---
title: "Mexico COFEPRIS - Cybersecurity Submission Playbook"
description: "How to submit a medical device to COFEPRIS in Mexico: step-by-step route, evidence checklist, common rejections, and typical review timeline. Compared with FD"
lang: en
json-ld: |
  [
    {
      "@context": "https://schema.org",
      "@type": "WebSite",
      "name": "The Medical Device Cybersecurity Crosswalk",
      "alternateName": "MDC Crosswalk",
      "url": "https://mdccrosswalk.com/",
      "description": "Compare FDA, EU MDR, MHRA, PMDA, NMPA, TGA, MFDS and Health Canada medical device cybersecurity requirements across 29 jurisdictions."
    },
    {
      "@context": "https://schema.org",
      "@type": "Organization",
      "name": "MDC Crosswalk",
      "url": "https://mdccrosswalk.com/",
      "logo": "https://mdccrosswalk.com/favicon.png",
      "sameAs": [
        "https://bluegoatcyber.com"
      ],
      "description": "An editorial reference comparing global medical-device cybersecurity regulations. Maintained by Blue Goat Cyber."
    },
    {
      "@context": "https://schema.org",
      "@type": "Article",
      "headline": "Mexico - NOM-241-SSA1-2021 + COFEPRIS digital-health criteria",
      "description": "How to submit a medical device to COFEPRIS in Mexico: step-by-step route, evidence checklist, common rejections, and typical review timeline. Compared with FD",
      "author": {
        "@type": "Organization",
        "name": "MDC Crosswalk"
      },
      "publisher": {
        "@type": "Organization",
        "name": "MDC Crosswalk"
      },
      "image": "https://mdccrosswalk.lovable.app/favicon.png",
      "datePublished": "2024",
      "about": "Comisión Federal para la Protección contra Riesgos Sanitarios",
      "dateModified": "2026-07-16",
      "mainEntityOfPage": "https://mdccrosswalk.lovable.app/standards/mx"
    },
    {
      "@context": "https://schema.org",
      "@type": "FAQPage",
      "mainEntity": [
        {
          "@type": "Question",
          "name": "Is SBOM required for medical devices in Mexico?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "Recommended. Encouraged in technical file, not strictly mandated."
          }
        },
        {
          "@type": "Question",
          "name": "What does COFEPRIS require for pre-market cybersecurity?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "Risk management dossier, software lifecycle evidence, evidence reuse from FDA / Health Canada accepted via equivalence."
          }
        },
        {
          "@type": "Question",
          "name": "What are the post-market cybersecurity obligations under COFEPRIS?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "Tecnovigilancia reporting, software change notifications."
          }
        },
        {
          "@type": "Question",
          "name": "What is the penalty for non-compliance with COFEPRIS cybersecurity rules?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "Sanitary registration suspension, fines under General Health Law."
          }
        },
        {
          "@type": "Question",
          "name": "How much of my FDA cybersecurity package is reusable in Mexico?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "Roughly 90% - an editorial estimate based on overlapping evidence requirements (threat model, SBOM, security risk assessment, pen-test report)."
          }
        },
        {
          "@type": "Question",
          "name": "Why do COFEPRIS submissions get rejected for \"reference agency certificate expired\"?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "Refresh the reference approval before filing."
          }
        }
      ]
    },
    {
      "@context": "https://schema.org",
      "@type": "HowTo",
      "name": "How to submit a medical device to COFEPRIS",
      "description": "COFEPRIS operates an equivalence route that dramatically shortens review time when a valid FDA or Health Canada certificate is presented.",
      "totalTime": "2-6 months (equivalence); 12-18 months (full)",
      "step": [
        {
          "@type": "HowToStep",
          "position": 1,
          "name": "Appoint local representation",
          "text": "Most jurisdictions require a locally-established entity to hold the registration or act as authorised representative before submission."
        },
        {
          "@type": "HowToStep",
          "position": 2,
          "name": "Reuse FDA or CE package as baseline",
          "text": "Adapt the cybersecurity subsection you already prepared for FDA or CE; regulators here typically accept the structure and ask for local labeling additions."
        },
        {
          "@type": "HowToStep",
          "position": 3,
          "name": "Translate and localise",
          "text": "Local-language technical summary and labeling are usually mandatory; certified translation is safest."
        },
        {
          "@type": "HowToStep",
          "position": 4,
          "name": "Submit + track queries",
          "text": "Respond to clarification rounds promptly; each unanswered question can add 30-90 days to the clock."
        }
      ]
    },
    {
      "@context": "https://schema.org",
      "@type": "BreadcrumbList",
      "itemListElement": [
        {
          "@type": "ListItem",
          "position": 1,
          "name": "Home",
          "item": "https://mdccrosswalk.lovable.app/"
        },
        {
          "@type": "ListItem",
          "position": 2,
          "name": "Standards"
        },
        {
          "@type": "ListItem",
          "position": 3,
          "name": "Mexico"
        }
      ]
    }
  ]
---

