---
title: "Australia TGA - Cybersecurity Submission Playbook"
description: "How to submit a medical device to TGA in Australia: step-by-step route, evidence checklist, common rejections, and typical review timeline. Compared with FDA"
lang: en
json-ld: |
  [
    {
      "@context": "https://schema.org",
      "@type": "WebSite",
      "name": "The Medical Device Cybersecurity Crosswalk",
      "alternateName": "MDC Crosswalk",
      "url": "https://mdccrosswalk.com/",
      "description": "Compare FDA, EU MDR, MHRA, PMDA, NMPA, TGA, MFDS and Health Canada medical device cybersecurity requirements across 29 jurisdictions."
    },
    {
      "@context": "https://schema.org",
      "@type": "Organization",
      "name": "MDC Crosswalk",
      "url": "https://mdccrosswalk.com/",
      "logo": "https://mdccrosswalk.com/favicon.png",
      "sameAs": [
        "https://bluegoatcyber.com"
      ],
      "description": "An editorial reference comparing global medical-device cybersecurity regulations. Maintained by Blue Goat Cyber."
    },
    {
      "@context": "https://schema.org",
      "@type": "Article",
      "headline": "Australia - Medical Device Cybersecurity Guidance",
      "description": "How to submit a medical device to TGA in Australia: step-by-step route, evidence checklist, common rejections, and typical review timeline. Compared with FDA ",
      "author": {
        "@type": "Organization",
        "name": "MDC Crosswalk"
      },
      "publisher": {
        "@type": "Organization",
        "name": "MDC Crosswalk"
      },
      "image": "https://mdccrosswalk.lovable.app/favicon.png",
      "datePublished": "Feb 2026 ('Understanding how we regulate software-based medical devices' refreshed Feb 24 2026; cyber-compliance guidance last updated Oct 2 2025)",
      "about": "Therapeutic Goods Administration",
      "dateModified": "2026-07-16",
      "mainEntityOfPage": "https://mdccrosswalk.lovable.app/standards/au"
    },
    {
      "@context": "https://schema.org",
      "@type": "FAQPage",
      "mainEntity": [
        {
          "@type": "Question",
          "name": "Is SBOM required for medical devices in Australia?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "Recommended. Encouraged; ACSC ISM compatibility valued."
          }
        },
        {
          "@type": "Question",
          "name": "What does TGA require for pre-market cybersecurity?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "Total Product Life Cycle (TPLC) approach, IEC 81001-5-1 referenced, evidence proportional to risk."
          }
        },
        {
          "@type": "Question",
          "name": "What are the post-market cybersecurity obligations under TGA?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "Incident reporting, MDSAP audits, ongoing patching."
          }
        },
        {
          "@type": "Question",
          "name": "What is the penalty for non-compliance with TGA cybersecurity rules?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "Cancellation from ARTG, civil penalties."
          }
        },
        {
          "@type": "Question",
          "name": "How much of my FDA cybersecurity package is reusable in Australia?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "Roughly 85% - an editorial estimate based on overlapping evidence requirements (threat model, SBOM, security risk assessment, pen-test report)."
          }
        },
        {
          "@type": "Question",
          "name": "Why do TGA submissions get rejected for \"no australian sponsor at time of application\"?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "Formalise the sponsor agreement before starting the ARTG application."
          }
        },
        {
          "@type": "Question",
          "name": "Why do TGA submissions get rejected for \"reliance on fda package without tga-specific labeling\"?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "Add Australian sponsor address and TGA-specific IFU statements."
          }
        }
      ]
    },
    {
      "@context": "https://schema.org",
      "@type": "HowTo",
      "name": "How to submit a medical device to TGA",
      "description": "TGA's cybersecurity guidance is largely aligned with FDA and MDCG 2019-16. Class IIb/III devices receive an application audit that may examine cybersecurity evidence directly.",
      "totalTime": "3-4 months for Class IIa (no audit); 8-14 months for Class IIb/III with audit.",
      "step": [
        {
          "@type": "HowToStep",
          "position": 1,
          "name": "Appoint an Australian sponsor",
          "text": "Non-Australian manufacturers must have an Australian sponsor listed on the ARTG entry."
        },
        {
          "@type": "HowToStep",
          "position": 2,
          "name": "Conformity assessment",
          "text": "Class IIa can rely on EU CE certificates; Class IIb/III often triggers a TGA conformity assessment or audit."
        },
        {
          "@type": "HowToStep",
          "position": 3,
          "name": "Prepare cybersecurity documentation",
          "text": "Follow the TGA Cyber Security Guidance structure; reuse FDA or EU content with Australian labeling additions."
        },
        {
          "@type": "HowToStep",
          "position": 4,
          "name": "Lodge ARTG application",
          "text": "Via the TGA Business Services portal; cybersecurity documentation is provided during application audit if triggered."
        }
      ]
    },
    {
      "@context": "https://schema.org",
      "@type": "BreadcrumbList",
      "itemListElement": [
        {
          "@type": "ListItem",
          "position": 1,
          "name": "Home",
          "item": "https://mdccrosswalk.lovable.app/"
        },
        {
          "@type": "ListItem",
          "position": 2,
          "name": "Standards"
        },
        {
          "@type": "ListItem",
          "position": 3,
          "name": "Australia"
        }
      ]
    }
  ]
---

