---
title: "Malaysia MDA - Cybersecurity Submission Playbook"
description: "How to submit a medical device to MDA in Malaysia: step-by-step route, evidence checklist, common rejections, and typical review timeline. Compared with FDA &amp;"
lang: en
json-ld: |
  [
    {
      "@context": "https://schema.org",
      "@type": "WebSite",
      "name": "The Medical Device Cybersecurity Crosswalk",
      "alternateName": "MDC Crosswalk",
      "url": "https://mdccrosswalk.com/",
      "description": "Compare FDA, EU MDR, MHRA, PMDA, NMPA, TGA, MFDS and Health Canada medical device cybersecurity requirements across 29 jurisdictions."
    },
    {
      "@context": "https://schema.org",
      "@type": "Organization",
      "name": "MDC Crosswalk",
      "url": "https://mdccrosswalk.com/",
      "logo": "https://mdccrosswalk.com/favicon.png",
      "sameAs": [
        "https://bluegoatcyber.com"
      ],
      "description": "An editorial reference comparing global medical-device cybersecurity regulations. Maintained by Blue Goat Cyber."
    },
    {
      "@context": "https://schema.org",
      "@type": "Article",
      "headline": "Malaysia - Medical Device Act 2012 + MDA Cybersecurity Guidance MDA/GD/0041",
      "description": "How to submit a medical device to MDA in Malaysia: step-by-step route, evidence checklist, common rejections, and typical review timeline. Compared with FDA &",
      "author": {
        "@type": "Organization",
        "name": "MDC Crosswalk"
      },
      "publisher": {
        "@type": "Organization",
        "name": "MDC Crosswalk"
      },
      "image": "https://mdccrosswalk.lovable.app/favicon.png",
      "datePublished": "2023",
      "about": "Medical Device Authority, Ministry of Health Malaysia",
      "dateModified": "2026-07-16",
      "mainEntityOfPage": "https://mdccrosswalk.lovable.app/standards/my"
    },
    {
      "@context": "https://schema.org",
      "@type": "FAQPage",
      "mainEntity": [
        {
          "@type": "Question",
          "name": "Is SBOM required for medical devices in Malaysia?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "Recommended. Encouraged for higher-risk devices; mirrors IMDRF N60 expectations."
          }
        },
        {
          "@type": "Question",
          "name": "What does MDA require for pre-market cybersecurity?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "Cybersecurity description in CSDT (Common Submission Dossier Template), evidence aligned to IMDRF N60."
          }
        },
        {
          "@type": "Question",
          "name": "What are the post-market cybersecurity obligations under MDA?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "Mandatory problem reporting, field corrective action notifications."
          }
        },
        {
          "@type": "Question",
          "name": "What is the penalty for non-compliance with MDA cybersecurity rules?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "Registration cancellation; PDPA fines and criminal liability for breaches."
          }
        },
        {
          "@type": "Question",
          "name": "How much of my FDA cybersecurity package is reusable in Malaysia?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "Roughly 80% - an editorial estimate based on overlapping evidence requirements (threat model, SBOM, security risk assessment, pen-test report)."
          }
        },
        {
          "@type": "Question",
          "name": "Why do MDA submissions get rejected for \"no cab engagement for class b+ devices\"?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "Engage an MDA-registered CAB early; capacity is limited."
          }
        }
      ]
    },
    {
      "@context": "https://schema.org",
      "@type": "HowTo",
      "name": "How to submit a medical device to MDA",
      "description": "MDA's cybersecurity guideline aligns with IMDRF. Class B-D devices require conformity assessment via a Registered Conformity Assessment Body.",
      "totalTime": "6-12 months",
      "step": [
        {
          "@type": "HowToStep",
          "position": 1,
          "name": "Appoint local representation",
          "text": "Most jurisdictions require a locally-established entity to hold the registration or act as authorised representative before submission."
        },
        {
          "@type": "HowToStep",
          "position": 2,
          "name": "Reuse FDA or CE package as baseline",
          "text": "Adapt the cybersecurity subsection you already prepared for FDA or CE; regulators here typically accept the structure and ask for local labeling additions."
        },
        {
          "@type": "HowToStep",
          "position": 3,
          "name": "Translate and localise",
          "text": "Local-language technical summary and labeling are usually mandatory; certified translation is safest."
        },
        {
          "@type": "HowToStep",
          "position": 4,
          "name": "Submit + track queries",
          "text": "Respond to clarification rounds promptly; each unanswered question can add 30-90 days to the clock."
        }
      ]
    },
    {
      "@context": "https://schema.org",
      "@type": "BreadcrumbList",
      "itemListElement": [
        {
          "@type": "ListItem",
          "position": 1,
          "name": "Home",
          "item": "https://mdccrosswalk.lovable.app/"
        },
        {
          "@type": "ListItem",
          "position": 2,
          "name": "Standards"
        },
        {
          "@type": "ListItem",
          "position": 3,
          "name": "Malaysia"
        }
      ]
    }
  ]
---

[

The Crosswalk



](/)

[Overview](/)[Playbook](/playbook)CompareReference

[New Per-page social previews and this changelog ](/changelog "Per-page social previews and this changelog") Search⌘K

1.  [Home ](/)
2.  Standards 
3.  Malaysia 

MDA

# ![Flag of Malaysia](/flags/my.svg)Malaysia - MDA 

Guidance Last updated · 2023 Verified · 2026-07-16 

Medical Device Act 2012 + MDA Cybersecurity Guidance MDA/GD/0041

Share Copy link X LinkedIn Email

Sources verified · 2026-07-16

MDA/GD/0041 is a non-binding guidance document under the Medical Device Act 2012.

