The Crosswalk

    NewPer-page social previews and this changelog

    DMP / Helsetilsynet

    Flag of NorwayNorway - DMP / Helsetilsynet

    MandatoryLast updated · 2024Verified · 2026-07-16

    Forskrift om medisinsk utstyr (mirrors EU MDR)

    Share

    Authority

    Norwegian Medical Products Agency (Direktoratet for medisinske produkter)

    Enforced

    May 2021

    Legal framework

    Norwegian MD Regulation + EU MDR (via EEA) + NSM cybersecurity guidance

    FDA package reuse

    ~60%

    Scope

    All medical devices marketed in Norway via EEA agreement; full EU MDR equivalence including SBOM and CRA pipeline.

    Pre-market

    EU MDR Annex I §17.2 evidence; Notified Body conformity assessment.

    Post-market

    Vigilance to DMP; NSM coordination for critical-infrastructure devices.

    SBOM

    Recommended

    Mirrors EU; CRA timeline applies via EEA.

    Vulnerability disclosure

    NSM NCSC coordinated disclosure recommended.

    Penalty

    EEA-aligned market removal and national fines.

    Unique requirements

    • 01Norwegian or EU Authorised Representative
    • 02Norwegian-language IFU and labelling
    • 03Helsetilsynet inspections

    Highlights

    • Full EU MDR equivalence via EEA
    • NSM overlay for hospital-deployed devices
    • CRA applies through EEA mechanism

    Aligns with

    EU MDR IEC 81001-5-1 ISO 14971

    Timeline

    1. May 2021

      MDR applicable via EEA

    2. Sep 11 2026

      CRA Art.14 reporting obligations apply via EEA mechanism

    3. Dec 2027

      CRA full compliance via EEA

    Key documents

    How to submit in Norway

    Playbook reviewed · 2026-07-16

    Submission route

    Norwegian Medicines Agency notification under EEA/MDR

    Norway applies MDR via EEA. Cybersecurity expectations mirror EU MDR / MDCG 2019-16 exactly.

    Authority portal

    Step-by-step

    1. Step 01

      Appoint local representation

      Most jurisdictions require a locally-established entity to hold the registration or act as authorised representative before submission.

    2. Step 02

      Reuse FDA or CE package as baseline

      Adapt the cybersecurity subsection you already prepared for FDA or CE; regulators here typically accept the structure and ask for local labeling additions.

    3. Step 03

      Translate and localise

      Local-language technical summary and labeling are usually mandatory; certified translation is safest.

    4. Step 04

      Submit + track queries

      Respond to clarification rounds promptly; each unanswered question can add 30-90 days to the clock.

    Evidence checklist

    Item Level FDA equivalent Notes
    Cybersecurity documentation (baseline FDA or CE) Required SPDF
    Local authorised representative agreement Required
    Local-language labeling and IFU Required
    SBOM Recommended Not mandatory but reduces clarification rounds.

    Common DMP rejections

    Norwegian AR not documented for non-EEA manufacturers

    Occasional

    Fix · Appoint an EEA AR and update labeling.

    Typical timeline

    End-to-end window: 0-4 weeks post-CE

    Phase 01

    Local rep + dossier prep

    2-4 months

    Phase 02

    Regulatory review

    0-4 weeks post-CE

    Phase 03

    Approval + market entry

    1-3 months

    Related markets

    Frequently asked about Norway

    Is SBOM required for medical devices in Norway?

    Recommended. Mirrors EU; CRA timeline applies via EEA.

    What does DMP / Helsetilsynet require for pre-market cybersecurity?

    EU MDR Annex I §17.2 evidence; Notified Body conformity assessment.

    What are the post-market cybersecurity obligations under DMP / Helsetilsynet?

    Vigilance to DMP; NSM coordination for critical-infrastructure devices.

    What is the penalty for non-compliance with DMP / Helsetilsynet cybersecurity rules?

    EEA-aligned market removal and national fines.

    How much of my FDA cybersecurity package is reusable in Norway?

    Roughly 60% - an editorial estimate based on overlapping evidence requirements (threat model, SBOM, security risk assessment, pen-test report).