The Crosswalk

    NewPer-page social previews and this changelog

    SFDA

    Flag of Saudi ArabiaSaudi Arabia - SFDA

    GuidanceLast updated · Aug 2025 (MDS-G027 Guidance on Digital Health Products, Version 1.0, Aug 11 2025)Verified · 2026-07-16

    SFDA Medical Device Cybersecurity Expectations (MDS-G027 Digital Health Products Guidance, Aug 2025)

    Share

    Authority

    Saudi Food and Drug Authority

    Enforced

    2022

    Legal framework

    Medical Devices Law + MDS-G42 + NCA Essential Cybersecurity Controls

    FDA package reuse

    ~85%

    Scope

    All medical devices with cybersecurity-relevant features. Reference jurisdiction model accelerates clearance.

    Pre-market

    Threat modelling, security risk management aligned to AAMI TIR57 / IEC 81001-5-1.

    Post-market

    Incident reporting to SFDA, coordinated disclosure expected.

    SBOM

    Recommended

    Encouraged, mirrors FDA approach.

    Vulnerability disclosure

    Recommended via Saudi NCA channels.

    Penalty

    Marketing authorisation withdrawal, sanctions under NCA framework.

    Unique requirements

    • 01Authorized Representative in KSA
    • 02MDMA (Medical Device Marketing Authorization)
    • 03NCA ECC overlap for healthcare entities

    Highlights

    • Closely tracks IMDRF N60 & FDA
    • Overlaps with NCA Essential Cybersecurity Controls
    • Reference jurisdiction model

    Aligns with

    IMDRF N60 FDA Feb 2026 Final Guidance IEC 81001-5-1 NCA ECC

    Timeline

    1. 2022

      MDS-G42 published

    2. Aug 11 2025

      SFDA MDS-G027 'Guidance on Digital Health Products' Version 1.0 published

    Key documents

    How to submit in Saudi Arabia

    Playbook reviewed · 2026-07-16

    Submission route

    SFDA Medical Device Marketing Authorisation (MDMA) under the Interim Regulation

    SFDA accepts GHTF founding-member approvals as prior evidence. Cybersecurity documentation is expected as part of the technical file for connected devices.

    Authority portal

    Step-by-step

    1. Step 01

      Appoint local representation

      Most jurisdictions require a locally-established entity to hold the registration or act as authorised representative before submission.

    2. Step 02

      Reuse FDA or CE package as baseline

      Adapt the cybersecurity subsection you already prepared for FDA or CE; regulators here typically accept the structure and ask for local labeling additions.

    3. Step 03

      Translate and localise

      Local-language technical summary and labeling are usually mandatory; certified translation is safest.

    4. Step 04

      Submit + track queries

      Respond to clarification rounds promptly; each unanswered question can add 30-90 days to the clock.

    Evidence checklist

    Item Level FDA equivalent Notes
    Cybersecurity documentation (baseline FDA or CE) Required SPDF
    Local authorised representative agreement Required
    Local-language labeling and IFU Required
    SBOM Recommended Not mandatory but reduces clarification rounds.

    Common SFDA rejections

    No Authorised Representative appointed

    Common

    Fix · Contract an SFDA-listed AR before submission.

    Reference GHTF approval not clearly cited

    Occasional

    Fix · Attach the FDA/CE certificate with an explicit scope table.

    Typical timeline

    End-to-end window: 4-9 months

    Phase 01

    Local rep + dossier prep

    2-4 months

    Phase 02

    Regulatory review

    4-9 months

    Phase 03

    Approval + market entry

    1-3 months

    Related markets

    Frequently asked about Saudi Arabia

    Is SBOM required for medical devices in Saudi Arabia?

    Recommended. Encouraged, mirrors FDA approach.

    What does SFDA require for pre-market cybersecurity?

    Threat modelling, security risk management aligned to AAMI TIR57 / IEC 81001-5-1.

    What are the post-market cybersecurity obligations under SFDA?

    Incident reporting to SFDA, coordinated disclosure expected.

    What is the penalty for non-compliance with SFDA cybersecurity rules?

    Marketing authorisation withdrawal, sanctions under NCA framework.

    How much of my FDA cybersecurity package is reusable in Saudi Arabia?

    Roughly 85% - an editorial estimate based on overlapping evidence requirements (threat model, SBOM, security risk assessment, pen-test report).