---
title: "Russia Roszdravnadzor - Cybersecurity Submission Playbook"
description: "How to submit a medical device to Roszdravnadzor in Russia: step-by-step route, evidence checklist, common rejections, and typical review timeline. Compared w"
lang: en
json-ld: |
  [
    {
      "@context": "https://schema.org",
      "@type": "WebSite",
      "name": "The Medical Device Cybersecurity Crosswalk",
      "alternateName": "MDC Crosswalk",
      "url": "https://mdccrosswalk.com/",
      "description": "Compare FDA, EU MDR, MHRA, PMDA, NMPA, TGA, MFDS and Health Canada medical device cybersecurity requirements across 29 jurisdictions."
    },
    {
      "@context": "https://schema.org",
      "@type": "Organization",
      "name": "MDC Crosswalk",
      "url": "https://mdccrosswalk.com/",
      "logo": "https://mdccrosswalk.com/favicon.png",
      "sameAs": [
        "https://bluegoatcyber.com"
      ],
      "description": "An editorial reference comparing global medical-device cybersecurity regulations. Maintained by Blue Goat Cyber."
    },
    {
      "@context": "https://schema.org",
      "@type": "Article",
      "headline": "Russia - Roszdravnadzor Medical Device Registration & FSTEC/FSB Cyber Overlay (informational - sanctions apply)",
      "description": "How to submit a medical device to Roszdravnadzor in Russia: step-by-step route, evidence checklist, common rejections, and typical review timeline. Compared w",
      "author": {
        "@type": "Organization",
        "name": "MDC Crosswalk"
      },
      "publisher": {
        "@type": "Organization",
        "name": "MDC Crosswalk"
      },
      "image": "https://mdccrosswalk.lovable.app/favicon.png",
      "datePublished": "2024",
      "about": "Federal Service for Surveillance in Healthcare",
      "dateModified": "2026-07-16",
      "mainEntityOfPage": "https://mdccrosswalk.lovable.app/standards/ru"
    },
    {
      "@context": "https://schema.org",
      "@type": "FAQPage",
      "mainEntity": [
        {
          "@type": "Question",
          "name": "Is SBOM required for medical devices in Russia?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "Not specified. No statutory SBOM rule; FSTEC certification process examines components but not in machine-readable SBOM form."
          }
        },
        {
          "@type": "Question",
          "name": "What does Roszdravnadzor require for pre-market cybersecurity?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "Roszdravnadzor registration dossier with QMS (GOST ISO 13485) and technical documentation. Software safety per GOST IEC 62304. Cybersecurity assessed where the device falls under KII; FSTEC certification may be required for connected hospital systems."
          }
        },
        {
          "@type": "Question",
          "name": "What are the post-market cybersecurity obligations under Roszdravnadzor?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "Vigilance reporting to Roszdravnadzor; serious incidents within tight timelines. KII operators report incidents to GosSOPKA (NCCCI)."
          }
        },
        {
          "@type": "Question",
          "name": "What is the penalty for non-compliance with Roszdravnadzor cybersecurity rules?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "Registration suspension, market withdrawal, administrative fines and, for KII violations, criminal liability under 187-FZ."
          }
        },
        {
          "@type": "Question",
          "name": "How much of my FDA cybersecurity package is reusable in Russia?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "Roughly 35% - an editorial estimate based on overlapping evidence requirements (threat model, SBOM, security risk assessment, pen-test report)."
          }
        },
        {
          "@type": "Question",
          "name": "Why do Roszdravnadzor submissions get rejected for \"sanctions-related documentation gaps\"?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "Confirm sanctions and payment routes with local counsel before starting."
          }
        }
      ]
    },
    {
      "@context": "https://schema.org",
      "@type": "HowTo",
      "name": "How to submit a medical device to Roszdravnadzor",
      "description": "Russia continues to operate a national registration pathway alongside EAEU. Sanctions and payment-channel friction affect practical filings; verify current status with local counsel.",
      "totalTime": "9-18 months",
      "step": [
        {
          "@type": "HowToStep",
          "position": 1,
          "name": "Appoint local representation",
          "text": "Most jurisdictions require a locally-established entity to hold the registration or act as authorised representative before submission."
        },
        {
          "@type": "HowToStep",
          "position": 2,
          "name": "Reuse FDA or CE package as baseline",
          "text": "Adapt the cybersecurity subsection you already prepared for FDA or CE; regulators here typically accept the structure and ask for local labeling additions."
        },
        {
          "@type": "HowToStep",
          "position": 3,
          "name": "Translate and localise",
          "text": "Local-language technical summary and labeling are usually mandatory; certified translation is safest."
        },
        {
          "@type": "HowToStep",
          "position": 4,
          "name": "Submit + track queries",
          "text": "Respond to clarification rounds promptly; each unanswered question can add 30-90 days to the clock."
        }
      ]
    },
    {
      "@context": "https://schema.org",
      "@type": "BreadcrumbList",
      "itemListElement": [
        {
          "@type": "ListItem",
          "position": 1,
          "name": "Home",
          "item": "https://mdccrosswalk.lovable.app/"
        },
        {
          "@type": "ListItem",
          "position": 2,
          "name": "Standards"
        },
        {
          "@type": "ListItem",
          "position": 3,
          "name": "Russia"
        }
      ]
    }
  ]
---

