---
title: "Brazil ANVISA - Cybersecurity Submission Playbook"
description: "How to submit a medical device to ANVISA in Brazil: step-by-step route, evidence checklist, common rejections, and typical review timeline. Compared with FDA"
lang: en
json-ld: |
  [
    {
      "@context": "https://schema.org",
      "@type": "WebSite",
      "name": "The Medical Device Cybersecurity Crosswalk",
      "alternateName": "MDC Crosswalk",
      "url": "https://mdccrosswalk.com/",
      "description": "Compare FDA, EU MDR, MHRA, PMDA, NMPA, TGA, MFDS and Health Canada medical device cybersecurity requirements across 29 jurisdictions."
    },
    {
      "@context": "https://schema.org",
      "@type": "Organization",
      "name": "MDC Crosswalk",
      "url": "https://mdccrosswalk.com/",
      "logo": "https://mdccrosswalk.com/favicon.png",
      "sameAs": [
        "https://bluegoatcyber.com"
      ],
      "description": "An editorial reference comparing global medical-device cybersecurity regulations. Maintained by Blue Goat Cyber."
    },
    {
      "@context": "https://schema.org",
      "@type": "Article",
      "headline": "Brazil - RDC 751/2022 + Cybersecurity Guide for Medical Devices",
      "description": "How to submit a medical device to ANVISA in Brazil: step-by-step route, evidence checklist, common rejections, and typical review timeline. Compared with FDA ",
      "author": {
        "@type": "Organization",
        "name": "MDC Crosswalk"
      },
      "publisher": {
        "@type": "Organization",
        "name": "MDC Crosswalk"
      },
      "image": "https://mdccrosswalk.lovable.app/favicon.png",
      "datePublished": "2023",
      "about": "Agência Nacional de Vigilância Sanitária",
      "dateModified": "2026-07-16",
      "mainEntityOfPage": "https://mdccrosswalk.lovable.app/standards/br"
    },
    {
      "@context": "https://schema.org",
      "@type": "FAQPage",
      "mainEntity": [
        {
          "@type": "Question",
          "name": "Is SBOM required for medical devices in Brazil?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "Recommended. Encouraged, not strictly required."
          }
        },
        {
          "@type": "Question",
          "name": "What does ANVISA require for pre-market cybersecurity?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "Cybersecurity documentation in registration dossier, risk management evidence aligned to ISO 14971."
          }
        },
        {
          "@type": "Question",
          "name": "What are the post-market cybersecurity obligations under ANVISA?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "Tecnovigilância reporting, lifecycle updates, post-market surveillance."
          }
        },
        {
          "@type": "Question",
          "name": "What is the penalty for non-compliance with ANVISA cybersecurity rules?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "Registration cancellation; LGPD fines up to 2% Brazilian revenue (max BRL 50M per infraction)."
          }
        },
        {
          "@type": "Question",
          "name": "How much of my FDA cybersecurity package is reusable in Brazil?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "Roughly 60% - an editorial estimate based on overlapping evidence requirements (threat model, SBOM, security risk assessment, pen-test report)."
          }
        },
        {
          "@type": "Question",
          "name": "Why do ANVISA submissions get rejected for \"cbpf not in place at time of registration filing\"?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "Use MDSAP-based CBPF path to compress the pre-registration timeline."
          }
        },
        {
          "@type": "Question",
          "name": "Why do ANVISA submissions get rejected for \"dossier not fully translated to portuguese\"?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "Portuguese translation is non-negotiable; budget 6-8 weeks for certified translation."
          }
        }
      ]
    },
    {
      "@context": "https://schema.org",
      "@type": "HowTo",
      "name": "How to submit a medical device to ANVISA",
      "description": "ANVISA aligns broadly with IMDRF and MDSAP. Cybersecurity documentation must be in Portuguese, and Class III/IV devices require the Brazilian Good Manufacturing Practices Certificate (CBPF) before registration.",
      "totalTime": "1-3 months (notification) to 18-30 months (Class III/IV with CBPF).",
      "step": [
        {
          "@type": "HowToStep",
          "position": 1,
          "name": "Appoint a Brazilian Registration Holder (BRH)",
          "text": "Foreign manufacturers cannot register directly."
        },
        {
          "@type": "HowToStep",
          "position": 2,
          "name": "Obtain CBPF (Class III/IV)",
          "text": "ANVISA GMP inspection or MDSAP-based CBPF; MDSAP path shortens the queue substantially."
        },
        {
          "@type": "HowToStep",
          "position": 3,
          "name": "Prepare cybersecurity dossier (Portuguese)",
          "text": "Follow RDC 657/2022 structure; reuse FDA content with Portuguese translation."
        },
        {
          "@type": "HowToStep",
          "position": 4,
          "name": "Submit via ANVISA portal",
          "text": "Petition includes the technical dossier and CBPF reference."
        }
      ]
    },
    {
      "@context": "https://schema.org",
      "@type": "BreadcrumbList",
      "itemListElement": [
        {
          "@type": "ListItem",
          "position": 1,
          "name": "Home",
          "item": "https://mdccrosswalk.lovable.app/"
        },
        {
          "@type": "ListItem",
          "position": 2,
          "name": "Standards"
        },
        {
          "@type": "ListItem",
          "position": 3,
          "name": "Brazil"
        }
      ]
    }
  ]
---

