---
title: "Argentina ANMAT - Cybersecurity Submission Playbook"
description: "How to submit a medical device to ANMAT in Argentina: step-by-step route, evidence checklist, common rejections, and typical review timeline. Compared with FD"
lang: en
json-ld: |
  [
    {
      "@context": "https://schema.org",
      "@type": "WebSite",
      "name": "The Medical Device Cybersecurity Crosswalk",
      "alternateName": "MDC Crosswalk",
      "url": "https://mdccrosswalk.com/",
      "description": "Compare FDA, EU MDR, MHRA, PMDA, NMPA, TGA, MFDS and Health Canada medical device cybersecurity requirements across 29 jurisdictions."
    },
    {
      "@context": "https://schema.org",
      "@type": "Organization",
      "name": "MDC Crosswalk",
      "url": "https://mdccrosswalk.com/",
      "logo": "https://mdccrosswalk.com/favicon.png",
      "sameAs": [
        "https://bluegoatcyber.com"
      ],
      "description": "An editorial reference comparing global medical-device cybersecurity regulations. Maintained by Blue Goat Cyber."
    },
    {
      "@context": "https://schema.org",
      "@type": "Article",
      "headline": "Argentina - Disposición 2318/02 + ANMAT cybersecurity criteria",
      "description": "How to submit a medical device to ANMAT in Argentina: step-by-step route, evidence checklist, common rejections, and typical review timeline. Compared with FD",
      "author": {
        "@type": "Organization",
        "name": "MDC Crosswalk"
      },
      "publisher": {
        "@type": "Organization",
        "name": "MDC Crosswalk"
      },
      "image": "https://mdccrosswalk.lovable.app/favicon.png",
      "datePublished": "2023",
      "about": "Administración Nacional de Medicamentos, Alimentos y Tecnología Médica",
      "dateModified": "2026-07-16",
      "mainEntityOfPage": "https://mdccrosswalk.lovable.app/standards/ar"
    },
    {
      "@context": "https://schema.org",
      "@type": "FAQPage",
      "mainEntity": [
        {
          "@type": "Question",
          "name": "Is SBOM required for medical devices in Argentina?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "Recommended. Encouraged in line with IMDRF N60; not yet mandated."
          }
        },
        {
          "@type": "Question",
          "name": "What does ANMAT require for pre-market cybersecurity?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "Risk-class registration dossier; reference-jurisdiction route accepts FDA / CE / Health Canada approvals."
          }
        },
        {
          "@type": "Question",
          "name": "What are the post-market cybersecurity obligations under ANMAT?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "Tecnovigilancia reporting to ANMAT, software change notifications."
          }
        },
        {
          "@type": "Question",
          "name": "What is the penalty for non-compliance with ANMAT cybersecurity rules?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "Registration cancellation, sanitary fines, criminal liability for adulteration."
          }
        },
        {
          "@type": "Question",
          "name": "How much of my FDA cybersecurity package is reusable in Argentina?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "Roughly 85% - an editorial estimate based on overlapping evidence requirements (threat model, SBOM, security risk assessment, pen-test report)."
          }
        },
        {
          "@type": "Question",
          "name": "Why do ANMAT submissions get rejected for \"no local technical director\"?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "Appoint a registered TD before submission."
          }
        }
      ]
    },
    {
      "@context": "https://schema.org",
      "@type": "HowTo",
      "name": "How to submit a medical device to ANMAT",
      "description": "ANMAT accepts GHTF and MDSAP evidence. Cybersecurity documentation is not mandated separately but recommended for connected devices.",
      "totalTime": "9-15 months",
      "step": [
        {
          "@type": "HowToStep",
          "position": 1,
          "name": "Appoint local representation",
          "text": "Most jurisdictions require a locally-established entity to hold the registration or act as authorised representative before submission."
        },
        {
          "@type": "HowToStep",
          "position": 2,
          "name": "Reuse FDA or CE package as baseline",
          "text": "Adapt the cybersecurity subsection you already prepared for FDA or CE; regulators here typically accept the structure and ask for local labeling additions."
        },
        {
          "@type": "HowToStep",
          "position": 3,
          "name": "Translate and localise",
          "text": "Local-language technical summary and labeling are usually mandatory; certified translation is safest."
        },
        {
          "@type": "HowToStep",
          "position": 4,
          "name": "Submit + track queries",
          "text": "Respond to clarification rounds promptly; each unanswered question can add 30-90 days to the clock."
        }
      ]
    },
    {
      "@context": "https://schema.org",
      "@type": "BreadcrumbList",
      "itemListElement": [
        {
          "@type": "ListItem",
          "position": 1,
          "name": "Home",
          "item": "https://mdccrosswalk.lovable.app/"
        },
        {
          "@type": "ListItem",
          "position": 2,
          "name": "Standards"
        },
        {
          "@type": "ListItem",
          "position": 3,
          "name": "Argentina"
        }
      ]
    }
  ]
---

[

The Crosswalk



](/)

[Overview](/)[Playbook](/playbook)CompareReference

[New Per-page social previews and this changelog ](/changelog "Per-page social previews and this changelog") Search⌘K

1.  [Home ](/)
2.  Standards 
3.  Argentina 

ANMAT

# ![Flag of Argentina](/flags/ar.svg)Argentina - ANMAT 

Guidance Last updated · 2023 Verified · 2026-07-16 

Disposición 2318/02 + ANMAT cybersecurity criteria

Share Copy link X LinkedIn Email

Sources verified · 2026-07-16

ANMAT device rules confirmed; cybersecurity expectations are emerging.

