---
title: "Indonesia Kemenkes - Cybersecurity Submission Playbook"
description: "How to submit a medical device to Kemenkes in Indonesia: step-by-step route, evidence checklist, common rejections, and typical review timeline. Compared with"
lang: en
json-ld: |
  [
    {
      "@context": "https://schema.org",
      "@type": "WebSite",
      "name": "The Medical Device Cybersecurity Crosswalk",
      "alternateName": "MDC Crosswalk",
      "url": "https://mdccrosswalk.com/",
      "description": "Compare FDA, EU MDR, MHRA, PMDA, NMPA, TGA, MFDS and Health Canada medical device cybersecurity requirements across 29 jurisdictions."
    },
    {
      "@context": "https://schema.org",
      "@type": "Organization",
      "name": "MDC Crosswalk",
      "url": "https://mdccrosswalk.com/",
      "logo": "https://mdccrosswalk.com/favicon.png",
      "sameAs": [
        "https://bluegoatcyber.com"
      ],
      "description": "An editorial reference comparing global medical-device cybersecurity regulations. Maintained by Blue Goat Cyber."
    },
    {
      "@context": "https://schema.org",
      "@type": "Article",
      "headline": "Indonesia - Permenkes No. 62/2017 + Kemenkes digital-health regulations",
      "description": "How to submit a medical device to Kemenkes in Indonesia: step-by-step route, evidence checklist, common rejections, and typical review timeline. Compared with",
      "author": {
        "@type": "Organization",
        "name": "MDC Crosswalk"
      },
      "publisher": {
        "@type": "Organization",
        "name": "MDC Crosswalk"
      },
      "image": "https://mdccrosswalk.lovable.app/favicon.png",
      "datePublished": "2024",
      "about": "Ministry of Health (Kemenkes); BPOM for combination products",
      "dateModified": "2026-07-16",
      "mainEntityOfPage": "https://mdccrosswalk.lovable.app/standards/id"
    },
    {
      "@context": "https://schema.org",
      "@type": "FAQPage",
      "mainEntity": [
        {
          "@type": "Question",
          "name": "Is SBOM required for medical devices in Indonesia?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "Recommended. Encouraged in line with IMDRF N60; mandate expected as digital-health rules mature."
          }
        },
        {
          "@type": "Question",
          "name": "What does Kemenkes require for pre-market cybersecurity?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "Risk-class registration dossier, halal certification where applicable, e-Watch reporting commitments."
          }
        },
        {
          "@type": "Question",
          "name": "What are the post-market cybersecurity obligations under Kemenkes?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "e-Watch adverse event reporting, distribution audits."
          }
        },
        {
          "@type": "Question",
          "name": "What is the penalty for non-compliance with Kemenkes cybersecurity rules?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "Registration revocation; UU PDP fines up to 2% of annual revenue."
          }
        },
        {
          "@type": "Question",
          "name": "How much of my FDA cybersecurity package is reusable in Indonesia?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "Roughly 65% - an editorial estimate based on overlapping evidence requirements (threat model, SBOM, security risk assessment, pen-test report)."
          }
        },
        {
          "@type": "Question",
          "name": "Why do Kemenkes submissions get rejected for \"ipak-holder appointment missing\"?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "Appoint an IPAK-licensed distributor before submission."
          }
        }
      ]
    },
    {
      "@context": "https://schema.org",
      "@type": "HowTo",
      "name": "How to submit a medical device to Kemenkes",
      "description": "Indonesia requires a local licence holder (IPAK holder). Cybersecurity documentation, when submitted, is reviewed as part of the technical file.",
      "totalTime": "4-10 months",
      "step": [
        {
          "@type": "HowToStep",
          "position": 1,
          "name": "Appoint local representation",
          "text": "Most jurisdictions require a locally-established entity to hold the registration or act as authorised representative before submission."
        },
        {
          "@type": "HowToStep",
          "position": 2,
          "name": "Reuse FDA or CE package as baseline",
          "text": "Adapt the cybersecurity subsection you already prepared for FDA or CE; regulators here typically accept the structure and ask for local labeling additions."
        },
        {
          "@type": "HowToStep",
          "position": 3,
          "name": "Translate and localise",
          "text": "Local-language technical summary and labeling are usually mandatory; certified translation is safest."
        },
        {
          "@type": "HowToStep",
          "position": 4,
          "name": "Submit + track queries",
          "text": "Respond to clarification rounds promptly; each unanswered question can add 30-90 days to the clock."
        }
      ]
    },
    {
      "@context": "https://schema.org",
      "@type": "BreadcrumbList",
      "itemListElement": [
        {
          "@type": "ListItem",
          "position": 1,
          "name": "Home",
          "item": "https://mdccrosswalk.lovable.app/"
        },
        {
          "@type": "ListItem",
          "position": 2,
          "name": "Standards"
        },
        {
          "@type": "ListItem",
          "position": 3,
          "name": "Indonesia"
        }
      ]
    }
  ]
---

[

The Crosswalk



](/)

[Overview](/)[Playbook](/playbook)CompareReference

[New Per-page social previews and this changelog ](/changelog "Per-page social previews and this changelog") Search⌘K

1.  [Home ](/)
2.  Standards 
3.  Indonesia 

Kemenkes

# ![Flag of Indonesia](/flags/id.svg)Indonesia - Kemenkes 

Guidance Last updated · 2024 Verified · 2026-07-16 

Permenkes No. 62/2017 + Kemenkes digital-health regulations

Share Copy link X LinkedIn Email

Sources verified · 2026-07-16

Kemenkes / BPOM device rules confirmed; standalone cybersecurity instrument awaiting SME review.