[

The Crosswalk



](/)

[Overview](/)[Playbook](/playbook)CompareReference

[New Per-page social previews and this changelog ](/changelog "Per-page social previews and this changelog") Search⌘K

1.  [Home ](/)
2.  Standards 
3.  Brazil 

ANVISA

# ![Flag of Brazil](/flags/br.svg)Brazil - ANVISA 

Mandatory Last updated · 2023 Verified · 2026-07-16 

RDC 751/2022 + Cybersecurity Guide for Medical Devices

Share Copy link X LinkedIn Email

Sources verified · 2026-07-16

RDC 751/2022 governs device registration broadly; cybersecurity expectations are layered via ANVISA cybersecurity guide rather than a single binding cyber rule.

Authority

Agência Nacional de Vigilância Sanitária

Enforced

Mar 2023 (RDC 751)

Legal framework

RDC 751/2022 + LGPD

FDA package reuse

~60%

[Editorial estimate · how →](/methodology#fda-reuse)

## Scope

All medical devices, with risk-class proportional cybersecurity scrutiny. SaMD specifically addressed.

Pre-market

Cybersecurity documentation in registration dossier, risk management evidence aligned to ISO 14971.

Post-market

Tecnovigilância reporting, lifecycle updates, post-market surveillance.

SBOM

Recommended 

Encouraged, not strictly required.

Vulnerability disclosure

Encouraged, CERT.br coordination.

Penalty

Registration cancellation; LGPD fines up to 2% Brazilian revenue (max BRL 50M per infraction).

## Unique requirements

-   01 Brazilian Registration Holder (BRH) 
-   02 Portuguese-language IFU and labelling 
-   03 INMETRO certification for electrical safety 

## Highlights

-   Risk-class based scrutiny 
-   MDSAP partially recognised 
-   Portuguese-language documentation required 

## Aligns with

IMDRF N60  MDSAP (partial) 

## Timeline

1.  2020
    
    ANVISA cybersecurity guide v1
    
2.  Sep 2022
    
    RDC 751/2022 published
    
3.  Mar 2023
    
    RDC 751 effective
    

## Key documents

[

RDC 751/2022

https://www.gov.br/anvisa/pt-br



](https://www.gov.br/anvisa/pt-br)[

ANVISA Cybersecurity Guide

https://www.gov.br/anvisa/pt-br



](https://www.gov.br/anvisa/pt-br)

## How to submit in Brazil

Playbook reviewed · 2026-07-16

Submission route

ANVISA registration or notification under RDC 751/2022 and cybersecurity guidance in RDC 657/2022 for SaMD

ANVISA aligns broadly with IMDRF and MDSAP. Cybersecurity documentation must be in Portuguese, and Class III/IV devices require the Brazilian Good Manufacturing Practices Certificate (CBPF) before registration.

