The Crosswalk

    NewPer-page social previews and this changelog

    NCEMP

    Flag of KazakhstanKazakhstan - NCEMP

    MandatoryLast updated · 2024Verified · 2026-07-16

    EAEU Medical Device Rules (Decision 46) - Kazakhstan implementation

    Share

    Authority

    National Center for Expertise of Medicines and Medical Products

    Enforced

    2016 (EAEU Decision 46)

    Legal framework

    Eurasian Economic Union (EAEU) Medical Device Rules adopted by Decision 46 of the EEC Council, implemented in Kazakhstan via the Code on People's Health and NCEMP procedural rules.

    FDA package reuse

    ~45%

    Scope

    All medical devices placed on the Kazakh market. EAEU registration grants access across RU, BY, AM, KG, KZ. Software-as-a-medical-device follows EAEU SaMD guidelines.

    Pre-market

    Common Technical Document-style dossier including QMS (ISO 13485), risk management, clinical evaluation, and software lifecycle (IEC 62304). Cybersecurity controls evaluated implicitly under software safety; explicit cyber expectations rely on Law on Personal Data and State Technical Service baselines.

    Post-market

    EAEU vigilance reporting via NCEMP; serious incidents within 15 working days. Cross-border data flows constrained by Law on Personal Data.

    SBOM

    Not specified

    Not addressed in EAEU rules today; CycloneDX accepted as supporting evidence on a voluntary basis.

    Vulnerability disclosure

    No medical-device-specific CVD regime; State Technical Service (STS) coordinates ICT incidents in healthcare.

    Penalty

    Registration suspension, removal from EAEU Unified Register, administrative fines under the Code on Administrative Offences.

    Unique requirements

    • 01EAEU dossier format (CTD-style)
    • 02Local authorised representative in Kazakhstan
    • 03Russian-language labelling and IFU

    Highlights

    • EAEU mutual recognition across 5 member states
    • ISO 13485 QMS expectation
    • No statutory medical-device cyber rule yet

    Aligns with

    EAEU SaMD guidance ISO 13485 IEC 62304 ISO 14971

    Timeline

    1. May 2017

      EAEU Decision 46 takes effect

    2. 2021

      EAEU SaMD guidance issued

    3. 2024

      NCEMP digital dossier portal expanded

    Key documents

    How to submit in Kazakhstan

    Playbook reviewed · 2026-07-16

    Submission route

    Ministry of Health registration under Eurasian Economic Union rules

    Kazakhstan operates a dual national / EAEU registration path. Cybersecurity documentation is not separately mandated but recommended for connected devices.

    Authority portal

    Step-by-step

    1. Step 01

      Appoint local representation

      Most jurisdictions require a locally-established entity to hold the registration or act as authorised representative before submission.

    2. Step 02

      Reuse FDA or CE package as baseline

      Adapt the cybersecurity subsection you already prepared for FDA or CE; regulators here typically accept the structure and ask for local labeling additions.

    3. Step 03

      Translate and localise

      Local-language technical summary and labeling are usually mandatory; certified translation is safest.

    4. Step 04

      Submit + track queries

      Respond to clarification rounds promptly; each unanswered question can add 30-90 days to the clock.

    Evidence checklist

    Item Level FDA equivalent Notes
    Cybersecurity documentation (baseline FDA or CE) Required SPDF
    Local authorised representative agreement Required
    Local-language labeling and IFU Required
    SBOM Recommended Not mandatory but reduces clarification rounds.

    Common NCEMP rejections

    EAEU dossier requirements not met

    Common

    Fix · Use the EAEU technical file structure to future-proof the submission.

    Typical timeline

    End-to-end window: 6-12 months

    Phase 01

    Local rep + dossier prep

    2-4 months

    Phase 02

    Regulatory review

    6-12 months

    Phase 03

    Approval + market entry

    1-3 months

    Related markets

    Frequently asked about Kazakhstan

    Is SBOM required for medical devices in Kazakhstan?

    Not specified. Not addressed in EAEU rules today; CycloneDX accepted as supporting evidence on a voluntary basis.

    What does NCEMP require for pre-market cybersecurity?

    Common Technical Document-style dossier including QMS (ISO 13485), risk management, clinical evaluation, and software lifecycle (IEC 62304). Cybersecurity controls evaluated implicitly under software safety; explicit cyber expectations rely on Law on Personal Data and State Technical Service baselines.

    What are the post-market cybersecurity obligations under NCEMP?

    EAEU vigilance reporting via NCEMP; serious incidents within 15 working days. Cross-border data flows constrained by Law on Personal Data.

    What is the penalty for non-compliance with NCEMP cybersecurity rules?

    Registration suspension, removal from EAEU Unified Register, administrative fines under the Code on Administrative Offences.

    How much of my FDA cybersecurity package is reusable in Kazakhstan?

    Roughly 45% - an editorial estimate based on overlapping evidence requirements (threat model, SBOM, security risk assessment, pen-test report).