---
title: "TIR97, AAMI TIR97 | MedTech Terms"
description: "AAMI Technical Information Report on post-market security risk management for medical device manufacturers, the operational companion to TIR57."
lang: en
json-ld: |
  {
    "@context": "https://schema.org",
    "@graph": [
      {
        "@type": "DefinedTerm",
        "@id": "https://medtechterms.com/terms/aami-tir97#term",
        "name": "AAMI TIR97",
        "alternateName": [
          "TIR97",
          "AAMI TIR97:2019",
          "Post-market security risk management for device manufacturers"
        ],
        "description": "AAMI TIR97 is a Technical Information Report providing guidance on post-market security risk management activities for medical device manufacturers. Where AAMI TIR57 covers security risk management across the full lifecycle (and aligns with ISO 14971), TIR97 zooms in on the post-market phase: vulnerability monitoring, intake and triage, exploitability and patient-safety impact assessment, coordinated disclosure, patch development, customer notification, and the metrics for an effective post-market security program.",
        "url": "https://medtechterms.com/terms/aami-tir97",
        "termCode": "aami-tir97",
        "inDefinedTermSet": {
          "@type": "DefinedTermSet",
          "name": "MedTech Terms",
          "url": "https://medtechterms.com/terms"
        }
      },
      {
        "@type": "Article",
        "@id": "https://medtechterms.com/terms/aami-tir97#article",
        "headline": "TIR97, AAMI TIR97",
        "description": "AAMI Technical Information Report on post-market security risk management for medical device manufacturers, the operational companion to TIR57.",
        "url": "https://medtechterms.com/terms/aami-tir97",
        "mainEntityOfPage": {
          "@type": "WebPage",
          "@id": "https://medtechterms.com/terms/aami-tir97"
        },
        "about": {
          "@id": "https://medtechterms.com/terms/aami-tir97#term"
        },
        "articleSection": "Cybersecurity",
        "inLanguage": "en",
        "keywords": "AAMI TIR97, TIR97, AAMI TIR97:2019, Post-market security risk management for device manufacturers, Cybersecurity, medical device, MedTech",
        "author": {
          "@type": "Person",
          "name": "Christian Espinosa",
          "jobTitle": "Founder, Blue Goat Cyber",
          "url": "https://bluegoatcyber.com"
        },
        "publisher": {
          "@type": "Organization",
          "name": "MedTech Terms",
          "url": "https://medtechterms.com"
        },
        "isPartOf": {
          "@type": "WebSite",
          "name": "MedTech Terms",
          "url": "https://medtechterms.com"
        },
        "datePublished": "2026-06-20",
        "dateModified": "2026-06-20",
        "citation": [
          {
            "@type": "CreativeWork",
            "name": "AAMI TIR97:2019",
            "url": "https://array.aami.org/doi/book/10.2345/9781570208744",
            "publisher": {
              "@type": "Organization",
              "name": "AAMI"
            }
          },
          {
            "@type": "CreativeWork",
            "name": "FDA Cybersecurity in Medical Devices Guidance (2023)",
            "url": "https://www.fda.gov/regulatory-information/search-fda-guidance-documents/cybersecurity-medical-devices-quality-system-considerations-and-content-premarket-submissions",
            "publisher": {
              "@type": "Organization",
              "name": "FDA"
            }
          },
          {
            "@type": "CreativeWork",
            "name": "HSCC - Health Sector Coordinating Council",
            "url": "https://healthsectorcouncil.org/",
            "publisher": {
              "@type": "Organization",
              "name": "HSCC"
            }
          }
        ],
        "mentions": [
          {
            "@type": "DefinedTerm",
            "@id": "https://medtechterms.com/terms/aami-tir57#term",
            "name": "AAMI TIR57",
            "url": "https://medtechterms.com/terms/aami-tir57"
          },
          {
            "@type": "DefinedTerm",
            "@id": "https://medtechterms.com/terms/section-524b#term",
            "name": "Section 524B of the FD&C Act",
            "alternateName": "524B",
            "url": "https://medtechterms.com/terms/section-524b"
          },
          {
            "@type": "DefinedTerm",
            "@id": "https://medtechterms.com/terms/premarket-cybersecurity#term",
            "name": "Premarket Cybersecurity Submission",
            "url": "https://medtechterms.com/terms/premarket-cybersecurity"
          },
          {
            "@type": "DefinedTerm",
            "@id": "https://medtechterms.com/terms/post-market-surveillance#term",
            "name": "Post-Market Surveillance",
            "alternateName": "PMS",
            "url": "https://medtechterms.com/terms/post-market-surveillance"
          },
          {
            "@type": "DefinedTerm",
            "@id": "https://medtechterms.com/terms/cvd#term",
            "name": "Coordinated Vulnerability Disclosure",
            "alternateName": "CVD",
            "url": "https://medtechterms.com/terms/cvd"
          },
          {
            "@type": "DefinedTerm",
            "@id": "https://medtechterms.com/terms/vex#term",
            "name": "Vulnerability Exploitability eXchange",
            "alternateName": "VEX",
            "url": "https://medtechterms.com/terms/vex"
          },
          {
            "@type": "DefinedTerm",
            "@id": "https://medtechterms.com/terms/iso-14971#term",
            "name": "ISO 14971",
            "url": "https://medtechterms.com/terms/iso-14971"
          },
          {
            "@type": "DefinedTerm",
            "@id": "https://medtechterms.com/terms/iec-81001-5-1#term",
            "name": "IEC 81001-5-1",
            "url": "https://medtechterms.com/terms/iec-81001-5-1"
          }
        ]
      },
      {
        "@type": "BreadcrumbList",
        "itemListElement": [
          {
            "@type": "ListItem",
            "position": 1,
            "name": "Home",
            "item": "https://medtechterms.com/"
          },
          {
            "@type": "ListItem",
            "position": 2,
            "name": "Terms",
            "item": "https://medtechterms.com/terms"
          },
          {
            "@type": "ListItem",
            "position": 3,
            "name": "Cybersecurity",
            "item": "https://medtechterms.com/terms?cat=Cybersecurity"
          },
          {
            "@type": "ListItem",
            "position": 4,
            "name": "AAMI TIR97",
            "item": "https://medtechterms.com/terms/aami-tir97"
          }
        ]
      }
    ]
  }
---

