---
title: "United Arab Emirates MOHAP - Cybersecurity Submission Pla…"
description: "How to submit a medical device to MOHAP / DHA / DoH in United Arab Emirates: step-by-step route, evidence checklist, common rejections, and typical review tim"
lang: en
json-ld: |
  [
    {
      "@context": "https://schema.org",
      "@type": "WebSite",
      "name": "The Medical Device Cybersecurity Crosswalk",
      "alternateName": "MDC Crosswalk",
      "url": "https://mdccrosswalk.com/",
      "description": "Compare FDA, EU MDR, MHRA, PMDA, NMPA, TGA, MFDS and Health Canada medical device cybersecurity requirements across 29 jurisdictions."
    },
    {
      "@context": "https://schema.org",
      "@type": "Organization",
      "name": "MDC Crosswalk",
      "url": "https://mdccrosswalk.com/",
      "logo": "https://mdccrosswalk.com/favicon.png",
      "sameAs": [
        "https://bluegoatcyber.com"
      ],
      "description": "An editorial reference comparing global medical-device cybersecurity regulations. Maintained by Blue Goat Cyber."
    },
    {
      "@context": "https://schema.org",
      "@type": "Article",
      "headline": "United Arab Emirates - MOHAP Medical Device Regulation + DoH / DHA cybersecurity standards",
      "description": "How to submit a medical device to MOHAP / DHA / DoH in United Arab Emirates: step-by-step route, evidence checklist, common rejections, and typical review tim",
      "author": {
        "@type": "Organization",
        "name": "MDC Crosswalk"
      },
      "publisher": {
        "@type": "Organization",
        "name": "MDC Crosswalk"
      },
      "image": "https://mdccrosswalk.lovable.app/favicon.png",
      "datePublished": "2024",
      "about": "Ministry of Health and Prevention; Dubai Health Authority; Department of Health Abu Dhabi",
      "dateModified": "2026-07-16",
      "mainEntityOfPage": "https://mdccrosswalk.lovable.app/standards/ae"
    },
    {
      "@context": "https://schema.org",
      "@type": "FAQPage",
      "mainEntity": [
        {
          "@type": "Question",
          "name": "Is SBOM required for medical devices in United Arab Emirates?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "Recommended. Encouraged for connected devices; mirrors FDA expectations."
          }
        },
        {
          "@type": "Question",
          "name": "What does MOHAP / DHA / DoH require for pre-market cybersecurity?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "Conformity to recognised standards (FDA/CE typically accepted), cybersecurity risk dossier, ADHICS / ISR alignment for hospital-deployed systems."
          }
        },
        {
          "@type": "Question",
          "name": "What are the post-market cybersecurity obligations under MOHAP / DHA / DoH?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "Adverse-event reporting, coordinated disclosure, ADHICS audit cycles for Abu Dhabi entities."
          }
        },
        {
          "@type": "Question",
          "name": "What is the penalty for non-compliance with MOHAP / DHA / DoH cybersecurity rules?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "Registration cancellation, fines under federal cybercrime law and ADHICS / ISR sanctions."
          }
        },
        {
          "@type": "Question",
          "name": "How much of my FDA cybersecurity package is reusable in United Arab Emirates?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "Roughly 85% - an editorial estimate based on overlapping evidence requirements (threat model, SBOM, security risk assessment, pen-test report)."
          }
        },
        {
          "@type": "Question",
          "name": "Why do MOHAP submissions get rejected for \"no local distributor with a valid establishment licence\"?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "Appoint a licensed distributor before submission."
          }
        }
      ]
    },
    {
      "@context": "https://schema.org",
      "@type": "HowTo",
      "name": "How to submit a medical device to MOHAP / DHA / DoH",
      "description": "MOHAP accepts GHTF founding-member approvals as pre-conditions. Cybersecurity is expected for connected devices as part of the technical file.",
      "totalTime": "3-6 months",
      "step": [
        {
          "@type": "HowToStep",
          "position": 1,
          "name": "Appoint local representation",
          "text": "Most jurisdictions require a locally-established entity to hold the registration or act as authorised representative before submission."
        },
        {
          "@type": "HowToStep",
          "position": 2,
          "name": "Reuse FDA or CE package as baseline",
          "text": "Adapt the cybersecurity subsection you already prepared for FDA or CE; regulators here typically accept the structure and ask for local labeling additions."
        },
        {
          "@type": "HowToStep",
          "position": 3,
          "name": "Translate and localise",
          "text": "Local-language technical summary and labeling are usually mandatory; certified translation is safest."
        },
        {
          "@type": "HowToStep",
          "position": 4,
          "name": "Submit + track queries",
          "text": "Respond to clarification rounds promptly; each unanswered question can add 30-90 days to the clock."
        }
      ]
    },
    {
      "@context": "https://schema.org",
      "@type": "BreadcrumbList",
      "itemListElement": [
        {
          "@type": "ListItem",
          "position": 1,
          "name": "Home",
          "item": "https://mdccrosswalk.lovable.app/"
        },
        {
          "@type": "ListItem",
          "position": 2,
          "name": "Standards"
        },
        {
          "@type": "ListItem",
          "position": 3,
          "name": "United Arab Emirates"
        }
      ]
    }
  ]
---

