The Crosswalk

    NewPer-page social previews and this changelog

    PMDA / MHLW

    Flag of JapanJapan - PMDA / MHLW

    MandatoryLast updated · Mar 2024Verified · 2026-07-16

    PMSD Act + MHLW Cybersecurity Notifications (2023–24)

    Share

    Authority

    Pharmaceuticals and Medical Devices Agency / Ministry of Health, Labour and Welfare

    Enforced

    Apr 2024 (cybersecurity notification)

    Legal framework

    Pharmaceuticals & Medical Devices Act + MHLW Notifications + IMDRF N60 alignment

    FDA package reuse

    ~70%

    Scope

    Programmed medical devices (PMD) and SaMD with network connectivity. Applies at marketing authorization (Shonin) and certification.

    Pre-market

    Cybersecurity documentation in STED, JIS T 81001-5-1 application, threat analysis, SBOM submission.

    Post-market

    Incident reporting to PMDA, lifetime support obligations, periodic safety updates.

    SBOM

    Required

    SBOM expected at submission since 2023 MHLW notification; format flexibility but machine-readable preferred.

    Vulnerability disclosure

    Required, IPA (Information-technology Promotion Agency) coordination.

    Penalty

    Approval suspension; recall orders; criminal penalties for misleading data.

    Unique requirements

    • 01Japanese-language documentation (STED)
    • 02Marketing Authorization Holder (MAH) must be Japan-based
    • 03JIS T 81001-5-1 (Japanese adoption of IEC 81001-5-1)

    Highlights

    • Closely tracks IMDRF N60
    • SBOM expected from 2024
    • Lifetime support clause

    Aligns with

    IMDRF N60 JIS T 81001-5-1 IEC 62443-4-1

    Timeline

    1. 2014

      PMSD Act revised

    2. Mar 2023

      MHLW cybersecurity notification issued

    3. Apr 2024

      Enforcement of updated requirements

    Key documents

    How to submit in Japan

    Playbook reviewed · 2026-07-16

    Submission route

    PMDA pre-market review under the PMD Act, with cybersecurity per MHLW Notification 0524-1 and JIS T 81001-5-1

    PMDA aligns with IMDRF principles and expects JIS T 81001-5-1 (the Japanese adoption of IEC 81001-5-1) as the reference lifecycle standard. Cybersecurity documentation must be submitted in Japanese, though English source documents are accepted with certified translation.

    Authority portal

    Step-by-step

    1. Step 01

      Appoint a Marketing Authorization Holder (MAH)

      Foreign manufacturers must appoint a D-MAH or use a local MAH; the MAH owns the PMDA relationship.

    2. Step 02

      Classify under the four-tier system

      Class II specified controlled, III, IV go through PMDA review; Class II general goes through Registered Certification Bodies.

    3. Step 03

      Prepare cybersecurity documentation

      Follow MHLW Notification 0524-1 structure: security risk analysis, security controls, verification, and lifecycle management per JIS T 81001-5-1.

    4. Step 04

      STED submission

      Use the IMDRF-based STED format; PMDA accepts English source files if a certified Japanese summary is included.

    Evidence checklist

    Item Level FDA equivalent Notes
    Security risk analysis (Japanese) Required Security risk assessment
    JIS T 81001-5-1 lifecycle evidence Required —
    SBOM Recommended — Increasingly requested in AI-based device reviews.
    MAH cybersecurity governance letter Required —

    Common PMDA rejections

    Documentation submitted only in English

    Common

    Fix · Provide certified Japanese translation for the security summary sections at minimum.

    Lifecycle evidence cites IEC 62443 without JIS T 81001-5-1 mapping

    Occasional

    Fix · Add an explicit mapping table to JIS T 81001-5-1 clauses.

    Typical timeline

    End-to-end window: 10-18 months for Class III/IV; 4-8 months for Class II via RCB.

    Phase 01

    MAH engagement + STED authoring

    3-6 months

    Phase 02

    PMDA review (standard)

    6-12 months

    Phase 03

    MHLW approval + shonin

    1-3 months

    PMDA head-to-head

    Related markets

    Frequently asked about Japan

    Is SBOM required for medical devices in Japan?

    Required. SBOM expected at submission since 2023 MHLW notification; format flexibility but machine-readable preferred.

    What does PMDA / MHLW require for pre-market cybersecurity?

    Cybersecurity documentation in STED, JIS T 81001-5-1 application, threat analysis, SBOM submission.

    What are the post-market cybersecurity obligations under PMDA / MHLW?

    Incident reporting to PMDA, lifetime support obligations, periodic safety updates.

    What is the penalty for non-compliance with PMDA / MHLW cybersecurity rules?

    Approval suspension; recall orders; criminal penalties for misleading data.

    How much of my FDA cybersecurity package is reusable in Japan?

    Roughly 70% - an editorial estimate based on overlapping evidence requirements (threat model, SBOM, security risk assessment, pen-test report).