The Crosswalk

    NewPer-page social previews and this changelog

    ANVISA

    Flag of BrazilBrazil - ANVISA

    MandatoryLast updated · 2023Verified · 2026-07-16

    RDC 751/2022 + Cybersecurity Guide for Medical Devices

    Share

    Authority

    Agência Nacional de Vigilância Sanitária

    Enforced

    Mar 2023 (RDC 751)

    Legal framework

    RDC 751/2022 + LGPD

    FDA package reuse

    ~60%

    Scope

    All medical devices, with risk-class proportional cybersecurity scrutiny. SaMD specifically addressed.

    Pre-market

    Cybersecurity documentation in registration dossier, risk management evidence aligned to ISO 14971.

    Post-market

    Tecnovigilância reporting, lifecycle updates, post-market surveillance.

    SBOM

    Recommended

    Encouraged, not strictly required.

    Vulnerability disclosure

    Encouraged, CERT.br coordination.

    Penalty

    Registration cancellation; LGPD fines up to 2% Brazilian revenue (max BRL 50M per infraction).

    Unique requirements

    • 01Brazilian Registration Holder (BRH)
    • 02Portuguese-language IFU and labelling
    • 03INMETRO certification for electrical safety

    Highlights

    • Risk-class based scrutiny
    • MDSAP partially recognised
    • Portuguese-language documentation required

    Aligns with

    IMDRF N60 MDSAP (partial)

    Timeline

    1. 2020

      ANVISA cybersecurity guide v1

    2. Sep 2022

      RDC 751/2022 published

    3. Mar 2023

      RDC 751 effective

    Key documents

    How to submit in Brazil

    Playbook reviewed · 2026-07-16

    Submission route

    ANVISA registration or notification under RDC 751/2022 and cybersecurity guidance in RDC 657/2022 for SaMD

    ANVISA aligns broadly with IMDRF and MDSAP. Cybersecurity documentation must be in Portuguese, and Class III/IV devices require the Brazilian Good Manufacturing Practices Certificate (CBPF) before registration.

    Authority portal

    Step-by-step

    1. Step 01

      Appoint a Brazilian Registration Holder (BRH)

      Foreign manufacturers cannot register directly.

    2. Step 02

      Obtain CBPF (Class III/IV)

      ANVISA GMP inspection or MDSAP-based CBPF; MDSAP path shortens the queue substantially.

    3. Step 03

      Prepare cybersecurity dossier (Portuguese)

      Follow RDC 657/2022 structure; reuse FDA content with Portuguese translation.

    4. Step 04

      Submit via ANVISA portal

      Petition includes the technical dossier and CBPF reference.

    Evidence checklist

    Item Level FDA equivalent Notes
    Cybersecurity dossier (Portuguese) Required
    CBPF (Class III/IV) Required
    SBOM Recommended
    BRH agreement Required

    Common ANVISA rejections

    CBPF not in place at time of registration filing

    Common

    Fix · Use MDSAP-based CBPF path to compress the pre-registration timeline.

    Dossier not fully translated to Portuguese

    Common

    Fix · Portuguese translation is non-negotiable; budget 6-8 weeks for certified translation.

    Typical timeline

    End-to-end window: 1-3 months (notification) to 18-30 months (Class III/IV with CBPF).

    Phase 01

    CBPF (MDSAP path)

    6-12 months

    Phase 02

    Registration review (Class III/IV)

    12-18 months

    Phase 03

    Registration review (Class I/II notification)

    1-3 months

    Related markets

    Frequently asked about Brazil

    Is SBOM required for medical devices in Brazil?

    Recommended. Encouraged, not strictly required.

    What does ANVISA require for pre-market cybersecurity?

    Cybersecurity documentation in registration dossier, risk management evidence aligned to ISO 14971.

    What are the post-market cybersecurity obligations under ANVISA?

    Tecnovigilância reporting, lifecycle updates, post-market surveillance.

    What is the penalty for non-compliance with ANVISA cybersecurity rules?

    Registration cancellation; LGPD fines up to 2% Brazilian revenue (max BRL 50M per infraction).

    How much of my FDA cybersecurity package is reusable in Brazil?

    Roughly 60% - an editorial estimate based on overlapping evidence requirements (threat model, SBOM, security risk assessment, pen-test report).