AMAR / MoH
Israel - AMAR / MoH
Medical Devices Law 5772-2012 + MoH Cybersecurity Circular
Authority
Medical Devices Division (AMAR), Israeli Ministry of Health
Enforced
2019 (cybersecurity circular)
Legal framework
Medical Devices Law + MoH Director-General Circulars + INCD guidance
Scope
All medical devices marketed in Israel; reference jurisdiction model accepts FDA, CE, Health Canada, TGA, PMDA approvals.
Pre-market
Cybersecurity risk management dossier, threat model, evidence of secure SDLC, alignment to FDA/IMDRF accepted.
Post-market
Adverse-event and cyber-incident reporting to MoH; coordination with INCD for critical infrastructure.
SBOM
RecommendedStrongly encouraged; aligned to FDA expectations for dual-market devices.
Vulnerability disclosure
INCD (Israel National Cyber Directorate) coordinated disclosure recommended.
Penalty
Registration suspension, recall orders, criminal liability under Medical Devices Law.
Unique requirements
- 01Israeli Registration Holder required
- 02Hebrew labelling for end users
- 03INCD critical-infrastructure notifications for hospital systems
Highlights
- Reference-jurisdiction abridged route
- INCD overlay for hospital-deployed devices
- Strong alignment to FDA SPDF
Aligns with
Timeline
-
2012
Medical Devices Law enacted
-
2019
MoH cybersecurity circular issued
-
2023
Updated alignment with FDA / IMDRF
Key documents
How to submit in Israel
Playbook reviewed · 2026-07-16
Submission route
AMAR registration with Israeli MoH under AMAR Regulations
Israeli MoH heavily leverages FDA and CE approvals through the AMAR abbreviated route. Cybersecurity documentation is not separately mandated but expected when submitted.
Authority portalStep-by-step
-
Step 01
Appoint local representation
Most jurisdictions require a locally-established entity to hold the registration or act as authorised representative before submission.
-
Step 02
Reuse FDA or CE package as baseline
Adapt the cybersecurity subsection you already prepared for FDA or CE; regulators here typically accept the structure and ask for local labeling additions.
-
Step 03
Translate and localise
Local-language technical summary and labeling are usually mandatory; certified translation is safest.
-
Step 04
Submit + track queries
Respond to clarification rounds promptly; each unanswered question can add 30-90 days to the clock.
Evidence checklist
| Item | Level | FDA equivalent | Notes |
|---|---|---|---|
| Cybersecurity documentation (baseline FDA or CE) | Required | SPDF | |
| Local authorised representative agreement | Required | — | |
| Local-language labeling and IFU | Required | — | |
| SBOM | Recommended | — | Not mandatory but reduces clarification rounds. |
Common AMAR rejections
Reference approval scope doesn't match Israeli intended use
OccasionalFix · Provide a variance letter or use the full route.
Typical timeline
End-to-end window: 2-6 months (abbreviated)
Phase 01
Local rep + dossier prep
2-4 months
Phase 02
Regulatory review
2-6 months (abbreviated)
Phase 03
Approval + market entry
1-3 months
Related markets
Frequently asked about Israel
Is SBOM required for medical devices in Israel?
Recommended. Strongly encouraged; aligned to FDA expectations for dual-market devices.
What does AMAR / MoH require for pre-market cybersecurity?
Cybersecurity risk management dossier, threat model, evidence of secure SDLC, alignment to FDA/IMDRF accepted.
What are the post-market cybersecurity obligations under AMAR / MoH?
Adverse-event and cyber-incident reporting to MoH; coordination with INCD for critical infrastructure.
What is the penalty for non-compliance with AMAR / MoH cybersecurity rules?
Registration suspension, recall orders, criminal liability under Medical Devices Law.
How much of my FDA cybersecurity package is reusable in Israel?
Roughly 90% - an editorial estimate based on overlapping evidence requirements (threat model, SBOM, security risk assessment, pen-test report).