---
title: "China NMPA - Cybersecurity Submission Playbook"
description: "How to submit a medical device to NMPA in China: step-by-step route, evidence checklist, common rejections, and typical review timeline. Compared with FDA &amp; g"
lang: en
json-ld: |
  [
    {
      "@context": "https://schema.org",
      "@type": "WebSite",
      "name": "The Medical Device Cybersecurity Crosswalk",
      "alternateName": "MDC Crosswalk",
      "url": "https://mdccrosswalk.com/",
      "description": "Compare FDA, EU MDR, MHRA, PMDA, NMPA, TGA, MFDS and Health Canada medical device cybersecurity requirements across 29 jurisdictions."
    },
    {
      "@context": "https://schema.org",
      "@type": "Organization",
      "name": "MDC Crosswalk",
      "url": "https://mdccrosswalk.com/",
      "logo": "https://mdccrosswalk.com/favicon.png",
      "sameAs": [
        "https://bluegoatcyber.com"
      ],
      "description": "An editorial reference comparing global medical-device cybersecurity regulations. Maintained by Blue Goat Cyber."
    },
    {
      "@context": "https://schema.org",
      "@type": "Article",
      "headline": "China - Technical Review Guideline on Medical Device Cybersecurity (2022 rev.)",
      "description": "How to submit a medical device to NMPA in China: step-by-step route, evidence checklist, common rejections, and typical review timeline. Compared with FDA & g",
      "author": {
        "@type": "Organization",
        "name": "MDC Crosswalk"
      },
      "publisher": {
        "@type": "Organization",
        "name": "MDC Crosswalk"
      },
      "image": "https://mdccrosswalk.lovable.app/favicon.png",
      "datePublished": "Dec 2025 (39 updated NMPA technical review guidelines effective Dec 1 2025; 2022 cybersecurity guideline remains the operative cyber document)",
      "about": "National Medical Products Administration",
      "dateModified": "2026-07-16",
      "mainEntityOfPage": "https://mdccrosswalk.lovable.app/standards/cn"
    },
    {
      "@context": "https://schema.org",
      "@type": "FAQPage",
      "mainEntity": [
        {
          "@type": "Question",
          "name": "Is SBOM required for medical devices in China?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "Recommended. Not strictly required; component lists must appear in technical documentation."
          }
        },
        {
          "@type": "Question",
          "name": "What does NMPA require for pre-market cybersecurity?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "Cybersecurity description, risk analysis, network type classification, verification & validation in registration dossier."
          }
        },
        {
          "@type": "Question",
          "name": "What are the post-market cybersecurity obligations under NMPA?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "Annual self-assessment, incident reporting within 24h, software upgrade approvals required."
          }
        },
        {
          "@type": "Question",
          "name": "What is the penalty for non-compliance with NMPA cybersecurity rules?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "Registration revocation, fines under DSL up to RMB 10M, criminal liability for serious data breaches."
          }
        },
        {
          "@type": "Question",
          "name": "How much of my FDA cybersecurity package is reusable in China?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "Roughly 45% - an editorial estimate based on overlapping evidence requirements (threat model, SBOM, security risk assessment, pen-test report)."
          }
        },
        {
          "@type": "Question",
          "name": "Why do NMPA submissions get rejected for \"no type test report from a recognised lab\"?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "Book testing 4-6 months before submission; capacity at recognised labs is a bottleneck."
          }
        },
        {
          "@type": "Question",
          "name": "Why do NMPA submissions get rejected for \"cybersecurity description doesn't follow 2022 guideline structure\"?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "Mirror the section headings verbatim, including empty sections with a rationale."
          }
        },
        {
          "@type": "Question",
          "name": "Why do NMPA submissions get rejected for \"missing pipl localisation analysis for connected devices\"?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "Add a data-flow diagram showing what personal information leaves China and the legal basis."
          }
        }
      ]
    },
    {
      "@context": "https://schema.org",
      "@type": "HowTo",
      "name": "How to submit a medical device to NMPA",
      "description": "NMPA has one of the most prescriptive cybersecurity review checklists globally. Documentation must be in Chinese, and type testing at an NMPA-recognised lab is mandatory for most Class II and all Class III devices with network connectivity.",
      "totalTime": "14-24 months for Class III; 10-18 months for Class II.",
      "step": [
        {
          "@type": "HowToStep",
          "position": 1,
          "name": "Appoint a Chinese Legal Agent",
          "text": "Foreign manufacturers cannot register directly; the Legal Agent holds the registration certificate."
        },
        {
          "@type": "HowToStep",
          "position": 2,
          "name": "Type testing at recognised lab",
          "text": "Includes cybersecurity testing per YY/T 1843; results have a 12-month shelf life for the submission."
        },
        {
          "@type": "HowToStep",
          "position": 3,
          "name": "Assemble the cybersecurity dossier in Chinese",
          "text": "Follow the 2022 Technical Guidelines section-by-section; NMPA reviewers use it as a strict checklist."
        },
        {
          "@type": "HowToStep",
          "position": 4,
          "name": "Submit via eRPS",
          "text": "Electronic Regulatory Product Submission portal; cybersecurity is a mandatory tab, not embedded in the main dossier."
        },
        {
          "@type": "HowToStep",
          "position": 5,
          "name": "Technical review with rounds of clarification",
          "text": "Expect 2-3 written clarification rounds; each adds 30-60 days to the clock."
        }
      ]
    },
    {
      "@context": "https://schema.org",
      "@type": "BreadcrumbList",
      "itemListElement": [
        {
          "@type": "ListItem",
          "position": 1,
          "name": "Home",
          "item": "https://mdccrosswalk.lovable.app/"
        },
        {
          "@type": "ListItem",
          "position": 2,
          "name": "Standards"
        },
        {
          "@type": "ListItem",
          "position": 3,
          "name": "China"
        }
      ]
    }
  ]
---

