Japan · MHLW / PMDA

Japan adopted the international standard, and made it enforceable.

Japan did not write its own rulebook. It adopted JIS T 2304 (IEC 62304) and JIS T 81001-5-1 (IEC 81001-5-1). One disciplines the software lifecycle, the other embeds cybersecurity inside it. Neither is satisfied by an annual assessment and a folder of PDFs. ELTON produces the living record both demand. ELTON is an exploitability management platform, delivered as a managed program. Our team runs the testing continuously. You get the platform, the evidence, and a TestLink™ appliance, with no new headcount.

The standards

Two standards, one continuous practice.

Read together, JIS T 2304 and JIS T 81001-5-1 close the loop most programs leave open. One makes maintenance a formal lifecycle phase with the same weight as development. The other makes security a property of every phase.

JIS T 2304 · IEC 62304

The lifecycle spine

Defined development processes, structured software maintenance across the whole operational life, and risk management that traces software decisions back to patient safety.

JIS T 81001-5-1 · IEC 81001-5-1

Security in the spine

Security requirements identified in design, continuous risk analysis of vulnerabilities and threats, secure implementation and verification, and postmarket monitoring.

The hard part

The defensible record

The standard does not just want fixes. It wants a record showing why you fixed what you fixed and why you accepted what you accepted. That is the evidence most programs never produce.

The ELTON mapping

The record both standards keep asking for.

Compliance at release is a moment. These standards describe a practice, and both keep asking what changed since the last time. ELTON is built as that continuous practice, not a point-in-time snapshot.

JAPAN ADOPTS THE STANDARDWHAT BOTH DEMANDELTON · A LIVING RECORDJIS T 2304= IEC 62304. The software lifecycle:development, maintenance, risk.JIS T 81001-5-1= IEC 81001-5-1. Security insideevery phase of that lifecycle.Security requirements in designContinuous vulnerability risk analysisPostmarket monitoringDefensible record of every decisionNot a folder of PDFsBoth standards keep asking whatchanged since the last assessment.Continuous AI discovery, every releaseExploitability proven on the deviceEvery fix and acceptance, with reasoningVEX and artifacts, always currentA defensible record, kept live.
Why it holds up

Devices in Japanese hospitals are connected, so the standards are real.

The annual snapshot

A folder, frozen in time

An assessment and a folder of PDFs answers the question once. Both JIS standards ask it again at every change, which a yearly engagement structurally cannot keep up with.

With ELTON

A record that stays current

Every release is discovered and verified, every decision carries its reasoning, and the evidence updates as vulnerabilities surface. The record is defensible on the day a reviewer asks, not reconstructed for them.

Get started

Keep a record Japan will accept.

Start with one device. We build the twin, run discovery across every release, and keep the defensible record JIS T 81001-5-1 expects, current and ready.

Questions

Common questions about medical device cybersecurity in Japan.

What cybersecurity standards does Japan require for medical devices?

Japan did not write its own rulebook. It adopted JIS T 2304, which is IEC 62304, and JIS T 81001-5-1, which is IEC 81001-5-1. One disciplines the software lifecycle including maintenance, the other embeds cybersecurity inside every phase of that lifecycle. Read together they close the loop most programs leave open.

What does JIS T 81001-5-1 require?

JIS T 81001-5-1 puts security inside the lifecycle: security requirements identified in design, continuous risk analysis of vulnerabilities and threats, secure implementation and verification, and postmarket monitoring. It makes security a property of every phase rather than a review at the end.

What does JIS T 2304 cover?

JIS T 2304 is Japan's adoption of IEC 62304, the lifecycle spine: defined development processes, structured software maintenance across the whole operational life, and risk management that traces software decisions back to patient safety. Maintenance is a formal phase carrying the same weight as development.

Is an annual security assessment enough to satisfy the Japanese standards?

No. An assessment and a folder of PDFs answers the question once, and both JIS standards keep asking what changed since the last assessment. A yearly engagement structurally cannot keep up with that, because the standards describe a continuous practice rather than a moment at release.

What makes a cybersecurity record defensible under these standards?

The standards do not just want fixes. They want a record showing why you fixed what you fixed and why you accepted what you accepted, tied to the release the decision was made against. ELTON runs discovery on every release, proves exploitability on the device, and keeps VEX and artifacts current so the record is ready on the day a reviewer asks.

Exploitability management for medical devices. FDA §524B methodologyExploitability proven at runtime95% faster than legacy testing Book a Demo
Platform
OverviewAvoid FDA DeficienciesAvoid Consulting FeesDigital Twin TraceabilityAI PentestingExploitability VerificationVulnerability ChainingRemediation OptimizationRemote TestLink™Incident ResponseAutomated VEX & MetricsCVSSv4 Migration
Solutions
Postmarket SurveillanceIncident ResponseSecurity EngineeringRegulatory AffairsFDA §524BEU MDR/CRAEU REDNIS2IMDRF N60 / N73Japan MHLW
Why ELTON
Subscription TestingAI-NativeFDA ComplianceVerified ExploitabilityELTON vs. Legacy TestingThreat-Led AI PentestingMDDT MethodologyCredentialsDevice ModalitiesPricing
Resources
FDA Deficiency ListFDA Testing RequirementsFDA Cyber SOPs & TemplatesRemediation LibraryRegulatory GuidesWebinarsAI NewsletterThe End of Legacy TestingThe AI Vulnerability ExplosionSecurity AdvisoriesWhitepapersIntelligence & Blog
Company
AboutLeadershipCareersPartnershipsContact Meet ELTON