The Crosswalk

    NewPer-page social previews and this changelog

    TGA

    Flag of AustraliaAustralia - TGA

    GuidanceLast updated · Feb 2026 ('Understanding how we regulate software-based medical devices' refreshed Feb 24 2026; cyber-compliance guidance last updated Oct 2 2025)Verified · 2026-07-16

    Medical Device Cybersecurity Guidance

    Share

    Authority

    Therapeutic Goods Administration

    Enforced

    Jul 2019 (rev. 2022)

    Legal framework

    Therapeutic Goods Act + Essential Principles 12.1

    FDA package reuse

    ~85%

    Scope

    All medical devices with software, networking or wireless connectivity. Two TGA documents: pre-market for industry and post-market for users.

    Pre-market

    Total Product Life Cycle (TPLC) approach, IEC 81001-5-1 referenced, evidence proportional to risk.

    Post-market

    Incident reporting, MDSAP audits, ongoing patching.

    SBOM

    Recommended

    Encouraged; ACSC ISM compatibility valued.

    Vulnerability disclosure

    Encouraged, ACSC alignment.

    Penalty

    Cancellation from ARTG, civil penalties.

    Unique requirements

    • 01Australian Sponsor required
    • 02ARTG inclusion process
    • 03Aligns to ACSC Essential Eight where applicable

    Highlights

    • TPLC philosophy
    • MDSAP recognition
    • Light-touch but tightening

    Aligns with

    IMDRF N60 IEC 81001-5-1 MDSAP

    Timeline

    1. Jul 2019

      First TGA cybersecurity guidance

    2. Jul 2022

      Revised guidance published

    3. Oct 2 2025

      TGA updates 'Complying with medical device cyber security requirements' online guidance

    4. Feb 24 2026

      TGA refreshes 'Understanding how we regulate software-based medical devices' guidance

    Key documents

    How to submit in Australia

    Playbook reviewed · 2026-07-16

    Submission route

    TGA inclusion on the ARTG, with cybersecurity per the Medical Device Cyber Security Guidance for Industry (2021, updated 2024)

    TGA's cybersecurity guidance is largely aligned with FDA and MDCG 2019-16. Class IIb/III devices receive an application audit that may examine cybersecurity evidence directly.

    Authority portal

    Step-by-step

    1. Step 01

      Appoint an Australian sponsor

      Non-Australian manufacturers must have an Australian sponsor listed on the ARTG entry.

    2. Step 02

      Conformity assessment

      Class IIa can rely on EU CE certificates; Class IIb/III often triggers a TGA conformity assessment or audit.

    3. Step 03

      Prepare cybersecurity documentation

      Follow the TGA Cyber Security Guidance structure; reuse FDA or EU content with Australian labeling additions.

    4. Step 04

      Lodge ARTG application

      Via the TGA Business Services portal; cybersecurity documentation is provided during application audit if triggered.

    Evidence checklist

    Item Level FDA equivalent Notes
    Cybersecurity documentation per TGA guidance Required
    SBOM Recommended
    Australian sponsor agreement Required
    Post-market cybersecurity monitoring plan Required

    Common TGA rejections

    No Australian sponsor at time of application

    Common

    Fix · Formalise the sponsor agreement before starting the ARTG application.

    Reliance on FDA package without TGA-specific labeling

    Occasional

    Fix · Add Australian sponsor address and TGA-specific IFU statements.

    Typical timeline

    End-to-end window: 3-4 months for Class IIa (no audit); 8-14 months for Class IIb/III with audit.

    Phase 01

    Sponsor + documentation prep

    2-4 months

    Phase 02

    ARTG lodgement + screening

    1-2 months

    Phase 03

    Application audit (if triggered)

    4-8 months

    TGA head-to-head

    Related markets

    Frequently asked about Australia

    Is SBOM required for medical devices in Australia?

    Recommended. Encouraged; ACSC ISM compatibility valued.

    What does TGA require for pre-market cybersecurity?

    Total Product Life Cycle (TPLC) approach, IEC 81001-5-1 referenced, evidence proportional to risk.

    What are the post-market cybersecurity obligations under TGA?

    Incident reporting, MDSAP audits, ongoing patching.

    What is the penalty for non-compliance with TGA cybersecurity rules?

    Cancellation from ARTG, civil penalties.

    How much of my FDA cybersecurity package is reusable in Australia?

    Roughly 85% - an editorial estimate based on overlapping evidence requirements (threat model, SBOM, security risk assessment, pen-test report).