[

The Crosswalk



](/)

[Overview](/)[Playbook](/playbook)CompareReference

[New Per-page social previews and this changelog ](/changelog "Per-page social previews and this changelog") Search⌘K

1.  [Home ](/)
2.  Standards 
3.  United Arab Emirates 

MOHAP / DHA / DoH

# ![Flag of United Arab Emirates](/flags/ae.svg)United Arab Emirates - MOHAP / DHA / DoH 

Mandatory Last updated · 2024 Verified · 2026-07-16 

MOHAP Medical Device Regulation + DoH / DHA cybersecurity standards

Share Copy link X LinkedIn Email

Sources verified · 2026-07-16

Federal MOHAP rules and Abu Dhabi ADHICS / Dubai DHA ISR are distinct regimes; treat this entry as a federation-level summary.

Authority

Ministry of Health and Prevention; Dubai Health Authority; Department of Health Abu Dhabi

Enforced

2020 (DoH ADHICS)

Legal framework

MOHAP Medical Devices Regulation + DoH ADHICS + DHA ISR + UAE IA

FDA package reuse

~85%

[Editorial estimate · how →](/methodology#fda-reuse)

## Scope

All medical devices and connected health products marketed in the UAE. Emirate-level cyber standards layer on top of federal device rules.

Pre-market

Conformity to recognised standards (FDA/CE typically accepted), cybersecurity risk dossier, ADHICS / ISR alignment for hospital-deployed systems.

Post-market

Adverse-event reporting, coordinated disclosure, ADHICS audit cycles for Abu Dhabi entities.

SBOM

Recommended 

Encouraged for connected devices; mirrors FDA expectations.

Vulnerability disclosure

UAE Cyber Security Council coordination expected.

Penalty

Registration cancellation, fines under federal cybercrime law and ADHICS / ISR sanctions.

## Unique requirements

-   01 Local Authorised Representative 
-   02 ADHICS v2 compliance for Abu Dhabi 
-   03 DHA ISR compliance for Dubai 
-   04 Arabic labelling for end users 

## Highlights

-   ADHICS v2 mandatory in Abu Dhabi healthcare 
-   DHA ISR for Dubai hospital deployment 
-   FDA / CE recognition shortens path 

## Aligns with

IMDRF N60  FDA 2023 Guidance  ISO 27001  NIST CSF 

## Timeline

1.  2014
    
    DoH HIIP precursor introduced
    
2.  2020
    
    ADHICS v1 published
    
3.  2024
    
    ADHICS v2 enforcement extended
    

## Key documents

[

MOHAP Digital Security

https://mohap.gov.ae/en/references/digital-security



](https://mohap.gov.ae/en/references/digital-security)[

Department of Health Abu Dhabi (ADHICS)

https://www.doh.gov.ae/en/



](https://www.doh.gov.ae/en/)[

Dubai Health Authority (DHA ISR)

https://www.dha.gov.ae/



](https://www.dha.gov.ae/)

## How to submit in United Arab Emirates

Playbook reviewed · 2026-07-16

Submission route

MOHAP registration under UAE Medical Device Regulations

MOHAP accepts GHTF founding-member approvals as pre-conditions. Cybersecurity is expected for connected devices as part of the technical file.

