---
title: "Kazakhstan NCEMP - Cybersecurity Submission Playbook"
description: "How to submit a medical device to NCEMP in Kazakhstan: step-by-step route, evidence checklist, common rejections, and typical review timeline. Compared with F"
lang: en
json-ld: |
  [
    {
      "@context": "https://schema.org",
      "@type": "WebSite",
      "name": "The Medical Device Cybersecurity Crosswalk",
      "alternateName": "MDC Crosswalk",
      "url": "https://mdccrosswalk.com/",
      "description": "Compare FDA, EU MDR, MHRA, PMDA, NMPA, TGA, MFDS and Health Canada medical device cybersecurity requirements across 29 jurisdictions."
    },
    {
      "@context": "https://schema.org",
      "@type": "Organization",
      "name": "MDC Crosswalk",
      "url": "https://mdccrosswalk.com/",
      "logo": "https://mdccrosswalk.com/favicon.png",
      "sameAs": [
        "https://bluegoatcyber.com"
      ],
      "description": "An editorial reference comparing global medical-device cybersecurity regulations. Maintained by Blue Goat Cyber."
    },
    {
      "@context": "https://schema.org",
      "@type": "Article",
      "headline": "Kazakhstan - EAEU Medical Device Rules (Decision 46) - Kazakhstan implementation",
      "description": "How to submit a medical device to NCEMP in Kazakhstan: step-by-step route, evidence checklist, common rejections, and typical review timeline. Compared with F",
      "author": {
        "@type": "Organization",
        "name": "MDC Crosswalk"
      },
      "publisher": {
        "@type": "Organization",
        "name": "MDC Crosswalk"
      },
      "image": "https://mdccrosswalk.lovable.app/favicon.png",
      "datePublished": "2024",
      "about": "National Center for Expertise of Medicines and Medical Products",
      "dateModified": "2026-07-16",
      "mainEntityOfPage": "https://mdccrosswalk.lovable.app/standards/kz"
    },
    {
      "@context": "https://schema.org",
      "@type": "FAQPage",
      "mainEntity": [
        {
          "@type": "Question",
          "name": "Is SBOM required for medical devices in Kazakhstan?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "Not specified. Not addressed in EAEU rules today; CycloneDX accepted as supporting evidence on a voluntary basis."
          }
        },
        {
          "@type": "Question",
          "name": "What does NCEMP require for pre-market cybersecurity?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "Common Technical Document-style dossier including QMS (ISO 13485), risk management, clinical evaluation, and software lifecycle (IEC 62304). Cybersecurity controls evaluated implicitly under software safety; explicit cyber expectations rely on Law on Personal Data and State Technical Service baselines."
          }
        },
        {
          "@type": "Question",
          "name": "What are the post-market cybersecurity obligations under NCEMP?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "EAEU vigilance reporting via NCEMP; serious incidents within 15 working days. Cross-border data flows constrained by Law on Personal Data."
          }
        },
        {
          "@type": "Question",
          "name": "What is the penalty for non-compliance with NCEMP cybersecurity rules?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "Registration suspension, removal from EAEU Unified Register, administrative fines under the Code on Administrative Offences."
          }
        },
        {
          "@type": "Question",
          "name": "How much of my FDA cybersecurity package is reusable in Kazakhstan?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "Roughly 45% - an editorial estimate based on overlapping evidence requirements (threat model, SBOM, security risk assessment, pen-test report)."
          }
        },
        {
          "@type": "Question",
          "name": "Why do NCEMP submissions get rejected for \"eaeu dossier requirements not met\"?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "Use the EAEU technical file structure to future-proof the submission."
          }
        }
      ]
    },
    {
      "@context": "https://schema.org",
      "@type": "HowTo",
      "name": "How to submit a medical device to NCEMP",
      "description": "Kazakhstan operates a dual national / EAEU registration path. Cybersecurity documentation is not separately mandated but recommended for connected devices.",
      "totalTime": "6-12 months",
      "step": [
        {
          "@type": "HowToStep",
          "position": 1,
          "name": "Appoint local representation",
          "text": "Most jurisdictions require a locally-established entity to hold the registration or act as authorised representative before submission."
        },
        {
          "@type": "HowToStep",
          "position": 2,
          "name": "Reuse FDA or CE package as baseline",
          "text": "Adapt the cybersecurity subsection you already prepared for FDA or CE; regulators here typically accept the structure and ask for local labeling additions."
        },
        {
          "@type": "HowToStep",
          "position": 3,
          "name": "Translate and localise",
          "text": "Local-language technical summary and labeling are usually mandatory; certified translation is safest."
        },
        {
          "@type": "HowToStep",
          "position": 4,
          "name": "Submit + track queries",
          "text": "Respond to clarification rounds promptly; each unanswered question can add 30-90 days to the clock."
        }
      ]
    },
    {
      "@context": "https://schema.org",
      "@type": "BreadcrumbList",
      "itemListElement": [
        {
          "@type": "ListItem",
          "position": 1,
          "name": "Home",
          "item": "https://mdccrosswalk.lovable.app/"
        },
        {
          "@type": "ListItem",
          "position": 2,
          "name": "Standards"
        },
        {
          "@type": "ListItem",
          "position": 3,
          "name": "Kazakhstan"
        }
      ]
    }
  ]
---