[

MedTech Terms

The authoritative reference



](/)

Browse

Learn

[Latest](/latest)

About

1.  [Home](/)
2.  /
3.  [Terms](/terms)
4.  /
5.  [Cybersecurity](/terms?cat=Cybersecurity)
6.  /
7.  AAMI TIR97

[All terms](/terms)

Cybersecurity [Connected & Cyber-Physical Devices](/ecosystems/connected-devices)[Quality System](/ecosystems/quality-system)TIR97 

# AAMI TIR97

AAMI Technical Information Report on post-market security risk management for medical device manufacturers, the operational companion to TIR57.

Reviewed by [Christian Espinosa, Founder, Blue Goat Cyber](/authors/christian-espinosa) Last reviewed June 20, 2026 

## Definition

[AAMI](/terms/aami) TIR97 is a Technical Information Report providing guidance on post-market security risk management activities for medical device manufacturers. Where  [AAMI TIR57](/terms/aami-tir57) covers security risk management across the full lifecycle (and aligns with  [ISO 14971](/terms/iso-14971)), TIR97 zooms in on the post-market phase: vulnerability monitoring, intake and triage, exploitability and patient-safety impact assessment, coordinated disclosure, patch development, customer notification, and the metrics for an effective post-market security program. 

What the regulation says

FDA's 2023 Cybersecurity in Medical Devices guidance recognizes  [AAMI TIR57](/terms/aami-tir57) and TIR97 as the consensus standards for security risk management, TIR97 specifically addressing the 'plan to monitor, identify, and address post-market vulnerabilities' required under Section  [524B](/terms/section-524b)(b)(2)(A). 

