---
title: "Israel AMAR - Cybersecurity Submission Playbook"
description: "How to submit a medical device to AMAR / MoH in Israel: step-by-step route, evidence checklist, common rejections, and typical review timeline. Compared with"
lang: en
json-ld: |
  [
    {
      "@context": "https://schema.org",
      "@type": "WebSite",
      "name": "The Medical Device Cybersecurity Crosswalk",
      "alternateName": "MDC Crosswalk",
      "url": "https://mdccrosswalk.com/",
      "description": "Compare FDA, EU MDR, MHRA, PMDA, NMPA, TGA, MFDS and Health Canada medical device cybersecurity requirements across 29 jurisdictions."
    },
    {
      "@context": "https://schema.org",
      "@type": "Organization",
      "name": "MDC Crosswalk",
      "url": "https://mdccrosswalk.com/",
      "logo": "https://mdccrosswalk.com/favicon.png",
      "sameAs": [
        "https://bluegoatcyber.com"
      ],
      "description": "An editorial reference comparing global medical-device cybersecurity regulations. Maintained by Blue Goat Cyber."
    },
    {
      "@context": "https://schema.org",
      "@type": "Article",
      "headline": "Israel - Medical Devices Law 5772-2012 + MoH Cybersecurity Circular",
      "description": "How to submit a medical device to AMAR / MoH in Israel: step-by-step route, evidence checklist, common rejections, and typical review timeline. Compared with ",
      "author": {
        "@type": "Organization",
        "name": "MDC Crosswalk"
      },
      "publisher": {
        "@type": "Organization",
        "name": "MDC Crosswalk"
      },
      "image": "https://mdccrosswalk.lovable.app/favicon.png",
      "datePublished": "2024 (MoH cybersecurity circular refresh)",
      "about": "Medical Devices Division (AMAR), Israeli Ministry of Health",
      "dateModified": "2026-07-16",
      "mainEntityOfPage": "https://mdccrosswalk.lovable.app/standards/il"
    },
    {
      "@context": "https://schema.org",
      "@type": "FAQPage",
      "mainEntity": [
        {
          "@type": "Question",
          "name": "Is SBOM required for medical devices in Israel?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "Recommended. Strongly encouraged; aligned to FDA expectations for dual-market devices."
          }
        },
        {
          "@type": "Question",
          "name": "What does AMAR / MoH require for pre-market cybersecurity?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "Cybersecurity risk management dossier, threat model, evidence of secure SDLC, alignment to FDA/IMDRF accepted."
          }
        },
        {
          "@type": "Question",
          "name": "What are the post-market cybersecurity obligations under AMAR / MoH?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "Adverse-event and cyber-incident reporting to MoH; coordination with INCD for critical infrastructure."
          }
        },
        {
          "@type": "Question",
          "name": "What is the penalty for non-compliance with AMAR / MoH cybersecurity rules?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "Registration suspension, recall orders, criminal liability under Medical Devices Law."
          }
        },
        {
          "@type": "Question",
          "name": "How much of my FDA cybersecurity package is reusable in Israel?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "Roughly 90% - an editorial estimate based on overlapping evidence requirements (threat model, SBOM, security risk assessment, pen-test report)."
          }
        },
        {
          "@type": "Question",
          "name": "Why do AMAR submissions get rejected for \"reference approval scope doesn't match israeli intended use\"?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "Provide a variance letter or use the full route."
          }
        }
      ]
    },
    {
      "@context": "https://schema.org",
      "@type": "HowTo",
      "name": "How to submit a medical device to AMAR / MoH",
      "description": "Israeli MoH heavily leverages FDA and CE approvals through the AMAR abbreviated route. Cybersecurity documentation is not separately mandated but expected when submitted.",
      "totalTime": "2-6 months (abbreviated)",
      "step": [
        {
          "@type": "HowToStep",
          "position": 1,
          "name": "Appoint local representation",
          "text": "Most jurisdictions require a locally-established entity to hold the registration or act as authorised representative before submission."
        },
        {
          "@type": "HowToStep",
          "position": 2,
          "name": "Reuse FDA or CE package as baseline",
          "text": "Adapt the cybersecurity subsection you already prepared for FDA or CE; regulators here typically accept the structure and ask for local labeling additions."
        },
        {
          "@type": "HowToStep",
          "position": 3,
          "name": "Translate and localise",
          "text": "Local-language technical summary and labeling are usually mandatory; certified translation is safest."
        },
        {
          "@type": "HowToStep",
          "position": 4,
          "name": "Submit + track queries",
          "text": "Respond to clarification rounds promptly; each unanswered question can add 30-90 days to the clock."
        }
      ]
    },
    {
      "@context": "https://schema.org",
      "@type": "BreadcrumbList",
      "itemListElement": [
        {
          "@type": "ListItem",
          "position": 1,
          "name": "Home",
          "item": "https://mdccrosswalk.lovable.app/"
        },
        {
          "@type": "ListItem",
          "position": 2,
          "name": "Standards"
        },
        {
          "@type": "ListItem",
          "position": 3,
          "name": "Israel"
        }
      ]
    }
  ]
---

