---
title: "Methodology: How We Tier 29 Medical Device Cyber Regulators"
description: "Transparent inclusion criteria, color tiers, the Emerging-tier definition, and the seven sanctioned jurisdictions we deliberately leave gray on the crosswalk."
lang: en
json-ld: |
  [
    {
      "@context": "https://schema.org",
      "@type": "WebSite",
      "name": "The Medical Device Cybersecurity Crosswalk",
      "alternateName": "MDC Crosswalk",
      "url": "https://mdccrosswalk.com/",
      "description": "Compare FDA, EU MDR, MHRA, PMDA, NMPA, TGA, MFDS and Health Canada medical device cybersecurity requirements across 29 jurisdictions."
    },
    {
      "@context": "https://schema.org",
      "@type": "Organization",
      "name": "MDC Crosswalk",
      "url": "https://mdccrosswalk.com/",
      "logo": "https://mdccrosswalk.com/favicon.png",
      "sameAs": [
        "https://bluegoatcyber.com"
      ],
      "description": "An editorial reference comparing global medical-device cybersecurity regulations. Maintained by Blue Goat Cyber."
    },
    {
      "@context": "https://schema.org",
      "@type": "BreadcrumbList",
      "itemListElement": [
        {
          "@type": "ListItem",
          "position": 1,
          "name": "Home",
          "item": "https://mdccrosswalk.lovable.app/"
        },
        {
          "@type": "ListItem",
          "position": 2,
          "name": "Methodology",
          "item": "https://mdccrosswalk.lovable.app/methodology"
        }
      ]
    }
  ]
---

[

The Crosswalk



](/)

[Overview](/)[Playbook](/playbook)CompareReference

[New Per-page social previews and this changelog ](/changelog "Per-page social previews and this changelog") Search⌘K

1.  [Home ](/)
2.  Methodology 

Methodology

# How we decide what's on the map.

Transparent inclusion criteria, color tiers, the Emerging tier definition, and the seven sanctioned jurisdictions we deliberately leave gray.

Last updated · July 25, 2026 

## What “covered” means

A jurisdiction earns a colored tile and a full crosswalk page when **all four** of these conditions hold:

1.  01 A national medical-device regulator exists and operates a registration, notification, or approval pathway. 
2.  02 Cybersecurity expectations for connected medical devices or SaMD are documented - either as named guidance, a circular, a recognized standard, or as enforced general data/health-security law that demonstrably applies to devices. 
3.  03 The market is reachable by a US/EU manufacturer (no comprehensive sanctions blocking commercial export of medical devices). 
4.  04 The jurisdiction is large or strategically important enough that an RA team would actually plan for it on a global rollout. 

Total covered today: 45 jurisdictions across 6 continents (38 with full crosswalks, 7 as emerging-tier profiles).

## Color tiers

Leading

Statutory cybersecurity requirements with SBOM mandated and pre-market refusal as enforcement.

Advanced

Mandatory cyber framework with named guidance, SBOM expected, post-market duties.

Developing

Cyber guidance published; tightening but not yet pre-market gating.

Emerging

Early-stage requirements; relies heavily on FDA/EU recognition and IMDRF principles.

Gray

Not yet profiled, or intentionally omitted under sanctions (7 jurisdictions, see below).

Tiers are an editorial judgment - a snapshot of regulatory maturity, not a compliance score for any specific manufacturer or device. Tiers are reviewed each time a covered jurisdiction publishes new guidance.

## The Emerging tier - and how it differs from Covered and Watchlist

Emerging is a real category, not a placeholder. A jurisdiction lands here when its device regulator and statutory framework are real and reachable - but cybersecurity-specific expectations have not been formally written down yet, or are being absorbed from foreign approvals and adjacent law (data protection, critical infrastructure). We publish a brief profile rather than a full crosswalk.

Covered

Full crosswalk page. Named cyber guidance or statute we can cite line-by-line.

-   ✓ Named cyber guidance
-   ✓ Pre-/post-market expectations documented
-   ✓ SBOM posture assessable
-   ✓ Crosswalk to FDA package

Emerging

Brief profile in the click-through panel. Real regulator, no cyber-specific text yet.

-   ✓ Device regulator + statutory framework
-   ✓ Reference-country approval pathway
-   ~ Cyber posture inferred from adjacent law
-   ✗ No medical-device cyber crosswalk yet

Watchlist

Reserved bucket for jurisdictions actively drafting guidance we expect to promote next.

-   ✓ Regulator known
-   ~ Draft guidance circulating
-   ✗ No reachable framework to summarise
-   ✗ Currently empty after the 2026 promotion pass

### How a country becomes Emerging

1.  01 There is an identifiable national medical-device regulator with a published registration or licensing pathway. 
2.  02 There is a statutory basis for that regulator (act, decree, ministerial order) - not just a draft Bill. 
3.  03 The market is reachable by a US/EU manufacturer (no comprehensive sanctions). 
4.  04 The regulator either accepts foreign approvals (FDA, CE, Health Canada, TGA, PMDA) as a route to entry, or has explicit IMDRF/GHTF alignment we can describe in a paragraph. 

**Promotion to Covered.** An Emerging jurisdiction graduates to a full crosswalk when the regulator publishes named medical-device cybersecurity guidance, a binding circular, or formally adopts a recognized standard (e.g. IMDRF N60, IEC 81001-5-1) with enforcement attached. At that point it earns its own profile page and slots into the side-by-side compare table.