[Authority portal](https://mohap.gov.ae/en)

### Step-by-step

1.  Step 01
    
    Appoint local representation
    
    Most jurisdictions require a locally-established entity to hold the registration or act as authorised representative before submission.
    
2.  Step 02
    
    Reuse FDA or CE package as baseline
    
    Adapt the cybersecurity subsection you already prepared for FDA or CE; regulators here typically accept the structure and ask for local labeling additions.
    
3.  Step 03
    
    Translate and localise
    
    Local-language technical summary and labeling are usually mandatory; certified translation is safest.
    
4.  Step 04
    
    Submit + track queries
    
    Respond to clarification rounds promptly; each unanswered question can add 30-90 days to the clock.
    

### Evidence checklist

Item

Level

FDA equivalent

Notes

Cybersecurity documentation (baseline FDA or CE)

Required 

SPDF

Local authorised representative agreement

Required 

—

Local-language labeling and IFU

Required 

—

SBOM

Recommended 

—

Not mandatory but reduces clarification rounds.

### Common MOHAP rejections

No local distributor with a valid establishment licence

Common 

Fix ·  Appoint a licensed distributor before submission.

### Typical timeline

End-to-end window: 3-6 months 

Phase 01

Local rep + dossier prep

2-4 months

Phase 02

Regulatory review

3-6 months

Phase 03

Approval + market entry

1-3 months

[Previous ![Flag of Mexico](/flags/mx.svg)Mexico ](/standards/mx)[Next  ![Flag of South Africa](/flags/za.svg)South Africa ](/standards/za)

## Related markets

[![Flag of Israel](/flags/il.svg)

Israel

~90% FDA reuse

](/standards/il)[![Flag of Canada](/flags/ca.svg)

Canada

~95% FDA reuse

](/standards/ca)[![Flag of United States](/flags/us.svg)

United States

~100% FDA reuse

](/standards/fda)[![Flag of Japan](/flags/jp.svg)

Japan

~70% FDA reuse

](/standards/jp)

## Frequently asked about United Arab Emirates

### Is SBOM required for medical devices in United Arab Emirates?

Recommended. Encouraged for connected devices; mirrors FDA expectations.

### What does MOHAP / DHA / DoH require for pre-market cybersecurity?

Conformity to recognised standards (FDA/CE typically accepted), cybersecurity risk dossier, ADHICS / ISR alignment for hospital-deployed systems.

### What are the post-market cybersecurity obligations under MOHAP / DHA / DoH?

Adverse-event reporting, coordinated disclosure, ADHICS audit cycles for Abu Dhabi entities.

### What is the penalty for non-compliance with MOHAP / DHA / DoH cybersecurity rules?

Registration cancellation, fines under federal cybercrime law and ADHICS / ISR sanctions.

### How much of my FDA cybersecurity package is reusable in United Arab Emirates?

Roughly 85% - an editorial estimate based on overlapping evidence requirements (threat model, SBOM, security risk assessment, pen-test report).

Sponsored note · Blue Goat Cyber

Submitting to MOHAP / DHA / DoH? Get a second pair of eyes before you file. Blue Goat Cyber has packaged cybersecurity evidence for United Arab Emirates alongside 37 other markets. We'll tell you what to keep, what to rework, and what's missing, in 30 minutes.  [Talk through your MOHAP submission](https://go.bluegoatcyber.com/meetings/blue-goat-cyber/discovery-session)

The Crosswalk

An independent reference for global medical device cybersecurity standards. A field guide for MedTech innovators and RA/QA teams charting an international path.

Resource

-   [Comparison matrix](/compare)
-   [Global playbook](/playbook)
-   [Glossary](/glossary)
-   [FAQ](/faq)

Sponsored by

[Blue Goat Cyber ↗](https://bluegoatcyber.com)

Editorially independent. Sponsorship keeps it free.

© 2026 The Crosswalk. Not legal advice.

Validate every requirement against current regulator publications.