The Crosswalk

    NewPer-page social previews and this changelog

    NMPA

    Flag of ChinaChina - NMPA

    MandatoryLast updated · Dec 2025 (39 updated NMPA technical review guidelines effective Dec 1 2025; 2022 cybersecurity guideline remains the operative cyber document)Verified · 2026-07-16

    Technical Review Guideline on Medical Device Cybersecurity (2022 rev.)

    Share

    Authority

    National Medical Products Administration

    Enforced

    2022

    Legal framework

    NMPA Cybersecurity Guideline + MLPS 2.0 + Data Security Law + PIPL

    FDA package reuse

    ~45%

    Scope

    All medical devices with cybersecurity features: data storage, exchange, remote control or interfaces. Network type classification determines depth of evidence.

    Pre-market

    Cybersecurity description, risk analysis, network type classification, verification & validation in registration dossier.

    Post-market

    Annual self-assessment, incident reporting within 24h, software upgrade approvals required.

    SBOM

    Recommended

    Not strictly required; component lists must appear in technical documentation.

    Vulnerability disclosure

    MIIT CNVD (China National Vulnerability Database) coordination required.

    Penalty

    Registration revocation, fines under DSL up to RMB 10M, criminal liability for serious data breaches.

    Unique requirements

    • 01MLPS 2.0 cybersecurity grading (Level 2 or 3 typical)
    • 02Cross-border data transfer security assessment
    • 03Chinese Legal Agent and registration via NMPA
    • 04Software changes may trigger re-registration

    Highlights

    • Data localisation under PIPL
    • MLPS 2.0 grading required
    • Cross-border data transfer restrictions

    Aligns with

    IMDRF N60 (partial) GB/T standards MLPS 2.0

    Timeline

    1. Jan 2017

      First NMPA cybersecurity guideline

    2. Sep 2021

      DSL & PIPL effective

    3. Mar 2022

      Revised cybersecurity guideline

    4. Dec 1 2025

      NMPA effects 39 updated medical device registration/technical review guidelines (cyber guideline unchanged)

    Key documents

    How to submit in China

    Playbook reviewed · 2026-07-16

    Submission route

    NMPA registration with cybersecurity technical review per the Technical Guidelines for Medical Device Cybersecurity Registration Review (2022 revision)

    NMPA has one of the most prescriptive cybersecurity review checklists globally. Documentation must be in Chinese, and type testing at an NMPA-recognised lab is mandatory for most Class II and all Class III devices with network connectivity.

    Authority portal

    Step-by-step

    1. Step 01

      Appoint a Chinese Legal Agent

      Foreign manufacturers cannot register directly; the Legal Agent holds the registration certificate.

    2. Step 02

      Type testing at recognised lab

      Includes cybersecurity testing per YY/T 1843; results have a 12-month shelf life for the submission.

    3. Step 03

      Assemble the cybersecurity dossier in Chinese

      Follow the 2022 Technical Guidelines section-by-section; NMPA reviewers use it as a strict checklist.

    4. Step 04

      Submit via eRPS

      Electronic Regulatory Product Submission portal; cybersecurity is a mandatory tab, not embedded in the main dossier.

    5. Step 05

      Technical review with rounds of clarification

      Expect 2-3 written clarification rounds; each adds 30-60 days to the clock.

    Evidence checklist

    Item Level FDA equivalent Notes
    Cybersecurity description document (Chinese) Required
    YY/T 1843 type test report Required
    SBOM Recommended Not yet mandatory but requested in most recent Class III reviews.
    Data localisation statement Situational Required if the device processes personal information under PIPL.

    Common NMPA rejections

    No type test report from a recognised lab

    Common

    Fix · Book testing 4-6 months before submission; capacity at recognised labs is a bottleneck.

    Cybersecurity description doesn't follow 2022 Guideline structure

    Common

    Fix · Mirror the section headings verbatim, including empty sections with a rationale.

    Missing PIPL localisation analysis for connected devices

    Occasional

    Fix · Add a data-flow diagram showing what personal information leaves China and the legal basis.

    Typical timeline

    End-to-end window: 14-24 months for Class III; 10-18 months for Class II.

    Phase 01

    Type testing

    3-6 months

    Phase 02

    eRPS submission + acceptance

    1-2 months

    Phase 03

    Technical review

    9-15 months

    Phase 04

    Certificate issuance

    1-3 months

    NMPA head-to-head

    Related markets

    Frequently asked about China

    Is SBOM required for medical devices in China?

    Recommended. Not strictly required; component lists must appear in technical documentation.

    What does NMPA require for pre-market cybersecurity?

    Cybersecurity description, risk analysis, network type classification, verification & validation in registration dossier.

    What are the post-market cybersecurity obligations under NMPA?

    Annual self-assessment, incident reporting within 24h, software upgrade approvals required.

    What is the penalty for non-compliance with NMPA cybersecurity rules?

    Registration revocation, fines under DSL up to RMB 10M, criminal liability for serious data breaches.

    How much of my FDA cybersecurity package is reusable in China?

    Roughly 45% - an editorial estimate based on overlapping evidence requirements (threat model, SBOM, security risk assessment, pen-test report).