## What this means in practice

TIR97 is the operational playbook for the post-market obligations introduced by FDA Section  [524B](/terms/section-524b) and the FDA 2023 Cybersecurity in Medical Devices guidance. It defines roles, intake workflows, severity classification (linking exploitability and patient harm), and the artifacts (advisories,  [VEX](/terms/vex) statements, customer letters) that prove a vulnerability monitoring plan is real. Many manufacturers structure their post-market security SOPs as a TIR97 implementation. 

Common pitfalls

-   • Implementing TIR57 without TIR97, the lifecycle standard sets requirements that TIR97 makes operationally measurable. 
-   • Skipping the patient-safety impact assessment step and defaulting to CVSS, TIR97 expects an explicit linkage between exploitability and harm. 
-   • Treating customer notification as a marketing artifact rather than a TIR97-required communication with defined content and timing. 

## Related terms

Grouped by theme 

### Editor's picks

· Hand-selected related concepts 

[

Cybersecurity

AAMI TIR57

AAMI Technical Information Report providing MedTech-specific guidance on cybersecurity risk management.





](/terms/aami-tir57)[

Cybersecurity

Coordinated Vulnerability Disclosure(CVD) 

A documented process for receiving, triaging, and responsibly disclosing security vulnerabilities reported by external researchers.





](/terms/cvd)[

Cybersecurity

IEC 81001-5-1

International standard defining secure-product-lifecycle activities for health software, including medical devices.





](/terms/iec-81001-5-1)[

Cybersecurity

Premarket Cybersecurity Submission

The bundle of cybersecurity artifacts a sponsor includes in a 510(k), De Novo, PMA, or HDE submission for a cyber device.





](/terms/premarket-cybersecurity)

### More in Cybersecurity

· Same category 

[

Cybersecurity

Section 524B of the FD&C Act(524B) 

The federal statute that gives FDA explicit premarket authority over cybersecurity for cyber devices.





](/terms/section-524b)[

Cybersecurity

Vulnerability Exploitability eXchange(VEX) 

A machine-readable statement that explains whether a known vulnerability is actually exploitable in a specific product.





](/terms/vex)[

Cybersecurity

AAMI SW96

AAMI/ANSI standard establishing requirements for medical-device cybersecurity activities throughout the lifecycle.





](/terms/aami-sw96)[

Cybersecurity

Brainjacking

Unauthorized remote control of an implanted neurostimulator (e.g., DBS) to alter stimulation parameters and harm a patient.





](/terms/brainjacking)

Cited by

Where this term appears across MedTech Terms.

Ecosystems (2)

-   [Connected & Cyber-Physical Devices](/ecosystems/connected-devices)
-   [Quality System](/ecosystems/quality-system)

## Primary references

3 sources 

Link health:  3 verified · last checked 2026-06-20 

AAMI· 1 FDA· 1 HSCC· 1 

1.  [1 
    
    AAMI TIR97:2019
    
    Verified 
    
    AAMI · array.aami.org 
    
    
    
    ](https://array.aami.org/doi/book/10.2345/9781570208744)
2.  [2 
    
    FDA Cybersecurity in Medical Devices Guidance (2023)
    
    Verified 
    
    FDA · fda.gov 
    
    
    
    ](https://www.fda.gov/regulatory-information/search-fda-guidance-documents/cybersecurity-medical-devices-quality-system-considerations-and-content-premarket-submissions)
3.  [3 
    
    HSCC - Health Sector Coordinating Council
    
    Verified 
    
    HSCC · healthsectorcouncil.org 
    
    
    
    ](https://healthsectorcouncil.org/)

Inline markers like \[1\]  jump to the matching reference above.

Sponsor note

### Working on medical device cybersecurity?

Blue Goat Cyber specializes in MedTech cybersecurity - threat modeling, SBOMs, penetration testing, and FDA premarket submissions.

