---
title: "Colombia INVIMA - Cybersecurity Submission Playbook"
description: "How to submit a medical device to INVIMA in Colombia: step-by-step route, evidence checklist, common rejections, and typical review timeline. Compared with FD"
lang: en
json-ld: |
  [
    {
      "@context": "https://schema.org",
      "@type": "WebSite",
      "name": "The Medical Device Cybersecurity Crosswalk",
      "alternateName": "MDC Crosswalk",
      "url": "https://mdccrosswalk.com/",
      "description": "Compare FDA, EU MDR, MHRA, PMDA, NMPA, TGA, MFDS and Health Canada medical device cybersecurity requirements across 29 jurisdictions."
    },
    {
      "@context": "https://schema.org",
      "@type": "Organization",
      "name": "MDC Crosswalk",
      "url": "https://mdccrosswalk.com/",
      "logo": "https://mdccrosswalk.com/favicon.png",
      "sameAs": [
        "https://bluegoatcyber.com"
      ],
      "description": "An editorial reference comparing global medical-device cybersecurity regulations. Maintained by Blue Goat Cyber."
    },
    {
      "@context": "https://schema.org",
      "@type": "Article",
      "headline": "Colombia - Decreto 4725/2005 + INVIMA SaMD and cybersecurity criteria",
      "description": "How to submit a medical device to INVIMA in Colombia: step-by-step route, evidence checklist, common rejections, and typical review timeline. Compared with FD",
      "author": {
        "@type": "Organization",
        "name": "MDC Crosswalk"
      },
      "publisher": {
        "@type": "Organization",
        "name": "MDC Crosswalk"
      },
      "image": "https://mdccrosswalk.lovable.app/favicon.png",
      "datePublished": "2023",
      "about": "Instituto Nacional de Vigilancia de Medicamentos y Alimentos",
      "dateModified": "2026-07-16",
      "mainEntityOfPage": "https://mdccrosswalk.lovable.app/standards/co"
    },
    {
      "@context": "https://schema.org",
      "@type": "FAQPage",
      "mainEntity": [
        {
          "@type": "Question",
          "name": "Is SBOM required for medical devices in Colombia?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "Recommended. Encouraged via FDA alignment."
          }
        },
        {
          "@type": "Question",
          "name": "What does INVIMA require for pre-market cybersecurity?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "Risk-class dossier; reference-jurisdiction route accepts FDA / CE / Health Canada / TGA / PMDA."
          }
        },
        {
          "@type": "Question",
          "name": "What are the post-market cybersecurity obligations under INVIMA?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "Tecnovigilancia reporting, sanitary surveillance."
          }
        },
        {
          "@type": "Question",
          "name": "What is the penalty for non-compliance with INVIMA cybersecurity rules?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "Registration cancellation, sanitary fines."
          }
        },
        {
          "@type": "Question",
          "name": "How much of my FDA cybersecurity package is reusable in Colombia?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "Roughly 85% - an editorial estimate based on overlapping evidence requirements (threat model, SBOM, security risk assessment, pen-test report)."
          }
        },
        {
          "@type": "Question",
          "name": "Why do INVIMA submissions get rejected for \"no colombian legal representative\"?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "Appoint a Colombian legal rep before filing."
          }
        }
      ]
    },
    {
      "@context": "https://schema.org",
      "@type": "HowTo",
      "name": "How to submit a medical device to INVIMA",
      "description": "INVIMA accepts CE and FDA evidence. Cybersecurity documentation, when present, is reviewed as part of the technical file.",
      "totalTime": "6-12 months",
      "step": [
        {
          "@type": "HowToStep",
          "position": 1,
          "name": "Appoint local representation",
          "text": "Most jurisdictions require a locally-established entity to hold the registration or act as authorised representative before submission."
        },
        {
          "@type": "HowToStep",
          "position": 2,
          "name": "Reuse FDA or CE package as baseline",
          "text": "Adapt the cybersecurity subsection you already prepared for FDA or CE; regulators here typically accept the structure and ask for local labeling additions."
        },
        {
          "@type": "HowToStep",
          "position": 3,
          "name": "Translate and localise",
          "text": "Local-language technical summary and labeling are usually mandatory; certified translation is safest."
        },
        {
          "@type": "HowToStep",
          "position": 4,
          "name": "Submit + track queries",
          "text": "Respond to clarification rounds promptly; each unanswered question can add 30-90 days to the clock."
        }
      ]
    },
    {
      "@context": "https://schema.org",
      "@type": "BreadcrumbList",
      "itemListElement": [
        {
          "@type": "ListItem",
          "position": 1,
          "name": "Home",
          "item": "https://mdccrosswalk.lovable.app/"
        },
        {
          "@type": "ListItem",
          "position": 2,
          "name": "Standards"
        },
        {
          "@type": "ListItem",
          "position": 3,
          "name": "Colombia"
        }
      ]
    }
  ]
---

[

The Crosswalk



](/)

[Overview](/)[Playbook](/playbook)CompareReference

[New Per-page social previews and this changelog ](/changelog "Per-page social previews and this changelog") Search⌘K

1.  [Home ](/)
2.  Standards 
3.  Colombia 

INVIMA

# ![Flag of Colombia](/flags/co.svg)Colombia - INVIMA 

Guidance Last updated · 2023 Verified · 2026-07-16 

Decreto 4725/2005 + INVIMA SaMD and cybersecurity criteria

Share Copy link X LinkedIn Email

Sources verified · 2026-07-16

INVIMA device rules confirmed; cybersecurity expectations awaiting SME review.

