The Crosswalk

    NewPer-page social previews and this changelog

    KDA

    Flag of KuwaitKuwait - KDA

    GuidanceLast updated · 2024Verified · 2026-07-16

    MoH Medical Device Registration with GHC Reference Route

    Share

    Authority

    Kuwait Drug and Food Control / Ministry of Health (KDFC)

    Enforced

    2017 (KDFC medical device circulars)

    Legal framework

    Ministry of Health KDFC medical device registration circulars; Gulf Health Council (GHC) Centralized Registration Procedure available as a regional pathway across GCC. Cyber overlay relies on Kuwait Data Privacy Protection Regulation (CITRA, 2021) and CITRA's national cybersecurity strategy.

    FDA package reuse

    ~80%

    Scope

    All medical devices placed on the Kuwaiti market. GCC manufacturers may use the centralised GHC route covering KW, SA, AE, BH, OM, QA in a single dossier.

    Pre-market

    Reliance-based on reference-country approvals (FDA, CE, Health Canada, TGA, PMDA, MHRA). No standalone medical-device cybersecurity guideline; connected-device posture inherited from reference-country evidence.

    Post-market

    Vigilance reporting to KDFC; CITRA handles ICT-incident coordination for connected devices in healthcare networks.

    SBOM

    Not specified

    Not required by KDFC today; CE/FDA SBOMs accepted as supporting evidence.

    Vulnerability disclosure

    CITRA National CERT for ICT incidents; no medical-device-specific CVD requirement.

    Penalty

    Registration cancellation, market withdrawal, fines under MoH and CITRA orders.

    Unique requirements

    • 01Kuwaiti authorised local agent
    • 02Arabic-language IFU and labelling
    • 03GHC route subject to per-country acceptance

    Highlights

    • GHC central route covers 6 GCC markets in one dossier
    • Reference-country reliance is the dominant route
    • CITRA data-protection overlay for connected devices

    Aligns with

    GHC Centralized Registration Procedure ISO 13485 IMDRF N60 (via reference countries)

    Timeline

    1. 2017

      KDFC medical device registration circulars

    2. 2021

      CITRA Data Privacy Protection Regulation in force

    3. 2024

      GHC centralised registration scope expanded

    Key documents

    How to submit in Kuwait

    Playbook reviewed · 2026-07-16

    Submission route

    MOH registration under Kuwaiti Medical Device Regulations

    Kuwait's MOH accepts GHTF approvals. Cybersecurity documentation is not separately mandated.

    Authority portal

    Step-by-step

    1. Step 01

      Appoint local representation

      Most jurisdictions require a locally-established entity to hold the registration or act as authorised representative before submission.

    2. Step 02

      Reuse FDA or CE package as baseline

      Adapt the cybersecurity subsection you already prepared for FDA or CE; regulators here typically accept the structure and ask for local labeling additions.

    3. Step 03

      Translate and localise

      Local-language technical summary and labeling are usually mandatory; certified translation is safest.

    4. Step 04

      Submit + track queries

      Respond to clarification rounds promptly; each unanswered question can add 30-90 days to the clock.

    Evidence checklist

    Item Level FDA equivalent Notes
    Cybersecurity documentation (baseline FDA or CE) Required SPDF
    Local authorised representative agreement Required
    Local-language labeling and IFU Required
    SBOM Recommended Not mandatory but reduces clarification rounds.

    Common KDFC rejections

    No local agent with valid MOH licence

    Common

    Fix · Appoint a licensed local agent.

    Typical timeline

    End-to-end window: 3-6 months

    Phase 01

    Local rep + dossier prep

    2-4 months

    Phase 02

    Regulatory review

    3-6 months

    Phase 03

    Approval + market entry

    1-3 months

    Related markets

    Frequently asked about Kuwait

    Is SBOM required for medical devices in Kuwait?

    Not specified. Not required by KDFC today; CE/FDA SBOMs accepted as supporting evidence.

    What does KDA require for pre-market cybersecurity?

    Reliance-based on reference-country approvals (FDA, CE, Health Canada, TGA, PMDA, MHRA). No standalone medical-device cybersecurity guideline; connected-device posture inherited from reference-country evidence.

    What are the post-market cybersecurity obligations under KDA?

    Vigilance reporting to KDFC; CITRA handles ICT-incident coordination for connected devices in healthcare networks.

    What is the penalty for non-compliance with KDA cybersecurity rules?

    Registration cancellation, market withdrawal, fines under MoH and CITRA orders.

    How much of my FDA cybersecurity package is reusable in Kuwait?

    Roughly 80% - an editorial estimate based on overlapping evidence requirements (threat model, SBOM, security risk assessment, pen-test report).