Authority

Ministry of Health (Kemenkes); BPOM for combination products

Enforced

2017

Legal framework

Permenkes 62/2017 + UU PDP (Personal Data Protection Law 2022) + BSSN guidance

FDA package reuse

~65%

[Editorial estimate · how →](/methodology#fda-reuse)

## Scope

All medical devices distributed in Indonesia, including SaMD. Risk-class based registration.

Pre-market

Risk-class registration dossier, halal certification where applicable, e-Watch reporting commitments.

Post-market

e-Watch adverse event reporting, distribution audits.

SBOM

Recommended 

Encouraged in line with IMDRF N60; mandate expected as digital-health rules mature.

Vulnerability disclosure

BSSN (National Cyber and Crypto Agency) coordinated disclosure recommended.

Penalty

Registration revocation; UU PDP fines up to 2% of annual revenue.

## Unique requirements

-   01 Indonesian Distributor Holder (IPAK) 
-   02 Bahasa Indonesia labelling 
-   03 Halal certification for relevant categories 

## Highlights

-   UU PDP closely modelled on GDPR 
-   BSSN cybersecurity overlay for hospitals 
-   Largest ASEAN device market by population 

## Aligns with

ASEAN MDD  IMDRF N60  ISO 13485 

## Timeline

1.  2017
    
    Permenkes 62/2017 issued
    
2.  Oct 2022
    
    UU PDP enacted
    
3.  Oct 2024
    
    UU PDP full enforcement
    

## Key documents

[

Kemenkes - Medical Device Registration (InfoAlkes)

https://infoalkes.kemkes.go.id/



](https://infoalkes.kemkes.go.id/)[

BSSN - National Cyber and Crypto Agency

https://www.bssn.go.id/



](https://www.bssn.go.id/)[

Komdigi (formerly Kominfo) - UU PDP authority

https://www.komdigi.go.id/



](https://www.komdigi.go.id/)

## How to submit in Indonesia

Playbook reviewed · 2026-07-16

Submission route

Ministry of Health (Kemenkes) registration via Regalkes portal

Indonesia requires a local licence holder (IPAK holder). Cybersecurity documentation, when submitted, is reviewed as part of the technical file.

[Authority portal](https://regalkes.kemkes.go.id/)

### Step-by-step

1.  Step 01
    
    Appoint local representation
    
    Most jurisdictions require a locally-established entity to hold the registration or act as authorised representative before submission.
    
2.  Step 02
    
    Reuse FDA or CE package as baseline
    
    Adapt the cybersecurity subsection you already prepared for FDA or CE; regulators here typically accept the structure and ask for local labeling additions.
    
3.  Step 03
    
    Translate and localise
    
    Local-language technical summary and labeling are usually mandatory; certified translation is safest.
    
4.  Step 04
    
    Submit + track queries
    
    Respond to clarification rounds promptly; each unanswered question can add 30-90 days to the clock.
    

### Evidence checklist

Item

Level

FDA equivalent

Notes

Cybersecurity documentation (baseline FDA or CE)

Required 

SPDF

Local authorised representative agreement

Required 

—

Local-language labeling and IFU

Required 

—

SBOM

Recommended 

—

Not mandatory but reduces clarification rounds.

### Common Kemenkes rejections

IPAK-holder appointment missing

Common 

Fix ·  Appoint an IPAK-licensed distributor before submission.

### Typical timeline

End-to-end window: 4-10 months 

Phase 01

Local rep + dossier prep

2-4 months

Phase 02

Regulatory review

4-10 months

Phase 03

Approval + market entry

1-3 months

[Previous ![Flag of Thailand](/flags/th.svg)Thailand ](/standards/th)[Next  ![Flag of Argentina](/flags/ar.svg)Argentina ](/standards/ar)

## Related markets

[![Flag of India](/flags/in.svg)

India

~60% FDA reuse

](/standards/in)[![Flag of Thailand](/flags/th.svg)

Thailand

~70% FDA reuse

](/standards/th)[![Flag of Thailand](/flags/th.svg)

Thailand

~75% FDA reuse

](/standards/th)[![Flag of Egypt](/flags/eg.svg)

Egypt

~75% FDA reuse

](/standards/eg)

## Frequently asked about Indonesia

### Is SBOM required for medical devices in Indonesia?

Recommended. Encouraged in line with IMDRF N60; mandate expected as digital-health rules mature.

### What does Kemenkes require for pre-market cybersecurity?

Risk-class registration dossier, halal certification where applicable, e-Watch reporting commitments.

### What are the post-market cybersecurity obligations under Kemenkes?

e-Watch adverse event reporting, distribution audits.

### What is the penalty for non-compliance with Kemenkes cybersecurity rules?

Registration revocation; UU PDP fines up to 2% of annual revenue.

### How much of my FDA cybersecurity package is reusable in Indonesia?

Roughly 65% - an editorial estimate based on overlapping evidence requirements (threat model, SBOM, security risk assessment, pen-test report).

Sponsored note · Blue Goat Cyber

Submitting to Kemenkes? Get a second pair of eyes before you file. Blue Goat Cyber has packaged cybersecurity evidence for Indonesia alongside 37 other markets. We'll tell you what to keep, what to rework, and what's missing, in 30 minutes.  [Talk through your Kemenkes submission](https://go.bluegoatcyber.com/meetings/blue-goat-cyber/discovery-session)

The Crosswalk

An independent reference for global medical device cybersecurity standards. A field guide for MedTech innovators and RA/QA teams charting an international path.

Resource

-   [Comparison matrix](/compare)
-   [Global playbook](/playbook)
-   [Glossary](/glossary)
-   [FAQ](/faq)

Sponsored by

[Blue Goat Cyber ↗](https://bluegoatcyber.com)

Editorially independent. Sponsorship keeps it free.

© 2026 The Crosswalk. Not legal advice.

Validate every requirement against current regulator publications.