Authority

Instituto Nacional de Vigilancia de Medicamentos y Alimentos

Enforced

2005 (rev. 2023)

Legal framework

Decreto 4725/2005 + Ley 1581 (data protection) + INVIMA circulars

FDA package reuse

~85%

[Editorial estimate · how →](/methodology#fda-reuse)

## Scope

All medical devices marketed in Colombia; risk-class based sanitary registration.

Pre-market

Risk-class dossier; reference-jurisdiction route accepts FDA / CE / Health Canada / TGA / PMDA.

Post-market

Tecnovigilancia reporting, sanitary surveillance.

SBOM

Recommended 

Encouraged via FDA alignment.

Vulnerability disclosure

ColCERT coordinated disclosure encouraged.

Penalty

Registration cancellation, sanitary fines.

## Unique requirements

-   01 Colombian Sanitary Registration Holder 
-   02 Spanish-language IFU and labelling 
-   03 BPM (Buenas Prácticas de Manufactura) certification 

## Highlights

-   Reference jurisdiction route accepted 
-   Spanish-language documentation 
-   Andean Community harmonisation 

## Aligns with

IMDRF N60  ISO 13485  FDA 2023 Guidance 

## Timeline

1.  2005
    
    Decreto 4725 published
    
2.  2023
    
    SaMD and cyber circulars updated
    

## Key documents

[

INVIMA - Dispositivos médicos y equipos biomédicos

https://www.invima.gov.co/productos-vigilados/dispositivos-medicos/dispositivos-medicos-equipos-biomedicos



](https://www.invima.gov.co/productos-vigilados/dispositivos-medicos/dispositivos-medicos-equipos-biomedicos)[

INVIMA - Dispositivos Médicos (programa)

https://www.invima.gov.co/productos-vigilados/dispositivos-medicos



](https://www.invima.gov.co/productos-vigilados/dispositivos-medicos)

## How to submit in Colombia

Playbook reviewed · 2026-07-16

Submission route

INVIMA sanitary registration

INVIMA accepts CE and FDA evidence. Cybersecurity documentation, when present, is reviewed as part of the technical file.

[Authority portal](https://www.invima.gov.co/)

### Step-by-step

1.  Step 01
    
    Appoint local representation
    
    Most jurisdictions require a locally-established entity to hold the registration or act as authorised representative before submission.
    
2.  Step 02
    
    Reuse FDA or CE package as baseline
    
    Adapt the cybersecurity subsection you already prepared for FDA or CE; regulators here typically accept the structure and ask for local labeling additions.
    
3.  Step 03
    
    Translate and localise
    
    Local-language technical summary and labeling are usually mandatory; certified translation is safest.
    
4.  Step 04
    
    Submit + track queries
    
    Respond to clarification rounds promptly; each unanswered question can add 30-90 days to the clock.
    

### Evidence checklist

Item

Level

FDA equivalent

Notes

Cybersecurity documentation (baseline FDA or CE)

Required 

SPDF

Local authorised representative agreement

Required 

—

Local-language labeling and IFU

Required 

—

SBOM

Recommended 

—

Not mandatory but reduces clarification rounds.

### Common INVIMA rejections

No Colombian legal representative

Common 

Fix ·  Appoint a Colombian legal rep before filing.

### Typical timeline

End-to-end window: 6-12 months 

Phase 01

Local rep + dossier prep

2-4 months

Phase 02

Regulatory review

6-12 months

Phase 03

Approval + market entry

1-3 months

[Previous ![Flag of Norway](/flags/no.svg)Norway ](/standards/no)[Next  ![Flag of Chile](/flags/cl.svg)Chile ](/standards/cl)

## Related markets

[![Flag of Australia](/flags/au.svg)

Australia

~85% FDA reuse

](/standards/au)[![Flag of Saudi Arabia](/flags/sa.svg)

Saudi Arabia

~85% FDA reuse

](/standards/sa)[![Flag of Argentina](/flags/ar.svg)

Argentina

~85% FDA reuse

](/standards/ar)[![Flag of Taiwan](/flags/tw.svg)

Taiwan

~85% FDA reuse

](/standards/tw)

## Frequently asked about Colombia

### Is SBOM required for medical devices in Colombia?

Recommended. Encouraged via FDA alignment.

### What does INVIMA require for pre-market cybersecurity?

Risk-class dossier; reference-jurisdiction route accepts FDA / CE / Health Canada / TGA / PMDA.

### What are the post-market cybersecurity obligations under INVIMA?

Tecnovigilancia reporting, sanitary surveillance.

### What is the penalty for non-compliance with INVIMA cybersecurity rules?

Registration cancellation, sanitary fines.

### How much of my FDA cybersecurity package is reusable in Colombia?

Roughly 85% - an editorial estimate based on overlapping evidence requirements (threat model, SBOM, security risk assessment, pen-test report).

Sponsored note · Blue Goat Cyber

Submitting to INVIMA? Get a second pair of eyes before you file. Blue Goat Cyber has packaged cybersecurity evidence for Colombia alongside 37 other markets. We'll tell you what to keep, what to rework, and what's missing, in 30 minutes.  [Talk through your INVIMA submission](https://go.bluegoatcyber.com/meetings/blue-goat-cyber/discovery-session)

The Crosswalk

An independent reference for global medical device cybersecurity standards. A field guide for MedTech innovators and RA/QA teams charting an international path.

Resource

-   [Comparison matrix](/compare)
-   [Global playbook](/playbook)
-   [Glossary](/glossary)
-   [FAQ](/faq)

Sponsored by

[Blue Goat Cyber ↗](https://bluegoatcyber.com)

Editorially independent. Sponsorship keeps it free.

© 2026 The Crosswalk. Not legal advice.

Validate every requirement against current regulator publications.