Framework overlap

Does Belgium CyberFundamentals cover IEC 62304:2015 Medical Device Software Lifecycle Processes?

You hold Belgium CyberFundamentals and have been told to do IEC 62304:2015 Medical Device Software Lifecycle Processes. Here is how much overlaps, control by control.

24% of IEC 62304:2015 Medical Device Software Lifecycle Processes you already have

Belgium CyberFundamentals already covers about 24% of IEC 62304:2015 Medical Device Software Lifecycle Processes, leaving 25 of 33 controls as genuinely new work.

Already covered 0 Likely covered 8 New work 25

No control in Belgium CyberFundamentals maps directly to one in IEC 62304:2015 Medical Device Software Lifecycle Processes. Everything counted as covered is covered because both map to the same third standard, which is what a crosswalk is, but it is an inference rather than a lookup.

What is genuinely new work

Nothing in Belgium CyberFundamentals reaches these. This is the list to scope.

IEC62304-4.2
Risk Management
IEC62304-4.3
Software Safety Classification
IEC62304-4.4
Legacy Software
IEC62304-5.1.1
Software Development Plan
IEC62304-5.1.6
SOUP Identification
IEC62304-5.4
Software Detailed Design
IEC62304-5.5
Software Unit Implementation and Verification
IEC62304-5.6
Software Integration and Testing
IEC62304-5.7
Software System Testing
IEC62304-5.8
Software Release
IEC62304-6.1
Software Maintenance Plan
IEC62304-6.2
Problem and Modification Analysis
IEC62304-6.3
Modification Implementation
IEC62304-7.1
Risk Analysis of Software Contributing to Hazardous Situations
IEC62304-7.3
Verification of Risk Control Measures
IEC62304-8.1
Configuration Identification
IEC62304-8.3
Configuration Status Accounting
IEC62304-9
Software Problem Resolution Process
IEC62304-9.1
Prepare Problem Reports
IEC62304-9.2
Investigate the Problem
IEC62304-9.3
Advise Relevant Parties
IEC62304-9.5
Maintain Records
IEC62304-9.6
Analyze Problems for Trends
IEC62304-9.7
Verify Software Problem Resolution
IEC62304-9.8
Test Documentation
Show the 8 you already have
IEC62304-4.1
Quality Management System
IEC62304-5.1
Software Development Planning
IEC62304-5.2
Software Requirements Analysis
IEC62304-5.3
Software Architectural Design
IEC62304-7.2
Risk Control Measures
IEC62304-7.4
Risk Management of Software Changes
IEC62304-8.2
Change Control
IEC62304-9.4
Use Change Control Process

How this is calculated

Already covered means a mapping runs from a control in Belgium CyberFundamentals to that control. Likely covered means no direct mapping exists but both frameworks map to the same control in a third standard. New work means neither. We keep those separate rather than adding them into one friendlier number, because blending them would present a two-hop inference as a verified fact.

Coverage is not symmetric. Run it the other way and you will get a different number; both are correct.

From 332,959 cross-framework control mappings across 723 frameworks, 531 of them verified against their source documents. It does not tell you that you are compliant: a mapped control means the two standards ask for the same thing, not that you have done it.

Try another pair ยท Today's edition