The Crosswalk

    NewPer-page social previews and this changelog

    COFEPRIS

    Flag of MexicoMexico - COFEPRIS

    GuidanceLast updated · 2024Verified · 2026-07-16

    NOM-241-SSA1-2021 + COFEPRIS digital-health criteria

    Share

    Authority

    Comisión Federal para la Protección contra Riesgos Sanitarios

    Enforced

    Dec 2021 (NOM-241)

    Legal framework

    Ley General de Salud + NOM-241-SSA1-2021 + LFPDPPP

    FDA package reuse

    ~90%

    Scope

    Medical devices and SaMD marketed in Mexico. Cybersecurity expectations folded into Good Manufacturing Practices.

    Pre-market

    Risk management dossier, software lifecycle evidence, evidence reuse from FDA / Health Canada accepted via equivalence.

    Post-market

    Tecnovigilancia reporting, software change notifications.

    SBOM

    Recommended

    Encouraged in technical file, not strictly mandated.

    Vulnerability disclosure

    Encouraged via CERT-MX coordination.

    Penalty

    Sanitary registration suspension, fines under General Health Law.

    Unique requirements

    • 01Mexican Registration Holder (Titular)
    • 02Spanish-language IFU and labelling
    • 03Equivalence dossier accelerates approval

    Highlights

    • Equivalence route for FDA / Health Canada
    • Top-3 LATAM market by device spend
    • NOM-241 GMP compliance underpins everything

    Aligns with

    IMDRF N60 FDA 2023 Guidance ISO 13485

    Timeline

    1. Dec 2021

      NOM-241-SSA1-2021 published

    2. 2023

      Equivalence agreements broadened

    3. 2024

      Digital-health criteria refined

    Key documents

    How to submit in Mexico

    Playbook reviewed · 2026-07-16

    Submission route

    COFEPRIS registration with equivalence route for FDA/Health Canada-cleared devices

    COFEPRIS operates an equivalence route that dramatically shortens review time when a valid FDA or Health Canada certificate is presented.

    Authority portal

    Step-by-step

    1. Step 01

      Appoint local representation

      Most jurisdictions require a locally-established entity to hold the registration or act as authorised representative before submission.

    2. Step 02

      Reuse FDA or CE package as baseline

      Adapt the cybersecurity subsection you already prepared for FDA or CE; regulators here typically accept the structure and ask for local labeling additions.

    3. Step 03

      Translate and localise

      Local-language technical summary and labeling are usually mandatory; certified translation is safest.

    4. Step 04

      Submit + track queries

      Respond to clarification rounds promptly; each unanswered question can add 30-90 days to the clock.

    Evidence checklist

    Item Level FDA equivalent Notes
    Cybersecurity documentation (baseline FDA or CE) Required SPDF
    Local authorised representative agreement Required
    Local-language labeling and IFU Required
    SBOM Recommended Not mandatory but reduces clarification rounds.

    Common COFEPRIS rejections

    Reference agency certificate expired

    Common

    Fix · Refresh the reference approval before filing.

    Typical timeline

    End-to-end window: 2-6 months (equivalence); 12-18 months (full)

    Phase 01

    Local rep + dossier prep

    2-4 months

    Phase 02

    Regulatory review

    2-6 months (equivalence); 12-18 months (full)

    Phase 03

    Approval + market entry

    1-3 months

    Related markets

    Frequently asked about Mexico

    Is SBOM required for medical devices in Mexico?

    Recommended. Encouraged in technical file, not strictly mandated.

    What does COFEPRIS require for pre-market cybersecurity?

    Risk management dossier, software lifecycle evidence, evidence reuse from FDA / Health Canada accepted via equivalence.

    What are the post-market cybersecurity obligations under COFEPRIS?

    Tecnovigilancia reporting, software change notifications.

    What is the penalty for non-compliance with COFEPRIS cybersecurity rules?

    Sanitary registration suspension, fines under General Health Law.

    How much of my FDA cybersecurity package is reusable in Mexico?

    Roughly 90% - an editorial estimate based on overlapping evidence requirements (threat model, SBOM, security risk assessment, pen-test report).