[

The Crosswalk



](/)

[Overview](/)[Playbook](/playbook)CompareReference

[New Per-page social previews and this changelog ](/changelog "Per-page social previews and this changelog") Search⌘K

1.  [Home ](/)
2.  Standards 
3.  Russia 

Roszdravnadzor

# ![Flag of Russia](/flags/ru.svg)Russia - Roszdravnadzor 

Mandatory Last updated · 2024 Verified · 2026-07-16 

Roszdravnadzor Medical Device Registration & FSTEC/FSB Cyber Overlay (informational - sanctions apply)

Share Copy link X LinkedIn Email

Sources verified · 2026-07-16

INFORMATIONAL ONLY - RESTRICTED MARKET. Russia is subject to comprehensive OFAC / EU / UK sanctions since 2022. Commercial export of connected medical devices is heavily restricted; humanitarian general licenses cover narrow categories. This entry documents the Roszdravnadzor + FSTEC framework for completeness but is NOT a market-entry recommendation. Verify sanctions exposure with counsel before any commercial activity.

Authority

Federal Service for Surveillance in Healthcare

Enforced

2012 (Gov. Decree 1416)

Legal framework

Government Decree 1416 on medical device registration + Roszdravnadzor procedural rules; Federal Law 152-FZ on Personal Data; FSTEC/FSB cryptographic and ICT-security rules for connected devices in critical information infrastructure (Federal Law 187-FZ).

FDA package reuse

~35%

[Editorial estimate · how →](/methodology#fda-reuse)

## Scope

All medical devices placed on the Russian market. Connected devices serving healthcare critical information infrastructure (KII) fall under 187-FZ obligations including state-certified cryptography (GOST) where applicable.

Pre-market

Roszdravnadzor registration dossier with QMS (GOST ISO 13485) and technical documentation. Software safety per GOST IEC 62304. Cybersecurity assessed where the device falls under KII; FSTEC certification may be required for connected hospital systems.

Post-market

Vigilance reporting to Roszdravnadzor; serious incidents within tight timelines. KII operators report incidents to GosSOPKA (NCCCI).

SBOM

Not specified 

No statutory SBOM rule; FSTEC certification process examines components but not in machine-readable SBOM form.

Vulnerability disclosure

NCCCI (GosSOPKA) for KII operators; no medical-device-specific CVD regime.

Penalty

Registration suspension, market withdrawal, administrative fines and, for KII violations, criminal liability under 187-FZ.

## Unique requirements

-   01 Russian authorised representative 
-   02 Russian-language labelling and IFU 
-   03 GOST IEC 62304 software lifecycle compliance 
-   04 FSTEC certification path for KII-connected devices 
-   05 OFAC / EU / UK sanctions screening before any market activity 

## Highlights

-   EAEU framework available in parallel (where sanctions allow) 
-   Critical Infrastructure (KII) overlay via 187-FZ 
-   GOST cryptography requirements where KII applies 

## Aligns with

GOST ISO 13485  GOST IEC 62304  EAEU rules (parallel route) 

## Timeline

1.  2012
    
    Gov. Decree 1416 establishes registration regime
    
2.  2018
    
    Federal Law 187-FZ on Critical Information Infrastructure takes effect
    
3.  Feb 2022
    
    Comprehensive Western sanctions imposed; market access restricted
    
4.  2024
    
    FSTEC tightens cryptography rules for hospital ICT
    

## Key documents

[

Roszdravnadzor

https://roszdravnadzor.gov.ru/en



](https://roszdravnadzor.gov.ru/en)[

Government Decree 1416 (medical device registration)

http://government.ru/docs/all/85928/



](http://government.ru/docs/all/85928/)

## How to submit in Russia

Playbook reviewed · 2026-07-16

Submission route

Roszdravnadzor registration under Government Decree 1416

Russia continues to operate a national registration pathway alongside EAEU. Sanctions and payment-channel friction affect practical filings; verify current status with local counsel.