Authority

Administración Nacional de Medicamentos, Alimentos y Tecnología Médica

Enforced

2002 (rev. 2022)

Legal framework

Ley 16.463 + Disposición 2318/02 + PDPA Argentina (Ley 25.326)

FDA package reuse

~85%

[Editorial estimate · how →](/methodology#fda-reuse)

## Scope

All medical devices marketed in Argentina, with SaMD and software updates increasingly under scrutiny.

Pre-market

Risk-class registration dossier; reference-jurisdiction route accepts FDA / CE / Health Canada approvals.

Post-market

Tecnovigilancia reporting to ANMAT, software change notifications.

SBOM

Recommended 

Encouraged in line with IMDRF N60; not yet mandated.

Vulnerability disclosure

Encouraged via CERT.ar coordination.

Penalty

Registration cancellation, sanitary fines, criminal liability for adulteration.

## Unique requirements

-   01 Argentine Registration Holder 
-   02 Spanish-language IFU and labelling 
-   03 Mercosur GMP audit accepted 

## Highlights

-   Reference jurisdiction route shortens timelines 
-   Spanish-language documentation throughout 
-   Mercosur harmonisation increasing 

## Aligns with

IMDRF N60  Mercosur GMP  ISO 13485 

## Timeline

1.  2002
    
    Disposición 2318/02 published
    
2.  2022
    
    Cybersecurity criteria added in revision
    

## Key documents

[

Disposición 2318/02 ANMAT

https://www.argentina.gob.ar/anmat



](https://www.argentina.gob.ar/anmat)

## How to submit in Argentina

Playbook reviewed · 2026-07-16

Submission route

ANMAT registration under Disposition 2318/2002

ANMAT accepts GHTF and MDSAP evidence. Cybersecurity documentation is not mandated separately but recommended for connected devices.

[Authority portal](https://www.argentina.gob.ar/anmat)

### Step-by-step

1.  Step 01
    
    Appoint local representation
    
    Most jurisdictions require a locally-established entity to hold the registration or act as authorised representative before submission.
    
2.  Step 02
    
    Reuse FDA or CE package as baseline
    
    Adapt the cybersecurity subsection you already prepared for FDA or CE; regulators here typically accept the structure and ask for local labeling additions.
    
3.  Step 03
    
    Translate and localise
    
    Local-language technical summary and labeling are usually mandatory; certified translation is safest.
    
4.  Step 04
    
    Submit + track queries
    
    Respond to clarification rounds promptly; each unanswered question can add 30-90 days to the clock.
    

### Evidence checklist

Item

Level

FDA equivalent

Notes

Cybersecurity documentation (baseline FDA or CE)

Required 

SPDF

Local authorised representative agreement

Required 

—

Local-language labeling and IFU

Required 

—

SBOM

Recommended 

—

Not mandatory but reduces clarification rounds.

### Common ANMAT rejections

No local Technical Director

Common 

Fix ·  Appoint a registered TD before submission.

### Typical timeline

End-to-end window: 9-15 months 

Phase 01

Local rep + dossier prep

2-4 months

Phase 02

Regulatory review

9-15 months

Phase 03

Approval + market entry

1-3 months

[Previous ![Flag of Indonesia](/flags/id.svg)Indonesia ](/standards/id)[Next  ![Flag of New Zealand](/flags/nz.svg)New Zealand ](/standards/nz)

## Related markets

[![Flag of Australia](/flags/au.svg)

Australia

~85% FDA reuse

](/standards/au)[![Flag of Saudi Arabia](/flags/sa.svg)

Saudi Arabia

~85% FDA reuse

](/standards/sa)[![Flag of Colombia](/flags/co.svg)

Colombia

~85% FDA reuse

](/standards/co)[![Flag of Taiwan](/flags/tw.svg)

Taiwan

~85% FDA reuse

](/standards/tw)

## Frequently asked about Argentina

### Is SBOM required for medical devices in Argentina?

Recommended. Encouraged in line with IMDRF N60; not yet mandated.

### What does ANMAT require for pre-market cybersecurity?

Risk-class registration dossier; reference-jurisdiction route accepts FDA / CE / Health Canada approvals.

### What are the post-market cybersecurity obligations under ANMAT?

Tecnovigilancia reporting to ANMAT, software change notifications.

### What is the penalty for non-compliance with ANMAT cybersecurity rules?

Registration cancellation, sanitary fines, criminal liability for adulteration.

### How much of my FDA cybersecurity package is reusable in Argentina?

Roughly 85% - an editorial estimate based on overlapping evidence requirements (threat model, SBOM, security risk assessment, pen-test report).

Sponsored note · Blue Goat Cyber

Submitting to ANMAT? Get a second pair of eyes before you file. Blue Goat Cyber has packaged cybersecurity evidence for Argentina alongside 37 other markets. We'll tell you what to keep, what to rework, and what's missing, in 30 minutes.  [Talk through your ANMAT submission](https://go.bluegoatcyber.com/meetings/blue-goat-cyber/discovery-session)

The Crosswalk

An independent reference for global medical device cybersecurity standards. A field guide for MedTech innovators and RA/QA teams charting an international path.

Resource

-   [Comparison matrix](/compare)
-   [Global playbook](/playbook)
-   [Glossary](/glossary)
-   [FAQ](/faq)

Sponsored by

[Blue Goat Cyber ↗](https://bluegoatcyber.com)

Editorially independent. Sponsorship keeps it free.

© 2026 The Crosswalk. Not legal advice.

Validate every requirement against current regulator publications.