---
title: "South Korea MFDS - Cybersecurity Submission Playbook"
description: "How to submit a medical device to MFDS in South Korea: step-by-step route, evidence checklist, common rejections, and typical review timeline. Compared with F"
lang: en
json-ld: |
  [
    {
      "@context": "https://schema.org",
      "@type": "WebSite",
      "name": "The Medical Device Cybersecurity Crosswalk",
      "alternateName": "MDC Crosswalk",
      "url": "https://mdccrosswalk.com/",
      "description": "Compare FDA, EU MDR, MHRA, PMDA, NMPA, TGA, MFDS and Health Canada medical device cybersecurity requirements across 29 jurisdictions."
    },
    {
      "@context": "https://schema.org",
      "@type": "Organization",
      "name": "MDC Crosswalk",
      "url": "https://mdccrosswalk.com/",
      "logo": "https://mdccrosswalk.com/favicon.png",
      "sameAs": [
        "https://bluegoatcyber.com"
      ],
      "description": "An editorial reference comparing global medical-device cybersecurity regulations. Maintained by Blue Goat Cyber."
    },
    {
      "@context": "https://schema.org",
      "@type": "Article",
      "headline": "South Korea - Cybersecurity Review Guideline for Medical Devices",
      "description": "How to submit a medical device to MFDS in South Korea: step-by-step route, evidence checklist, common rejections, and typical review timeline. Compared with F",
      "author": {
        "@type": "Organization",
        "name": "MDC Crosswalk"
      },
      "publisher": {
        "@type": "Organization",
        "name": "MDC Crosswalk"
      },
      "image": "https://mdccrosswalk.lovable.app/favicon.png",
      "datePublished": "DMPA in force Jan 24 2025; MFDS DMPA implementing regulations continued to build out through 2026 (notification procedure, classification and performance-certification). See MFDS DMPA hub for the current text.",
      "about": "Ministry of Food and Drug Safety",
      "dateModified": "2026-07-16",
      "mainEntityOfPage": "https://mdccrosswalk.lovable.app/standards/kr"
    },
    {
      "@context": "https://schema.org",
      "@type": "FAQPage",
      "mainEntity": [
        {
          "@type": "Question",
          "name": "Is SBOM required for medical devices in South Korea?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "Recommended. Aligns to IMDRF N60 expectations."
          }
        },
        {
          "@type": "Question",
          "name": "What does MFDS require for pre-market cybersecurity?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "Cybersecurity assessment report at submission, K-GMP integration."
          }
        },
        {
          "@type": "Question",
          "name": "What are the post-market cybersecurity obligations under MFDS?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "Periodic re-evaluation every 5 years, incident reporting."
          }
        },
        {
          "@type": "Question",
          "name": "What is the penalty for non-compliance with MFDS cybersecurity rules?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "Approval revocation, public recall orders."
          }
        },
        {
          "@type": "Question",
          "name": "How much of my FDA cybersecurity package is reusable in South Korea?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "Roughly 65% - an editorial estimate based on overlapping evidence requirements (threat model, SBOM, security risk assessment, pen-test report)."
          }
        },
        {
          "@type": "Question",
          "name": "Why do MFDS submissions get rejected for \"documentation not translated to korean\"?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "Provide full Korean translation for the security dossier before submission."
          }
        },
        {
          "@type": "Question",
          "name": "Why do MFDS submissions get rejected for \"no post-market monitoring plan for dmpa-scope devices\"?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "Add a plan covering vulnerability monitoring, patch cadence, and MFDS notification triggers."
          }
        }
      ]
    },
    {
      "@context": "https://schema.org",
      "@type": "HowTo",
      "name": "How to submit a medical device to MFDS",
      "description": "The Digital Medical Products Act created a dedicated pathway for software and AI devices with explicit cybersecurity and post-market monitoring obligations. MFDS aligns with IEC 81001-5-1 and expects a Korean-language dossier.",
      "totalTime": "10-18 months for Class III/IV; 6-10 months for Class II.",
      "step": [
        {
          "@type": "HowToStep",
          "position": 1,
          "name": "Appoint a Korean licence holder",
          "text": "Foreign manufacturers use a Korean Licence Holder (KLH) who owns the approval."
        },
        {
          "@type": "HowToStep",
          "position": 2,
          "name": "Determine review track",
          "text": "Digital medical products get a fast-track review if pre-consulted; standard track otherwise."
        },
        {
          "@type": "HowToStep",
          "position": 3,
          "name": "Prepare cybersecurity documentation (Korean)",
          "text": "Follow MFDS Notice 2022-30 structure; include SBOM and post-market monitoring plan."
        },
        {
          "@type": "HowToStep",
          "position": 4,
          "name": "GMP audit + technical review",
          "text": "MFDS GMP inspection precedes final approval for Class III/IV."
        }
      ]
    },
    {
      "@context": "https://schema.org",
      "@type": "BreadcrumbList",
      "itemListElement": [
        {
          "@type": "ListItem",
          "position": 1,
          "name": "Home",
          "item": "https://mdccrosswalk.lovable.app/"
        },
        {
          "@type": "ListItem",
          "position": 2,
          "name": "Standards"
        },
        {
          "@type": "ListItem",
          "position": 3,
          "name": "South Korea"
        }
      ]
    }
  ]
---

