Skip to main content

> specifications

Specifications

Standards are not red tape; they are the codified postmortems of industrial and software catastrophes.

AI Summary

The TinyCTO Technical and Regulatory Specifications directory catalogs 46 foundational engineering standards across medical device regulations, industrial OT cybersecurity, functional safety, enterprise ISMS, and sovereign governance. Each record details key controls, auditable evidence matrices, and bidirectional relationships to production systems and incident playbooks.

STATUS: 46 / 46 ENTRIES ACTIVE
SURFACE: SPECIFICATIONS // ALL
SPEC // SECURITY_ISMSSürüm 2.0 / 2026 Güncellemesi

CBDDO BİG Rehberi v2026

Information and Communication Security Guide (CBDDO Guide v2026)

The national cybersecurity baseline regulation issued by the Digital Transformation Office of the Presidency of Türkiye for public institutions and critical infrastructure operators.

#national-cybersecurity#turkiye-regulations#critical-infrastructure
Inspect Specification →
SPEC // HEALTH_INTEROPAnnual Multi-Part Standard Release

DICOM PS3 Series (NEMA / ISO 12052)

Digital Imaging and Communications in Medicine (DICOM)

The international standard for medical images and related information, defining file formats and network communications protocols for clinical imaging.

#clinical-systems#medical-software
Inspect Specification →
SPEC // OT_CYBERSECURITY2024 Resmi Gazete Düzenlemesi

EPDK Siber Güvenlik Modeli:2024

EMRA Cybersecurity Competency Model for the Energy Sector

Statutory cybersecurity regulation by the Energy Market Regulatory Authority (EPDK) establishing mandatory maturity levels for generation, transmission, and distribution utilities.

#energy-utilities#industrial-cybersecurity#turkiye-regulations
Inspect Specification →
SPEC // MEDTECH_REGEnacted 2017 / Applicable May 2022

Regulation (EU) 2017/746

European In Vitro Diagnostic Medical Devices Regulation (EU IVDR)

EU regulatory standard for in vitro diagnostic medical devices, diagnostic reagents, and analytical software used on human biological specimens.

#medical-software#clinical-systems
Inspect Specification →
SPEC // MEDTECH_REGEnacted 2017 / Applicable May 2021

Regulation (EU) 2017/745

European Medical Device Regulation (EU MDR)

The European Union regulatory framework establishing robust standards for clinical safety, performance, post-market surveillance, and technical documentation of medical devices.

#medical-software#clinical-systems#regulated-saas
Inspect Specification →
SPEC // MEDTECH_REGTitle 21 Code of Federal Regulations Part 11

21 CFR Part 11

Electronic Records; Electronic Signatures (Part 11)

FDA regulations establishing criteria under which electronic records and electronic signatures are considered equivalent to paper records and handwritten signatures.

#regulated-saas#clinical-systems#medical-software
Inspect Specification →
SPEC // MEDTECH_REGFinal Rule (Effective Feb 2, 2026)

21 CFR Part 820 / FDA QMSR

FDA Quality Management System Regulation (QMSR)

The modernized US federal medical device quality regulation harmonized with ISO 13485:2016, effective February 2026.

#medical-software#regulated-saas#clinical-systems
Inspect Specification →
SPEC // PRIVACY_PIMSEnacted 2016 / Applicable May 2018

Regulation (EU) 2016/679

General Data Protection Regulation (GDPR)

The European Union's comprehensive data privacy and protection law governing the processing of personal data of EU citizens.

#regulated-saas#clinical-systems#medical-software
Inspect Specification →
SPEC // PRIVACY_PIMSOmnibus Rule Updated

45 CFR Parts 160 & 164

HIPAA Security and Privacy Rules

US federal law establishing national standards to protect sensitive patient health information (PHI) from being disclosed without patient consent or knowledge.

#clinical-systems#regulated-saas#medical-software
Inspect Specification →
SPEC // HEALTH_INTEROPRelease 5 (2023 / 2026 Core)

HL7 FHIR Release 5

Fast Healthcare Interoperability Resources (HL7 FHIR)

Next-generation standards framework for electronic health data exchange utilizing modern web APIs, RESTful architectures, and JSON/XML representations.

#clinical-systems#regulated-saas#medical-software
Inspect Specification →
SPEC // HEALTH_INTEROPHL7 v2.9

HL7 Version 2.x Series

Health Level Seven (HL7) Version 2 Messaging Standard

The ubiquitous messaging standard for exchanging electronic health information between clinical and hospital information systems worldwide.

