The Crosswalk

    NewPer-page social previews and this changelog

    AMAR / MoH

    Flag of IsraelIsrael - AMAR / MoH

    MandatoryLast updated · 2024 (MoH cybersecurity circular refresh)Verified · 2026-07-16

    Medical Devices Law 5772-2012 + MoH Cybersecurity Circular

    Share

    Authority

    Medical Devices Division (AMAR), Israeli Ministry of Health

    Enforced

    2019 (cybersecurity circular)

    Legal framework

    Medical Devices Law + MoH Director-General Circulars + INCD guidance

    FDA package reuse

    ~90%

    Scope

    All medical devices marketed in Israel; reference jurisdiction model accepts FDA, CE, Health Canada, TGA, PMDA approvals.

    Pre-market

    Cybersecurity risk management dossier, threat model, evidence of secure SDLC, alignment to FDA/IMDRF accepted.

    Post-market

    Adverse-event and cyber-incident reporting to MoH; coordination with INCD for critical infrastructure.

    SBOM

    Recommended

    Strongly encouraged; aligned to FDA expectations for dual-market devices.

    Vulnerability disclosure

    INCD (Israel National Cyber Directorate) coordinated disclosure recommended.

    Penalty

    Registration suspension, recall orders, criminal liability under Medical Devices Law.

    Unique requirements

    • 01Israeli Registration Holder required
    • 02Hebrew labelling for end users
    • 03INCD critical-infrastructure notifications for hospital systems

    Highlights

    • Reference-jurisdiction abridged route
    • INCD overlay for hospital-deployed devices
    • Strong alignment to FDA SPDF

    Aligns with

    FDA 2023 Guidance IMDRF N60 IEC 81001-5-1

    Timeline

    1. 2012

      Medical Devices Law enacted

    2. 2019

      MoH cybersecurity circular issued

    3. 2023

      Updated alignment with FDA / IMDRF

    Key documents

    How to submit in Israel

    Playbook reviewed · 2026-07-16

    Submission route

    AMAR registration with Israeli MoH under AMAR Regulations

    Israeli MoH heavily leverages FDA and CE approvals through the AMAR abbreviated route. Cybersecurity documentation is not separately mandated but expected when submitted.

    Authority portal

    Step-by-step

    1. Step 01

      Appoint local representation

      Most jurisdictions require a locally-established entity to hold the registration or act as authorised representative before submission.

    2. Step 02

      Reuse FDA or CE package as baseline

      Adapt the cybersecurity subsection you already prepared for FDA or CE; regulators here typically accept the structure and ask for local labeling additions.

    3. Step 03

      Translate and localise

      Local-language technical summary and labeling are usually mandatory; certified translation is safest.

    4. Step 04

      Submit + track queries

      Respond to clarification rounds promptly; each unanswered question can add 30-90 days to the clock.

    Evidence checklist

    Item Level FDA equivalent Notes
    Cybersecurity documentation (baseline FDA or CE) Required SPDF
    Local authorised representative agreement Required
    Local-language labeling and IFU Required
    SBOM Recommended Not mandatory but reduces clarification rounds.

    Common AMAR rejections

    Reference approval scope doesn't match Israeli intended use

    Occasional

    Fix · Provide a variance letter or use the full route.

    Typical timeline

    End-to-end window: 2-6 months (abbreviated)

    Phase 01

    Local rep + dossier prep

    2-4 months

    Phase 02

    Regulatory review

    2-6 months (abbreviated)

    Phase 03

    Approval + market entry

    1-3 months

    Related markets

    Frequently asked about Israel

    Is SBOM required for medical devices in Israel?

    Recommended. Strongly encouraged; aligned to FDA expectations for dual-market devices.

    What does AMAR / MoH require for pre-market cybersecurity?

    Cybersecurity risk management dossier, threat model, evidence of secure SDLC, alignment to FDA/IMDRF accepted.

    What are the post-market cybersecurity obligations under AMAR / MoH?

    Adverse-event and cyber-incident reporting to MoH; coordination with INCD for critical infrastructure.

    What is the penalty for non-compliance with AMAR / MoH cybersecurity rules?

    Registration suspension, recall orders, criminal liability under Medical Devices Law.

    How much of my FDA cybersecurity package is reusable in Israel?

    Roughly 90% - an editorial estimate based on overlapping evidence requirements (threat model, SBOM, security risk assessment, pen-test report).