[

The Crosswalk



](/)

[Overview](/)[Playbook](/playbook)CompareReference

[New Per-page social previews and this changelog ](/changelog "Per-page social previews and this changelog") Search⌘K

1.  [Home ](/)
2.  Standards 
3.  Israel 

AMAR / MoH

# ![Flag of Israel](/flags/il.svg)Israel - AMAR / MoH 

Mandatory Last updated · 2024 (MoH cybersecurity circular refresh) Verified · 2026-07-16 

Medical Devices Law 5772-2012 + MoH Cybersecurity Circular

Share Copy link X LinkedIn Email

Sources verified · 2026-07-16

Cross-checked against Israeli MoH cybersecurity circular and INCD guidance.

Authority

Medical Devices Division (AMAR), Israeli Ministry of Health

Enforced

2019 (cybersecurity circular)

Legal framework

Medical Devices Law + MoH Director-General Circulars + INCD guidance

FDA package reuse

~90%

[Editorial estimate · how →](/methodology#fda-reuse)

## Scope

All medical devices marketed in Israel; reference jurisdiction model accepts FDA, CE, Health Canada, TGA, PMDA approvals.

Pre-market

Cybersecurity risk management dossier, threat model, evidence of secure SDLC, alignment to FDA/IMDRF accepted.

Post-market

Adverse-event and cyber-incident reporting to MoH; coordination with INCD for critical infrastructure.

SBOM

Recommended 

Strongly encouraged; aligned to FDA expectations for dual-market devices.

Vulnerability disclosure

INCD (Israel National Cyber Directorate) coordinated disclosure recommended.

Penalty

Registration suspension, recall orders, criminal liability under Medical Devices Law.

## Unique requirements

-   01 Israeli Registration Holder required 
-   02 Hebrew labelling for end users 
-   03 INCD critical-infrastructure notifications for hospital systems 

## Highlights

-   Reference-jurisdiction abridged route 
-   INCD overlay for hospital-deployed devices 
-   Strong alignment to FDA SPDF 

## Aligns with

FDA 2023 Guidance  IMDRF N60  IEC 81001-5-1 

## Timeline

1.  2012
    
    Medical Devices Law enacted
    
2.  2019
    
    MoH cybersecurity circular issued
    
3.  2023
    
    Updated alignment with FDA / IMDRF
    

## Key documents

[

Israeli MoH Medical Devices Division

https://www.health.gov.il/English/MinistryUnits/HealthDivision/MedicalTechnologies/Pages/default.aspx



](https://www.health.gov.il/English/MinistryUnits/HealthDivision/MedicalTechnologies/Pages/default.aspx)[

INCD Guidance Library

https://www.gov.il/en/departments/israel\_national\_cyber\_directorate



](https://www.gov.il/en/departments/israel_national_cyber_directorate)

## How to submit in Israel

Playbook reviewed · 2026-07-16

Submission route

AMAR registration with Israeli MoH under AMAR Regulations

Israeli MoH heavily leverages FDA and CE approvals through the AMAR abbreviated route. Cybersecurity documentation is not separately mandated but expected when submitted.

