The Workbench · Craft

The device, not the standard, defines essential performance

A test plan for an electrical medical device often carries one line item labeled “safety testing,” as if IEC 60601-1 tested for a single thing. The standard's own structure says otherwise: basic safety and essential performance are two separate, defined terms, evaluated by two different questions, and a device can pass one cleanly while the file has never actually answered the other. The harder problem for a manufacturer isn't running the second test. It's that IEC 60601-1 doesn't tell them what to test — it tells them who has to decide, and that's the manufacturer, not the standard.

Two definitions, and they don't overlap

IEC 60601-1 defines basic safety as freedom from unacceptable risk directly caused by physical hazards — electric shock, mechanical crushing, excessive temperature — under both normal and single-fault conditions. Essential performance is defined separately: performance of a clinical function, other than performance related to basic safety, where loss or degradation beyond the limits the manufacturer specifies results in unacceptable risk. The first term is about the device not hurting anyone through a physical fault. The second is about the device's clinical function not silently failing in a way that hurts someone through absence rather than injury — a monitor that stops alarming is a basic-safety pass and an essential-performance failure at the same time.

The standard names the concept; it doesn't name your device's list

Outside the particular and collateral standards in the 60601 series that specify essential performance for a defined device type — a ventilator, an infusion pump, a patient monitor — the base standard doesn't hand a manufacturer a checklist of which functions qualify. That determination runs through the device's own risk management file, built the way a risk management file has to prove, hazard by hazard, under ISO 14971: the manufacturer identifies the device's clinical functions, asks what happens if each one degrades or disappears, and names the ones where the answer is unacceptable risk. A device with no applicable collateral standard and no documented essential-performance determination in its risk file has skipped a decision IEC 60601-1 requires, not deferred one the standard was going to make for it.

Single-fault condition is where the two tests actually diverge

Under normal conditions, a well-designed device is unlikely to reveal much difference between the two requirements. The distinction shows up under single-fault condition testing, where one component is deliberately failed and the device's response is evaluated against both bars separately: does the fault create an unacceptable physical hazard, and does it cause an essential-performance function to degrade below the limit the manufacturer specified without the device failing safe. A test protocol that runs single-fault testing only against the basic-safety question has covered half of what the standard's own dual definition requires, and the missing half is the one a risk file can't recover after the device ships.

Essential performance has to survive contact with everything else in the file

Once a function is named essential performance, that designation isn't a footnote in a test report — it has to show up wherever the device's safe operation is documented elsewhere: in the instructions for use, in the design outputs that specify how the function is built, and in any post-market surveillance triggers tied to a report of that function failing in the field. A function tested as essential performance in a lab and never carried into the labeling or the design record has left the test result stranded, disconnected from the rest of the file it's supposed to inform.

A collateral standard can hand the list over, but only for what it covers

Where a device type has its own particular standard in the 60601-2 series — a ventilator under 60601-2-12, an infusion pump under 60601-2-24 — that standard typically names the essential performance the base standard leaves general, closing the gap a manufacturer would otherwise have to fill from its own risk analysis alone. That coverage stops at the standard's own scope. A device that combines a function the particular standard addresses with an additional clinical function the standard's authors never anticipated still owes that second function its own risk-based determination; borrowing the particular standard's list wholesale and assuming it's exhaustive is the same shortcut as assuming the base standard supplies one.

Where this meets the rest of the file

A test-plan worksheet that keeps basic safety and essential performance as two named columns, each traced to its own risk-file determination rather than one shared assumption of “safety testing,” is previewed in the launch catalog. If your program documents this distinction differently, the shelf takes that correction directly.

The Regulatory Toolkit launches soon — a free shelf of source-mapped templates, checklists and browser-only tools for regulatory teams. Get one email when it opens, or contribute a template.

All Workbench notes