Currently emerging · 7 jurisdictions

![Flag of Pakistan](/flags/pk.svg)Pakistan· DRAP ![Flag of Nigeria](/flags/ng.svg)Nigeria· NAFDAC ![Flag of Kenya](/flags/ke.svg)Kenya· PPB ![Flag of Morocco](/flags/ma.svg)Morocco· DMP ![Flag of Peru](/flags/pe.svg)Peru· DIGEMID ![Flag of Bangladesh](/flags/bd.svg)Bangladesh· DGDA ![Flag of Sri Lanka](/flags/lk.svg)Sri Lanka· NMRA 

Click any of these on the world map to see their regulator, statutory framework, current cyber posture, and which foreign approvals they recognize.

## How we estimate "FDA package reuse"

Each crosswalk page shows an `~X%` figure labeled _FDA package reuse_. It is an editorial estimate of how much of a complete FDA cybersecurity submission package - SPDF artifacts, SBOM, threat model, security testing, architecture views, CVD plan, and post-market lifecycle commitments - can be reused as-is in another jurisdiction's submission, before localization, format conversion, or additional local evidence is needed.

The number is **not** a regulatory equivalence rating, a clearance prediction, or a quantitative score. The tilde (`~`) is doing real work: treat it as a rough planning band for RA/QA scoping, not a percentage you'd defend in an audit.

Six dimensions we weigh

01 

SBOM acceptance

Will the regulator accept a SPDX/CycloneDX SBOM produced for FDA, or do they require a specific local format/registry?

02 

SPDF / SSDLC alignment

Does the regulator recognize the FDA Secure Product Development Framework, IEC 81001-5-1, or IEC 62443-4-1 as evidence of secure development?

03 

Threat model & risk evidence

Is an AAMI TIR57 / ISO 14971 cybersecurity risk file accepted, or is a locally formatted risk dossier required?

04 

CVD plan & post-market

Are the FDA CVD plan and patch SLAs sufficient, or does the jurisdiction require a local PSIRT, in-country contact, or different reporting timelines?

05 

Standards recognition

Does the regulator publish a recognized-consensus-standards list that includes the same standards FDA recognizes?

06 

Localization & sovereignty

Language requirements, in-country data/representation rules, sovereign certification regimes, and registration-flow deltas.

How the bands map

100%

Source

FDA itself - the reference package.

85–95%

High reuse

Strong IMDRF + SPDF alignment, recognizes FDA submissions or equivalent standards (Canada, Switzerland, Israel, UAE, Norway).

70–80%

Solid base

IEC 81001-5-1 / IMDRF aligned but local registration flow and language deltas (UK, Japan, Australia, Singapore, Brazil, Taiwan).

55–65%

Partial

Substantive process, format, or representation deltas (EU MDR, MFDS, India, Mexico, Vietnam, Indonesia).

≤ 50%

Low reuse

Sovereign certification, data-localization, or fundamentally different framework (China, Saudi Arabia in some cases).

n/a

Emerging

Not scored - no formal cyber expectations to map FDA artifacts against.

Limitations

-   • Editorial estimate by reviewers familiar with the underlying frameworks - not a peer-reviewed scoring rubric.
-   • Assumes a typical Class II / moderate-risk connected device. High-risk implants, AI/ML SaMD, and combination products will deviate.
-   • Reflects the regulator's published expectations as of each entry's _Last reviewed_ date - not informal reviewer practice.
-   • Does _not_ include QMS, clinical, labeling, or general device-registration effort - only cybersecurity submission artifacts.

## Why a country might be gray

Not yet covered

The country has no national medical-device regulator, the regulator has no public registration pathway, or the market is too small to warrant a profile on a global rollout. If a jurisdiction has a real regulator _and_ a statutory framework but no named cyber guidance, it sits in the Emerging tier above instead - not gray.

Intentionally omitted (sanctions)

US OFAC, EU and UK sanctions regimes restrict commercial export of medical devices - particularly connected and software-driven devices - to the following markets without specific licenses. Listing a crosswalk for them would be misleading guidance for the typical reader of this site:

-   🇷🇺 Russia
-   🇧🇾 Belarus
-   🇮🇷 Iran
-   🇰🇵 North Korea
-   🇸🇾 Syria
-   🇨🇺 Cuba
-   🇻🇪 Venezuela

Humanitarian medical-device exports are often permitted under general licenses; commercial market access is functionally closed. Some of these jurisdictions (notably Russia) maintain real medical-device cyber frameworks - we just don't crosswalk them here.

## What this map is not

-   It is not a substitute for legal or regulatory counsel. Tier colors don't tell you whether your specific device clears in any given market. 
-   It is not a global trade compliance map. We flag sanctions only to explain omissions - not to assess export controls for your product. 
-   It is not exhaustive. ~190 UN member states exist; we cover the jurisdictions that matter most for typical global medical-device launches. 

### Think we're missing one?

If you've shipped into a market you'd like added - or you disagree with a tier - tell us. We add jurisdictions in batches when they meet the four-condition test above.

[Read the FAQ →](/faq)

The Crosswalk

An independent reference for global medical device cybersecurity standards. A field guide for MedTech innovators and RA/QA teams charting an international path.

Resource

-   [Comparison matrix](/compare)
-   [Global playbook](/playbook)
-   [Glossary](/glossary)
-   [FAQ](/faq)

Sponsored by

[Blue Goat Cyber ↗](https://bluegoatcyber.com)

Editorially independent. Sponsorship keeps it free.

© 2026 The Crosswalk. Not legal advice.

Validate every requirement against current regulator publications.