[Authority portal](https://roszdravnadzor.gov.ru/en)

### Step-by-step

1.  Step 01
    
    Appoint local representation
    
    Most jurisdictions require a locally-established entity to hold the registration or act as authorised representative before submission.
    
2.  Step 02
    
    Reuse FDA or CE package as baseline
    
    Adapt the cybersecurity subsection you already prepared for FDA or CE; regulators here typically accept the structure and ask for local labeling additions.
    
3.  Step 03
    
    Translate and localise
    
    Local-language technical summary and labeling are usually mandatory; certified translation is safest.
    
4.  Step 04
    
    Submit + track queries
    
    Respond to clarification rounds promptly; each unanswered question can add 30-90 days to the clock.
    

### Evidence checklist

Item

Level

FDA equivalent

Notes

Cybersecurity documentation (baseline FDA or CE)

Required 

SPDF

Local authorised representative agreement

Required 

—

Local-language labeling and IFU

Required 

—

SBOM

Recommended 

—

Not mandatory but reduces clarification rounds.

### Common Roszdravnadzor rejections

Sanctions-related documentation gaps

Common 

Fix ·  Confirm sanctions and payment routes with local counsel before starting.

### Typical timeline

End-to-end window: 9-18 months 

Phase 01

Local rep + dossier prep

2-4 months

Phase 02

Regulatory review

9-18 months

Phase 03

Approval + market entry

1-3 months

[Previous ![Flag of South Africa](/flags/za.svg)South Africa ](/standards/za)[Next  ![Flag of United States](/flags/us.svg)United States ](/standards/fda)

## Related markets

[![Flag of China](/flags/cn.svg)

China

~45% FDA reuse

](/standards/cn)[![Flag of Kazakhstan](/flags/kz.svg)

Kazakhstan

~45% FDA reuse

](/standards/kz)[![Flag of Switzerland](/flags/ch.svg)

Switzerland

~55% FDA reuse

](/standards/ch)[![Flag of Turkey](/flags/tr.svg)

Turkey

~55% FDA reuse

](/standards/tr)

## Frequently asked about Russia

### Is SBOM required for medical devices in Russia?

Not specified. No statutory SBOM rule; FSTEC certification process examines components but not in machine-readable SBOM form.

### What does Roszdravnadzor require for pre-market cybersecurity?

Roszdravnadzor registration dossier with QMS (GOST ISO 13485) and technical documentation. Software safety per GOST IEC 62304. Cybersecurity assessed where the device falls under KII; FSTEC certification may be required for connected hospital systems.

### What are the post-market cybersecurity obligations under Roszdravnadzor?

Vigilance reporting to Roszdravnadzor; serious incidents within tight timelines. KII operators report incidents to GosSOPKA (NCCCI).

### What is the penalty for non-compliance with Roszdravnadzor cybersecurity rules?

Registration suspension, market withdrawal, administrative fines and, for KII violations, criminal liability under 187-FZ.

### How much of my FDA cybersecurity package is reusable in Russia?

Roughly 35% - an editorial estimate based on overlapping evidence requirements (threat model, SBOM, security risk assessment, pen-test report).

Sponsored note · Blue Goat Cyber

Submitting to Roszdravnadzor? Get a second pair of eyes before you file. Blue Goat Cyber has packaged cybersecurity evidence for Russia alongside 37 other markets. We'll tell you what to keep, what to rework, and what's missing, in 30 minutes.  [Talk through your Roszdravnadzor submission](https://go.bluegoatcyber.com/meetings/blue-goat-cyber/discovery-session)

The Crosswalk

An independent reference for global medical device cybersecurity standards. A field guide for MedTech innovators and RA/QA teams charting an international path.

Resource

-   [Comparison matrix](/compare)
-   [Global playbook](/playbook)
-   [Glossary](/glossary)
-   [FAQ](/faq)

Sponsored by

[Blue Goat Cyber ↗](https://bluegoatcyber.com)

Editorially independent. Sponsorship keeps it free.

© 2026 The Crosswalk. Not legal advice.

Validate every requirement against current regulator publications.