> specifications
Specifications
Standards are not red tape; they are the codified postmortems of industrial and software catastrophes.
AI Summary
The TinyCTO Technical and Regulatory Specifications directory catalogs 46 foundational engineering standards across medical device regulations, industrial OT cybersecurity, functional safety, enterprise ISMS, and sovereign governance. Each record details key controls, auditable evidence matrices, and bidirectional relationships to production systems and incident playbooks.
CBDDO BİG Rehberi v2026
Information and Communication Security Guide (CBDDO Guide v2026)
The national cybersecurity baseline regulation issued by the Digital Transformation Office of the Presidency of Türkiye for public institutions and critical infrastructure operators.
DICOM PS3 Series (NEMA / ISO 12052)
Digital Imaging and Communications in Medicine (DICOM)
The international standard for medical images and related information, defining file formats and network communications protocols for clinical imaging.
EPDK Siber Güvenlik Modeli:2024
EMRA Cybersecurity Competency Model for the Energy Sector
Statutory cybersecurity regulation by the Energy Market Regulatory Authority (EPDK) establishing mandatory maturity levels for generation, transmission, and distribution utilities.
Regulation (EU) 2017/746
European In Vitro Diagnostic Medical Devices Regulation (EU IVDR)
EU regulatory standard for in vitro diagnostic medical devices, diagnostic reagents, and analytical software used on human biological specimens.
Regulation (EU) 2017/745
European Medical Device Regulation (EU MDR)
The European Union regulatory framework establishing robust standards for clinical safety, performance, post-market surveillance, and technical documentation of medical devices.
21 CFR Part 11
Electronic Records; Electronic Signatures (Part 11)
FDA regulations establishing criteria under which electronic records and electronic signatures are considered equivalent to paper records and handwritten signatures.
21 CFR Part 820 / FDA QMSR
FDA Quality Management System Regulation (QMSR)
The modernized US federal medical device quality regulation harmonized with ISO 13485:2016, effective February 2026.
Regulation (EU) 2016/679
General Data Protection Regulation (GDPR)
The European Union's comprehensive data privacy and protection law governing the processing of personal data of EU citizens.
45 CFR Parts 160 & 164
HIPAA Security and Privacy Rules
US federal law establishing national standards to protect sensitive patient health information (PHI) from being disclosed without patient consent or knowledge.
HL7 FHIR Release 5
Fast Healthcare Interoperability Resources (HL7 FHIR)
Next-generation standards framework for electronic health data exchange utilizing modern web APIs, RESTful architectures, and JSON/XML representations.
HL7 Version 2.x Series
Health Level Seven (HL7) Version 2 Messaging Standard
The ubiquitous messaging standard for exchanging electronic health information between clinical and hospital information systems worldwide.
IEC 60870-5-104:2016
Telecontrol Equipment and Systems — Part 5-104: Network Access for IEC 60870-5-101 Using Standard Transport Profiles
The dominant European and international SCADA telecontrol protocol mapping industrial telemetry over standard TCP/IP port 2404.
IEC 61508:2010
Functional Safety of Electrical/Electronic/Programmable Electronic Safety-related Systems
The umbrella international standard for functional safety across all industries, defining Safety Integrity Levels (SIL 1–4) and safety lifecycles.
IEC 61511:2016
Functional Safety — Safety Instrumented Systems for the Process Industry Sector
Sector implementation of IEC 61508 tailored for petrochemical, chemical, refining, and power generation process plants (Safety Instrumented Systems).
IEC 61850 Series
Communication Networks and Systems for Power Utility Automation
The global cornerstone standard for digital substation automation, enabling high-speed GOOSE messaging, Sampled Values, and XML-based engineering configuration.
IEC 62304:2006+AMD1:2015
Medical Device Software — Software Life Cycle Processes
Global benchmark defining life cycle process requirements for medical device software and embedded firmware.
IEC 62366-1:2015+AMD1:2020
Medical Devices — Part 1: Application of Usability Engineering to Medical Devices
Standard specifying a process for a manufacturer to analyze, specify, develop and evaluate the usability of a medical device as it relates to safety.
IEC 62443-2-1:2010
Security for Industrial Automation and Control Systems — Part 2-1: Establishing an IACS Security Program
Standard defining requirements for an asset owner to establish, implement, maintain, and continually improve an industrial cybersecurity management system.
IEC 62443-2-4:2015+AMD1:2017
Security for Industrial Automation and Control Systems — Part 2-4: Security Program Requirements for IACS Service Providers
Standard specifying cybersecurity requirements for integration and maintenance service providers during the design, commissioning, and servicing of IACS.
IEC 62443-3-2:2020
Security for Industrial Automation and Control Systems — Part 3-2: Security Risk Assessment for System Design
Standard establishing engineering methods to partition an IACS into zones and conduits, assess cybersecurity risk, and establish target security levels.
IEC 62443-3-3:2013
Security for Industrial Automation and Control Systems — Part 3-3: System Security Requirements and Security Levels
Standard defining technical system security requirements associated with seven foundational requirements (FRs) across four security levels.
IEC 62443-4-1:2018
Security for Industrial Automation and Control Systems — Part 4-1: Secure Product Development Lifecycle Requirements
Standard specifying process requirements for the secure development of products used in industrial automation and control systems.
IEC 62443-4-2:2019
Security for Industrial Automation and Control Systems — Part 4-2: Technical Security Requirements for IACS Components
Standard specifying technical cybersecurity requirements for embedded devices, network devices, host devices, and software applications used in industrial systems.
