CDSCO
India - CDSCO
Medical Devices Rules 2017 + 2024 cybersecurity amendments
Authority
Central Drugs Standard Control Organization
Enforced
Oct 2023 (full notified-device coverage)
Legal framework
Medical Devices Rules 2017 + DPDP Act 2023 + CERT-In Directions
Scope
All notified medical devices and IVDs, including SaMD with networking capability. Cybersecurity expectations layered onto existing licence application.
Pre-market
Risk management aligned to ISO 14971, software lifecycle per IEC 62304, cybersecurity description in Plant Master File and Device Master File.
Post-market
Materiovigilance Programme of India (MvPI) reporting; CERT-In 6-hour incident reporting for connected systems.
SBOM
RecommendedEncouraged in technical documentation; not yet a hard line item but expected for Class C/D under 2024 amendments.
Vulnerability disclosure
CERT-In coordinated disclosure mandatory for service providers; recommended for manufacturers.
Penalty
Licence cancellation, imprisonment up to 5 years under D&C Act, DPDP penalties up to ₹250 crore.
Unique requirements
- 01Indian Authorised Agent required for foreign manufacturers
- 02BIS standards referenced for electrical safety
- 03CERT-In empanelled auditor often expected for cyber claims
Highlights
- CERT-In 6-hour incident rule
- DPDP Act data localisation pressure
- Voluntary registration ending, mandatory licensing in force
Aligns with
Timeline
-
Jan 2018
MDR 2017 effective
-
Apr 2022
CERT-In Directions on incident reporting
-
Oct 2023
All notified devices require licence
-
2024
Cybersecurity amendments and DPDP Act rules
Key documents
How to submit in India
Playbook reviewed · 2026-07-16
Submission route
CDSCO registration under Medical Devices Rules 2017 with cybersecurity per CDSCO 2023 draft guidance
CDSCO expects cybersecurity documentation for Class C and D devices; the 2023 draft guidance references FDA and MDCG 2019-16.
Authority portalStep-by-step
-
Step 01
Appoint local representation
Most jurisdictions require a locally-established entity to hold the registration or act as authorised representative before submission.
-
Step 02
Reuse FDA or CE package as baseline
Adapt the cybersecurity subsection you already prepared for FDA or CE; regulators here typically accept the structure and ask for local labeling additions.
-
Step 03
Translate and localise
Local-language technical summary and labeling are usually mandatory; certified translation is safest.
-
Step 04
Submit + track queries
Respond to clarification rounds promptly; each unanswered question can add 30-90 days to the clock.
Evidence checklist
| Item | Level | FDA equivalent | Notes |
|---|---|---|---|
| Cybersecurity documentation (baseline FDA or CE) | Required | SPDF | |
| Local authorised representative agreement | Required | — | |
| Local-language labeling and IFU | Required | — | |
| SBOM | Recommended | — | Not mandatory but reduces clarification rounds. |
Common CDSCO rejections
No Indian Authorised Agent
CommonFix · Appoint an AA holding a valid wholesale licence before filing.
Cybersecurity file missing for Class C/D connected device
OccasionalFix · Adapt the FDA package; CDSCO reviewers accept it as a starting point.
Typical timeline
End-to-end window: 6-12 months
Phase 01
Local rep + dossier prep
2-4 months
Phase 02
Regulatory review
6-12 months
Phase 03
Approval + market entry
1-3 months
Related markets
Frequently asked about India
Is SBOM required for medical devices in India?
Recommended. Encouraged in technical documentation; not yet a hard line item but expected for Class C/D under 2024 amendments.
What does CDSCO require for pre-market cybersecurity?
Risk management aligned to ISO 14971, software lifecycle per IEC 62304, cybersecurity description in Plant Master File and Device Master File.
What are the post-market cybersecurity obligations under CDSCO?
Materiovigilance Programme of India (MvPI) reporting; CERT-In 6-hour incident reporting for connected systems.
What is the penalty for non-compliance with CDSCO cybersecurity rules?
Licence cancellation, imprisonment up to 5 years under D&C Act, DPDP penalties up to ₹250 crore.
How much of my FDA cybersecurity package is reusable in India?
Roughly 60% - an editorial estimate based on overlapping evidence requirements (threat model, SBOM, security risk assessment, pen-test report).