[

The Crosswalk



](/)

[Overview](/)[Playbook](/playbook)CompareReference

[New Per-page social previews and this changelog ](/changelog "Per-page social previews and this changelog") Search⌘K

1.  [Home ](/)
2.  Standards 
3.  Kazakhstan 

NCEMP

# ![Flag of Kazakhstan](/flags/kz.svg)Kazakhstan - NCEMP 

Mandatory Last updated · 2024 Verified · 2026-07-16 

EAEU Medical Device Rules (Decision 46) - Kazakhstan implementation

Share Copy link X LinkedIn Email

Sources verified · 2026-07-16

Cross-checked against EEC Council Decision 46 (2016) and NCEMP procedural rules.

Authority

National Center for Expertise of Medicines and Medical Products

Enforced

2016 (EAEU Decision 46)

Legal framework

Eurasian Economic Union (EAEU) Medical Device Rules adopted by Decision 46 of the EEC Council, implemented in Kazakhstan via the Code on People's Health and NCEMP procedural rules.

FDA package reuse

~45%

[Editorial estimate · how →](/methodology#fda-reuse)

## Scope

All medical devices placed on the Kazakh market. EAEU registration grants access across RU, BY, AM, KG, KZ. Software-as-a-medical-device follows EAEU SaMD guidelines.

Pre-market

Common Technical Document-style dossier including QMS (ISO 13485), risk management, clinical evaluation, and software lifecycle (IEC 62304). Cybersecurity controls evaluated implicitly under software safety; explicit cyber expectations rely on Law on Personal Data and State Technical Service baselines.

Post-market

EAEU vigilance reporting via NCEMP; serious incidents within 15 working days. Cross-border data flows constrained by Law on Personal Data.

SBOM

Not specified 

Not addressed in EAEU rules today; CycloneDX accepted as supporting evidence on a voluntary basis.

Vulnerability disclosure

No medical-device-specific CVD regime; State Technical Service (STS) coordinates ICT incidents in healthcare.

Penalty

Registration suspension, removal from EAEU Unified Register, administrative fines under the Code on Administrative Offences.

## Unique requirements

-   01 EAEU dossier format (CTD-style) 
-   02 Local authorised representative in Kazakhstan 
-   03 Russian-language labelling and IFU 

## Highlights

-   EAEU mutual recognition across 5 member states 
-   ISO 13485 QMS expectation 
-   No statutory medical-device cyber rule yet 

## Aligns with

EAEU SaMD guidance  ISO 13485  IEC 62304  ISO 14971 

## Timeline

1.  May 2017
    
    EAEU Decision 46 takes effect
    
2.  2021
    
    EAEU SaMD guidance issued
    
3.  2024
    
    NCEMP digital dossier portal expanded
    

## Key documents

[

EEC Decision 46 - EAEU Medical Device Rules

https://docs.eaeunion.org/docs/en-us/0149032/cncd\_15022017\_46



](https://docs.eaeunion.org/docs/en-us/0149032/cncd_15022017_46)[

NCEMP - National Center for Expertise

https://www.ndda.kz/



](https://www.ndda.kz/)

## How to submit in Kazakhstan

Playbook reviewed · 2026-07-16

Submission route

Ministry of Health registration under Eurasian Economic Union rules

Kazakhstan operates a dual national / EAEU registration path. Cybersecurity documentation is not separately mandated but recommended for connected devices.