[

The Crosswalk



](/)

[Overview](/)[Playbook](/playbook)CompareReference

[New Per-page social previews and this changelog ](/changelog "Per-page social previews and this changelog") Search⌘K

1.  [Home ](/)
2.  Standards 
3.  South Korea 

MFDS

# ![Flag of South Korea](/flags/kr.svg)South Korea - MFDS 

Mandatory Last updated · DMPA in force Jan 24 2025; MFDS DMPA implementing regulations continued to build out through 2026 (notification procedure, classification and performance-certification). See MFDS DMPA hub for the current text. Verified · 2026-07-16 

Cybersecurity Review Guideline for Medical Devices

Share Copy link X LinkedIn Email

Sources verified · 2026-07-16

MFDS 2019 cybersecurity guidance re-verified; DMPA enforcement (Jan 24 2025) verified against Act No. 20139. Specific PM/Enforcement Decree amendment numbers softened to avoid asserting citations we haven't primary-source-verified against law.go.kr.

Authority

Ministry of Food and Drug Safety

Enforced

2019 (rev. 2023); Digital Medical Products Act (DMPA) enforced Jan 24 2025

Legal framework

Medical Devices Act + MFDS Cybersecurity Notification + Digital Medical Products Act (DMPA, Act No. 20139, enforced Jan 24 2025)

FDA package reuse

~65%

[Editorial estimate · how →](/methodology#fda-reuse)

## Scope

Medical devices with wired/wireless communication. AI/ML medical devices have additional addendum.

Pre-market

Cybersecurity assessment report at submission, K-GMP integration.

Post-market

Periodic re-evaluation every 5 years, incident reporting.

SBOM

Recommended 

Aligns to IMDRF N60 expectations.

Vulnerability disclosure

KISA (Korea Internet & Security Agency) coordination.

Penalty

Approval revocation, public recall orders.

## Unique requirements

-   01 K-GMP audit 
-   02 Korean Licence Holder (KLH) 
-   03 AI/ML addendum requires change control plan 

## Highlights

-   5-year periodic review 
-   K-GMP integration 
-   AI/ML specific addendum (2023) 

## Aligns with

IMDRF N60  K-GMP  ISO 13485 

## Timeline

1.  Nov 2019
    
    First cybersecurity guideline
    
2.  2023
    
    AI/ML addendum and revision
    
3.  Jan 24 2025
    
    Digital Medical Products Act (DMPA) enters into force; dedicated regulatory framework for digital medical products, with companion Electronic Intrusion Security Guidelines
    

## Key documents

[

MFDS Medical Devices (English)

https://www.mfds.go.kr/eng/brd/m\_40/list.do



](https://www.mfds.go.kr/eng/brd/m_40/list.do)[

MFDS Medical Device Information Portal (eMed)

https://emed.mfds.go.kr/



](https://emed.mfds.go.kr/)

## How to submit in South Korea

Playbook reviewed · 2026-07-16

Submission route

MFDS approval or notification under the Digital Medical Products Act (in force from Jan 2025), with cybersecurity per MFDS Notice 2022-30

The Digital Medical Products Act created a dedicated pathway for software and AI devices with explicit cybersecurity and post-market monitoring obligations. MFDS aligns with IEC 81001-5-1 and expects a Korean-language dossier.

