COFEPRIS
Mexico - COFEPRIS
NOM-241-SSA1-2021 + COFEPRIS digital-health criteria
Authority
Comisión Federal para la Protección contra Riesgos Sanitarios
Enforced
Dec 2021 (NOM-241)
Legal framework
Ley General de Salud + NOM-241-SSA1-2021 + LFPDPPP
Scope
Medical devices and SaMD marketed in Mexico. Cybersecurity expectations folded into Good Manufacturing Practices.
Pre-market
Risk management dossier, software lifecycle evidence, evidence reuse from FDA / Health Canada accepted via equivalence.
Post-market
Tecnovigilancia reporting, software change notifications.
SBOM
RecommendedEncouraged in technical file, not strictly mandated.
Vulnerability disclosure
Encouraged via CERT-MX coordination.
Penalty
Sanitary registration suspension, fines under General Health Law.
Unique requirements
- 01Mexican Registration Holder (Titular)
- 02Spanish-language IFU and labelling
- 03Equivalence dossier accelerates approval
Highlights
- Equivalence route for FDA / Health Canada
- Top-3 LATAM market by device spend
- NOM-241 GMP compliance underpins everything
Aligns with
Timeline
-
Dec 2021
NOM-241-SSA1-2021 published
-
2023
Equivalence agreements broadened
-
2024
Digital-health criteria refined
Key documents
How to submit in Mexico
Playbook reviewed · 2026-07-16
Submission route
COFEPRIS registration with equivalence route for FDA/Health Canada-cleared devices
COFEPRIS operates an equivalence route that dramatically shortens review time when a valid FDA or Health Canada certificate is presented.
Authority portalStep-by-step
-
Step 01
Appoint local representation
Most jurisdictions require a locally-established entity to hold the registration or act as authorised representative before submission.
-
Step 02
Reuse FDA or CE package as baseline
Adapt the cybersecurity subsection you already prepared for FDA or CE; regulators here typically accept the structure and ask for local labeling additions.
-
Step 03
Translate and localise
Local-language technical summary and labeling are usually mandatory; certified translation is safest.
-
Step 04
Submit + track queries
Respond to clarification rounds promptly; each unanswered question can add 30-90 days to the clock.
Evidence checklist
| Item | Level | FDA equivalent | Notes |
|---|---|---|---|
| Cybersecurity documentation (baseline FDA or CE) | Required | SPDF | |
| Local authorised representative agreement | Required | — | |
| Local-language labeling and IFU | Required | — | |
| SBOM | Recommended | — | Not mandatory but reduces clarification rounds. |
Common COFEPRIS rejections
Reference agency certificate expired
CommonFix · Refresh the reference approval before filing.
Typical timeline
End-to-end window: 2-6 months (equivalence); 12-18 months (full)
Phase 01
Local rep + dossier prep
2-4 months
Phase 02
Regulatory review
2-6 months (equivalence); 12-18 months (full)
Phase 03
Approval + market entry
1-3 months
Related markets
Frequently asked about Mexico
Is SBOM required for medical devices in Mexico?
Recommended. Encouraged in technical file, not strictly mandated.
What does COFEPRIS require for pre-market cybersecurity?
Risk management dossier, software lifecycle evidence, evidence reuse from FDA / Health Canada accepted via equivalence.
What are the post-market cybersecurity obligations under COFEPRIS?
Tecnovigilancia reporting, software change notifications.
What is the penalty for non-compliance with COFEPRIS cybersecurity rules?
Sanitary registration suspension, fines under General Health Law.
How much of my FDA cybersecurity package is reusable in Mexico?
Roughly 90% - an editorial estimate based on overlapping evidence requirements (threat model, SBOM, security risk assessment, pen-test report).