[

The Crosswalk



](/)

[Overview](/)[Playbook](/playbook)CompareReference

[New Per-page social previews and this changelog ](/changelog "Per-page social previews and this changelog") Search⌘K

1.  [Home ](/)
2.  Standards 
3.  Australia 

TGA

# ![Flag of Australia](/flags/au.svg)Australia - TGA 

Guidance Last updated · Feb 2026 ('Understanding how we regulate software-based medical devices' refreshed Feb 24 2026; cyber-compliance guidance last updated Oct 2 2025) Verified · 2026-07-16 

Medical Device Cybersecurity Guidance

Share Copy link X LinkedIn Email

Sources verified · 2026-07-16

Cross-checked against TGA medical device cybersecurity guidance.

Authority

Therapeutic Goods Administration

Enforced

Jul 2019 (rev. 2022)

Legal framework

Therapeutic Goods Act + Essential Principles 12.1

FDA package reuse

~85%

[Editorial estimate · how →](/methodology#fda-reuse)

## Scope

All medical devices with software, networking or wireless connectivity. Two TGA documents: pre-market for industry and post-market for users.

Pre-market

Total Product Life Cycle (TPLC) approach, IEC 81001-5-1 referenced, evidence proportional to risk.

Post-market

Incident reporting, MDSAP audits, ongoing patching.

SBOM

Recommended 

Encouraged; ACSC ISM compatibility valued.

Vulnerability disclosure

Encouraged, ACSC alignment.

Penalty

Cancellation from ARTG, civil penalties.

## Unique requirements

-   01 Australian Sponsor required 
-   02 ARTG inclusion process 
-   03 Aligns to ACSC Essential Eight where applicable 

## Highlights

-   TPLC philosophy 
-   MDSAP recognition 
-   Light-touch but tightening 

## Aligns with

IMDRF N60  IEC 81001-5-1  MDSAP 

## Timeline

1.  Jul 2019
    
    First TGA cybersecurity guidance
    
2.  Jul 2022
    
    Revised guidance published
    
3.  Oct 2 2025
    
    TGA updates 'Complying with medical device cyber security requirements' online guidance
    
4.  Feb 24 2026
    
    TGA refreshes 'Understanding how we regulate software-based medical devices' guidance
    

## Key documents

[

Medical device cyber security guidance for industry (PDF)

https://www.tga.gov.au/sites/default/files/medical-device-cyber-security-guidance-industry.pdf



](https://www.tga.gov.au/sites/default/files/medical-device-cyber-security-guidance-industry.pdf)[

Complying with medical device cyber security requirements

https://www.tga.gov.au/resources/guidance/complying-medical-device-cyber-security-requirements



](https://www.tga.gov.au/resources/guidance/complying-medical-device-cyber-security-requirements)[

TGA medical device cyber security hub

https://www.tga.gov.au/safety/safety-monitoring-and-information/medical-device-cyber-security



](https://www.tga.gov.au/safety/safety-monitoring-and-information/medical-device-cyber-security)

## How to submit in Australia

Playbook reviewed · 2026-07-16

Submission route

TGA inclusion on the ARTG, with cybersecurity per the Medical Device Cyber Security Guidance for Industry (2021, updated 2024)

TGA's cybersecurity guidance is largely aligned with FDA and MDCG 2019-16. Class IIb/III devices receive an application audit that may examine cybersecurity evidence directly.

