---
title: "Canada Health Canada - Cybersecurity Submission Playbook"
description: "How to submit a medical device to Health Canada in Canada: step-by-step route, evidence checklist, common rejections, and typical review timeline. Compared wi"
lang: en
json-ld: |
  [
    {
      "@context": "https://schema.org",
      "@type": "WebSite",
      "name": "The Medical Device Cybersecurity Crosswalk",
      "alternateName": "MDC Crosswalk",
      "url": "https://mdccrosswalk.com/",
      "description": "Compare FDA, EU MDR, MHRA, PMDA, NMPA, TGA, MFDS and Health Canada medical device cybersecurity requirements across 29 jurisdictions."
    },
    {
      "@context": "https://schema.org",
      "@type": "Organization",
      "name": "MDC Crosswalk",
      "url": "https://mdccrosswalk.com/",
      "logo": "https://mdccrosswalk.com/favicon.png",
      "sameAs": [
        "https://bluegoatcyber.com"
      ],
      "description": "An editorial reference comparing global medical-device cybersecurity regulations. Maintained by Blue Goat Cyber."
    },
    {
      "@context": "https://schema.org",
      "@type": "Article",
      "headline": "Canada - Pre-market Requirements for Medical Device Cybersecurity",
      "description": "How to submit a medical device to Health Canada in Canada: step-by-step route, evidence checklist, common rejections, and typical review timeline. Compared wi",
      "author": {
        "@type": "Organization",
        "name": "MDC Crosswalk"
      },
      "publisher": {
        "@type": "Organization",
        "name": "MDC Crosswalk"
      },
      "image": "https://mdccrosswalk.lovable.app/favicon.png",
      "datePublished": "2019 (no cybersecurity-specific revision confirmed at canada.ca as of Jun 2026)",
      "about": "Health Canada, Medical Devices Bureau",
      "dateModified": "2026-07-16",
      "mainEntityOfPage": "https://mdccrosswalk.lovable.app/standards/ca"
    },
    {
      "@context": "https://schema.org",
      "@type": "FAQPage",
      "mainEntity": [
        {
          "@type": "Question",
          "name": "Is SBOM required for medical devices in Canada?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "Recommended. Not strictly mandatory but strongly aligned to FDA expectations; reuse FDA package."
          }
        },
        {
          "@type": "Question",
          "name": "What does Health Canada require for pre-market cybersecurity?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "Risk management, secure design, verification evidence in licence application; aligns with FDA SPDF."
          }
        },
        {
          "@type": "Question",
          "name": "What are the post-market cybersecurity obligations under Health Canada?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "Mandatory problem reporting, CVD plan, software change reports."
          }
        },
        {
          "@type": "Question",
          "name": "What is the penalty for non-compliance with Health Canada cybersecurity rules?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "Licence cancellation, suspension, public advisories."
          }
        },
        {
          "@type": "Question",
          "name": "How much of my FDA cybersecurity package is reusable in Canada?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "Roughly 95% - an editorial estimate based on overlapping evidence requirements (threat model, SBOM, security risk assessment, pen-test report)."
          }
        },
        {
          "@type": "Question",
          "name": "Why do Health Canada submissions get rejected for \"ifu only in english\"?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "Provide fully bilingual EN/FR labeling and IFU before submission."
          }
        },
        {
          "@type": "Question",
          "name": "Why do Health Canada submissions get rejected for \"mdsap scope excludes the manufacturing site\"?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "Amend the MDSAP certificate scope before filing."
          }
        }
      ]
    },
    {
      "@context": "https://schema.org",
      "@type": "HowTo",
      "name": "How to submit a medical device to Health Canada",
      "description": "Health Canada explicitly recognises FDA content and IMDRF principles. A well-prepared FDA cybersecurity subsection covers most Canadian expectations, with only minor labeling and MDSAP-linked QMS additions.",
      "totalTime": "4-9 months for Class III/IV with a strong FDA-reusable package.",
      "step": [
        {
          "@type": "HowToStep",
          "position": 1,
          "name": "Confirm MDSAP certificate",
          "text": "MDSAP is mandatory for Class II-IV; make sure the certificate covers your manufacturing site."
        },
        {
          "@type": "HowToStep",
          "position": 2,
          "name": "Adapt FDA cybersecurity subsection",
          "text": "Reuse the FDA package; add Canadian-specific labeling references and update authority names."
        },
        {
          "@type": "HowToStep",
          "position": 3,
          "name": "Submit MDL application",
          "text": "Electronic submission via CESG portal; cybersecurity documentation is embedded in the technical file."
        },
        {
          "@type": "HowToStep",
          "position": 4,
          "name": "Respond to screening + review questions",
          "text": "Health Canada issues a screening letter within 15 days; substantive questions follow."
        }
      ]
    },
    {
      "@context": "https://schema.org",
      "@type": "BreadcrumbList",
      "itemListElement": [
        {
          "@type": "ListItem",
          "position": 1,
          "name": "Home",
          "item": "https://mdccrosswalk.lovable.app/"
        },
        {
          "@type": "ListItem",
          "position": 2,
          "name": "Standards"
        },
        {
          "@type": "ListItem",
          "position": 3,
          "name": "Canada"
        }
      ]
    }
  ]
---

