The Crosswalk

    NewPer-page social previews and this changelog

    MFDS

    Flag of South KoreaSouth Korea - MFDS

    MandatoryLast updated · DMPA in force Jan 24 2025; MFDS DMPA implementing regulations continued to build out through 2026 (notification procedure, classification and performance-certification). See MFDS DMPA hub for the current text.Verified · 2026-07-16

    Cybersecurity Review Guideline for Medical Devices

    Share

    Authority

    Ministry of Food and Drug Safety

    Enforced

    2019 (rev. 2023); Digital Medical Products Act (DMPA) enforced Jan 24 2025

    Legal framework

    Medical Devices Act + MFDS Cybersecurity Notification + Digital Medical Products Act (DMPA, Act No. 20139, enforced Jan 24 2025)

    FDA package reuse

    ~65%

    Scope

    Medical devices with wired/wireless communication. AI/ML medical devices have additional addendum.

    Pre-market

    Cybersecurity assessment report at submission, K-GMP integration.

    Post-market

    Periodic re-evaluation every 5 years, incident reporting.

    SBOM

    Recommended

    Aligns to IMDRF N60 expectations.

    Vulnerability disclosure

    KISA (Korea Internet & Security Agency) coordination.

    Penalty

    Approval revocation, public recall orders.

    Unique requirements

    • 01K-GMP audit
    • 02Korean Licence Holder (KLH)
    • 03AI/ML addendum requires change control plan

    Highlights

    • 5-year periodic review
    • K-GMP integration
    • AI/ML specific addendum (2023)

    Aligns with

    IMDRF N60 K-GMP ISO 13485

    Timeline

    1. Nov 2019

      First cybersecurity guideline

    2. 2023

      AI/ML addendum and revision

    3. Jan 24 2025

      Digital Medical Products Act (DMPA) enters into force; dedicated regulatory framework for digital medical products, with companion Electronic Intrusion Security Guidelines

    Key documents

    How to submit in South Korea

    Playbook reviewed · 2026-07-16

    Submission route

    MFDS approval or notification under the Digital Medical Products Act (in force from Jan 2025), with cybersecurity per MFDS Notice 2022-30

    The Digital Medical Products Act created a dedicated pathway for software and AI devices with explicit cybersecurity and post-market monitoring obligations. MFDS aligns with IEC 81001-5-1 and expects a Korean-language dossier.

    Authority portal

    Step-by-step

    1. Step 01

      Appoint a Korean licence holder

      Foreign manufacturers use a Korean Licence Holder (KLH) who owns the approval.

    2. Step 02

      Determine review track

      Digital medical products get a fast-track review if pre-consulted; standard track otherwise.

    3. Step 03

      Prepare cybersecurity documentation (Korean)

      Follow MFDS Notice 2022-30 structure; include SBOM and post-market monitoring plan.

    4. Step 04

      GMP audit + technical review

      MFDS GMP inspection precedes final approval for Class III/IV.

    Evidence checklist

    Item Level FDA equivalent Notes
    Cybersecurity dossier (Korean) Required
    SBOM Recommended Increasingly requested under Digital Medical Products Act reviews.
    KLH agreement Required
    Post-market cybersecurity monitoring plan Required

    Common MFDS rejections

    Documentation not translated to Korean

    Common

    Fix · Provide full Korean translation for the security dossier before submission.

    No post-market monitoring plan for DMPA-scope devices

    Common

    Fix · Add a plan covering vulnerability monitoring, patch cadence, and MFDS notification triggers.

    Typical timeline

    End-to-end window: 10-18 months for Class III/IV; 6-10 months for Class II.

    Phase 01

    KLH + dossier prep

    3-6 months

    Phase 02

    MFDS technical review

    6-12 months

    Phase 03

    GMP inspection + approval

    2-4 months

    MFDS head-to-head

    Related markets

    Frequently asked about South Korea

    Is SBOM required for medical devices in South Korea?

    Recommended. Aligns to IMDRF N60 expectations.

    What does MFDS require for pre-market cybersecurity?

    Cybersecurity assessment report at submission, K-GMP integration.

    What are the post-market cybersecurity obligations under MFDS?

    Periodic re-evaluation every 5 years, incident reporting.

    What is the penalty for non-compliance with MFDS cybersecurity rules?

    Approval revocation, public recall orders.

    How much of my FDA cybersecurity package is reusable in South Korea?

    Roughly 65% - an editorial estimate based on overlapping evidence requirements (threat model, SBOM, security risk assessment, pen-test report).