MOHAP / DHA / DoH
United Arab Emirates - MOHAP / DHA / DoH
MOHAP Medical Device Regulation + DoH / DHA cybersecurity standards
Authority
Ministry of Health and Prevention; Dubai Health Authority; Department of Health Abu Dhabi
Enforced
2020 (DoH ADHICS)
Legal framework
MOHAP Medical Devices Regulation + DoH ADHICS + DHA ISR + UAE IA
Scope
All medical devices and connected health products marketed in the UAE. Emirate-level cyber standards layer on top of federal device rules.
Pre-market
Conformity to recognised standards (FDA/CE typically accepted), cybersecurity risk dossier, ADHICS / ISR alignment for hospital-deployed systems.
Post-market
Adverse-event reporting, coordinated disclosure, ADHICS audit cycles for Abu Dhabi entities.
SBOM
RecommendedEncouraged for connected devices; mirrors FDA expectations.
Vulnerability disclosure
UAE Cyber Security Council coordination expected.
Penalty
Registration cancellation, fines under federal cybercrime law and ADHICS / ISR sanctions.
Unique requirements
- 01Local Authorised Representative
- 02ADHICS v2 compliance for Abu Dhabi
- 03DHA ISR compliance for Dubai
- 04Arabic labelling for end users
Highlights
- ADHICS v2 mandatory in Abu Dhabi healthcare
- DHA ISR for Dubai hospital deployment
- FDA / CE recognition shortens path
Aligns with
Timeline
-
2014
DoH HIIP precursor introduced
-
2020
ADHICS v1 published
-
2024
ADHICS v2 enforcement extended
Key documents
How to submit in United Arab Emirates
Playbook reviewed · 2026-07-16
Submission route
MOHAP registration under UAE Medical Device Regulations
MOHAP accepts GHTF founding-member approvals as pre-conditions. Cybersecurity is expected for connected devices as part of the technical file.
Authority portalStep-by-step
-
Step 01
Appoint local representation
Most jurisdictions require a locally-established entity to hold the registration or act as authorised representative before submission.
-
Step 02
Reuse FDA or CE package as baseline
Adapt the cybersecurity subsection you already prepared for FDA or CE; regulators here typically accept the structure and ask for local labeling additions.
-
Step 03
Translate and localise
Local-language technical summary and labeling are usually mandatory; certified translation is safest.
-
Step 04
Submit + track queries
Respond to clarification rounds promptly; each unanswered question can add 30-90 days to the clock.
Evidence checklist
| Item | Level | FDA equivalent | Notes |
|---|---|---|---|
| Cybersecurity documentation (baseline FDA or CE) | Required | SPDF | |
| Local authorised representative agreement | Required | — | |
| Local-language labeling and IFU | Required | — | |
| SBOM | Recommended | — | Not mandatory but reduces clarification rounds. |
Common MOHAP rejections
No local distributor with a valid establishment licence
CommonFix · Appoint a licensed distributor before submission.
Typical timeline
End-to-end window: 3-6 months
Phase 01
Local rep + dossier prep
2-4 months
Phase 02
Regulatory review
3-6 months
Phase 03
Approval + market entry
1-3 months
Related markets
Frequently asked about United Arab Emirates
Is SBOM required for medical devices in United Arab Emirates?
Recommended. Encouraged for connected devices; mirrors FDA expectations.
What does MOHAP / DHA / DoH require for pre-market cybersecurity?
Conformity to recognised standards (FDA/CE typically accepted), cybersecurity risk dossier, ADHICS / ISR alignment for hospital-deployed systems.
What are the post-market cybersecurity obligations under MOHAP / DHA / DoH?
Adverse-event reporting, coordinated disclosure, ADHICS audit cycles for Abu Dhabi entities.
What is the penalty for non-compliance with MOHAP / DHA / DoH cybersecurity rules?
Registration cancellation, fines under federal cybercrime law and ADHICS / ISR sanctions.
How much of my FDA cybersecurity package is reusable in United Arab Emirates?
Roughly 85% - an editorial estimate based on overlapping evidence requirements (threat model, SBOM, security risk assessment, pen-test report).