and Health Canada too.

## Adopted or referenced by

FDA  Health Canada  SFDA 

## Key clauses

Security risk = patient safety risk

Threats are evaluated for impact on safety, effectiveness and data.

Threat modelling

STRIDE-based approach commonly applied.

[Previous ISO 14971 ](/frameworks/iso-14971)[Next  IMDRF N60 ](/frameworks/imdrf-n60)

The Crosswalk

An independent reference for global medical device cybersecurity standards. A field guide for MedTech innovators and RA/QA teams charting an international path.

Resource

-   [Comparison matrix](/compare)
-   [Global playbook](/playbook)
-   [Glossary](/glossary)
-   [FAQ](/faq)

Sponsored by

[Blue Goat Cyber ↗](https://bluegoatcyber.com)

Editorially independent. Sponsorship keeps it free.

© 2026 The Crosswalk. Not legal advice.

Validate every requirement against current regulator publications.