---
title: "India CDSCO - Cybersecurity Submission Playbook"
description: "How to submit a medical device to CDSCO in India: step-by-step route, evidence checklist, common rejections, and typical review timeline. Compared with FDA &amp;"
lang: en
json-ld: |
  [
    {
      "@context": "https://schema.org",
      "@type": "WebSite",
      "name": "The Medical Device Cybersecurity Crosswalk",
      "alternateName": "MDC Crosswalk",
      "url": "https://mdccrosswalk.com/",
      "description": "Compare FDA, EU MDR, MHRA, PMDA, NMPA, TGA, MFDS and Health Canada medical device cybersecurity requirements across 29 jurisdictions."
    },
    {
      "@context": "https://schema.org",
      "@type": "Organization",
      "name": "MDC Crosswalk",
      "url": "https://mdccrosswalk.com/",
      "logo": "https://mdccrosswalk.com/favicon.png",
      "sameAs": [
        "https://bluegoatcyber.com"
      ],
      "description": "An editorial reference comparing global medical-device cybersecurity regulations. Maintained by Blue Goat Cyber."
    },
    {
      "@context": "https://schema.org",
      "@type": "Article",
      "headline": "India - Medical Devices Rules 2017 + 2024 cybersecurity amendments",
      "description": "How to submit a medical device to CDSCO in India: step-by-step route, evidence checklist, common rejections, and typical review timeline. Compared with FDA & ",
      "author": {
        "@type": "Organization",
        "name": "MDC Crosswalk"
      },
      "publisher": {
        "@type": "Organization",
        "name": "MDC Crosswalk"
      },
      "image": "https://mdccrosswalk.lovable.app/favicon.png",
      "datePublished": "2024",
      "about": "Central Drugs Standard Control Organization",
      "dateModified": "2026-07-16",
      "mainEntityOfPage": "https://mdccrosswalk.lovable.app/standards/in"
    },
    {
      "@context": "https://schema.org",
      "@type": "FAQPage",
      "mainEntity": [
        {
          "@type": "Question",
          "name": "Is SBOM required for medical devices in India?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "Recommended. Encouraged in technical documentation; not yet a hard line item but expected for Class C/D under 2024 amendments."
          }
        },
        {
          "@type": "Question",
          "name": "What does CDSCO require for pre-market cybersecurity?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "Risk management aligned to ISO 14971, software lifecycle per IEC 62304, cybersecurity description in Plant Master File and Device Master File."
          }
        },
        {
          "@type": "Question",
          "name": "What are the post-market cybersecurity obligations under CDSCO?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "Materiovigilance Programme of India (MvPI) reporting; CERT-In 6-hour incident reporting for connected systems."
          }
        },
        {
          "@type": "Question",
          "name": "What is the penalty for non-compliance with CDSCO cybersecurity rules?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "Licence cancellation, imprisonment up to 5 years under D&C Act, DPDP penalties up to ₹250 crore."
          }
        },
        {
          "@type": "Question",
          "name": "How much of my FDA cybersecurity package is reusable in India?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "Roughly 60% - an editorial estimate based on overlapping evidence requirements (threat model, SBOM, security risk assessment, pen-test report)."
          }
        },
        {
          "@type": "Question",
          "name": "Why do CDSCO submissions get rejected for \"no indian authorised agent\"?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "Appoint an AA holding a valid wholesale licence before filing."
          }
        },
        {
          "@type": "Question",
          "name": "Why do CDSCO submissions get rejected for \"cybersecurity file missing for class c/d connected device\"?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "Adapt the FDA package; CDSCO reviewers accept it as a starting point."
          }
        }
      ]
    },
    {
      "@context": "https://schema.org",
      "@type": "HowTo",
      "name": "How to submit a medical device to CDSCO",
      "description": "CDSCO expects cybersecurity documentation for Class C and D devices; the 2023 draft guidance references FDA and MDCG 2019-16.",
      "totalTime": "6-12 months",
      "step": [
        {
          "@type": "HowToStep",
          "position": 1,
          "name": "Appoint local representation",
          "text": "Most jurisdictions require a locally-established entity to hold the registration or act as authorised representative before submission."
        },
        {
          "@type": "HowToStep",
          "position": 2,
          "name": "Reuse FDA or CE package as baseline",
          "text": "Adapt the cybersecurity subsection you already prepared for FDA or CE; regulators here typically accept the structure and ask for local labeling additions."
        },
        {
          "@type": "HowToStep",
          "position": 3,
          "name": "Translate and localise",
          "text": "Local-language technical summary and labeling are usually mandatory; certified translation is safest."
        },
        {
          "@type": "HowToStep",
          "position": 4,
          "name": "Submit + track queries",
          "text": "Respond to clarification rounds promptly; each unanswered question can add 30-90 days to the clock."
        }
      ]
    },
    {
      "@context": "https://schema.org",
      "@type": "BreadcrumbList",
      "itemListElement": [
        {
          "@type": "ListItem",
          "position": 1,
          "name": "Home",
          "item": "https://mdccrosswalk.lovable.app/"
        },
        {
          "@type": "ListItem",
          "position": 2,
          "name": "Standards"
        },
        {
          "@type": "ListItem",
          "position": 3,
          "name": "India"
        }
      ]
    }
  ]
---