[

The Crosswalk



](/)

[Overview](/)[Playbook](/playbook)CompareReference

[New Per-page social previews and this changelog ](/changelog "Per-page social previews and this changelog") Search⌘K

1.  [Home ](/)
2.  Standards 
3.  China 

NMPA

# ![Flag of China](/flags/cn.svg)China - NMPA 

Mandatory Last updated · Dec 2025 (39 updated NMPA technical review guidelines effective Dec 1 2025; 2022 cybersecurity guideline remains the operative cyber document) Verified · 2026-07-16 

Technical Review Guideline on Medical Device Cybersecurity (2022 rev.)

Share Copy link X LinkedIn Email

Sources verified · 2026-07-16

Cross-checked against NMPA 2022 Technical Review Guideline and DSL/PIPL.

Authority

National Medical Products Administration

Enforced

2022

Legal framework

NMPA Cybersecurity Guideline + MLPS 2.0 + Data Security Law + PIPL

FDA package reuse

~45%

[Editorial estimate · how →](/methodology#fda-reuse)

## Scope

All medical devices with cybersecurity features: data storage, exchange, remote control or interfaces. Network type classification determines depth of evidence.

Pre-market

Cybersecurity description, risk analysis, network type classification, verification & validation in registration dossier.

Post-market

Annual self-assessment, incident reporting within 24h, software upgrade approvals required.

SBOM

Recommended 

Not strictly required; component lists must appear in technical documentation.

Vulnerability disclosure

MIIT CNVD (China National Vulnerability Database) coordination required.

Penalty

Registration revocation, fines under DSL up to RMB 10M, criminal liability for serious data breaches.

## Unique requirements

-   01 MLPS 2.0 cybersecurity grading (Level 2 or 3 typical) 
-   02 Cross-border data transfer security assessment 
-   03 Chinese Legal Agent and registration via NMPA 
-   04 Software changes may trigger re-registration 

## Highlights

-   Data localisation under PIPL 
-   MLPS 2.0 grading required 
-   Cross-border data transfer restrictions 

## Aligns with

IMDRF N60 (partial)  GB/T standards  MLPS 2.0 

## Timeline

1.  Jan 2017
    
    First NMPA cybersecurity guideline
    
2.  Sep 2021
    
    DSL & PIPL effective
    
3.  Mar 2022
    
    Revised cybersecurity guideline
    
4.  Dec 1 2025
    
    NMPA effects 39 updated medical device registration/technical review guidelines (cyber guideline unchanged)
    

## Key documents

[

NMPA Cybersecurity Guideline (2022)

https://www.nmpa.gov.cn/



](https://www.nmpa.gov.cn/)[

Data Security Law of the PRC

http://www.npc.gov.cn/



](http://www.npc.gov.cn/)[

PIPL, Personal Information Protection Law

http://www.npc.gov.cn/



](http://www.npc.gov.cn/)

## How to submit in China

Playbook reviewed · 2026-07-16

Submission route

NMPA registration with cybersecurity technical review per the Technical Guidelines for Medical Device Cybersecurity Registration Review (2022 revision)

NMPA has one of the most prescriptive cybersecurity review checklists globally. Documentation must be in Chinese, and type testing at an NMPA-recognised lab is mandatory for most Class II and all Class III devices with network connectivity.

