NMPA
China - NMPA
Technical Review Guideline on Medical Device Cybersecurity (2022 rev.)
Authority
National Medical Products Administration
Enforced
2022
Legal framework
NMPA Cybersecurity Guideline + MLPS 2.0 + Data Security Law + PIPL
Scope
All medical devices with cybersecurity features: data storage, exchange, remote control or interfaces. Network type classification determines depth of evidence.
Pre-market
Cybersecurity description, risk analysis, network type classification, verification & validation in registration dossier.
Post-market
Annual self-assessment, incident reporting within 24h, software upgrade approvals required.
SBOM
RecommendedNot strictly required; component lists must appear in technical documentation.
Vulnerability disclosure
MIIT CNVD (China National Vulnerability Database) coordination required.
Penalty
Registration revocation, fines under DSL up to RMB 10M, criminal liability for serious data breaches.
Unique requirements
- 01MLPS 2.0 cybersecurity grading (Level 2 or 3 typical)
- 02Cross-border data transfer security assessment
- 03Chinese Legal Agent and registration via NMPA
- 04Software changes may trigger re-registration
Highlights
- Data localisation under PIPL
- MLPS 2.0 grading required
- Cross-border data transfer restrictions
Aligns with
Timeline
-
Jan 2017
First NMPA cybersecurity guideline
-
Sep 2021
DSL & PIPL effective
-
Mar 2022
Revised cybersecurity guideline
-
Dec 1 2025
NMPA effects 39 updated medical device registration/technical review guidelines (cyber guideline unchanged)
Key documents
How to submit in China
Playbook reviewed · 2026-07-16
Submission route
NMPA registration with cybersecurity technical review per the Technical Guidelines for Medical Device Cybersecurity Registration Review (2022 revision)
NMPA has one of the most prescriptive cybersecurity review checklists globally. Documentation must be in Chinese, and type testing at an NMPA-recognised lab is mandatory for most Class II and all Class III devices with network connectivity.
Authority portalStep-by-step
-
Step 01
Appoint a Chinese Legal Agent
Foreign manufacturers cannot register directly; the Legal Agent holds the registration certificate.
-
Step 02
Type testing at recognised lab
Includes cybersecurity testing per YY/T 1843; results have a 12-month shelf life for the submission.
-
Step 03
Assemble the cybersecurity dossier in Chinese
Follow the 2022 Technical Guidelines section-by-section; NMPA reviewers use it as a strict checklist.
-
Step 04
Submit via eRPS
Electronic Regulatory Product Submission portal; cybersecurity is a mandatory tab, not embedded in the main dossier.
-
Step 05
Technical review with rounds of clarification
Expect 2-3 written clarification rounds; each adds 30-60 days to the clock.
Evidence checklist
| Item | Level | FDA equivalent | Notes |
|---|---|---|---|
| Cybersecurity description document (Chinese) | Required | — | |
| YY/T 1843 type test report | Required | — | |
| SBOM | Recommended | — | Not yet mandatory but requested in most recent Class III reviews. |
| Data localisation statement | Situational | — | Required if the device processes personal information under PIPL. |
Common NMPA rejections
No type test report from a recognised lab
CommonFix · Book testing 4-6 months before submission; capacity at recognised labs is a bottleneck.
Cybersecurity description doesn't follow 2022 Guideline structure
CommonFix · Mirror the section headings verbatim, including empty sections with a rationale.
Missing PIPL localisation analysis for connected devices
OccasionalFix · Add a data-flow diagram showing what personal information leaves China and the legal basis.
Typical timeline
End-to-end window: 14-24 months for Class III; 10-18 months for Class II.
Phase 01
Type testing
3-6 months
Phase 02
eRPS submission + acceptance
1-2 months
Phase 03
Technical review
9-15 months
Phase 04
Certificate issuance
1-3 months
NMPA head-to-head
Related markets
Frequently asked about China
Is SBOM required for medical devices in China?
Recommended. Not strictly required; component lists must appear in technical documentation.
What does NMPA require for pre-market cybersecurity?
Cybersecurity description, risk analysis, network type classification, verification & validation in registration dossier.
What are the post-market cybersecurity obligations under NMPA?
Annual self-assessment, incident reporting within 24h, software upgrade approvals required.
What is the penalty for non-compliance with NMPA cybersecurity rules?
Registration revocation, fines under DSL up to RMB 10M, criminal liability for serious data breaches.
How much of my FDA cybersecurity package is reusable in China?
Roughly 45% - an editorial estimate based on overlapping evidence requirements (threat model, SBOM, security risk assessment, pen-test report).