[

The Crosswalk



](/)

[Overview](/)[Playbook](/playbook)CompareReference

[New Per-page social previews and this changelog ](/changelog "Per-page social previews and this changelog") Search⌘K

1.  [Home ](/)
2.  Standards 
3.  India 

CDSCO

# ![Flag of India](/flags/in.svg)India - CDSCO 

Guidance Last updated · 2024 Verified · 2026-07-16 

Medical Devices Rules 2017 + 2024 cybersecurity amendments

Share Copy link X LinkedIn Email

Sources verified · 2026-07-16

MDR 2017 + CERT-In Directions confirmed; specific 2024 cybersecurity amendments label awaiting confirmation.

Authority

Central Drugs Standard Control Organization

Enforced

Oct 2023 (full notified-device coverage)

Legal framework

Medical Devices Rules 2017 + DPDP Act 2023 + CERT-In Directions

FDA package reuse

~60%

[Editorial estimate · how →](/methodology#fda-reuse)

## Scope

All notified medical devices and IVDs, including SaMD with networking capability. Cybersecurity expectations layered onto existing licence application.

Pre-market

Risk management aligned to ISO 14971, software lifecycle per IEC 62304, cybersecurity description in Plant Master File and Device Master File.

Post-market

Materiovigilance Programme of India (MvPI) reporting; CERT-In 6-hour incident reporting for connected systems.

SBOM

Recommended 

Encouraged in technical documentation; not yet a hard line item but expected for Class C/D under 2024 amendments.

Vulnerability disclosure

CERT-In coordinated disclosure mandatory for service providers; recommended for manufacturers.

Penalty

Licence cancellation, imprisonment up to 5 years under D&C Act, DPDP penalties up to ₹250 crore.

## Unique requirements

-   01 Indian Authorised Agent required for foreign manufacturers 
-   02 BIS standards referenced for electrical safety 
-   03 CERT-In empanelled auditor often expected for cyber claims 

## Highlights

-   CERT-In 6-hour incident rule 
-   DPDP Act data localisation pressure 
-   Voluntary registration ending, mandatory licensing in force 

## Aligns with

IMDRF N60  ISO 14971  IEC 62304 

## Timeline

1.  Jan 2018
    
    MDR 2017 effective
    
2.  Apr 2022
    
    CERT-In Directions on incident reporting
    
3.  Oct 2023
    
    All notified devices require licence
    
4.  2024
    
    Cybersecurity amendments and DPDP Act rules
    

## Key documents

[

Medical Devices Rules 2017

https://cdsco.gov.in/opencms/opencms/en/Medical-Device-Diagnostics/Medical-Device-Diagnostics/



](https://cdsco.gov.in/opencms/opencms/en/Medical-Device-Diagnostics/Medical-Device-Diagnostics/)[

CERT-In Directions, April 2022

https://www.cert-in.org.in/



](https://www.cert-in.org.in/)[

Digital Personal Data Protection Act 2023

https://www.meity.gov.in/



](https://www.meity.gov.in/)

## How to submit in India

Playbook reviewed · 2026-07-16

Submission route

CDSCO registration under Medical Devices Rules 2017 with cybersecurity per CDSCO 2023 draft guidance

CDSCO expects cybersecurity documentation for Class C and D devices; the 2023 draft guidance references FDA and MDCG 2019-16.

