---
title: "Japan PMDA - Cybersecurity Submission Playbook"
description: "How to submit a medical device to PMDA / MHLW in Japan: step-by-step route, evidence checklist, common rejections, and typical review timeline. Compared with"
lang: en
json-ld: |
  [
    {
      "@context": "https://schema.org",
      "@type": "WebSite",
      "name": "The Medical Device Cybersecurity Crosswalk",
      "alternateName": "MDC Crosswalk",
      "url": "https://mdccrosswalk.com/",
      "description": "Compare FDA, EU MDR, MHRA, PMDA, NMPA, TGA, MFDS and Health Canada medical device cybersecurity requirements across 29 jurisdictions."
    },
    {
      "@context": "https://schema.org",
      "@type": "Organization",
      "name": "MDC Crosswalk",
      "url": "https://mdccrosswalk.com/",
      "logo": "https://mdccrosswalk.com/favicon.png",
      "sameAs": [
        "https://bluegoatcyber.com"
      ],
      "description": "An editorial reference comparing global medical-device cybersecurity regulations. Maintained by Blue Goat Cyber."
    },
    {
      "@context": "https://schema.org",
      "@type": "Article",
      "headline": "Japan - PMSD Act + MHLW Cybersecurity Notifications (2023–24)",
      "description": "How to submit a medical device to PMDA / MHLW in Japan: step-by-step route, evidence checklist, common rejections, and typical review timeline. Compared with ",
      "author": {
        "@type": "Organization",
        "name": "MDC Crosswalk"
      },
      "publisher": {
        "@type": "Organization",
        "name": "MDC Crosswalk"
      },
      "image": "https://mdccrosswalk.lovable.app/favicon.png",
      "datePublished": "Mar 2024",
      "about": "Pharmaceuticals and Medical Devices Agency / Ministry of Health, Labour and Welfare",
      "dateModified": "2026-07-16",
      "mainEntityOfPage": "https://mdccrosswalk.lovable.app/standards/jp"
    },
    {
      "@context": "https://schema.org",
      "@type": "FAQPage",
      "mainEntity": [
        {
          "@type": "Question",
          "name": "Is SBOM required for medical devices in Japan?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "Required. SBOM expected at submission since 2023 MHLW notification; format flexibility but machine-readable preferred."
          }
        },
        {
          "@type": "Question",
          "name": "What does PMDA / MHLW require for pre-market cybersecurity?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "Cybersecurity documentation in STED, JIS T 81001-5-1 application, threat analysis, SBOM submission."
          }
        },
        {
          "@type": "Question",
          "name": "What are the post-market cybersecurity obligations under PMDA / MHLW?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "Incident reporting to PMDA, lifetime support obligations, periodic safety updates."
          }
        },
        {
          "@type": "Question",
          "name": "What is the penalty for non-compliance with PMDA / MHLW cybersecurity rules?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "Approval suspension; recall orders; criminal penalties for misleading data."
          }
        },
        {
          "@type": "Question",
          "name": "How much of my FDA cybersecurity package is reusable in Japan?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "Roughly 70% - an editorial estimate based on overlapping evidence requirements (threat model, SBOM, security risk assessment, pen-test report)."
          }
        },
        {
          "@type": "Question",
          "name": "Why do PMDA submissions get rejected for \"documentation submitted only in english\"?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "Provide certified Japanese translation for the security summary sections at minimum."
          }
        },
        {
          "@type": "Question",
          "name": "Why do PMDA submissions get rejected for \"lifecycle evidence cites iec 62443 without jis t 81001-5-1 mapping\"?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "Add an explicit mapping table to JIS T 81001-5-1 clauses."
          }
        }
      ]
    },
    {
      "@context": "https://schema.org",
      "@type": "HowTo",
      "name": "How to submit a medical device to PMDA / MHLW",
      "description": "PMDA aligns with IMDRF principles and expects JIS T 81001-5-1 (the Japanese adoption of IEC 81001-5-1) as the reference lifecycle standard. Cybersecurity documentation must be submitted in Japanese, though English source documents are accepted with certified translation.",
      "totalTime": "10-18 months for Class III/IV; 4-8 months for Class II via RCB.",
      "step": [
        {
          "@type": "HowToStep",
          "position": 1,
          "name": "Appoint a Marketing Authorization Holder (MAH)",
          "text": "Foreign manufacturers must appoint a D-MAH or use a local MAH; the MAH owns the PMDA relationship."
        },
        {
          "@type": "HowToStep",
          "position": 2,
          "name": "Classify under the four-tier system",
          "text": "Class II specified controlled, III, IV go through PMDA review; Class II general goes through Registered Certification Bodies."
        },
        {
          "@type": "HowToStep",
          "position": 3,
          "name": "Prepare cybersecurity documentation",
          "text": "Follow MHLW Notification 0524-1 structure: security risk analysis, security controls, verification, and lifecycle management per JIS T 81001-5-1."
        },
        {
          "@type": "HowToStep",
          "position": 4,
          "name": "STED submission",
          "text": "Use the IMDRF-based STED format; PMDA accepts English source files if a certified Japanese summary is included."
        }
      ]
    },
    {
      "@context": "https://schema.org",
      "@type": "BreadcrumbList",
      "itemListElement": [
        {
          "@type": "ListItem",
          "position": 1,
          "name": "Home",
          "item": "https://mdccrosswalk.lovable.app/"
        },
        {
          "@type": "ListItem",
          "position": 2,
          "name": "Standards"
        },
        {
          "@type": "ListItem",
          "position": 3,
          "name": "Japan"
        }
      ]
    }
  ]
---

