PMDA / MHLW
Japan - PMDA / MHLW
PMSD Act + MHLW Cybersecurity Notifications (2023–24)
Authority
Pharmaceuticals and Medical Devices Agency / Ministry of Health, Labour and Welfare
Enforced
Apr 2024 (cybersecurity notification)
Legal framework
Pharmaceuticals & Medical Devices Act + MHLW Notifications + IMDRF N60 alignment
Scope
Programmed medical devices (PMD) and SaMD with network connectivity. Applies at marketing authorization (Shonin) and certification.
Pre-market
Cybersecurity documentation in STED, JIS T 81001-5-1 application, threat analysis, SBOM submission.
Post-market
Incident reporting to PMDA, lifetime support obligations, periodic safety updates.
SBOM
RequiredSBOM expected at submission since 2023 MHLW notification; format flexibility but machine-readable preferred.
Vulnerability disclosure
Required, IPA (Information-technology Promotion Agency) coordination.
Penalty
Approval suspension; recall orders; criminal penalties for misleading data.
Unique requirements
- 01Japanese-language documentation (STED)
- 02Marketing Authorization Holder (MAH) must be Japan-based
- 03JIS T 81001-5-1 (Japanese adoption of IEC 81001-5-1)
Highlights
- Closely tracks IMDRF N60
- SBOM expected from 2024
- Lifetime support clause
Aligns with
Timeline
-
2014
PMSD Act revised
-
Mar 2023
MHLW cybersecurity notification issued
-
Apr 2024
Enforcement of updated requirements
Key documents
How to submit in Japan
Playbook reviewed · 2026-07-16
Submission route
PMDA pre-market review under the PMD Act, with cybersecurity per MHLW Notification 0524-1 and JIS T 81001-5-1
PMDA aligns with IMDRF principles and expects JIS T 81001-5-1 (the Japanese adoption of IEC 81001-5-1) as the reference lifecycle standard. Cybersecurity documentation must be submitted in Japanese, though English source documents are accepted with certified translation.
Authority portalStep-by-step
-
Step 01
Appoint a Marketing Authorization Holder (MAH)
Foreign manufacturers must appoint a D-MAH or use a local MAH; the MAH owns the PMDA relationship.
-
Step 02
Classify under the four-tier system
Class II specified controlled, III, IV go through PMDA review; Class II general goes through Registered Certification Bodies.
-
Step 03
Prepare cybersecurity documentation
Follow MHLW Notification 0524-1 structure: security risk analysis, security controls, verification, and lifecycle management per JIS T 81001-5-1.
-
Step 04
STED submission
Use the IMDRF-based STED format; PMDA accepts English source files if a certified Japanese summary is included.
Evidence checklist
| Item | Level | FDA equivalent | Notes |
|---|---|---|---|
| Security risk analysis (Japanese) | Required | Security risk assessment | |
| JIS T 81001-5-1 lifecycle evidence | Required | — | |
| SBOM | Recommended | — | Increasingly requested in AI-based device reviews. |
| MAH cybersecurity governance letter | Required | — |
Common PMDA rejections
Documentation submitted only in English
CommonFix · Provide certified Japanese translation for the security summary sections at minimum.
Lifecycle evidence cites IEC 62443 without JIS T 81001-5-1 mapping
OccasionalFix · Add an explicit mapping table to JIS T 81001-5-1 clauses.
Typical timeline
End-to-end window: 10-18 months for Class III/IV; 4-8 months for Class II via RCB.
Phase 01
MAH engagement + STED authoring
3-6 months
Phase 02
PMDA review (standard)
6-12 months
Phase 03
MHLW approval + shonin
1-3 months
PMDA head-to-head
Related markets
Frequently asked about Japan
Is SBOM required for medical devices in Japan?
Required. SBOM expected at submission since 2023 MHLW notification; format flexibility but machine-readable preferred.
What does PMDA / MHLW require for pre-market cybersecurity?
Cybersecurity documentation in STED, JIS T 81001-5-1 application, threat analysis, SBOM submission.
What are the post-market cybersecurity obligations under PMDA / MHLW?
Incident reporting to PMDA, lifetime support obligations, periodic safety updates.
What is the penalty for non-compliance with PMDA / MHLW cybersecurity rules?
Approval suspension; recall orders; criminal penalties for misleading data.
How much of my FDA cybersecurity package is reusable in Japan?
Roughly 70% - an editorial estimate based on overlapping evidence requirements (threat model, SBOM, security risk assessment, pen-test report).