[Authority portal](https://cdsco.gov.in/)

### Step-by-step

1.  Step 01
    
    Appoint local representation
    
    Most jurisdictions require a locally-established entity to hold the registration or act as authorised representative before submission.
    
2.  Step 02
    
    Reuse FDA or CE package as baseline
    
    Adapt the cybersecurity subsection you already prepared for FDA or CE; regulators here typically accept the structure and ask for local labeling additions.
    
3.  Step 03
    
    Translate and localise
    
    Local-language technical summary and labeling are usually mandatory; certified translation is safest.
    
4.  Step 04
    
    Submit + track queries
    
    Respond to clarification rounds promptly; each unanswered question can add 30-90 days to the clock.
    

### Evidence checklist

Item

Level

FDA equivalent

Notes

Cybersecurity documentation (baseline FDA or CE)

Required 

SPDF

Local authorised representative agreement

Required 

—

Local-language labeling and IFU

Required 

—

SBOM

Recommended 

—

Not mandatory but reduces clarification rounds.

### Common CDSCO rejections

No Indian Authorised Agent

Common 

Fix ·  Appoint an AA holding a valid wholesale licence before filing.

Cybersecurity file missing for Class C/D connected device

Occasional 

Fix ·  Adapt the FDA package; CDSCO reviewers accept it as a starting point.

### Typical timeline

End-to-end window: 6-12 months 

Phase 01

Local rep + dossier prep

2-4 months

Phase 02

Regulatory review

6-12 months

Phase 03

Approval + market entry

1-3 months

[Previous ![Flag of Switzerland](/flags/ch.svg)Switzerland ](/standards/ch)[Next  ![Flag of Israel](/flags/il.svg)Israel ](/standards/il)

## Related markets

[![Flag of Indonesia](/flags/id.svg)

Indonesia

~65% FDA reuse

](/standards/id)[![Flag of Thailand](/flags/th.svg)

Thailand

~70% FDA reuse

](/standards/th)[![Flag of Thailand](/flags/th.svg)

Thailand

~75% FDA reuse

](/standards/th)[![Flag of Egypt](/flags/eg.svg)

Egypt

~75% FDA reuse

](/standards/eg)

## Frequently asked about India

### Is SBOM required for medical devices in India?

Recommended. Encouraged in technical documentation; not yet a hard line item but expected for Class C/D under 2024 amendments.

### What does CDSCO require for pre-market cybersecurity?

Risk management aligned to ISO 14971, software lifecycle per IEC 62304, cybersecurity description in Plant Master File and Device Master File.

### What are the post-market cybersecurity obligations under CDSCO?

Materiovigilance Programme of India (MvPI) reporting; CERT-In 6-hour incident reporting for connected systems.

### What is the penalty for non-compliance with CDSCO cybersecurity rules?

Licence cancellation, imprisonment up to 5 years under D&C Act, DPDP penalties up to ₹250 crore.

### How much of my FDA cybersecurity package is reusable in India?

Roughly 60% - an editorial estimate based on overlapping evidence requirements (threat model, SBOM, security risk assessment, pen-test report).

Sponsored note · Blue Goat Cyber

Submitting to CDSCO? Get a second pair of eyes before you file. Blue Goat Cyber has packaged cybersecurity evidence for India alongside 37 other markets. We'll tell you what to keep, what to rework, and what's missing, in 30 minutes.  [Talk through your CDSCO submission](https://go.bluegoatcyber.com/meetings/blue-goat-cyber/discovery-session)

The Crosswalk

An independent reference for global medical device cybersecurity standards. A field guide for MedTech innovators and RA/QA teams charting an international path.

Resource

-   [Comparison matrix](/compare)
-   [Global playbook](/playbook)
-   [Glossary](/glossary)
-   [FAQ](/faq)

Sponsored by

[Blue Goat Cyber ↗](https://bluegoatcyber.com)

Editorially independent. Sponsorship keeps it free.

© 2026 The Crosswalk. Not legal advice.

Validate every requirement against current regulator publications.