IEC 62443 Series
Security for Industrial Automation and Control Systems (IACS) — Series Overview
The global foundational cybersecurity standard family for industrial automation, operational technology (OT), SCADA, and critical infrastructure.
IEC 80001-1:2021
Safety, Effectiveness and Security in the Implementation and Use of Connected Medical Devices or Connected Health Software — Part 1: Application of Risk Management
Standard defining roles and risk management responsibilities when medical devices and health software connect to hospital IT networks.
IEC 81001-5-1:2021
Health Software and Health IT Systems — Part 5-1: Security, Activities in the Product Life Cycle
Foundational international standard establishing cybersecurity activities across the software life cycle for health software.
IEC 82304-1:2016
Health Software — Part 1: General Requirements for Product Safety
International standard specifying general requirements for product safety of standalone health software products designed to operate on general computing platforms.
ISO 13485:2016
Medical Devices — Quality Management Systems — Requirements for Regulatory Purposes
The internationally agreed standard that sets out requirements for a quality management system specific to the medical device industry.
ISO 14001:2026
Environmental Management Systems — Requirements with Guidance for Use
The international benchmark standard for environmental management, governing emissions, resource lifecycle, and climate resilience.
ISO 14155:2020
Clinical Investigation of Medical Devices for Human Subjects — Good Clinical Practice (GCP)
Standard addressing good clinical practice for the design, conduct, recording and reporting of clinical investigations carried out in human subjects to assess device safety or performance.
ISO 14971:2019
Medical Devices — Application of Risk Management to Medical Devices
The global benchmark standard for managing risks throughout the entire lifecycle of medical devices, including software.
ISO 22301:2019
Security and Resilience — Business Continuity Management Systems — Requirements
International standard specifying requirements to implement, maintain, and improve a Business Continuity Management System (BCMS).
ISO 31000:2018
Risk Management — Guidelines
The global gold standard guideline providing principles, framework, and process for managing enterprise risk across all operational domains.
ISO 45001:2018
Occupational Health and Safety Management Systems — Requirements with Guidance for Use
International benchmark standard for occupational health and safety (OH&S), preventing work-related injury and ill health in hazardous operational environments.
ISO 50001:2018
Energy Management Systems — Requirements with Guidance for Use
International standard specifying requirements to establish, implement, maintain, and improve an Energy Management System (EnMS) for measurable efficiency gains.
ISO 55001:2024
Asset Management — Management Systems — Requirements
Global management system standard for optimizing the lifecycle value, risk, and performance of physical, digital, and critical infrastructure assets.
ISO 9001:2026
Quality Management Systems — Requirements
The global benchmark standard for quality management systems (QMS), establishing customer satisfaction and risk-based process control across industries.
ISO/IEC 20000-1:2018
Information Technology — Service Management — Part 1: Service Management System Requirements
The international benchmark standard for IT Service Management (ITSM), establishing auditable requirements for SLA delivery, incident, and change control.
ISO/IEC 25010:2023
Systems and Software Engineering — Systems and Software Quality Requirements and Evaluation (SQuaRE) — Product Quality Model
The global benchmark quality model defining nine distinct product quality characteristics for evaluating software and systems.
ISO/IEC 27001:2022
Information Security Management Systems (ISMS) — Requirements
The leading international standard specifying requirements for establishing, implementing, maintaining and continually improving an Information Security Management System (ISMS).
ISO/IEC 27002:2022
Information Security, Cybersecurity and Privacy Protection — Information Security Controls
Code of practice providing implementation guidance for the 93 information security controls defined in ISO/IEC 27001 Annex A.
ISO/IEC 27005:2022
Information Security, Cybersecurity and Privacy Protection — Guidance on Managing Information Security Risks
International standard providing guidance on information security risk assessment, treatment, acceptance, communication, and monitoring.
ISO/IEC 27019:2024
Information Security Controls for the Energy Utility Industry
Domain-specific standard establishing cybersecurity and process control protection requirements tailored directly for electric power generation, transmission, and distribution.
ISO/IEC 27701:2025
Privacy Information Management System (PIMS) — Requirements and Guidance
International privacy extension to ISO/IEC 27001 and ISO/IEC 27002 for managing Personally Identifiable Information (PII) as a controller and processor.
KVKK Kanun No. 6698
Law on Protection of Personal Data (KVKK Law No. 6698)
The statutory personal data protection framework of Türkiye, establishing data controller obligations, VERBİS registry, and cross-border transfer rules.
IEC 62541 Series
OPC Unified Architecture (OPC UA) — IEC 62541
The cross-platform, service-oriented industrial communications standard featuring rich information modeling and end-to-end cryptographic security.
Frequently Asked Questions
What domains are covered in the TinyCTO Specifications directory?
Medical device software lifecycle (IEC 62304, FDA 21 CFR Part 11/820), industrial OT cybersecurity (IEC 62443 series), information security (ISO 27001/27002/27019), functional safety (IEC 61508, IEC 61511), utility grid protocols (IEC 61850, IEC 60870-5-104), and national frameworks (KVKK, EPDK, CBDDO).
How do these specifications assist engineering teams during compliance audits?
Every record provides prioritized key control clauses, tangible audit evidence checklists requested by independent assessors (TÜV, FDA, notified bodies), and executive leadership takeaways.
How are specifications cross-linked to Incidentpedia and Systems?
Each specification explicitly maps to affected production systems (e.g., SCADA, PACS, DCS), operational incidents where non-compliance caused failures, and reference architecture guides.
