---
title: "Norway DMP - Cybersecurity Submission Playbook"
description: "How to submit a medical device to DMP / Helsetilsynet in Norway: step-by-step route, evidence checklist, common rejections, and typical review timeline. Compa"
lang: en
json-ld: |
  [
    {
      "@context": "https://schema.org",
      "@type": "WebSite",
      "name": "The Medical Device Cybersecurity Crosswalk",
      "alternateName": "MDC Crosswalk",
      "url": "https://mdccrosswalk.com/",
      "description": "Compare FDA, EU MDR, MHRA, PMDA, NMPA, TGA, MFDS and Health Canada medical device cybersecurity requirements across 29 jurisdictions."
    },
    {
      "@context": "https://schema.org",
      "@type": "Organization",
      "name": "MDC Crosswalk",
      "url": "https://mdccrosswalk.com/",
      "logo": "https://mdccrosswalk.com/favicon.png",
      "sameAs": [
        "https://bluegoatcyber.com"
      ],
      "description": "An editorial reference comparing global medical-device cybersecurity regulations. Maintained by Blue Goat Cyber."
    },
    {
      "@context": "https://schema.org",
      "@type": "Article",
      "headline": "Norway - Forskrift om medisinsk utstyr (mirrors EU MDR)",
      "description": "How to submit a medical device to DMP / Helsetilsynet in Norway: step-by-step route, evidence checklist, common rejections, and typical review timeline. Compa",
      "author": {
        "@type": "Organization",
        "name": "MDC Crosswalk"
      },
      "publisher": {
        "@type": "Organization",
        "name": "MDC Crosswalk"
      },
      "image": "https://mdccrosswalk.lovable.app/favicon.png",
      "datePublished": "2024",
      "about": "Norwegian Medical Products Agency (Direktoratet for medisinske produkter)",
      "dateModified": "2026-07-16",
      "mainEntityOfPage": "https://mdccrosswalk.lovable.app/standards/no"
    },
    {
      "@context": "https://schema.org",
      "@type": "FAQPage",
      "mainEntity": [
        {
          "@type": "Question",
          "name": "Is SBOM required for medical devices in Norway?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "Recommended. Mirrors EU; CRA timeline applies via EEA."
          }
        },
        {
          "@type": "Question",
          "name": "What does DMP / Helsetilsynet require for pre-market cybersecurity?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "EU MDR Annex I §17.2 evidence; Notified Body conformity assessment."
          }
        },
        {
          "@type": "Question",
          "name": "What are the post-market cybersecurity obligations under DMP / Helsetilsynet?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "Vigilance to DMP; NSM coordination for critical-infrastructure devices."
          }
        },
        {
          "@type": "Question",
          "name": "What is the penalty for non-compliance with DMP / Helsetilsynet cybersecurity rules?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "EEA-aligned market removal and national fines."
          }
        },
        {
          "@type": "Question",
          "name": "How much of my FDA cybersecurity package is reusable in Norway?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "Roughly 60% - an editorial estimate based on overlapping evidence requirements (threat model, SBOM, security risk assessment, pen-test report)."
          }
        },
        {
          "@type": "Question",
          "name": "Why do DMP submissions get rejected for \"norwegian ar not documented for non-eea manufacturers\"?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "Appoint an EEA AR and update labeling."
          }
        }
      ]
    },
    {
      "@context": "https://schema.org",
      "@type": "HowTo",
      "name": "How to submit a medical device to DMP / Helsetilsynet",
      "description": "Norway applies MDR via EEA. Cybersecurity expectations mirror EU MDR / MDCG 2019-16 exactly.",
      "totalTime": "0-4 weeks post-CE",
      "step": [
        {
          "@type": "HowToStep",
          "position": 1,
          "name": "Appoint local representation",
          "text": "Most jurisdictions require a locally-established entity to hold the registration or act as authorised representative before submission."
        },
        {
          "@type": "HowToStep",
          "position": 2,
          "name": "Reuse FDA or CE package as baseline",
          "text": "Adapt the cybersecurity subsection you already prepared for FDA or CE; regulators here typically accept the structure and ask for local labeling additions."
        },
        {
          "@type": "HowToStep",
          "position": 3,
          "name": "Translate and localise",
          "text": "Local-language technical summary and labeling are usually mandatory; certified translation is safest."
        },
        {
          "@type": "HowToStep",
          "position": 4,
          "name": "Submit + track queries",
          "text": "Respond to clarification rounds promptly; each unanswered question can add 30-90 days to the clock."
        }
      ]
    },
    {
      "@context": "https://schema.org",
      "@type": "BreadcrumbList",
      "itemListElement": [
        {
          "@type": "ListItem",
          "position": 1,
          "name": "Home",
          "item": "https://mdccrosswalk.lovable.app/"
        },
        {
          "@type": "ListItem",
          "position": 2,
          "name": "Standards"
        },
        {
          "@type": "ListItem",
          "position": 3,
          "name": "Norway"
        }
      ]
    }
  ]
---

[

The Crosswalk



](/)

[Overview](/)[Playbook](/playbook)CompareReference

[New Per-page social previews and this changelog ](/changelog "Per-page social previews and this changelog") Search⌘K

1.  [Home ](/)
2.  Standards 
3.  Norway 

DMP / Helsetilsynet

# ![Flag of Norway](/flags/no.svg)Norway - DMP / Helsetilsynet 

Mandatory Last updated · 2024 Verified · 2026-07-16 

Forskrift om medisinsk utstyr (mirrors EU MDR)

Share Copy link X LinkedIn Email

Sources verified · 2026-07-16

Norway applies EU MDR via EEA; cross-checked against DMP guidance.

