---
title: "Hong Kong MDACS - Cybersecurity Submission Playbook"
description: "How to submit a medical device to MDD in Hong Kong: step-by-step route, evidence checklist, common rejections, and typical review timeline. Compared with FDA"
lang: en
json-ld: |
  [
    {
      "@context": "https://schema.org",
      "@type": "WebSite",
      "name": "The Medical Device Cybersecurity Crosswalk",
      "alternateName": "MDC Crosswalk",
      "url": "https://mdccrosswalk.com/",
      "description": "Compare FDA, EU MDR, MHRA, PMDA, NMPA, TGA, MFDS and Health Canada medical device cybersecurity requirements across 29 jurisdictions."
    },
    {
      "@context": "https://schema.org",
      "@type": "Organization",
      "name": "MDC Crosswalk",
      "url": "https://mdccrosswalk.com/",
      "logo": "https://mdccrosswalk.com/favicon.png",
      "sameAs": [
        "https://bluegoatcyber.com"
      ],
      "description": "An editorial reference comparing global medical-device cybersecurity regulations. Maintained by Blue Goat Cyber."
    },
    {
      "@context": "https://schema.org",
      "@type": "Article",
      "headline": "Hong Kong - Medical Device Administrative Control System (MDACS)",
      "description": "How to submit a medical device to MDD in Hong Kong: step-by-step route, evidence checklist, common rejections, and typical review timeline. Compared with FDA ",
      "author": {
        "@type": "Organization",
        "name": "MDC Crosswalk"
      },
      "publisher": {
        "@type": "Organization",
        "name": "MDC Crosswalk"
      },
      "image": "https://mdccrosswalk.lovable.app/favicon.png",
      "datePublished": "2024",
      "about": "Medical Device Division, Department of Health",
      "dateModified": "2026-07-16",
      "mainEntityOfPage": "https://mdccrosswalk.lovable.app/standards/hk"
    },
    {
      "@context": "https://schema.org",
      "@type": "FAQPage",
      "mainEntity": [
        {
          "@type": "Question",
          "name": "Is SBOM required for medical devices in Hong Kong?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "Recommended. Not mandated by MDACS, but reference-country SBOMs accepted as part of the listing dossier."
          }
        },
        {
          "@type": "Question",
          "name": "What does MDD require for pre-market cybersecurity?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "Reliance-based: listing requires evidence of approval by at least one Reference Country regulator (FDA, EU, Health Canada, TGA, PMDA). Cybersecurity expectations follow the reference-country submission."
          }
        },
        {
          "@type": "Question",
          "name": "What are the post-market cybersecurity obligations under MDD?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "MDACS adverse-event reporting; PCPD handles personal-data breach notifications under PDPO."
          }
        },
        {
          "@type": "Question",
          "name": "What is the penalty for non-compliance with MDD cybersecurity rules?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "Removal from MDACS listing; healthcare procurement consequences (most HA tenders require MDACS-listed devices)."
          }
        },
        {
          "@type": "Question",
          "name": "How much of my FDA cybersecurity package is reusable in Hong Kong?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "Roughly 90% - an editorial estimate based on overlapping evidence requirements (threat model, SBOM, security risk assessment, pen-test report)."
          }
        },
        {
          "@type": "Question",
          "name": "Why do MDACS submissions get rejected for \"documentation not aligned with mdacs classification\"?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "Follow the MDACS classification rules and provide matching evidence."
          }
        }
      ]
    },
    {
      "@context": "https://schema.org",
      "@type": "HowTo",
      "name": "How to submit a medical device to MDD",
      "description": "Hong Kong's Medical Device Administrative Control System is voluntary. Cybersecurity documentation is not separately mandated but recommended.",
      "totalTime": "3-6 months",
      "step": [
        {
          "@type": "HowToStep",
          "position": 1,
          "name": "Appoint local representation",
          "text": "Most jurisdictions require a locally-established entity to hold the registration or act as authorised representative before submission."
        },
        {
          "@type": "HowToStep",
          "position": 2,
          "name": "Reuse FDA or CE package as baseline",
          "text": "Adapt the cybersecurity subsection you already prepared for FDA or CE; regulators here typically accept the structure and ask for local labeling additions."
        },
        {
          "@type": "HowToStep",
          "position": 3,
          "name": "Translate and localise",
          "text": "Local-language technical summary and labeling are usually mandatory; certified translation is safest."
        },
        {
          "@type": "HowToStep",
          "position": 4,
          "name": "Submit + track queries",
          "text": "Respond to clarification rounds promptly; each unanswered question can add 30-90 days to the clock."
        }
      ]
    },
    {
      "@context": "https://schema.org",
      "@type": "BreadcrumbList",
      "itemListElement": [
        {
          "@type": "ListItem",
          "position": 1,
          "name": "Home",
          "item": "https://mdccrosswalk.lovable.app/"
        },
        {
          "@type": "ListItem",
          "position": 2,
          "name": "Standards"
        },
        {
          "@type": "ListItem",
          "position": 3,
          "name": "Hong Kong"
        }
      ]
    }
  ]
---