[

The Crosswalk



](/)

[Overview](/)[Playbook](/playbook)CompareReference

[New Per-page social previews and this changelog ](/changelog "Per-page social previews and this changelog") Search⌘K

1.  [Home ](/)
2.  Standards 
3.  Mexico 

COFEPRIS

# ![Flag of Mexico](/flags/mx.svg)Mexico - COFEPRIS 

Guidance Last updated · 2024 Verified · 2026-07-16 

NOM-241-SSA1-2021 + COFEPRIS digital-health criteria

Share Copy link X LinkedIn Email

Sources verified · 2026-07-16

NOM-241-SSA1-2021 confirmed; cybersecurity expectations are layered into GMP and equivalence reviews.

Authority

Comisión Federal para la Protección contra Riesgos Sanitarios

Enforced

Dec 2021 (NOM-241)

Legal framework

Ley General de Salud + NOM-241-SSA1-2021 + LFPDPPP

FDA package reuse

~90%

[Editorial estimate · how →](/methodology#fda-reuse)

## Scope

Medical devices and SaMD marketed in Mexico. Cybersecurity expectations folded into Good Manufacturing Practices.

Pre-market

Risk management dossier, software lifecycle evidence, evidence reuse from FDA / Health Canada accepted via equivalence.

Post-market

Tecnovigilancia reporting, software change notifications.

SBOM

Recommended 

Encouraged in technical file, not strictly mandated.

Vulnerability disclosure

Encouraged via CERT-MX coordination.

Penalty

Sanitary registration suspension, fines under General Health Law.

## Unique requirements

-   01 Mexican Registration Holder (Titular) 
-   02 Spanish-language IFU and labelling 
-   03 Equivalence dossier accelerates approval 

## Highlights

-   Equivalence route for FDA / Health Canada 
-   Top-3 LATAM market by device spend 
-   NOM-241 GMP compliance underpins everything 

## Aligns with

IMDRF N60  FDA 2023 Guidance  ISO 13485 

## Timeline

1.  Dec 2021
    
    NOM-241-SSA1-2021 published
    
2.  2023
    
    Equivalence agreements broadened
    
3.  2024
    
    Digital-health criteria refined
    

## Key documents

[

NOM-241-SSA1-2021

https://www.gob.mx/cofepris



](https://www.gob.mx/cofepris)[

COFEPRIS Medical Devices

https://www.gob.mx/cofepris/acciones-y-programas/dispositivos-medicos



](https://www.gob.mx/cofepris/acciones-y-programas/dispositivos-medicos)

## How to submit in Mexico

Playbook reviewed · 2026-07-16

Submission route

COFEPRIS registration with equivalence route for FDA/Health Canada-cleared devices

COFEPRIS operates an equivalence route that dramatically shortens review time when a valid FDA or Health Canada certificate is presented.