Authority

Norwegian Medical Products Agency (Direktoratet for medisinske produkter)

Enforced

May 2021

Legal framework

Norwegian MD Regulation + EU MDR (via EEA) + NSM cybersecurity guidance

FDA package reuse

~60%

[Editorial estimate · how →](/methodology#fda-reuse)

## Scope

All medical devices marketed in Norway via EEA agreement; full EU MDR equivalence including SBOM and CRA pipeline.

Pre-market

EU MDR Annex I §17.2 evidence; Notified Body conformity assessment.

Post-market

Vigilance to DMP; NSM coordination for critical-infrastructure devices.

SBOM

Recommended 

Mirrors EU; CRA timeline applies via EEA.

Vulnerability disclosure

NSM NCSC coordinated disclosure recommended.

Penalty

EEA-aligned market removal and national fines.

## Unique requirements

-   01 Norwegian or EU Authorised Representative 
-   02 Norwegian-language IFU and labelling 
-   03 Helsetilsynet inspections 

## Highlights

-   Full EU MDR equivalence via EEA 
-   NSM overlay for hospital-deployed devices 
-   CRA applies through EEA mechanism 

## Aligns with

EU MDR  IEC 81001-5-1  ISO 14971 

## Timeline

1.  May 2021
    
    MDR applicable via EEA
    
2.  Sep 11 2026
    
    CRA Art.14 reporting obligations apply via EEA mechanism
    
3.  Dec 2027
    
    CRA full compliance via EEA
    

## Key documents

[

DMP Medical Devices

https://www.dmp.no/en/medical-devices



](https://www.dmp.no/en/medical-devices)

## How to submit in Norway

Playbook reviewed · 2026-07-16

Submission route

Norwegian Medicines Agency notification under EEA/MDR

Norway applies MDR via EEA. Cybersecurity expectations mirror EU MDR / MDCG 2019-16 exactly.

[Authority portal](https://legemiddelverket.no/english/medical-devices)

### Step-by-step

1.  Step 01
    
    Appoint local representation
    
    Most jurisdictions require a locally-established entity to hold the registration or act as authorised representative before submission.
    
2.  Step 02
    
    Reuse FDA or CE package as baseline
    
    Adapt the cybersecurity subsection you already prepared for FDA or CE; regulators here typically accept the structure and ask for local labeling additions.
    
3.  Step 03
    
    Translate and localise
    
    Local-language technical summary and labeling are usually mandatory; certified translation is safest.
    
4.  Step 04
    
    Submit + track queries
    
    Respond to clarification rounds promptly; each unanswered question can add 30-90 days to the clock.
    

### Evidence checklist

Item

Level

FDA equivalent

Notes

Cybersecurity documentation (baseline FDA or CE)

Required 

SPDF

Local authorised representative agreement

Required 

—

Local-language labeling and IFU

Required 

—

SBOM

Recommended 

—

Not mandatory but reduces clarification rounds.

### Common DMP rejections

Norwegian AR not documented for non-EEA manufacturers

Occasional 

Fix ·  Appoint an EEA AR and update labeling.

### Typical timeline

End-to-end window: 0-4 weeks post-CE 

Phase 01

Local rep + dossier prep

2-4 months

Phase 02

Regulatory review

0-4 weeks post-CE

Phase 03

Approval + market entry

1-3 months

[Previous ![Flag of Turkey](/flags/tr.svg)Turkey ](/standards/tr)[Next  ![Flag of Colombia](/flags/co.svg)Colombia ](/standards/co)

## Related markets

[![Flag of European Union](/flags/eu.svg)

European Union

~60% FDA reuse

](/standards/eu)[![Flag of Brazil](/flags/br.svg)

Brazil

~60% FDA reuse

](/standards/br)[![Flag of South Korea](/flags/kr.svg)

South Korea

~65% FDA reuse

](/standards/kr)[![Flag of Switzerland](/flags/ch.svg)

Switzerland

~55% FDA reuse

](/standards/ch)

## Frequently asked about Norway

### Is SBOM required for medical devices in Norway?

Recommended. Mirrors EU; CRA timeline applies via EEA.

### What does DMP / Helsetilsynet require for pre-market cybersecurity?

EU MDR Annex I §17.2 evidence; Notified Body conformity assessment.

### What are the post-market cybersecurity obligations under DMP / Helsetilsynet?

Vigilance to DMP; NSM coordination for critical-infrastructure devices.

### What is the penalty for non-compliance with DMP / Helsetilsynet cybersecurity rules?

EEA-aligned market removal and national fines.

### How much of my FDA cybersecurity package is reusable in Norway?

Roughly 60% - an editorial estimate based on overlapping evidence requirements (threat model, SBOM, security risk assessment, pen-test report).

Sponsored note · Blue Goat Cyber

Submitting to DMP / Helsetilsynet? Get a second pair of eyes before you file. Blue Goat Cyber has packaged cybersecurity evidence for Norway alongside 37 other markets. We'll tell you what to keep, what to rework, and what's missing, in 30 minutes.  [Talk through your DMP submission](https://go.bluegoatcyber.com/meetings/blue-goat-cyber/discovery-session)

The Crosswalk

An independent reference for global medical device cybersecurity standards. A field guide for MedTech innovators and RA/QA teams charting an international path.

Resource

-   [Comparison matrix](/compare)
-   [Global playbook](/playbook)
-   [Glossary](/glossary)
-   [FAQ](/faq)

Sponsored by

[Blue Goat Cyber ↗](https://bluegoatcyber.com)

Editorially independent. Sponsorship keeps it free.

© 2026 The Crosswalk. Not legal advice.

Validate every requirement against current regulator publications.