[Authority portal](https://www.mfds.go.kr/eng/index.do)

### Step-by-step

1.  Step 01
    
    Appoint a Korean licence holder
    
    Foreign manufacturers use a Korean Licence Holder (KLH) who owns the approval.
    
2.  Step 02
    
    Determine review track
    
    Digital medical products get a fast-track review if pre-consulted; standard track otherwise.
    
3.  Step 03
    
    Prepare cybersecurity documentation (Korean)
    
    Follow MFDS Notice 2022-30 structure; include SBOM and post-market monitoring plan.
    
4.  Step 04
    
    GMP audit + technical review
    
    MFDS GMP inspection precedes final approval for Class III/IV.
    

### Evidence checklist

Item

Level

FDA equivalent

Notes

Cybersecurity dossier (Korean)

Required 

—

SBOM

Recommended 

—

Increasingly requested under Digital Medical Products Act reviews.

KLH agreement

Required 

—

Post-market cybersecurity monitoring plan

Required 

—

### Common MFDS rejections

Documentation not translated to Korean

Common 

Fix ·  Provide full Korean translation for the security dossier before submission.

No post-market monitoring plan for DMPA-scope devices

Common 

Fix ·  Add a plan covering vulnerability monitoring, patch cadence, and MFDS notification triggers.

### Typical timeline

End-to-end window: 10-18 months for Class III/IV; 6-10 months for Class II. 

Phase 01

KLH + dossier prep

3-6 months

Phase 02

MFDS technical review

6-12 months

Phase 03

GMP inspection + approval

2-4 months

[Previous ![Flag of Australia](/flags/au.svg)Australia ](/standards/au)[Next  ![Flag of Singapore](/flags/sg.svg)Singapore ](/standards/sg)

## MFDS head-to-head

[

Compare

![Flag of South Korea](/flags/kr.svg)MFDSvs ![Flag of United States](/flags/us.svg)FDA 524B

Open comparison ](/compare/fda-vs-mfds)

## Related markets

[![Flag of European Union](/flags/eu.svg)

European Union

~60% FDA reuse

](/standards/eu)[![Flag of Japan](/flags/jp.svg)

Japan

~70% FDA reuse

](/standards/jp)[![Flag of Brazil](/flags/br.svg)

Brazil

~60% FDA reuse

](/standards/br)[![Flag of Norway](/flags/no.svg)

Norway

~60% FDA reuse

](/standards/no)

## Frequently asked about South Korea

### Is SBOM required for medical devices in South Korea?

Recommended. Aligns to IMDRF N60 expectations.

### What does MFDS require for pre-market cybersecurity?

Cybersecurity assessment report at submission, K-GMP integration.

### What are the post-market cybersecurity obligations under MFDS?

Periodic re-evaluation every 5 years, incident reporting.

### What is the penalty for non-compliance with MFDS cybersecurity rules?

Approval revocation, public recall orders.

### How much of my FDA cybersecurity package is reusable in South Korea?

Roughly 65% - an editorial estimate based on overlapping evidence requirements (threat model, SBOM, security risk assessment, pen-test report).

Sponsored note · Blue Goat Cyber

Submitting to MFDS? Get a second pair of eyes before you file. Blue Goat Cyber has packaged cybersecurity evidence for South Korea alongside 37 other markets. We'll tell you what to keep, what to rework, and what's missing, in 30 minutes.  [Talk through your MFDS submission](https://go.bluegoatcyber.com/meetings/blue-goat-cyber/discovery-session)

The Crosswalk

An independent reference for global medical device cybersecurity standards. A field guide for MedTech innovators and RA/QA teams charting an international path.

Resource

-   [Comparison matrix](/compare)
-   [Global playbook](/playbook)
-   [Glossary](/glossary)
-   [FAQ](/faq)

Sponsored by

[Blue Goat Cyber ↗](https://bluegoatcyber.com)

Editorially independent. Sponsorship keeps it free.

© 2026 The Crosswalk. Not legal advice.

Validate every requirement against current regulator publications.