The Crosswalk

    NewPer-page social previews and this changelog

    Health Canada

    Flag of CanadaCanada - Health Canada

    MandatoryLast updated · 2019 (no cybersecurity-specific revision confirmed at canada.ca as of Jun 2026)Verified · 2026-07-16

    Pre-market Requirements for Medical Device Cybersecurity

    Share

    Authority

    Health Canada, Medical Devices Bureau

    Enforced

    Jun 2019

    Legal framework

    Medical Devices Regulations (SOR/98-282)

    FDA package reuse

    ~95%

    Scope

    Class II, III, IV devices with software. Cybersecurity evidence required as part of licence application.

    Pre-market

    Risk management, secure design, verification evidence in licence application; aligns with FDA SPDF.

    Post-market

    Mandatory problem reporting, CVD plan, software change reports.

    SBOM

    Recommended

    Not strictly mandatory but strongly aligned to FDA expectations; reuse FDA package.

    Vulnerability disclosure

    Recommended via Canadian Centre for Cyber Security (CCCS).

    Penalty

    Licence cancellation, suspension, public advisories.

    Unique requirements

    • 01Bilingual labelling and IFU
    • 02Canadian Importer or Resident
    • 03MDSAP audit accepted in lieu of dedicated QMS audit

    Highlights

    • Aligned with FDA premarket cybersecurity guidance (Feb 2026)
    • MDSAP-friendly evidence reuse
    • Bilingual labelling (EN/FR)

    Aligns with

    FDA Feb 2026 Final Guidance IMDRF N60 ISO 13485 via MDSAP

    Timeline

    1. Jun 2019

      Original guidance published

    Key documents

    How to submit in Canada

    Playbook reviewed · 2026-07-16

    Submission route

    Medical Device Licence application to Health Canada under the Food and Drugs Act, with cybersecurity per Health Canada's 2019 Pre-market Guidance

    Health Canada explicitly recognises FDA content and IMDRF principles. A well-prepared FDA cybersecurity subsection covers most Canadian expectations, with only minor labeling and MDSAP-linked QMS additions.

    Authority portal

    Step-by-step

    1. Step 01

      Confirm MDSAP certificate

      MDSAP is mandatory for Class II-IV; make sure the certificate covers your manufacturing site.

    2. Step 02

      Adapt FDA cybersecurity subsection

      Reuse the FDA package; add Canadian-specific labeling references and update authority names.

    3. Step 03

      Submit MDL application

      Electronic submission via CESG portal; cybersecurity documentation is embedded in the technical file.

    4. Step 04

      Respond to screening + review questions

      Health Canada issues a screening letter within 15 days; substantive questions follow.

    Evidence checklist

    Item Level FDA equivalent Notes
    Cybersecurity documentation aligned to 2019 Health Canada guidance Required SPDF
    MDSAP certificate Required
    SBOM Recommended Not mandatory but requested for higher-risk connected devices.
    Canadian labeling and IFU Required Bilingual EN/FR.

    Common Health Canada rejections

    IFU only in English

    Common

    Fix · Provide fully bilingual EN/FR labeling and IFU before submission.

    MDSAP scope excludes the manufacturing site

    Occasional

    Fix · Amend the MDSAP certificate scope before filing.

    Typical timeline

    End-to-end window: 4-9 months for Class III/IV with a strong FDA-reusable package.

    Phase 01

    Screening

    15-30 days

    Phase 02

    Class III/IV review

    60-75 days performance target

    Phase 03

    Response to questions

    30-90 days

    Health Canada head-to-head

    Related markets

    Frequently asked about Canada

    Is SBOM required for medical devices in Canada?

    Recommended. Not strictly mandatory but strongly aligned to FDA expectations; reuse FDA package.

    What does Health Canada require for pre-market cybersecurity?

    Risk management, secure design, verification evidence in licence application; aligns with FDA SPDF.

    What are the post-market cybersecurity obligations under Health Canada?

    Mandatory problem reporting, CVD plan, software change reports.

    What is the penalty for non-compliance with Health Canada cybersecurity rules?

    Licence cancellation, suspension, public advisories.

    How much of my FDA cybersecurity package is reusable in Canada?

    Roughly 95% - an editorial estimate based on overlapping evidence requirements (threat model, SBOM, security risk assessment, pen-test report).