MFDS
South Korea - MFDS
Cybersecurity Review Guideline for Medical Devices
Authority
Ministry of Food and Drug Safety
Enforced
2019 (rev. 2023); Digital Medical Products Act (DMPA) enforced Jan 24 2025
Legal framework
Medical Devices Act + MFDS Cybersecurity Notification + Digital Medical Products Act (DMPA, Act No. 20139, enforced Jan 24 2025)
Scope
Medical devices with wired/wireless communication. AI/ML medical devices have additional addendum.
Pre-market
Cybersecurity assessment report at submission, K-GMP integration.
Post-market
Periodic re-evaluation every 5 years, incident reporting.
SBOM
RecommendedAligns to IMDRF N60 expectations.
Vulnerability disclosure
KISA (Korea Internet & Security Agency) coordination.
Penalty
Approval revocation, public recall orders.
Unique requirements
- 01K-GMP audit
- 02Korean Licence Holder (KLH)
- 03AI/ML addendum requires change control plan
Highlights
- 5-year periodic review
- K-GMP integration
- AI/ML specific addendum (2023)
Aligns with
Timeline
-
Nov 2019
First cybersecurity guideline
-
2023
AI/ML addendum and revision
-
Jan 24 2025
Digital Medical Products Act (DMPA) enters into force; dedicated regulatory framework for digital medical products, with companion Electronic Intrusion Security Guidelines
Key documents
How to submit in South Korea
Playbook reviewed · 2026-07-16
Submission route
MFDS approval or notification under the Digital Medical Products Act (in force from Jan 2025), with cybersecurity per MFDS Notice 2022-30
The Digital Medical Products Act created a dedicated pathway for software and AI devices with explicit cybersecurity and post-market monitoring obligations. MFDS aligns with IEC 81001-5-1 and expects a Korean-language dossier.
Authority portalStep-by-step
-
Step 01
Appoint a Korean licence holder
Foreign manufacturers use a Korean Licence Holder (KLH) who owns the approval.
-
Step 02
Determine review track
Digital medical products get a fast-track review if pre-consulted; standard track otherwise.
-
Step 03
Prepare cybersecurity documentation (Korean)
Follow MFDS Notice 2022-30 structure; include SBOM and post-market monitoring plan.
-
Step 04
GMP audit + technical review
MFDS GMP inspection precedes final approval for Class III/IV.
Evidence checklist
| Item | Level | FDA equivalent | Notes |
|---|---|---|---|
| Cybersecurity dossier (Korean) | Required | — | |
| SBOM | Recommended | — | Increasingly requested under Digital Medical Products Act reviews. |
| KLH agreement | Required | — | |
| Post-market cybersecurity monitoring plan | Required | — |
Common MFDS rejections
Documentation not translated to Korean
CommonFix · Provide full Korean translation for the security dossier before submission.
No post-market monitoring plan for DMPA-scope devices
CommonFix · Add a plan covering vulnerability monitoring, patch cadence, and MFDS notification triggers.
Typical timeline
End-to-end window: 10-18 months for Class III/IV; 6-10 months for Class II.
Phase 01
KLH + dossier prep
3-6 months
Phase 02
MFDS technical review
6-12 months
Phase 03
GMP inspection + approval
2-4 months
MFDS head-to-head
Related markets
Frequently asked about South Korea
Is SBOM required for medical devices in South Korea?
Recommended. Aligns to IMDRF N60 expectations.
What does MFDS require for pre-market cybersecurity?
Cybersecurity assessment report at submission, K-GMP integration.
What are the post-market cybersecurity obligations under MFDS?
Periodic re-evaluation every 5 years, incident reporting.
What is the penalty for non-compliance with MFDS cybersecurity rules?
Approval revocation, public recall orders.
How much of my FDA cybersecurity package is reusable in South Korea?
Roughly 65% - an editorial estimate based on overlapping evidence requirements (threat model, SBOM, security risk assessment, pen-test report).