Authority

Medical Device Authority, Ministry of Health Malaysia

Enforced

2021 (cybersecurity guidance)

Legal framework

Medical Device Act 737 + MDA Guidance Documents + PDPA

FDA package reuse

~80%

[Editorial estimate · how →](/methodology#fda-reuse)

## Scope

All medical devices and SaMD requiring registration with MDA. Cybersecurity proportional to risk class.

Pre-market

Cybersecurity description in CSDT (Common Submission Dossier Template), evidence aligned to IMDRF N60.

Post-market

Mandatory problem reporting, field corrective action notifications.

SBOM

Recommended 

Encouraged for higher-risk devices; mirrors IMDRF N60 expectations.

Vulnerability disclosure

MyCERT coordinated disclosure encouraged.

Penalty

Registration cancellation; PDPA fines and criminal liability for breaches.

## Unique requirements

-   01 Malaysian Authorised Representative 
-   02 Conformity Assessment Body (CAB) involvement 
-   03 Bahasa Malaysia labelling 

## Highlights

-   ASEAN CSDT template alignment 
-   Risk-class proportional evidence 
-   PDPA overhaul in progress (2024–25) 

## Aligns with

IMDRF N60  ASEAN MDD  ISO 13485 

## Timeline

1.  Jul 2013
    
    Medical Device Act 737 effective
    
2.  2021
    
    Cybersecurity guidance MDA/GD/0041 issued
    
3.  2024
    
    PDPA amendments tighten breach reporting
    

## Key documents

[

MDA Guidance Documents

https://www.mda.gov.my/



](https://www.mda.gov.my/)

## How to submit in Malaysia

Playbook reviewed · 2026-07-16

Submission route

MDA registration under the Medical Device Act 2012 with cybersecurity per MDA/GD/0055

MDA's cybersecurity guideline aligns with IMDRF. Class B-D devices require conformity assessment via a Registered Conformity Assessment Body.

[Authority portal](https://www.mda.gov.my/)

### Step-by-step

1.  Step 01
    
    Appoint local representation
    
    Most jurisdictions require a locally-established entity to hold the registration or act as authorised representative before submission.
    
2.  Step 02
    
    Reuse FDA or CE package as baseline
    
    Adapt the cybersecurity subsection you already prepared for FDA or CE; regulators here typically accept the structure and ask for local labeling additions.
    
3.  Step 03
    
    Translate and localise
    
    Local-language technical summary and labeling are usually mandatory; certified translation is safest.
    
4.  Step 04
    
    Submit + track queries
    
    Respond to clarification rounds promptly; each unanswered question can add 30-90 days to the clock.
    

### Evidence checklist

Item

Level

FDA equivalent

Notes

Cybersecurity documentation (baseline FDA or CE)

Required 

SPDF

Local authorised representative agreement

Required 

—

Local-language labeling and IFU

Required 

—

SBOM

Recommended 

—

Not mandatory but reduces clarification rounds.

### Common MDA rejections

No CAB engagement for Class B+ devices

Common 

Fix ·  Engage an MDA-registered CAB early; capacity is limited.

### Typical timeline

End-to-end window: 6-12 months 

Phase 01

Local rep + dossier prep

2-4 months

Phase 02

Regulatory review

6-12 months

Phase 03

Approval + market entry

1-3 months

[Previous ![Flag of South Africa](/flags/za.svg)South Africa ](/standards/za)[Next  ![Flag of Thailand](/flags/th.svg)Thailand ](/standards/th)

## Related markets

[![Flag of United Kingdom](/flags/gb.svg)

United Kingdom

~80% FDA reuse

](/standards/uk)[![Flag of Taiwan](/flags/tw.svg)

Taiwan

~80% FDA reuse

](/standards/tw)[![Flag of South Africa](/flags/za.svg)

South Africa

~80% FDA reuse

](/standards/za)[![Flag of Philippines](/flags/ph.svg)

Philippines

~80% FDA reuse

](/standards/ph)

## Frequently asked about Malaysia

### Is SBOM required for medical devices in Malaysia?

Recommended. Encouraged for higher-risk devices; mirrors IMDRF N60 expectations.

### What does MDA require for pre-market cybersecurity?

Cybersecurity description in CSDT (Common Submission Dossier Template), evidence aligned to IMDRF N60.

### What are the post-market cybersecurity obligations under MDA?

Mandatory problem reporting, field corrective action notifications.

### What is the penalty for non-compliance with MDA cybersecurity rules?

Registration cancellation; PDPA fines and criminal liability for breaches.

### How much of my FDA cybersecurity package is reusable in Malaysia?

Roughly 80% - an editorial estimate based on overlapping evidence requirements (threat model, SBOM, security risk assessment, pen-test report).

Sponsored note · Blue Goat Cyber

Submitting to MDA? Get a second pair of eyes before you file. Blue Goat Cyber has packaged cybersecurity evidence for Malaysia alongside 37 other markets. We'll tell you what to keep, what to rework, and what's missing, in 30 minutes.  [Talk through your MDA submission](https://go.bluegoatcyber.com/meetings/blue-goat-cyber/discovery-session)

The Crosswalk

An independent reference for global medical device cybersecurity standards. A field guide for MedTech innovators and RA/QA teams charting an international path.

Resource

-   [Comparison matrix](/compare)
-   [Global playbook](/playbook)
-   [Glossary](/glossary)
-   [FAQ](/faq)

Sponsored by

[Blue Goat Cyber ↗](https://bluegoatcyber.com)

Editorially independent. Sponsorship keeps it free.

© 2026 The Crosswalk. Not legal advice.

Validate every requirement against current regulator publications.