The Crosswalk

    NewPer-page social previews and this changelog

    MDD

    Flag of Hong KongHong Kong - MDD

    GuidanceLast updated · 2024Verified · 2026-07-16

    Medical Device Administrative Control System (MDACS)

    Share

    Authority

    Medical Device Division, Department of Health

    Enforced

    2004 (voluntary MDACS launched)

    Legal framework

    Voluntary Medical Device Administrative Control System (MDACS) operated by the MDD; PDPO (Cap. 486) for personal data; CSL bill under development for critical infrastructure including healthcare.

    FDA package reuse

    ~90%

    Scope

    All medical devices marketed in Hong Kong via voluntary MDACS listing. Separate from mainland China's NMPA regime. SaMD covered by MDACS Technical Reference TR-004.

    Pre-market

    Reliance-based: listing requires evidence of approval by at least one Reference Country regulator (FDA, EU, Health Canada, TGA, PMDA). Cybersecurity expectations follow the reference-country submission.

    Post-market

    MDACS adverse-event reporting; PCPD handles personal-data breach notifications under PDPO.

    SBOM

    Recommended

    Not mandated by MDACS, but reference-country SBOMs accepted as part of the listing dossier.

    Vulnerability disclosure

    HKCERT coordinates ICT incidents; no medical-device-specific CVD requirement.

    Penalty

    Removal from MDACS listing; healthcare procurement consequences (most HA tenders require MDACS-listed devices).

    Unique requirements

    • 01Local Responsible Person appointment
    • 02Reference-country approval as the gating evidence
    • 03Traditional Chinese labelling for consumer devices

    Highlights

    • Reliance on FDA/CE/HC/TGA/PMDA approvals
    • Listing is voluntary but de-facto required for HA procurement
    • Separate regime from mainland China NMPA

    Aligns with

    IMDRF N60 (via reference countries) ISO 13485

    Timeline

    1. 2004

      MDACS voluntary listing launched

    2. 2021

      PDPO amendments tighten doxxing/data-protection rules

    3. 2024

      Cybersecurity Legislation Bill (CSL) for CII published for consultation

    Key documents

    How to submit in Hong Kong

    Playbook reviewed · 2026-07-16

    Submission route

    MDACS voluntary listing with Hong Kong Department of Health

    Hong Kong's Medical Device Administrative Control System is voluntary. Cybersecurity documentation is not separately mandated but recommended.

    Authority portal

    Step-by-step

    1. Step 01

      Appoint local representation

      Most jurisdictions require a locally-established entity to hold the registration or act as authorised representative before submission.

    2. Step 02

      Reuse FDA or CE package as baseline

      Adapt the cybersecurity subsection you already prepared for FDA or CE; regulators here typically accept the structure and ask for local labeling additions.

    3. Step 03

      Translate and localise

      Local-language technical summary and labeling are usually mandatory; certified translation is safest.

    4. Step 04

      Submit + track queries

      Respond to clarification rounds promptly; each unanswered question can add 30-90 days to the clock.

    Evidence checklist

    Item Level FDA equivalent Notes
    Cybersecurity documentation (baseline FDA or CE) Required SPDF
    Local authorised representative agreement Required
    Local-language labeling and IFU Required
    SBOM Recommended Not mandatory but reduces clarification rounds.

    Common MDACS rejections

    Documentation not aligned with MDACS classification

    Occasional

    Fix · Follow the MDACS classification rules and provide matching evidence.

    Typical timeline

    End-to-end window: 3-6 months

    Phase 01

    Local rep + dossier prep

    2-4 months

    Phase 02

    Regulatory review

    3-6 months

    Phase 03

    Approval + market entry

    1-3 months

    Related markets

    Frequently asked about Hong Kong

    Is SBOM required for medical devices in Hong Kong?

    Recommended. Not mandated by MDACS, but reference-country SBOMs accepted as part of the listing dossier.

    What does MDD require for pre-market cybersecurity?

    Reliance-based: listing requires evidence of approval by at least one Reference Country regulator (FDA, EU, Health Canada, TGA, PMDA). Cybersecurity expectations follow the reference-country submission.

    What are the post-market cybersecurity obligations under MDD?

    MDACS adverse-event reporting; PCPD handles personal-data breach notifications under PDPO.

    What is the penalty for non-compliance with MDD cybersecurity rules?

    Removal from MDACS listing; healthcare procurement consequences (most HA tenders require MDACS-listed devices).

    How much of my FDA cybersecurity package is reusable in Hong Kong?

    Roughly 90% - an editorial estimate based on overlapping evidence requirements (threat model, SBOM, security risk assessment, pen-test report).