#clinical-systems#medical-software
Inspect Specification →
SPEC // GRID_PROTOCOLSEdition 2.1 (2016)

IEC 60870-5-104:2016

Telecontrol Equipment and Systems — Part 5-104: Network Access for IEC 60870-5-101 Using Standard Transport Profiles

The dominant European and international SCADA telecontrol protocol mapping industrial telemetry over standard TCP/IP port 2404.

#energy-utilities#telecontrol#scada
Inspect Specification →
SPEC // SAFETY_INTEGRITYEdition 2 (2010 / Multi-part 1 to 7)

IEC 61508:2010

Functional Safety of Electrical/Electronic/Programmable Electronic Safety-related Systems

The umbrella international standard for functional safety across all industries, defining Safety Integrity Levels (SIL 1–4) and safety lifecycles.

#functional-safety#industrial-automation#embedded-systems
Inspect Specification →
SPEC // SAFETY_INTEGRITYEdition 2.1 (2016 / Consolidated)

IEC 61511:2016

Functional Safety — Safety Instrumented Systems for the Process Industry Sector

Sector implementation of IEC 61508 tailored for petrochemical, chemical, refining, and power generation process plants (Safety Instrumented Systems).

#functional-safety#process-safety#energy-utilities
Inspect Specification →
SPEC // GRID_PROTOCOLSEdition 2.1 (Multi-part standard)

IEC 61850 Series

Communication Networks and Systems for Power Utility Automation

The global cornerstone standard for digital substation automation, enabling high-speed GOOSE messaging, Sampled Values, and XML-based engineering configuration.

#energy-utilities#substation-automation#smart-grid
Inspect Specification →
SPEC // LIFECYCLEEdition 1.1 (2006 + AMD1:2015)

IEC 62304:2006+AMD1:2015

Medical Device Software — Software Life Cycle Processes

Global benchmark defining life cycle process requirements for medical device software and embedded firmware.

#medical-software#regulated-saas#clinical-systems
Inspect Specification →
SPEC // LIFECYCLEEdition 1.1 (2015 + AMD1:2020)

IEC 62366-1:2015+AMD1:2020

Medical Devices — Part 1: Application of Usability Engineering to Medical Devices

Standard specifying a process for a manufacturer to analyze, specify, develop and evaluate the usability of a medical device as it relates to safety.

#medical-software#clinical-systems
Inspect Specification →
SPEC // OT_CYBERSECURITYEdition 1 (2010 / Under Revision 2026)

IEC 62443-2-1:2010

Security for Industrial Automation and Control Systems — Part 2-1: Establishing an IACS Security Program

Standard defining requirements for an asset owner to establish, implement, maintain, and continually improve an industrial cybersecurity management system.

#operational-technology#energy-utilities#industrial-cybersecurity
Inspect Specification →
SPEC // OT_CYBERSECURITYEdition 1.1 (2015 + AMD1:2017)

IEC 62443-2-4:2015+AMD1:2017

Security for Industrial Automation and Control Systems — Part 2-4: Security Program Requirements for IACS Service Providers

Standard specifying cybersecurity requirements for integration and maintenance service providers during the design, commissioning, and servicing of IACS.

#operational-technology#energy-utilities#industrial-cybersecurity
Inspect Specification →
SPEC // OT_CYBERSECURITYEdition 1 (2020)

IEC 62443-3-2:2020

Security for Industrial Automation and Control Systems — Part 3-2: Security Risk Assessment for System Design

Standard establishing engineering methods to partition an IACS into zones and conduits, assess cybersecurity risk, and establish target security levels.

#operational-technology#industrial-cybersecurity#energy-utilities
Inspect Specification →
SPEC // OT_CYBERSECURITYEdition 1 (2013 / Reconfirmed)

IEC 62443-3-3:2013

Security for Industrial Automation and Control Systems — Part 3-3: System Security Requirements and Security Levels

Standard defining technical system security requirements associated with seven foundational requirements (FRs) across four security levels.

#operational-technology#industrial-cybersecurity#energy-utilities
Inspect Specification →
SPEC // OT_CYBERSECURITYEdition 1 (2018)

IEC 62443-4-1:2018

Security for Industrial Automation and Control Systems — Part 4-1: Secure Product Development Lifecycle Requirements

Standard specifying process requirements for the secure development of products used in industrial automation and control systems.

