FDA Philippines
Philippines - FDA Philippines
AO 2018-0002 + FDA Circulars on SaMD and cybersecurity
Authority
Food and Drug Administration, Philippines, Center for Device Regulation, Radiation Health and Research
Enforced
2018
Legal framework
RA 9711 (FDA Act) + AO 2018-0002 + Data Privacy Act 2012
Scope
All medical devices marketed in the Philippines; SaMD scope expanding via FDA Circulars.
Pre-market
Risk-class registration; ASEAN CSDT template; FDA / CE accepted.
Post-market
Adverse-event reporting; National Privacy Commission breach notifications.
SBOM
RecommendedEncouraged for SaMD; not yet mandated.
Vulnerability disclosure
DICT-CERT coordinated disclosure recommended.
Penalty
Registration cancellation; Data Privacy Act fines and criminal liability.
Unique requirements
- 01Philippine License to Operate (LTO)
- 02Philippine Authorised Representative
- 03Filipino / English IFU and labelling
Highlights
- ASEAN CSDT template alignment
- Data Privacy Act overlay
- FDA / CE approvals accepted
Aligns with
Timeline
-
2018
AO 2018-0002 published
-
2023
SaMD and cyber circulars expanded
Key documents
How to submit in Philippines
Playbook reviewed · 2026-07-16
Submission route
Philippine FDA Certificate of Product Registration (CPR)
Philippine FDA operates a CPR route with heavy reliance on GHTF founding-member approvals for higher-risk devices.
Authority portalStep-by-step
-
Step 01
Appoint local representation
Most jurisdictions require a locally-established entity to hold the registration or act as authorised representative before submission.
-
Step 02
Reuse FDA or CE package as baseline
Adapt the cybersecurity subsection you already prepared for FDA or CE; regulators here typically accept the structure and ask for local labeling additions.
-
Step 03
Translate and localise
Local-language technical summary and labeling are usually mandatory; certified translation is safest.
-
Step 04
Submit + track queries
Respond to clarification rounds promptly; each unanswered question can add 30-90 days to the clock.
Evidence checklist
| Item | Level | FDA equivalent | Notes |
|---|---|---|---|
| Cybersecurity documentation (baseline FDA or CE) | Required | SPDF | |
| Local authorised representative agreement | Required | — | |
| Local-language labeling and IFU | Required | — | |
| SBOM | Recommended | — | Not mandatory but reduces clarification rounds. |
Common FDA-PH rejections
No Licence to Operate (LTO) for local importer
CommonFix · Ensure importer holds a valid LTO before filing.
Typical timeline
End-to-end window: 4-9 months
Phase 01
Local rep + dossier prep
2-4 months
Phase 02
Regulatory review
4-9 months
Phase 03
Approval + market entry
1-3 months
Related markets
Frequently asked about Philippines
Is SBOM required for medical devices in Philippines?
Recommended. Encouraged for SaMD; not yet mandated.
What does FDA Philippines require for pre-market cybersecurity?
Risk-class registration; ASEAN CSDT template; FDA / CE accepted.
What are the post-market cybersecurity obligations under FDA Philippines?
Adverse-event reporting; National Privacy Commission breach notifications.
What is the penalty for non-compliance with FDA Philippines cybersecurity rules?
Registration cancellation; Data Privacy Act fines and criminal liability.
How much of my FDA cybersecurity package is reusable in Philippines?
Roughly 80% - an editorial estimate based on overlapping evidence requirements (threat model, SBOM, security risk assessment, pen-test report).