[Authority portal](https://www.gov.il/en/departments/ministry_of_health)

### Step-by-step

1.  Step 01
    
    Appoint local representation
    
    Most jurisdictions require a locally-established entity to hold the registration or act as authorised representative before submission.
    
2.  Step 02
    
    Reuse FDA or CE package as baseline
    
    Adapt the cybersecurity subsection you already prepared for FDA or CE; regulators here typically accept the structure and ask for local labeling additions.
    
3.  Step 03
    
    Translate and localise
    
    Local-language technical summary and labeling are usually mandatory; certified translation is safest.
    
4.  Step 04
    
    Submit + track queries
    
    Respond to clarification rounds promptly; each unanswered question can add 30-90 days to the clock.
    

### Evidence checklist

Item

Level

FDA equivalent

Notes

Cybersecurity documentation (baseline FDA or CE)

Required 

SPDF

Local authorised representative agreement

Required 

—

Local-language labeling and IFU

Required 

—

SBOM

Recommended 

—

Not mandatory but reduces clarification rounds.

### Common AMAR rejections

Reference approval scope doesn't match Israeli intended use

Occasional 

Fix ·  Provide a variance letter or use the full route.

### Typical timeline

End-to-end window: 2-6 months (abbreviated) 

Phase 01

Local rep + dossier prep

2-4 months

Phase 02

Regulatory review

2-6 months (abbreviated)

Phase 03

Approval + market entry

1-3 months

[Previous ![Flag of India](/flags/in.svg)India ](/standards/in)[Next  ![Flag of Taiwan](/flags/tw.svg)Taiwan ](/standards/tw)

## Related markets

[![Flag of Canada](/flags/ca.svg)

Canada

~95% FDA reuse

](/standards/ca)[![Flag of United Arab Emirates](/flags/ae.svg)

United Arab Emirates

~85% FDA reuse

](/standards/ae)[![Flag of United States](/flags/us.svg)

United States

~100% FDA reuse

](/standards/fda)[![Flag of Japan](/flags/jp.svg)

Japan

~70% FDA reuse

](/standards/jp)

## Frequently asked about Israel

### Is SBOM required for medical devices in Israel?

Recommended. Strongly encouraged; aligned to FDA expectations for dual-market devices.

### What does AMAR / MoH require for pre-market cybersecurity?

Cybersecurity risk management dossier, threat model, evidence of secure SDLC, alignment to FDA/IMDRF accepted.

### What are the post-market cybersecurity obligations under AMAR / MoH?

Adverse-event and cyber-incident reporting to MoH; coordination with INCD for critical infrastructure.

### What is the penalty for non-compliance with AMAR / MoH cybersecurity rules?

Registration suspension, recall orders, criminal liability under Medical Devices Law.

### How much of my FDA cybersecurity package is reusable in Israel?

Roughly 90% - an editorial estimate based on overlapping evidence requirements (threat model, SBOM, security risk assessment, pen-test report).

Sponsored note · Blue Goat Cyber

Submitting to AMAR / MoH? Get a second pair of eyes before you file. Blue Goat Cyber has packaged cybersecurity evidence for Israel alongside 37 other markets. We'll tell you what to keep, what to rework, and what's missing, in 30 minutes.  [Talk through your AMAR submission](https://go.bluegoatcyber.com/meetings/blue-goat-cyber/discovery-session)

The Crosswalk

An independent reference for global medical device cybersecurity standards. A field guide for MedTech innovators and RA/QA teams charting an international path.

Resource

-   [Comparison matrix](/compare)
-   [Global playbook](/playbook)
-   [Glossary](/glossary)
-   [FAQ](/faq)

Sponsored by

[Blue Goat Cyber ↗](https://bluegoatcyber.com)

Editorially independent. Sponsorship keeps it free.

© 2026 The Crosswalk. Not legal advice.

Validate every requirement against current regulator publications.