#operational-technology#industrial-cybersecurity
Inspect Specification →
SPEC // OT_CYBERSECURITYEdition 1 (2019)

IEC 62443-4-2:2019

Security for Industrial Automation and Control Systems — Part 4-2: Technical Security Requirements for IACS Components

Standard specifying technical cybersecurity requirements for embedded devices, network devices, host devices, and software applications used in industrial systems.

#operational-technology#industrial-cybersecurity
Inspect Specification →
SPEC // OT_CYBERSECURITYMulti-Part Living Standard

IEC 62443 Series

Security for Industrial Automation and Control Systems (IACS) — Series Overview

The global foundational cybersecurity standard family for industrial automation, operational technology (OT), SCADA, and critical infrastructure.

#operational-technology#industrial-cybersecurity#energy-utilities
Inspect Specification →
SPEC // HEALTH_INTEROPEdition 2 (2021)

IEC 80001-1:2021

Safety, Effectiveness and Security in the Implementation and Use of Connected Medical Devices or Connected Health Software — Part 1: Application of Risk Management

Standard defining roles and risk management responsibilities when medical devices and health software connect to hospital IT networks.

#clinical-systems#medical-software
Inspect Specification →
SPEC // SECURITY_ISMSEdition 1 (2021)

IEC 81001-5-1:2021

Health Software and Health IT Systems — Part 5-1: Security, Activities in the Product Life Cycle

Foundational international standard establishing cybersecurity activities across the software life cycle for health software.

#medical-software#regulated-saas#clinical-systems
Inspect Specification →
SPEC // LIFECYCLEEdition 1 (2016)

IEC 82304-1:2016

Health Software — Part 1: General Requirements for Product Safety

International standard specifying general requirements for product safety of standalone health software products designed to operate on general computing platforms.

#regulated-saas#medical-software
Inspect Specification →
SPEC // QUALITYEdition 3 (2016)

ISO 13485:2016

Medical Devices — Quality Management Systems — Requirements for Regulatory Purposes

The internationally agreed standard that sets out requirements for a quality management system specific to the medical device industry.

#medical-software#clinical-systems#regulated-saas
Inspect Specification →
SPEC // ENV_MGMT2026 Edition

ISO 14001:2026

Environmental Management Systems — Requirements with Guidance for Use

The international benchmark standard for environmental management, governing emissions, resource lifecycle, and climate resilience.

#environmental-management#sustainability#esg
Inspect Specification →
SPEC // QUALITYEdition 3 (2020)

ISO 14155:2020

Clinical Investigation of Medical Devices for Human Subjects — Good Clinical Practice (GCP)

Standard addressing good clinical practice for the design, conduct, recording and reporting of clinical investigations carried out in human subjects to assess device safety or performance.

#clinical-systems#regulated-saas#medical-software
Inspect Specification →
SPEC // RISK_GOVERNANCEEdition 3 (2019)

ISO 14971:2019

Medical Devices — Application of Risk Management to Medical Devices

The global benchmark standard for managing risks throughout the entire lifecycle of medical devices, including software.

#medical-software#regulated-saas#clinical-systems
Inspect Specification →
SPEC // CONTINUITY_BCMSSecond Edition (2019)

ISO 22301:2019

Security and Resilience — Business Continuity Management Systems — Requirements

International standard specifying requirements to implement, maintain, and improve a Business Continuity Management System (BCMS).

#business-continuity#disaster-recovery#enterprise-risk
Inspect Specification →
SPEC // RISK_GOVERNANCESecond Edition (2018)

ISO 31000:2018

Risk Management — Guidelines

The global gold standard guideline providing principles, framework, and process for managing enterprise risk across all operational domains.

#risk-management#enterprise-risk#governance
Inspect Specification →
SPEC // OHS_MGMTFirst Edition (2018 / Current)

ISO 45001:2018

Occupational Health and Safety Management Systems — Requirements with Guidance for Use

International benchmark standard for occupational health and safety (OH&S), preventing work-related injury and ill health in hazardous operational environments.

#occupational-safety#industrial-operations#field-engineering
Inspect Specification →
SPEC // ENERGY_MGMTSecond Edition (2018)

ISO 50001:2018

Energy Management Systems — Requirements with Guidance for Use

International standard specifying requirements to establish, implement, maintain, and improve an Energy Management System (EnMS) for measurable efficiency gains.