[

The Crosswalk



](/)

[Overview](/)[Playbook](/playbook)CompareReference

[New Per-page social previews and this changelog ](/changelog "Per-page social previews and this changelog") Search⌘K

1.  [Home ](/)
2.  Standards 
3.  Canada 

Health Canada

# ![Flag of Canada](/flags/ca.svg)Canada - Health Canada 

Mandatory Last updated · 2019 (no cybersecurity-specific revision confirmed at canada.ca as of Jun 2026) Verified · 2026-07-16 

Pre-market Requirements for Medical Device Cybersecurity

Share Copy link X LinkedIn Email

Sources verified · 2026-07-16

Cross-checked against Health Canada premarket cybersecurity guidance at canada.ca - confirmed as Jun 2019 document with no revision; any '2024 update' claim is unconfirmed against the primary source.

Authority

Health Canada, Medical Devices Bureau

Enforced

Jun 2019

Legal framework

Medical Devices Regulations (SOR/98-282)

FDA package reuse

~95%

[Editorial estimate · how →](/methodology#fda-reuse)

## Scope

Class II, III, IV devices with software. Cybersecurity evidence required as part of licence application.

Pre-market

Risk management, secure design, verification evidence in licence application; aligns with FDA SPDF.

Post-market

Mandatory problem reporting, CVD plan, software change reports.

SBOM

Recommended 

Not strictly mandatory but strongly aligned to FDA expectations; reuse FDA package.

Vulnerability disclosure

Recommended via Canadian Centre for Cyber Security (CCCS).

Penalty

Licence cancellation, suspension, public advisories.

## Unique requirements

-   01 Bilingual labelling and IFU 
-   02 Canadian Importer or Resident 
-   03 MDSAP audit accepted in lieu of dedicated QMS audit 

## Highlights

-   Aligned with FDA premarket cybersecurity guidance (Feb 2026) 
-   MDSAP-friendly evidence reuse 
-   Bilingual labelling (EN/FR) 

## Aligns with

FDA Feb 2026 Final Guidance  IMDRF N60  ISO 13485 via MDSAP 

## Timeline

1.  Jun 2019
    
    Original guidance published
    

## Key documents

[

Pre-market Requirements for Medical Device Cybersecurity (Health Canada)

https://www.canada.ca/en/health-canada/services/drugs-health-products/medical-devices/application-information/guidance-documents/cybersecurity.html



](https://www.canada.ca/en/health-canada/services/drugs-health-products/medical-devices/application-information/guidance-documents/cybersecurity.html)[

Medical Devices Regulations SOR/98-282

https://laws-lois.justice.gc.ca/eng/regulations/sor-98-282/



](https://laws-lois.justice.gc.ca/eng/regulations/sor-98-282/)

## How to submit in Canada

Playbook reviewed · 2026-07-16

Submission route

Medical Device Licence application to Health Canada under the Food and Drugs Act, with cybersecurity per Health Canada's 2019 Pre-market Guidance

Health Canada explicitly recognises FDA content and IMDRF principles. A well-prepared FDA cybersecurity subsection covers most Canadian expectations, with only minor labeling and MDSAP-linked QMS additions.