[

The Crosswalk



](/)

[Overview](/)[Playbook](/playbook)CompareReference

[New Per-page social previews and this changelog ](/changelog "Per-page social previews and this changelog") Search⌘K

1.  [Home ](/)
2.  Standards 
3.  Hong Kong 

MDD

# ![Flag of Hong Kong](/flags/hk.svg)Hong Kong - MDD 

Guidance Last updated · 2024 Verified · 2026-07-16 

Medical Device Administrative Control System (MDACS)

Share Copy link X LinkedIn Email

Sources verified · 2026-07-16

Cross-checked against MDD listing requirements, MDACS technical references, and PDPO 2021 amendments.

Authority

Medical Device Division, Department of Health

Enforced

2004 (voluntary MDACS launched)

Legal framework

Voluntary Medical Device Administrative Control System (MDACS) operated by the MDD; PDPO (Cap. 486) for personal data; CSL bill under development for critical infrastructure including healthcare.

FDA package reuse

~90%

[Editorial estimate · how →](/methodology#fda-reuse)

## Scope

All medical devices marketed in Hong Kong via voluntary MDACS listing. Separate from mainland China's NMPA regime. SaMD covered by MDACS Technical Reference TR-004.

Pre-market

Reliance-based: listing requires evidence of approval by at least one Reference Country regulator (FDA, EU, Health Canada, TGA, PMDA). Cybersecurity expectations follow the reference-country submission.

Post-market

MDACS adverse-event reporting; PCPD handles personal-data breach notifications under PDPO.

SBOM

Recommended 

Not mandated by MDACS, but reference-country SBOMs accepted as part of the listing dossier.

Vulnerability disclosure

HKCERT coordinates ICT incidents; no medical-device-specific CVD requirement.

Penalty

Removal from MDACS listing; healthcare procurement consequences (most HA tenders require MDACS-listed devices).

## Unique requirements

-   01 Local Responsible Person appointment 
-   02 Reference-country approval as the gating evidence 
-   03 Traditional Chinese labelling for consumer devices 

## Highlights

-   Reliance on FDA/CE/HC/TGA/PMDA approvals 
-   Listing is voluntary but de-facto required for HA procurement 
-   Separate regime from mainland China NMPA 

## Aligns with

IMDRF N60 (via reference countries)  ISO 13485 

## Timeline

1.  2004
    
    MDACS voluntary listing launched
    
2.  2021
    
    PDPO amendments tighten doxxing/data-protection rules
    
3.  2024
    
    Cybersecurity Legislation Bill (CSL) for CII published for consultation
    

## Key documents

[

Medical Device Division, Department of Health

https://www.mdd.gov.hk/



](https://www.mdd.gov.hk/)[

MDACS Technical References

https://www.mdd.gov.hk/english/regcontrol/regcontrol\_tr/regcontrol\_tr.html



](https://www.mdd.gov.hk/english/regcontrol/regcontrol_tr/regcontrol_tr.html)

## How to submit in Hong Kong

Playbook reviewed · 2026-07-16

Submission route

MDACS voluntary listing with Hong Kong Department of Health

Hong Kong's Medical Device Administrative Control System is voluntary. Cybersecurity documentation is not separately mandated but recommended.