[Authority portal](https://www.gob.mx/cofepris)

### Step-by-step

1.  Step 01
    
    Appoint local representation
    
    Most jurisdictions require a locally-established entity to hold the registration or act as authorised representative before submission.
    
2.  Step 02
    
    Reuse FDA or CE package as baseline
    
    Adapt the cybersecurity subsection you already prepared for FDA or CE; regulators here typically accept the structure and ask for local labeling additions.
    
3.  Step 03
    
    Translate and localise
    
    Local-language technical summary and labeling are usually mandatory; certified translation is safest.
    
4.  Step 04
    
    Submit + track queries
    
    Respond to clarification rounds promptly; each unanswered question can add 30-90 days to the clock.
    

### Evidence checklist

Item

Level

FDA equivalent

Notes

Cybersecurity documentation (baseline FDA or CE)

Required 

SPDF

Local authorised representative agreement

Required 

—

Local-language labeling and IFU

Required 

—

SBOM

Recommended 

—

Not mandatory but reduces clarification rounds.

### Common COFEPRIS rejections

Reference agency certificate expired

Common 

Fix ·  Refresh the reference approval before filing.

### Typical timeline

End-to-end window: 2-6 months (equivalence); 12-18 months (full) 

Phase 01

Local rep + dossier prep

2-4 months

Phase 02

Regulatory review

2-6 months (equivalence); 12-18 months (full)

Phase 03

Approval + market entry

1-3 months

[Previous ![Flag of Taiwan](/flags/tw.svg)Taiwan ](/standards/tw)[Next  ![Flag of United Arab Emirates](/flags/ae.svg)United Arab Emirates ](/standards/ae)

## Related markets

[![Flag of Singapore](/flags/sg.svg)

Singapore

~90% FDA reuse

](/standards/sg)[![Flag of New Zealand](/flags/nz.svg)

New Zealand

~90% FDA reuse

](/standards/nz)[![Flag of Hong Kong](/flags/hk.svg)

Hong Kong

~90% FDA reuse

](/standards/hk)[![Flag of Australia](/flags/au.svg)

Australia

~85% FDA reuse

](/standards/au)

## Frequently asked about Mexico

### Is SBOM required for medical devices in Mexico?

Recommended. Encouraged in technical file, not strictly mandated.

### What does COFEPRIS require for pre-market cybersecurity?

Risk management dossier, software lifecycle evidence, evidence reuse from FDA / Health Canada accepted via equivalence.

### What are the post-market cybersecurity obligations under COFEPRIS?

Tecnovigilancia reporting, software change notifications.

### What is the penalty for non-compliance with COFEPRIS cybersecurity rules?

Sanitary registration suspension, fines under General Health Law.

### How much of my FDA cybersecurity package is reusable in Mexico?

Roughly 90% - an editorial estimate based on overlapping evidence requirements (threat model, SBOM, security risk assessment, pen-test report).

Sponsored note · Blue Goat Cyber

Submitting to COFEPRIS? Get a second pair of eyes before you file. Blue Goat Cyber has packaged cybersecurity evidence for Mexico alongside 37 other markets. We'll tell you what to keep, what to rework, and what's missing, in 30 minutes.  [Talk through your COFEPRIS submission](https://go.bluegoatcyber.com/meetings/blue-goat-cyber/discovery-session)

The Crosswalk

An independent reference for global medical device cybersecurity standards. A field guide for MedTech innovators and RA/QA teams charting an international path.

Resource

-   [Comparison matrix](/compare)
-   [Global playbook](/playbook)
-   [Glossary](/glossary)
-   [FAQ](/faq)

Sponsored by

[Blue Goat Cyber ↗](https://bluegoatcyber.com)

Editorially independent. Sponsorship keeps it free.

© 2026 The Crosswalk. Not legal advice.

Validate every requirement against current regulator publications.