[Authority portal](https://english.nmpa.gov.cn/)

### Step-by-step

1.  Step 01
    
    Appoint a Chinese Legal Agent
    
    Foreign manufacturers cannot register directly; the Legal Agent holds the registration certificate.
    
2.  Step 02
    
    Type testing at recognised lab
    
    Includes cybersecurity testing per YY/T 1843; results have a 12-month shelf life for the submission.
    
3.  Step 03
    
    Assemble the cybersecurity dossier in Chinese
    
    Follow the 2022 Technical Guidelines section-by-section; NMPA reviewers use it as a strict checklist.
    
4.  Step 04
    
    Submit via eRPS
    
    Electronic Regulatory Product Submission portal; cybersecurity is a mandatory tab, not embedded in the main dossier.
    
5.  Step 05
    
    Technical review with rounds of clarification
    
    Expect 2-3 written clarification rounds; each adds 30-60 days to the clock.
    

### Evidence checklist

Item

Level

FDA equivalent

Notes

Cybersecurity description document (Chinese)

Required 

—

YY/T 1843 type test report

Required 

—

SBOM

Recommended 

—

Not yet mandatory but requested in most recent Class III reviews.

Data localisation statement

Situational 

—

Required if the device processes personal information under PIPL.

### Common NMPA rejections

No type test report from a recognised lab

Common 

Fix ·  Book testing 4-6 months before submission; capacity at recognised labs is a bottleneck.

Cybersecurity description doesn't follow 2022 Guideline structure

Common 

Fix ·  Mirror the section headings verbatim, including empty sections with a rationale.

Missing PIPL localisation analysis for connected devices

Occasional 

Fix ·  Add a data-flow diagram showing what personal information leaves China and the legal basis.

### Typical timeline

End-to-end window: 14-24 months for Class III; 10-18 months for Class II. 

Phase 01

Type testing

3-6 months

Phase 02

eRPS submission + acceptance

1-2 months

Phase 03

Technical review

9-15 months

Phase 04

Certificate issuance

1-3 months

[Previous ![Flag of Japan](/flags/jp.svg)Japan ](/standards/jp)[Next  ![Flag of Canada](/flags/ca.svg)Canada ](/standards/ca)

## NMPA head-to-head

[

Compare

![Flag of China](/flags/cn.svg)NMPAvs ![Flag of United States](/flags/us.svg)FDA 524B

Open comparison ](/compare/fda-vs-nmpa)

## Related markets

[![Flag of Kazakhstan](/flags/kz.svg)

Kazakhstan

~45% FDA reuse

](/standards/kz)[![Flag of Switzerland](/flags/ch.svg)

Switzerland

~55% FDA reuse

](/standards/ch)[![Flag of Turkey](/flags/tr.svg)

Turkey

~55% FDA reuse

](/standards/tr)[![Flag of Russia](/flags/ru.svg)

Russia

~35% FDA reuse

](/standards/ru)

## Frequently asked about China

### Is SBOM required for medical devices in China?

Recommended. Not strictly required; component lists must appear in technical documentation.

### What does NMPA require for pre-market cybersecurity?

Cybersecurity description, risk analysis, network type classification, verification & validation in registration dossier.

### What are the post-market cybersecurity obligations under NMPA?

Annual self-assessment, incident reporting within 24h, software upgrade approvals required.

### What is the penalty for non-compliance with NMPA cybersecurity rules?

Registration revocation, fines under DSL up to RMB 10M, criminal liability for serious data breaches.

### How much of my FDA cybersecurity package is reusable in China?

Roughly 45% - an editorial estimate based on overlapping evidence requirements (threat model, SBOM, security risk assessment, pen-test report).

Sponsored note · Blue Goat Cyber

Submitting to NMPA? Get a second pair of eyes before you file. Blue Goat Cyber has packaged cybersecurity evidence for China alongside 37 other markets. We'll tell you what to keep, what to rework, and what's missing, in 30 minutes.  [Talk through your NMPA submission](https://go.bluegoatcyber.com/meetings/blue-goat-cyber/discovery-session)

The Crosswalk

An independent reference for global medical device cybersecurity standards. A field guide for MedTech innovators and RA/QA teams charting an international path.

Resource

-   [Comparison matrix](/compare)
-   [Global playbook](/playbook)
-   [Glossary](/glossary)
-   [FAQ](/faq)

Sponsored by

[Blue Goat Cyber ↗](https://bluegoatcyber.com)

Editorially independent. Sponsorship keeps it free.

© 2026 The Crosswalk. Not legal advice.

Validate every requirement against current regulator publications.