EDA
Egypt - EDA
EDA Medical Device Registration & PDPL Cyber Overlay
Authority
Egyptian Drug Authority
Enforced
2019 (Law 151/2019 - EDA establishment)
Legal framework
Law 151/2019 establishing the EDA + EDA medical device registration decrees; Personal Data Protection Law 151/2020 (PDPL) for connected-device data handling.
Scope
All medical devices placed on the Egyptian market. SaMD reviewed under EDA's software-as-a-medical-device circulars. Connected devices subject to PDPL when processing patient data.
Pre-market
Registration dossier modelled on GHTF/IMDRF, with reliance on reference-country approvals (FDA, CE, Health Canada). No standalone medical-device cybersecurity guideline yet; cyber posture assessed via SaMD review.
Post-market
Vigilance reporting to EDA; PDPC handles data-breach notifications under PDPL.
SBOM
Not specifiedNot addressed by EDA today; CE/FDA SBOMs accepted as supporting evidence.
Vulnerability disclosure
EG-CERT coordination for healthcare ICT incidents; no medical-device-specific CVD requirement.
Penalty
Registration cancellation, market withdrawal, fines under Law 151/2019.
Unique requirements
- 01Egyptian authorised representative
- 02Arabic-language labelling
- 03Reliance dossier referencing reference-country approval
Highlights
- Reference-country pathway (FDA, CE, HC, TGA, PMDA)
- Largest MENA market by population
- PDPL data overlay for connected devices
Aligns with
Timeline
-
2019
Law 151/2019 establishes EDA as independent authority
-
2020
PDPL 151/2020 enacted
-
2024
EDA reliance-pathway circulars expanded
Key documents
How to submit in Egypt
Playbook reviewed · 2026-07-16
Submission route
EDA registration under Ministerial Decree 296/2009 and updates
EDA accepts GHTF and CE evidence. Local scientific office representation is required for foreign manufacturers.
Authority portalStep-by-step
-
Step 01
Appoint local representation
Most jurisdictions require a locally-established entity to hold the registration or act as authorised representative before submission.
-
Step 02
Reuse FDA or CE package as baseline
Adapt the cybersecurity subsection you already prepared for FDA or CE; regulators here typically accept the structure and ask for local labeling additions.
-
Step 03
Translate and localise
Local-language technical summary and labeling are usually mandatory; certified translation is safest.
-
Step 04
Submit + track queries
Respond to clarification rounds promptly; each unanswered question can add 30-90 days to the clock.
Evidence checklist
| Item | Level | FDA equivalent | Notes |
|---|---|---|---|
| Cybersecurity documentation (baseline FDA or CE) | Required | SPDF | |
| Local authorised representative agreement | Required | — | |
| Local-language labeling and IFU | Required | — | |
| SBOM | Recommended | — | Not mandatory but reduces clarification rounds. |
Common EDA rejections
No scientific office appointed
CommonFix · Contract a licensed Egyptian scientific office before filing.
Typical timeline
End-to-end window: 6-12 months
Phase 01
Local rep + dossier prep
2-4 months
Phase 02
Regulatory review
6-12 months
Phase 03
Approval + market entry
1-3 months
Related markets
Frequently asked about Egypt
Is SBOM required for medical devices in Egypt?
Not specified. Not addressed by EDA today; CE/FDA SBOMs accepted as supporting evidence.
What does EDA require for pre-market cybersecurity?
Registration dossier modelled on GHTF/IMDRF, with reliance on reference-country approvals (FDA, CE, Health Canada). No standalone medical-device cybersecurity guideline yet; cyber posture assessed via SaMD review.
What are the post-market cybersecurity obligations under EDA?
Vigilance reporting to EDA; PDPC handles data-breach notifications under PDPL.
What is the penalty for non-compliance with EDA cybersecurity rules?
Registration cancellation, market withdrawal, fines under Law 151/2019.
How much of my FDA cybersecurity package is reusable in Egypt?
Roughly 75% - an editorial estimate based on overlapping evidence requirements (threat model, SBOM, security risk assessment, pen-test report).