DMP / Helsetilsynet
Norway - DMP / Helsetilsynet
Forskrift om medisinsk utstyr (mirrors EU MDR)
Authority
Norwegian Medical Products Agency (Direktoratet for medisinske produkter)
Enforced
May 2021
Legal framework
Norwegian MD Regulation + EU MDR (via EEA) + NSM cybersecurity guidance
Scope
All medical devices marketed in Norway via EEA agreement; full EU MDR equivalence including SBOM and CRA pipeline.
Pre-market
EU MDR Annex I §17.2 evidence; Notified Body conformity assessment.
Post-market
Vigilance to DMP; NSM coordination for critical-infrastructure devices.
SBOM
RecommendedMirrors EU; CRA timeline applies via EEA.
Vulnerability disclosure
NSM NCSC coordinated disclosure recommended.
Penalty
EEA-aligned market removal and national fines.
Unique requirements
- 01Norwegian or EU Authorised Representative
- 02Norwegian-language IFU and labelling
- 03Helsetilsynet inspections
Highlights
- Full EU MDR equivalence via EEA
- NSM overlay for hospital-deployed devices
- CRA applies through EEA mechanism
Aligns with
Timeline
-
May 2021
MDR applicable via EEA
-
Sep 11 2026
CRA Art.14 reporting obligations apply via EEA mechanism
-
Dec 2027
CRA full compliance via EEA
Key documents
How to submit in Norway
Playbook reviewed · 2026-07-16
Submission route
Norwegian Medicines Agency notification under EEA/MDR
Norway applies MDR via EEA. Cybersecurity expectations mirror EU MDR / MDCG 2019-16 exactly.
Authority portalStep-by-step
-
Step 01
Appoint local representation
Most jurisdictions require a locally-established entity to hold the registration or act as authorised representative before submission.
-
Step 02
Reuse FDA or CE package as baseline
Adapt the cybersecurity subsection you already prepared for FDA or CE; regulators here typically accept the structure and ask for local labeling additions.
-
Step 03
Translate and localise
Local-language technical summary and labeling are usually mandatory; certified translation is safest.
-
Step 04
Submit + track queries
Respond to clarification rounds promptly; each unanswered question can add 30-90 days to the clock.
Evidence checklist
| Item | Level | FDA equivalent | Notes |
|---|---|---|---|
| Cybersecurity documentation (baseline FDA or CE) | Required | SPDF | |
| Local authorised representative agreement | Required | — | |
| Local-language labeling and IFU | Required | — | |
| SBOM | Recommended | — | Not mandatory but reduces clarification rounds. |
Common DMP rejections
Norwegian AR not documented for non-EEA manufacturers
OccasionalFix · Appoint an EEA AR and update labeling.
Typical timeline
End-to-end window: 0-4 weeks post-CE
Phase 01
Local rep + dossier prep
2-4 months
Phase 02
Regulatory review
0-4 weeks post-CE
Phase 03
Approval + market entry
1-3 months
Related markets
Frequently asked about Norway
Is SBOM required for medical devices in Norway?
Recommended. Mirrors EU; CRA timeline applies via EEA.
What does DMP / Helsetilsynet require for pre-market cybersecurity?
EU MDR Annex I §17.2 evidence; Notified Body conformity assessment.
What are the post-market cybersecurity obligations under DMP / Helsetilsynet?
Vigilance to DMP; NSM coordination for critical-infrastructure devices.
What is the penalty for non-compliance with DMP / Helsetilsynet cybersecurity rules?
EEA-aligned market removal and national fines.
How much of my FDA cybersecurity package is reusable in Norway?
Roughly 60% - an editorial estimate based on overlapping evidence requirements (threat model, SBOM, security risk assessment, pen-test report).