SFDA
Saudi Arabia - SFDA
SFDA Medical Device Cybersecurity Expectations (MDS-G027 Digital Health Products Guidance, Aug 2025)
Authority
Saudi Food and Drug Authority
Enforced
2022
Legal framework
Medical Devices Law + MDS-G42 + NCA Essential Cybersecurity Controls
Scope
All medical devices with cybersecurity-relevant features. Reference jurisdiction model accelerates clearance.
Pre-market
Threat modelling, security risk management aligned to AAMI TIR57 / IEC 81001-5-1.
Post-market
Incident reporting to SFDA, coordinated disclosure expected.
SBOM
RecommendedEncouraged, mirrors FDA approach.
Vulnerability disclosure
Recommended via Saudi NCA channels.
Penalty
Marketing authorisation withdrawal, sanctions under NCA framework.
Unique requirements
- 01Authorized Representative in KSA
- 02MDMA (Medical Device Marketing Authorization)
- 03NCA ECC overlap for healthcare entities
Highlights
- Closely tracks IMDRF N60 & FDA
- Overlaps with NCA Essential Cybersecurity Controls
- Reference jurisdiction model
Aligns with
Timeline
-
2022
MDS-G42 published
-
Aug 11 2025
SFDA MDS-G027 'Guidance on Digital Health Products' Version 1.0 published
Key documents
How to submit in Saudi Arabia
Playbook reviewed · 2026-07-16
Submission route
SFDA Medical Device Marketing Authorisation (MDMA) under the Interim Regulation
SFDA accepts GHTF founding-member approvals as prior evidence. Cybersecurity documentation is expected as part of the technical file for connected devices.
Authority portalStep-by-step
-
Step 01
Appoint local representation
Most jurisdictions require a locally-established entity to hold the registration or act as authorised representative before submission.
-
Step 02
Reuse FDA or CE package as baseline
Adapt the cybersecurity subsection you already prepared for FDA or CE; regulators here typically accept the structure and ask for local labeling additions.
-
Step 03
Translate and localise
Local-language technical summary and labeling are usually mandatory; certified translation is safest.
-
Step 04
Submit + track queries
Respond to clarification rounds promptly; each unanswered question can add 30-90 days to the clock.
Evidence checklist
| Item | Level | FDA equivalent | Notes |
|---|---|---|---|
| Cybersecurity documentation (baseline FDA or CE) | Required | SPDF | |
| Local authorised representative agreement | Required | — | |
| Local-language labeling and IFU | Required | — | |
| SBOM | Recommended | — | Not mandatory but reduces clarification rounds. |
Common SFDA rejections
No Authorised Representative appointed
CommonFix · Contract an SFDA-listed AR before submission.
Reference GHTF approval not clearly cited
OccasionalFix · Attach the FDA/CE certificate with an explicit scope table.
Typical timeline
End-to-end window: 4-9 months
Phase 01
Local rep + dossier prep
2-4 months
Phase 02
Regulatory review
4-9 months
Phase 03
Approval + market entry
1-3 months
Related markets
Frequently asked about Saudi Arabia
Is SBOM required for medical devices in Saudi Arabia?
Recommended. Encouraged, mirrors FDA approach.
What does SFDA require for pre-market cybersecurity?
Threat modelling, security risk management aligned to AAMI TIR57 / IEC 81001-5-1.
What are the post-market cybersecurity obligations under SFDA?
Incident reporting to SFDA, coordinated disclosure expected.
What is the penalty for non-compliance with SFDA cybersecurity rules?
Marketing authorisation withdrawal, sanctions under NCA framework.
How much of my FDA cybersecurity package is reusable in Saudi Arabia?
Roughly 85% - an editorial estimate based on overlapping evidence requirements (threat model, SBOM, security risk assessment, pen-test report).