[Authority portal](https://www.tga.gov.au/products/medical-devices)

### Step-by-step

1.  Step 01
    
    Appoint an Australian sponsor
    
    Non-Australian manufacturers must have an Australian sponsor listed on the ARTG entry.
    
2.  Step 02
    
    Conformity assessment
    
    Class IIa can rely on EU CE certificates; Class IIb/III often triggers a TGA conformity assessment or audit.
    
3.  Step 03
    
    Prepare cybersecurity documentation
    
    Follow the TGA Cyber Security Guidance structure; reuse FDA or EU content with Australian labeling additions.
    
4.  Step 04
    
    Lodge ARTG application
    
    Via the TGA Business Services portal; cybersecurity documentation is provided during application audit if triggered.
    

### Evidence checklist

Item

Level

FDA equivalent

Notes

Cybersecurity documentation per TGA guidance

Required 

—

SBOM

Recommended 

—

Australian sponsor agreement

Required 

—

Post-market cybersecurity monitoring plan

Required 

—

### Common TGA rejections

No Australian sponsor at time of application

Common 

Fix ·  Formalise the sponsor agreement before starting the ARTG application.

Reliance on FDA package without TGA-specific labeling

Occasional 

Fix ·  Add Australian sponsor address and TGA-specific IFU statements.

### Typical timeline

End-to-end window: 3-4 months for Class IIa (no audit); 8-14 months for Class IIb/III with audit. 

Phase 01

Sponsor + documentation prep

2-4 months

Phase 02

ARTG lodgement + screening

1-2 months

Phase 03

Application audit (if triggered)

4-8 months

[Previous ![Flag of Canada](/flags/ca.svg)Canada ](/standards/ca)[Next  ![Flag of South Korea](/flags/kr.svg)South Korea ](/standards/kr)

## TGA head-to-head

[

Compare

![Flag of Australia](/flags/au.svg)TGAvs ![Flag of United States](/flags/us.svg)FDA 524B

Open comparison ](/compare/fda-vs-tga)

## Related markets

[![Flag of Saudi Arabia](/flags/sa.svg)

Saudi Arabia

~85% FDA reuse

](/standards/sa)[![Flag of Argentina](/flags/ar.svg)

Argentina

~85% FDA reuse

](/standards/ar)[![Flag of Colombia](/flags/co.svg)

Colombia

~85% FDA reuse

](/standards/co)[![Flag of Taiwan](/flags/tw.svg)

Taiwan

~85% FDA reuse

](/standards/tw)

## Frequently asked about Australia

### Is SBOM required for medical devices in Australia?

Recommended. Encouraged; ACSC ISM compatibility valued.

### What does TGA require for pre-market cybersecurity?

Total Product Life Cycle (TPLC) approach, IEC 81001-5-1 referenced, evidence proportional to risk.

### What are the post-market cybersecurity obligations under TGA?

Incident reporting, MDSAP audits, ongoing patching.

### What is the penalty for non-compliance with TGA cybersecurity rules?

Cancellation from ARTG, civil penalties.

### How much of my FDA cybersecurity package is reusable in Australia?

Roughly 85% - an editorial estimate based on overlapping evidence requirements (threat model, SBOM, security risk assessment, pen-test report).

Sponsored note · Blue Goat Cyber

Submitting to TGA? Get a second pair of eyes before you file. Blue Goat Cyber has packaged cybersecurity evidence for Australia alongside 37 other markets. We'll tell you what to keep, what to rework, and what's missing, in 30 minutes.  [Talk through your TGA submission](https://go.bluegoatcyber.com/meetings/blue-goat-cyber/discovery-session)

The Crosswalk

An independent reference for global medical device cybersecurity standards. A field guide for MedTech innovators and RA/QA teams charting an international path.

Resource

-   [Comparison matrix](/compare)
-   [Global playbook](/playbook)
-   [Glossary](/glossary)
-   [FAQ](/faq)

Sponsored by

[Blue Goat Cyber ↗](https://bluegoatcyber.com)

Editorially independent. Sponsorship keeps it free.

© 2026 The Crosswalk. Not legal advice.

Validate every requirement against current regulator publications.