[Authority portal](https://www.mdd.gov.hk/)

### Step-by-step

1.  Step 01
    
    Appoint local representation
    
    Most jurisdictions require a locally-established entity to hold the registration or act as authorised representative before submission.
    
2.  Step 02
    
    Reuse FDA or CE package as baseline
    
    Adapt the cybersecurity subsection you already prepared for FDA or CE; regulators here typically accept the structure and ask for local labeling additions.
    
3.  Step 03
    
    Translate and localise
    
    Local-language technical summary and labeling are usually mandatory; certified translation is safest.
    
4.  Step 04
    
    Submit + track queries
    
    Respond to clarification rounds promptly; each unanswered question can add 30-90 days to the clock.
    

### Evidence checklist

Item

Level

FDA equivalent

Notes

Cybersecurity documentation (baseline FDA or CE)

Required 

SPDF

Local authorised representative agreement

Required 

—

Local-language labeling and IFU

Required 

—

SBOM

Recommended 

—

Not mandatory but reduces clarification rounds.

### Common MDACS rejections

Documentation not aligned with MDACS classification

Occasional 

Fix ·  Follow the MDACS classification rules and provide matching evidence.

### Typical timeline

End-to-end window: 3-6 months 

Phase 01

Local rep + dossier prep

2-4 months

Phase 02

Regulatory review

3-6 months

Phase 03

Approval + market entry

1-3 months

[Previous ![Flag of Egypt](/flags/eg.svg)Egypt ](/standards/eg)[Next  ![Flag of Kuwait](/flags/kw.svg)Kuwait ](/standards/kw)

## Related markets

[![Flag of Singapore](/flags/sg.svg)

Singapore

~90% FDA reuse

](/standards/sg)[![Flag of Mexico](/flags/mx.svg)

Mexico

~90% FDA reuse

](/standards/mx)[![Flag of New Zealand](/flags/nz.svg)

New Zealand

~90% FDA reuse

](/standards/nz)[![Flag of Australia](/flags/au.svg)

Australia

~85% FDA reuse

](/standards/au)

## Frequently asked about Hong Kong

### Is SBOM required for medical devices in Hong Kong?

Recommended. Not mandated by MDACS, but reference-country SBOMs accepted as part of the listing dossier.

### What does MDD require for pre-market cybersecurity?

Reliance-based: listing requires evidence of approval by at least one Reference Country regulator (FDA, EU, Health Canada, TGA, PMDA). Cybersecurity expectations follow the reference-country submission.

### What are the post-market cybersecurity obligations under MDD?

MDACS adverse-event reporting; PCPD handles personal-data breach notifications under PDPO.

### What is the penalty for non-compliance with MDD cybersecurity rules?

Removal from MDACS listing; healthcare procurement consequences (most HA tenders require MDACS-listed devices).

### How much of my FDA cybersecurity package is reusable in Hong Kong?

Roughly 90% - an editorial estimate based on overlapping evidence requirements (threat model, SBOM, security risk assessment, pen-test report).

Sponsored note · Blue Goat Cyber

Submitting to MDD? Get a second pair of eyes before you file. Blue Goat Cyber has packaged cybersecurity evidence for Hong Kong alongside 37 other markets. We'll tell you what to keep, what to rework, and what's missing, in 30 minutes.  [Talk through your MDACS submission](https://go.bluegoatcyber.com/meetings/blue-goat-cyber/discovery-session)

The Crosswalk

An independent reference for global medical device cybersecurity standards. A field guide for MedTech innovators and RA/QA teams charting an international path.

Resource

-   [Comparison matrix](/compare)
-   [Global playbook](/playbook)
-   [Glossary](/glossary)
-   [FAQ](/faq)

Sponsored by

[Blue Goat Cyber ↗](https://bluegoatcyber.com)

Editorially independent. Sponsorship keeps it free.

© 2026 The Crosswalk. Not legal advice.

Validate every requirement against current regulator publications.