[Book a 30-minute discovery session](https://go.bluegoatcyber.com/meetings/blue-goat-cyber/discovery-session)

-   No obligation
-   Expert-led from minute one
-   NDA available on request

MedTech Terms is a community resource sponsored by [Blue Goat Cyber](https://bluegoatcyber.com). Definitions are independent of any vendor.

On this term

Category

Cybersecurity

Acronym

TIR97

Sources

3

Updated

6/20/2026

[Compare with another term](/compare?a=aami-tir97)

Learn in 60 seconds

Card Lesson Quiz

AAMI Technical Information Report on post-market security risk management for medical device manufacturers, the operational companion to TIR57.

-   · TIR97 is the operational playbook for the post-market obligations introduced by FDA Section 524B and the FDA 2023 Cybersecurity in Medical Devices guidance. 
-   · Many manufacturers structure their post-market security SOPs as a TIR97 implementation. 

Remember this

Watch out: Implementing TIR57 without TIR97, the lifecycle standard sets requirements that TIR97 makes operationally measurable.

Related terms

-   [AAMI TIR57 ](/terms/aami-tir57)
-   [Section 524B of the FD&C Act(524B) ](/terms/section-524b)
-   [Premarket Cybersecurity Submission ](/terms/premarket-cybersecurity)
-   [Post-Market Surveillance(PMS) ](/terms/post-market-surveillance)
-   [Coordinated Vulnerability Disclosure(CVD) ](/terms/cvd)
-   [Vulnerability Exploitability eXchange(VEX) ](/terms/vex)
-   [ISO 14971 ](/terms/iso-14971)
-   [IEC 81001-5-1 ](/terms/iec-81001-5-1)

You may also need

Auto-suggested from Cybersecurity and shared keywords.

-   [AAMI SW96 ](/terms/aami-sw96)
-   [Secure Product Development Framework(SPDF) ](/terms/spdf)
-   [Threat Modeling ](/terms/threat-modeling)
-   [AAMI TIR45(TIR45) ](/terms/aami-tir45)
-   [Common Vulnerabilities and Exposures(CVE) ](/terms/cve)
-   [FedRAMP(FedRAMP) ](/terms/fedramp)

[All Cybersecurity terms](/terms?cat=Cybersecurity)

From the Blue Goat network

Related resources and services on this topic.

-   [
    
    MedTech Cybersecurity Standards 
    
    Authoritative reference for the standards and guidances behind medical device cybersecurity.
    
    ](https://medtechcyberstandards.com)
-   [
    
    MedTech Cyber Tips 
    
    Practical, organized tips for medical device cybersecurity teams.
    
    ](https://medtechcybertips.com)
-   [
    
    MedTech Cybersecurity Crosswalk 
    
    International crosswalk of medical device cybersecurity requirements across regulators.
    
    ](https://mdccrosswalk.com)
-   [
    
    Code Blue 
    
    Real medical device cybersecurity incidents and their lessons.
    
    ](https://codebluechart.com)

MedTech Terms 

An authoritative, plain-language reference for the regulatory, quality, cybersecurity, and software terms that shape modern medical devices.

Browse

-   [All terms](/terms)
-   [A–Z index](/a-z)
-   [Categories](/categories)
-   [Ecosystems](/ecosystems)
-   [Learning paths](/paths)
-   [Compare terms](/compare)
-   [Quiz](/quiz)

Resources

-   [FDA Medical Devices](https://www.fda.gov/medical-devices)
-   [EU MDR](https://eur-lex.europa.eu/eli/reg/2017/745/oj)
-   [IMDRF](https://www.imdrf.org/)
-   [Methodology](/methodology)
-   [Changelog](/changelog)
-   [Editor: Christian Espinosa](/authors/christian-espinosa)
-   [About this site](/about)

© 2026 MedTech Terms. Reference content for educational purposes - not regulatory advice. A community resource sponsored by [Blue Goat Cyber](https://bluegoatcyber.com)