[

The Crosswalk



](/)

[Overview](/)[Playbook](/playbook)CompareReference

[New Per-page social previews and this changelog ](/changelog "Per-page social previews and this changelog") Search⌘K

1.  [Home ](/)
2.  Standards 
3.  Japan 

PMDA / MHLW

# ![Flag of Japan](/flags/jp.svg)Japan - PMDA / MHLW 

Mandatory Last updated · Mar 2024 Verified · 2026-07-16 

PMSD Act + MHLW Cybersecurity Notifications (2023–24)

Share Copy link X LinkedIn Email

Sources verified · 2026-07-16

Cross-checked against MHLW 2023 cybersecurity notification and JIS T 81001-5-1.

Authority

Pharmaceuticals and Medical Devices Agency / Ministry of Health, Labour and Welfare

Enforced

Apr 2024 (cybersecurity notification)

Legal framework

Pharmaceuticals & Medical Devices Act + MHLW Notifications + IMDRF N60 alignment

FDA package reuse

~70%

[Editorial estimate · how →](/methodology#fda-reuse)

## Scope

Programmed medical devices (PMD) and SaMD with network connectivity. Applies at marketing authorization (Shonin) and certification.

Pre-market

Cybersecurity documentation in STED, JIS T 81001-5-1 application, threat analysis, SBOM submission.

Post-market

Incident reporting to PMDA, lifetime support obligations, periodic safety updates.

SBOM

Required 

SBOM expected at submission since 2023 MHLW notification; format flexibility but machine-readable preferred.

Vulnerability disclosure

Required, IPA (Information-technology Promotion Agency) coordination.

Penalty

Approval suspension; recall orders; criminal penalties for misleading data.

## Unique requirements

-   01 Japanese-language documentation (STED) 
-   02 Marketing Authorization Holder (MAH) must be Japan-based 
-   03 JIS T 81001-5-1 (Japanese adoption of IEC 81001-5-1) 

## Highlights

-   Closely tracks IMDRF N60 
-   SBOM expected from 2024 
-   Lifetime support clause 

## Aligns with

IMDRF N60  JIS T 81001-5-1  IEC 62443-4-1 

## Timeline

1.  2014
    
    PMSD Act revised
    
2.  Mar 2023
    
    MHLW cybersecurity notification issued
    
3.  Apr 2024
    
    Enforcement of updated requirements
    

## Key documents

[

PMDA Medical Device Cybersecurity Page

https://www.pmda.go.jp/english/review-services/reviews/0002.html



](https://www.pmda.go.jp/english/review-services/reviews/0002.html)[

MHLW Cybersecurity Notification (2023)

https://www.mhlw.go.jp/



](https://www.mhlw.go.jp/)[

JIS T 81001-5-1

https://www.jisc.go.jp/



](https://www.jisc.go.jp/)

## How to submit in Japan

Playbook reviewed · 2026-07-16

Submission route

PMDA pre-market review under the PMD Act, with cybersecurity per MHLW Notification 0524-1 and JIS T 81001-5-1

PMDA aligns with IMDRF principles and expects JIS T 81001-5-1 (the Japanese adoption of IEC 81001-5-1) as the reference lifecycle standard. Cybersecurity documentation must be submitted in Japanese, though English source documents are accepted with certified translation.