#energy-management#sustainability#datacenter-efficiency
Inspect Specification →
SPEC // ASSET_MGMTSecond Edition (2024)

ISO 55001:2024

Asset Management — Management Systems — Requirements

Global management system standard for optimizing the lifecycle value, risk, and performance of physical, digital, and critical infrastructure assets.

#asset-management#energy-utilities#enterprise-asset-management
Inspect Specification →
SPEC // QUALITY2026 Edition

ISO 9001:2026

Quality Management Systems — Requirements

The global benchmark standard for quality management systems (QMS), establishing customer satisfaction and risk-based process control across industries.

#quality-management#qms#continuous-improvement
Inspect Specification →
SPEC // ITSM_SMSThird Edition (2018)

ISO/IEC 20000-1:2018

Information Technology — Service Management — Part 1: Service Management System Requirements

The international benchmark standard for IT Service Management (ITSM), establishing auditable requirements for SLA delivery, incident, and change control.

#it-service-management#itil#itsm
Inspect Specification →
SPEC // SQ_MODELEdition 2 (2023)

ISO/IEC 25010:2023

Systems and Software Engineering — Systems and Software Quality Requirements and Evaluation (SQuaRE) — Product Quality Model

The global benchmark quality model defining nine distinct product quality characteristics for evaluating software and systems.

#enterprise-it#regulated-saas#operational-technology
Inspect Specification →
Edition 3 (2022)

ISO/IEC 27001:2022

Information Security Management Systems (ISMS) — Requirements

The leading international standard specifying requirements for establishing, implementing, maintaining and continually improving an Information Security Management System (ISMS).

#enterprise-it#operational-technology#regulated-saas
Inspect Specification →
Edition 3 (2022)

ISO/IEC 27002:2022

Information Security, Cybersecurity and Privacy Protection — Information Security Controls

Code of practice providing implementation guidance for the 93 information security controls defined in ISO/IEC 27001 Annex A.

#enterprise-it#operational-technology#regulated-saas
Inspect Specification →
SPEC // RISK_GOVERNANCEEdition 4 (2022)

ISO/IEC 27005:2022

Information Security, Cybersecurity and Privacy Protection — Guidance on Managing Information Security Risks

International standard providing guidance on information security risk assessment, treatment, acceptance, communication, and monitoring.

#enterprise-it#regulated-saas#energy-utilities
Inspect Specification →
Edition 2 (2024)

ISO/IEC 27019:2024

Information Security Controls for the Energy Utility Industry

Domain-specific standard establishing cybersecurity and process control protection requirements tailored directly for electric power generation, transmission, and distribution.

#energy-utilities#operational-technology#industrial-cybersecurity
Inspect Specification →
Edition 2 (2025)

ISO/IEC 27701:2025

Privacy Information Management System (PIMS) — Requirements and Guidance

International privacy extension to ISO/IEC 27001 and ISO/IEC 27002 for managing Personally Identifiable Information (PII) as a controller and processor.

#regulated-saas#enterprise-it#clinical-systems
Inspect Specification →
2016 (Amended 2024/2026)

KVKK Kanun No. 6698

Law on Protection of Personal Data (KVKK Law No. 6698)

The statutory personal data protection framework of Türkiye, establishing data controller obligations, VERBİS registry, and cross-border transfer rules.

#privacy#data-protection#turkiye-regulations
Inspect Specification →
SPEC // IND_INTEROPIEC 62541 Multi-part (Current / Part 1 to 14)

IEC 62541 Series

OPC Unified Architecture (OPC UA) — IEC 62541

The cross-platform, service-oriented industrial communications standard featuring rich information modeling and end-to-end cryptographic security.

#industrial-iot#industry-40#scada
Inspect Specification →

Frequently Asked Questions

What domains are covered in the TinyCTO Specifications directory?

Medical device software lifecycle (IEC 62304, FDA 21 CFR Part 11/820), industrial OT cybersecurity (IEC 62443 series), information security (ISO 27001/27002/27019), functional safety (IEC 61508, IEC 61511), utility grid protocols (IEC 61850, IEC 60870-5-104), and national frameworks (KVKK, EPDK, CBDDO).

How do these specifications assist engineering teams during compliance audits?

Every record provides prioritized key control clauses, tangible audit evidence checklists requested by independent assessors (TÜV, FDA, notified bodies), and executive leadership takeaways.

How are specifications cross-linked to Incidentpedia and Systems?

Each specification explicitly maps to affected production systems (e.g., SCADA, PACS, DCS), operational incidents where non-compliance caused failures, and reference architecture guides.