AI & Threat Landscape

AAMI CR515 is the AI cybersecurity guidance FDA already recognizes

Most of the AI standards on the horizon are still in ballot or development. AAMI CR515 is published, and more than that, the FDA has added it to its database of recognized consensus standards. For a manufacturer writing a submission this year, that recognition is the whole point. You can cite it now, and a reviewer already knows what it is.

CR515 covers the cybersecurity considerations that are unique to machine learning-enabled medical device software. It deliberately skips the threats that ordinary security practice already handles and focuses on the ones that are new or that behave differently for ML, across the full arc: data collection, product design, deployment, use, and maintenance. AAMI shipped it as a consensus report rather than a slower technical standard precisely because the threat picture was moving too fast to wait.

THE STANDARDS LANDSCAPE FOR AI-ENABLED MEDICAL DEVICESIN DEVELOPMENTIEEE P63685BALLOTEDISO/IEC 27090IEC 63450PUBLISHEDAAMI CR515ISO/TS 24971-2IEC PAS 63621HARMONISEDnone
AAMI CR515: published and FDA-recognized, the one you can cite in a submission today.

How to use it

Treat CR515 as the bridge between the FDA's threat list and your actual program. The January 2025 draft tells you the agency cares about poisoning, evasion, model theft, and the rest. CR515 gives you a recognized document that walks those considerations across the lifecycle, so your rationale points at something the reviewer accepts instead of your own internal memo.

It is guidance, not a pass or fail bar, so it will not carry a submission by itself. What it does is lower the friction. Of everything arriving, this is the one I would reach for first, because recognition is worth more in a review than novelty.

Get started

See your device through ELTON.

Start with one device. We build the twin from documentation your quality system already produces, run AI discovery remotely, and show you the graph: the handful to fix, and the evidence for everything else.

Exploitability management for medical devices. FDA §524B methodologyExploitability proven at runtime95% faster than legacy testing Book a Demo
Platform
OverviewAvoid FDA DeficienciesAvoid Consulting FeesDigital Twin TraceabilityAI MedDevice PentestingExploitability VerificationVulnerability ChainingRemediation OptimizationRemote TestLink™Incident ResponseAutomated VEX & MetricsCVSSv4 Migration
Solutions
EnterpriseStartups / SMBs Postmarket SurveillanceIncident ResponseSecurity EngineeringRegulatory AffairsFDA §524BEU MDR/CRAEU REDNIS2IMDRF N60 / N73Japan MHLW
Why ELTON
One Solution Subscription TestingAI-NativeFDA ComplianceVerified ExploitabilityELTON vs. Legacy TestingThreat-Led AI PentestingMDDT MethodologyCredentialsDevice ModalitiesPricing
Resources
FDA Deficiency ListFDA Testing RequirementsFDA Cyber SOPs & TemplatesRemediation LibraryRegulatory GuidesWebinarsAI NewsletterThe End of Legacy TestingThe AI Vulnerability ExplosionSecurity AdvisoriesWhitepapersIntelligence & Blog
Company
AboutLeadershipCareersPartnershipsContact Meet ELTON