[Authority portal](https://www.gov.br/anvisa/pt-br/english)

### Step-by-step

1.  Step 01
    
    Appoint a Brazilian Registration Holder (BRH)
    
    Foreign manufacturers cannot register directly.
    
2.  Step 02
    
    Obtain CBPF (Class III/IV)
    
    ANVISA GMP inspection or MDSAP-based CBPF; MDSAP path shortens the queue substantially.
    
3.  Step 03
    
    Prepare cybersecurity dossier (Portuguese)
    
    Follow RDC 657/2022 structure; reuse FDA content with Portuguese translation.
    
4.  Step 04
    
    Submit via ANVISA portal
    
    Petition includes the technical dossier and CBPF reference.
    

### Evidence checklist

Item

Level

FDA equivalent

Notes

Cybersecurity dossier (Portuguese)

Required 

—

CBPF (Class III/IV)

Required 

—

SBOM

Recommended 

—

BRH agreement

Required 

—

### Common ANVISA rejections

CBPF not in place at time of registration filing

Common 

Fix ·  Use MDSAP-based CBPF path to compress the pre-registration timeline.

Dossier not fully translated to Portuguese

Common 

Fix ·  Portuguese translation is non-negotiable; budget 6-8 weeks for certified translation.

### Typical timeline

End-to-end window: 1-3 months (notification) to 18-30 months (Class III/IV with CBPF). 

Phase 01

CBPF (MDSAP path)

6-12 months

Phase 02

Registration review (Class III/IV)

12-18 months

Phase 03

Registration review (Class I/II notification)

1-3 months

[Previous ![Flag of Singapore](/flags/sg.svg)Singapore ](/standards/sg)[Next  ![Flag of Saudi Arabia](/flags/sa.svg)Saudi Arabia ](/standards/sa)

## Related markets

[![Flag of European Union](/flags/eu.svg)

European Union

~60% FDA reuse

](/standards/eu)[![Flag of Norway](/flags/no.svg)

Norway

~60% FDA reuse

](/standards/no)[![Flag of South Korea](/flags/kr.svg)

South Korea

~65% FDA reuse

](/standards/kr)[![Flag of Switzerland](/flags/ch.svg)

Switzerland

~55% FDA reuse

](/standards/ch)

## Frequently asked about Brazil

### Is SBOM required for medical devices in Brazil?

Recommended. Encouraged, not strictly required.

### What does ANVISA require for pre-market cybersecurity?

Cybersecurity documentation in registration dossier, risk management evidence aligned to ISO 14971.

### What are the post-market cybersecurity obligations under ANVISA?

Tecnovigilância reporting, lifecycle updates, post-market surveillance.

### What is the penalty for non-compliance with ANVISA cybersecurity rules?

Registration cancellation; LGPD fines up to 2% Brazilian revenue (max BRL 50M per infraction).

### How much of my FDA cybersecurity package is reusable in Brazil?

Roughly 60% - an editorial estimate based on overlapping evidence requirements (threat model, SBOM, security risk assessment, pen-test report).

Sponsored note · Blue Goat Cyber

Submitting to ANVISA? Get a second pair of eyes before you file. Blue Goat Cyber has packaged cybersecurity evidence for Brazil alongside 37 other markets. We'll tell you what to keep, what to rework, and what's missing, in 30 minutes.  [Talk through your ANVISA submission](https://go.bluegoatcyber.com/meetings/blue-goat-cyber/discovery-session)

The Crosswalk

An independent reference for global medical device cybersecurity standards. A field guide for MedTech innovators and RA/QA teams charting an international path.

Resource

-   [Comparison matrix](/compare)
-   [Global playbook](/playbook)
-   [Glossary](/glossary)
-   [FAQ](/faq)

Sponsored by

[Blue Goat Cyber ↗](https://bluegoatcyber.com)

Editorially independent. Sponsorship keeps it free.

© 2026 The Crosswalk. Not legal advice.

Validate every requirement against current regulator publications.