[Authority portal](https://www.canada.ca/en/health-canada/services/drugs-health-products/medical-devices.html)

### Step-by-step

1.  Step 01
    
    Confirm MDSAP certificate
    
    MDSAP is mandatory for Class II-IV; make sure the certificate covers your manufacturing site.
    
2.  Step 02
    
    Adapt FDA cybersecurity subsection
    
    Reuse the FDA package; add Canadian-specific labeling references and update authority names.
    
3.  Step 03
    
    Submit MDL application
    
    Electronic submission via CESG portal; cybersecurity documentation is embedded in the technical file.
    
4.  Step 04
    
    Respond to screening + review questions
    
    Health Canada issues a screening letter within 15 days; substantive questions follow.
    

### Evidence checklist

Item

Level

FDA equivalent

Notes

Cybersecurity documentation aligned to 2019 Health Canada guidance

Required 

SPDF

MDSAP certificate

Required 

—

SBOM

Recommended 

—

Not mandatory but requested for higher-risk connected devices.

Canadian labeling and IFU

Required 

—

Bilingual EN/FR.

### Common Health Canada rejections

IFU only in English

Common 

Fix ·  Provide fully bilingual EN/FR labeling and IFU before submission.

MDSAP scope excludes the manufacturing site

Occasional 

Fix ·  Amend the MDSAP certificate scope before filing.

### Typical timeline

End-to-end window: 4-9 months for Class III/IV with a strong FDA-reusable package. 

Phase 01

Screening

15-30 days

Phase 02

Class III/IV review

60-75 days performance target

Phase 03

Response to questions

30-90 days

[Previous ![Flag of China](/flags/cn.svg)China ](/standards/cn)[Next  ![Flag of Australia](/flags/au.svg)Australia ](/standards/au)

## Health Canada head-to-head

[

Compare

![Flag of Canada](/flags/ca.svg)Health Canadavs ![Flag of United States](/flags/us.svg)FDA 524B

Open comparison ](/compare/fda-vs-health-canada)[

Compare

![Flag of Canada](/flags/ca.svg)Health Canadavs ![Flag of European Union](/flags/eu.svg)EU MDR

Open comparison ](/compare/eu-mdr-vs-health-canada)

## Related markets

[![Flag of United States](/flags/us.svg)

United States

~100% FDA reuse

](/standards/fda)[![Flag of Israel](/flags/il.svg)

Israel

~90% FDA reuse

](/standards/il)[![Flag of United Arab Emirates](/flags/ae.svg)

United Arab Emirates

~85% FDA reuse

](/standards/ae)[![Flag of Japan](/flags/jp.svg)

Japan

~70% FDA reuse

](/standards/jp)

## Frequently asked about Canada

### Is SBOM required for medical devices in Canada?

Recommended. Not strictly mandatory but strongly aligned to FDA expectations; reuse FDA package.

### What does Health Canada require for pre-market cybersecurity?

Risk management, secure design, verification evidence in licence application; aligns with FDA SPDF.

### What are the post-market cybersecurity obligations under Health Canada?

Mandatory problem reporting, CVD plan, software change reports.

### What is the penalty for non-compliance with Health Canada cybersecurity rules?

Licence cancellation, suspension, public advisories.

### How much of my FDA cybersecurity package is reusable in Canada?

Roughly 95% - an editorial estimate based on overlapping evidence requirements (threat model, SBOM, security risk assessment, pen-test report).

Sponsored note · Blue Goat Cyber

Submitting to Health Canada? Get a second pair of eyes before you file. Blue Goat Cyber has packaged cybersecurity evidence for Canada alongside 37 other markets. We'll tell you what to keep, what to rework, and what's missing, in 30 minutes.  [Talk through your Health Canada submission](https://go.bluegoatcyber.com/meetings/blue-goat-cyber/discovery-session)

The Crosswalk

An independent reference for global medical device cybersecurity standards. A field guide for MedTech innovators and RA/QA teams charting an international path.

Resource

-   [Comparison matrix](/compare)
-   [Global playbook](/playbook)
-   [Glossary](/glossary)
-   [FAQ](/faq)

Sponsored by

[Blue Goat Cyber ↗](https://bluegoatcyber.com)

Editorially independent. Sponsorship keeps it free.

© 2026 The Crosswalk. Not legal advice.

Validate every requirement against current regulator publications.