TGA
Australia - TGA
Medical Device Cybersecurity Guidance
Authority
Therapeutic Goods Administration
Enforced
Jul 2019 (rev. 2022)
Legal framework
Therapeutic Goods Act + Essential Principles 12.1
Scope
All medical devices with software, networking or wireless connectivity. Two TGA documents: pre-market for industry and post-market for users.
Pre-market
Total Product Life Cycle (TPLC) approach, IEC 81001-5-1 referenced, evidence proportional to risk.
Post-market
Incident reporting, MDSAP audits, ongoing patching.
SBOM
RecommendedEncouraged; ACSC ISM compatibility valued.
Vulnerability disclosure
Encouraged, ACSC alignment.
Penalty
Cancellation from ARTG, civil penalties.
Unique requirements
- 01Australian Sponsor required
- 02ARTG inclusion process
- 03Aligns to ACSC Essential Eight where applicable
Highlights
- TPLC philosophy
- MDSAP recognition
- Light-touch but tightening
Aligns with
Timeline
-
Jul 2019
First TGA cybersecurity guidance
-
Jul 2022
Revised guidance published
-
Oct 2 2025
TGA updates 'Complying with medical device cyber security requirements' online guidance
-
Feb 24 2026
TGA refreshes 'Understanding how we regulate software-based medical devices' guidance
Key documents
Medical device cyber security guidance for industry (PDF)
https://www.tga.gov.au/sites/default/files/medical-device-cyber-security-guidance-industry.pdf
Complying with medical device cyber security requirements
https://www.tga.gov.au/resources/guidance/complying-medical-device-cyber-security-requirements
TGA medical device cyber security hub
https://www.tga.gov.au/safety/safety-monitoring-and-information/medical-device-cyber-security
How to submit in Australia
Playbook reviewed · 2026-07-16
Submission route
TGA inclusion on the ARTG, with cybersecurity per the Medical Device Cyber Security Guidance for Industry (2021, updated 2024)
TGA's cybersecurity guidance is largely aligned with FDA and MDCG 2019-16. Class IIb/III devices receive an application audit that may examine cybersecurity evidence directly.
Authority portalStep-by-step
-
Step 01
Appoint an Australian sponsor
Non-Australian manufacturers must have an Australian sponsor listed on the ARTG entry.
-
Step 02
Conformity assessment
Class IIa can rely on EU CE certificates; Class IIb/III often triggers a TGA conformity assessment or audit.
-
Step 03
Prepare cybersecurity documentation
Follow the TGA Cyber Security Guidance structure; reuse FDA or EU content with Australian labeling additions.
-
Step 04
Lodge ARTG application
Via the TGA Business Services portal; cybersecurity documentation is provided during application audit if triggered.
Evidence checklist
| Item | Level | FDA equivalent | Notes |
|---|---|---|---|
| Cybersecurity documentation per TGA guidance | Required | — | |
| SBOM | Recommended | — | |
| Australian sponsor agreement | Required | — | |
| Post-market cybersecurity monitoring plan | Required | — |
Common TGA rejections
No Australian sponsor at time of application
CommonFix · Formalise the sponsor agreement before starting the ARTG application.
Reliance on FDA package without TGA-specific labeling
OccasionalFix · Add Australian sponsor address and TGA-specific IFU statements.
Typical timeline
End-to-end window: 3-4 months for Class IIa (no audit); 8-14 months for Class IIb/III with audit.
Phase 01
Sponsor + documentation prep
2-4 months
Phase 02
ARTG lodgement + screening
1-2 months
Phase 03
Application audit (if triggered)
4-8 months
TGA head-to-head
Related markets
Frequently asked about Australia
Is SBOM required for medical devices in Australia?
Recommended. Encouraged; ACSC ISM compatibility valued.
What does TGA require for pre-market cybersecurity?
Total Product Life Cycle (TPLC) approach, IEC 81001-5-1 referenced, evidence proportional to risk.
What are the post-market cybersecurity obligations under TGA?
Incident reporting, MDSAP audits, ongoing patching.
What is the penalty for non-compliance with TGA cybersecurity rules?
Cancellation from ARTG, civil penalties.
How much of my FDA cybersecurity package is reusable in Australia?
Roughly 85% - an editorial estimate based on overlapping evidence requirements (threat model, SBOM, security risk assessment, pen-test report).