[Authority portal](https://www.pmda.go.jp/english/)

### Step-by-step

1.  Step 01
    
    Appoint a Marketing Authorization Holder (MAH)
    
    Foreign manufacturers must appoint a D-MAH or use a local MAH; the MAH owns the PMDA relationship.
    
2.  Step 02
    
    Classify under the four-tier system
    
    Class II specified controlled, III, IV go through PMDA review; Class II general goes through Registered Certification Bodies.
    
3.  Step 03
    
    Prepare cybersecurity documentation
    
    Follow MHLW Notification 0524-1 structure: security risk analysis, security controls, verification, and lifecycle management per JIS T 81001-5-1.
    
4.  Step 04
    
    STED submission
    
    Use the IMDRF-based STED format; PMDA accepts English source files if a certified Japanese summary is included.
    

### Evidence checklist

Item

Level

FDA equivalent

Notes

Security risk analysis (Japanese)

Required 

Security risk assessment

JIS T 81001-5-1 lifecycle evidence

Required 

—

SBOM

Recommended 

—

Increasingly requested in AI-based device reviews.

MAH cybersecurity governance letter

Required 

—

### Common PMDA rejections

Documentation submitted only in English

Common 

Fix ·  Provide certified Japanese translation for the security summary sections at minimum.

Lifecycle evidence cites IEC 62443 without JIS T 81001-5-1 mapping

Occasional 

Fix ·  Add an explicit mapping table to JIS T 81001-5-1 clauses.

### Typical timeline

End-to-end window: 10-18 months for Class III/IV; 4-8 months for Class II via RCB. 

Phase 01

MAH engagement + STED authoring

3-6 months

Phase 02

PMDA review (standard)

6-12 months

Phase 03

MHLW approval + shonin

1-3 months

[Previous ![Flag of United Kingdom](/flags/gb.svg)United Kingdom ](/standards/uk)[Next  ![Flag of China](/flags/cn.svg)China ](/standards/cn)

## PMDA head-to-head

[

Compare

![Flag of Japan](/flags/jp.svg)PMDAvs ![Flag of United States](/flags/us.svg)FDA 524B

Open comparison ](/compare/fda-vs-pmda)[

Compare

![Flag of Japan](/flags/jp.svg)PMDAvs ![Flag of European Union](/flags/eu.svg)EU MDR

Open comparison ](/compare/eu-mdr-vs-pmda)

## Related markets

[![Flag of Vietnam](/flags/vn.svg)

Vietnam

~70% FDA reuse

](/standards/vn)[![Flag of Ukraine](/flags/ua.svg)

Ukraine

~70% FDA reuse

](/standards/ua)[![Flag of South Korea](/flags/kr.svg)

South Korea

~65% FDA reuse

](/standards/kr)[![Flag of European Union](/flags/eu.svg)

European Union

~60% FDA reuse

](/standards/eu)

## Frequently asked about Japan

### Is SBOM required for medical devices in Japan?

Required. SBOM expected at submission since 2023 MHLW notification; format flexibility but machine-readable preferred.

### What does PMDA / MHLW require for pre-market cybersecurity?

Cybersecurity documentation in STED, JIS T 81001-5-1 application, threat analysis, SBOM submission.

### What are the post-market cybersecurity obligations under PMDA / MHLW?

Incident reporting to PMDA, lifetime support obligations, periodic safety updates.

### What is the penalty for non-compliance with PMDA / MHLW cybersecurity rules?

Approval suspension; recall orders; criminal penalties for misleading data.

### How much of my FDA cybersecurity package is reusable in Japan?

Roughly 70% - an editorial estimate based on overlapping evidence requirements (threat model, SBOM, security risk assessment, pen-test report).

Sponsored note · Blue Goat Cyber

Submitting to PMDA / MHLW? Get a second pair of eyes before you file. Blue Goat Cyber has packaged cybersecurity evidence for Japan alongside 37 other markets. We'll tell you what to keep, what to rework, and what's missing, in 30 minutes.  [Talk through your PMDA submission](https://go.bluegoatcyber.com/meetings/blue-goat-cyber/discovery-session)

The Crosswalk

An independent reference for global medical device cybersecurity standards. A field guide for MedTech innovators and RA/QA teams charting an international path.

Resource

-   [Comparison matrix](/compare)
-   [Global playbook](/playbook)
-   [Glossary](/glossary)
-   [FAQ](/faq)

Sponsored by

[Blue Goat Cyber ↗](https://bluegoatcyber.com)

Editorially independent. Sponsorship keeps it free.

© 2026 The Crosswalk. Not legal advice.

Validate every requirement against current regulator publications.