Japan · MHLW / PMDA

Japan adopted the international standard, and made it enforceable.

Japan did not write its own rulebook. It adopted JIS T 2304 (IEC 62304) and JIS T 81001-5-1 (IEC 81001-5-1). One disciplines the software lifecycle, the other embeds cybersecurity inside it. Neither is satisfied by an annual assessment and a folder of PDFs. ELTON produces the living record both demand.

The standards

Two standards, one continuous practice.

Read together, JIS T 2304 and JIS T 81001-5-1 close the loop most programs leave open. One makes maintenance a formal lifecycle phase with the same weight as development. The other makes security a property of every phase.

JIS T 2304 · IEC 62304

The lifecycle spine

Defined development processes, structured software maintenance across the whole operational life, and risk management that traces software decisions back to patient safety.

JIS T 81001-5-1 · IEC 81001-5-1

Security in the spine

Security requirements identified in design, continuous risk analysis of vulnerabilities and threats, secure implementation and verification, and postmarket monitoring.

The hard part

The defensible record

The standard does not just want fixes. It wants a record showing why you fixed what you fixed and why you accepted what you accepted. That is the evidence most programs never produce.

The ELTON mapping

The record both standards keep asking for.

Compliance at release is a moment. These standards describe a practice, and both keep asking what changed since the last time. ELTON is built as that continuous practice, not a point-in-time snapshot.

JAPAN ADOPTS THE STANDARDWHAT BOTH DEMANDELTON · A LIVING RECORDJIS T 2304= IEC 62304. The software lifecycle:development, maintenance, risk.JIS T 81001-5-1= IEC 81001-5-1. Security insideevery phase of that lifecycle.Security requirements in designContinuous vulnerability risk analysisPostmarket monitoringDefensible record of every decisionNot a folder of PDFsBoth standards keep asking whatchanged since the last assessment.Continuous AI discovery, every releaseExploitability proven on the deviceEvery fix and acceptance, with reasoningVEX and artifacts, always currentA defensible record, kept live.
Why it holds up

Devices in Japanese hospitals are connected, so the standards are real.

The annual snapshot

A folder, frozen in time

An assessment and a folder of PDFs answers the question once. Both JIS standards ask it again at every change, which a yearly engagement structurally cannot keep up with.

With ELTON

A record that stays current

Every release is discovered and verified, every decision carries its reasoning, and the evidence updates as vulnerabilities surface. The record is defensible on the day a reviewer asks, not reconstructed for them.

Get started

Keep a record Japan will accept.

Start with one device. We build the twin, run discovery across every release, and keep the defensible record JIS T 81001-5-1 expects, current and ready.

Automate medical device vulnerability discovery and verification. FDA §524B methodologyExploitability proven on-device95% faster than legacy testing Book a Demo
Platform
Platform OverviewDigital TwinAutonomous TestingExploitability VerificationVulnerability GraphRemediation OptimizationELTON TestLink™Lifecycle & MetricsCVSSv4 Migration
Solutions
FDA §524BEU MDR/CRAEU REDNIS2IMDRF N60 / N73Postmarket SurveillanceIncident Response
Why ELTON
Why ELTONPricing
Resources
Intelligence & BlogRegulatory GuidesWebinarsWhitepapers
Company
AboutLeadershipCareersContact Book a Demo