The Crosswalk

    NewPer-page social previews and this changelog

    MDA

    Flag of MalaysiaMalaysia - MDA

    GuidanceLast updated · 2023Verified · 2026-07-16

    Medical Device Act 2012 + MDA Cybersecurity Guidance MDA/GD/0041

    Share

    Authority

    Medical Device Authority, Ministry of Health Malaysia

    Enforced

    2021 (cybersecurity guidance)

    Legal framework

    Medical Device Act 737 + MDA Guidance Documents + PDPA

    FDA package reuse

    ~80%

    Scope

    All medical devices and SaMD requiring registration with MDA. Cybersecurity proportional to risk class.

    Pre-market

    Cybersecurity description in CSDT (Common Submission Dossier Template), evidence aligned to IMDRF N60.

    Post-market

    Mandatory problem reporting, field corrective action notifications.

    SBOM

    Recommended

    Encouraged for higher-risk devices; mirrors IMDRF N60 expectations.

    Vulnerability disclosure

    MyCERT coordinated disclosure encouraged.

    Penalty

    Registration cancellation; PDPA fines and criminal liability for breaches.

    Unique requirements

    • 01Malaysian Authorised Representative
    • 02Conformity Assessment Body (CAB) involvement
    • 03Bahasa Malaysia labelling

    Highlights

    • ASEAN CSDT template alignment
    • Risk-class proportional evidence
    • PDPA overhaul in progress (2024–25)

    Aligns with

    IMDRF N60 ASEAN MDD ISO 13485

    Timeline

    1. Jul 2013

      Medical Device Act 737 effective

    2. 2021

      Cybersecurity guidance MDA/GD/0041 issued

    3. 2024

      PDPA amendments tighten breach reporting

    Key documents

    How to submit in Malaysia

    Playbook reviewed · 2026-07-16

    Submission route

    MDA registration under the Medical Device Act 2012 with cybersecurity per MDA/GD/0055

    MDA's cybersecurity guideline aligns with IMDRF. Class B-D devices require conformity assessment via a Registered Conformity Assessment Body.

    Authority portal

    Step-by-step

    1. Step 01

      Appoint local representation

      Most jurisdictions require a locally-established entity to hold the registration or act as authorised representative before submission.

    2. Step 02

      Reuse FDA or CE package as baseline

      Adapt the cybersecurity subsection you already prepared for FDA or CE; regulators here typically accept the structure and ask for local labeling additions.

    3. Step 03

      Translate and localise

      Local-language technical summary and labeling are usually mandatory; certified translation is safest.

    4. Step 04

      Submit + track queries

      Respond to clarification rounds promptly; each unanswered question can add 30-90 days to the clock.

    Evidence checklist

    Item Level FDA equivalent Notes
    Cybersecurity documentation (baseline FDA or CE) Required SPDF
    Local authorised representative agreement Required
    Local-language labeling and IFU Required
    SBOM Recommended Not mandatory but reduces clarification rounds.

    Common MDA rejections

    No CAB engagement for Class B+ devices

    Common

    Fix · Engage an MDA-registered CAB early; capacity is limited.

    Typical timeline

    End-to-end window: 6-12 months

    Phase 01

    Local rep + dossier prep

    2-4 months

    Phase 02

    Regulatory review

    6-12 months

    Phase 03

    Approval + market entry

    1-3 months

    Related markets

    Frequently asked about Malaysia

    Is SBOM required for medical devices in Malaysia?

    Recommended. Encouraged for higher-risk devices; mirrors IMDRF N60 expectations.

    What does MDA require for pre-market cybersecurity?

    Cybersecurity description in CSDT (Common Submission Dossier Template), evidence aligned to IMDRF N60.

    What are the post-market cybersecurity obligations under MDA?

    Mandatory problem reporting, field corrective action notifications.

    What is the penalty for non-compliance with MDA cybersecurity rules?

    Registration cancellation; PDPA fines and criminal liability for breaches.

    How much of my FDA cybersecurity package is reusable in Malaysia?

    Roughly 80% - an editorial estimate based on overlapping evidence requirements (threat model, SBOM, security risk assessment, pen-test report).