[Authority portal](https://www.gov.kz/memleket/entities/dsm?lang=en)

### Step-by-step

1.  Step 01
    
    Appoint local representation
    
    Most jurisdictions require a locally-established entity to hold the registration or act as authorised representative before submission.
    
2.  Step 02
    
    Reuse FDA or CE package as baseline
    
    Adapt the cybersecurity subsection you already prepared for FDA or CE; regulators here typically accept the structure and ask for local labeling additions.
    
3.  Step 03
    
    Translate and localise
    
    Local-language technical summary and labeling are usually mandatory; certified translation is safest.
    
4.  Step 04
    
    Submit + track queries
    
    Respond to clarification rounds promptly; each unanswered question can add 30-90 days to the clock.
    

### Evidence checklist

Item

Level

FDA equivalent

Notes

Cybersecurity documentation (baseline FDA or CE)

Required 

SPDF

Local authorised representative agreement

Required 

—

Local-language labeling and IFU

Required 

—

SBOM

Recommended 

—

Not mandatory but reduces clarification rounds.

### Common NCEMP rejections

EAEU dossier requirements not met

Common 

Fix ·  Use the EAEU technical file structure to future-proof the submission.

### Typical timeline

End-to-end window: 6-12 months 

Phase 01

Local rep + dossier prep

2-4 months

Phase 02

Regulatory review

6-12 months

Phase 03

Approval + market entry

1-3 months

[Previous ![Flag of Ukraine](/flags/ua.svg)Ukraine ](/standards/ua)[Next  ![Flag of Egypt](/flags/eg.svg)Egypt ](/standards/eg)

## Related markets

[![Flag of China](/flags/cn.svg)

China

~45% FDA reuse

](/standards/cn)[![Flag of Switzerland](/flags/ch.svg)

Switzerland

~55% FDA reuse

](/standards/ch)[![Flag of Turkey](/flags/tr.svg)

Turkey

~55% FDA reuse

](/standards/tr)[![Flag of Russia](/flags/ru.svg)

Russia

~35% FDA reuse

](/standards/ru)

## Frequently asked about Kazakhstan

### Is SBOM required for medical devices in Kazakhstan?

Not specified. Not addressed in EAEU rules today; CycloneDX accepted as supporting evidence on a voluntary basis.

### What does NCEMP require for pre-market cybersecurity?

Common Technical Document-style dossier including QMS (ISO 13485), risk management, clinical evaluation, and software lifecycle (IEC 62304). Cybersecurity controls evaluated implicitly under software safety; explicit cyber expectations rely on Law on Personal Data and State Technical Service baselines.

### What are the post-market cybersecurity obligations under NCEMP?

EAEU vigilance reporting via NCEMP; serious incidents within 15 working days. Cross-border data flows constrained by Law on Personal Data.

### What is the penalty for non-compliance with NCEMP cybersecurity rules?

Registration suspension, removal from EAEU Unified Register, administrative fines under the Code on Administrative Offences.

### How much of my FDA cybersecurity package is reusable in Kazakhstan?

Roughly 45% - an editorial estimate based on overlapping evidence requirements (threat model, SBOM, security risk assessment, pen-test report).

Sponsored note · Blue Goat Cyber

Submitting to NCEMP? Get a second pair of eyes before you file. Blue Goat Cyber has packaged cybersecurity evidence for Kazakhstan alongside 37 other markets. We'll tell you what to keep, what to rework, and what's missing, in 30 minutes.  [Talk through your NCEMP submission](https://go.bluegoatcyber.com/meetings/blue-goat-cyber/discovery-session)

The Crosswalk

An independent reference for global medical device cybersecurity standards. A field guide for MedTech innovators and RA/QA teams charting an international path.

Resource

-   [Comparison matrix](/compare)
-   [Global playbook](/playbook)
-   [Glossary](/glossary)
-   [FAQ](/faq)

Sponsored by

[Blue Goat Cyber ↗](https://bluegoatcyber.com)

Editorially independent. Sponsorship keeps it free.

© 2026 The Crosswalk. Not legal advice.

Validate every requirement against current regulator publications.