---
title: "Saudi Arabia SFDA - Cybersecurity Submission Playbook"
description: "How to submit a medical device to SFDA in Saudi Arabia: step-by-step route, evidence checklist, common rejections, and typical review timeline. Compared with"
lang: en
json-ld: |
  [
    {
      "@context": "https://schema.org",
      "@type": "WebSite",
      "name": "The Medical Device Cybersecurity Crosswalk",
      "alternateName": "MDC Crosswalk",
      "url": "https://mdccrosswalk.com/",
      "description": "Compare FDA, EU MDR, MHRA, PMDA, NMPA, TGA, MFDS and Health Canada medical device cybersecurity requirements across 29 jurisdictions."
    },
    {
      "@context": "https://schema.org",
      "@type": "Organization",
      "name": "MDC Crosswalk",
      "url": "https://mdccrosswalk.com/",
      "logo": "https://mdccrosswalk.com/favicon.png",
      "sameAs": [
        "https://bluegoatcyber.com"
      ],
      "description": "An editorial reference comparing global medical-device cybersecurity regulations. Maintained by Blue Goat Cyber."
    },
    {
      "@context": "https://schema.org",
      "@type": "Article",
      "headline": "Saudi Arabia - SFDA Medical Device Cybersecurity Expectations (MDS-G027 Digital Health Products Guidance, Aug 2025)",
      "description": "How to submit a medical device to SFDA in Saudi Arabia: step-by-step route, evidence checklist, common rejections, and typical review timeline. Compared with ",
      "author": {
        "@type": "Organization",
        "name": "MDC Crosswalk"
      },
      "publisher": {
        "@type": "Organization",
        "name": "MDC Crosswalk"
      },
      "image": "https://mdccrosswalk.lovable.app/favicon.png",
      "datePublished": "Aug 2025 (MDS-G027 Guidance on Digital Health Products, Version 1.0, Aug 11 2025)",
      "about": "Saudi Food and Drug Authority",
      "dateModified": "2026-07-16",
      "mainEntityOfPage": "https://mdccrosswalk.lovable.app/standards/sa"
    },
    {
      "@context": "https://schema.org",
      "@type": "FAQPage",
      "mainEntity": [
        {
          "@type": "Question",
          "name": "Is SBOM required for medical devices in Saudi Arabia?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "Recommended. Encouraged, mirrors FDA approach."
          }
        },
        {
          "@type": "Question",
          "name": "What does SFDA require for pre-market cybersecurity?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "Threat modelling, security risk management aligned to AAMI TIR57 / IEC 81001-5-1."
          }
        },
        {
          "@type": "Question",
          "name": "What are the post-market cybersecurity obligations under SFDA?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "Incident reporting to SFDA, coordinated disclosure expected."
          }
        },
        {
          "@type": "Question",
          "name": "What is the penalty for non-compliance with SFDA cybersecurity rules?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "Marketing authorisation withdrawal, sanctions under NCA framework."
          }
        },
        {
          "@type": "Question",
          "name": "How much of my FDA cybersecurity package is reusable in Saudi Arabia?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "Roughly 85% - an editorial estimate based on overlapping evidence requirements (threat model, SBOM, security risk assessment, pen-test report)."
          }
        },
        {
          "@type": "Question",
          "name": "Why do SFDA submissions get rejected for \"no authorised representative appointed\"?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "Contract an SFDA-listed AR before submission."
          }
        },
        {
          "@type": "Question",
          "name": "Why do SFDA submissions get rejected for \"reference ghtf approval not clearly cited\"?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "Attach the FDA/CE certificate with an explicit scope table."
          }
        }
      ]
    },
    {
      "@context": "https://schema.org",
      "@type": "HowTo",
      "name": "How to submit a medical device to SFDA",
      "description": "SFDA accepts GHTF founding-member approvals as prior evidence. Cybersecurity documentation is expected as part of the technical file for connected devices.",
      "totalTime": "4-9 months",
      "step": [
        {
          "@type": "HowToStep",
          "position": 1,
          "name": "Appoint local representation",
          "text": "Most jurisdictions require a locally-established entity to hold the registration or act as authorised representative before submission."
        },
        {
          "@type": "HowToStep",
          "position": 2,
          "name": "Reuse FDA or CE package as baseline",
          "text": "Adapt the cybersecurity subsection you already prepared for FDA or CE; regulators here typically accept the structure and ask for local labeling additions."
        },
        {
          "@type": "HowToStep",
          "position": 3,
          "name": "Translate and localise",
          "text": "Local-language technical summary and labeling are usually mandatory; certified translation is safest."
        },
        {
          "@type": "HowToStep",
          "position": 4,
          "name": "Submit + track queries",
          "text": "Respond to clarification rounds promptly; each unanswered question can add 30-90 days to the clock."
        }
      ]
    },
    {
      "@context": "https://schema.org",
      "@type": "BreadcrumbList",
      "itemListElement": [
        {
          "@type": "ListItem",
          "position": 1,
          "name": "Home",
          "item": "https://mdccrosswalk.lovable.app/"
        },
        {
          "@type": "ListItem",
          "position": 2,
          "name": "Standards"
        },
        {
          "@type": "ListItem",
          "position": 3,
          "name": "Saudi Arabia"
        }
      ]
    }
  ]
---

[

The Crosswalk



](/)

[Overview](/)[Playbook](/playbook)CompareReference

[New Per-page social previews and this changelog ](/changelog "Per-page social previews and this changelog") Search⌘K

1.  [Home ](/)
2.  Standards 
3.  Saudi Arabia 

SFDA

# ![Flag of Saudi Arabia](/flags/sa.svg)Saudi Arabia - SFDA 

Guidance Last updated · Aug 2025 (MDS-G027 Guidance on Digital Health Products, Version 1.0, Aug 11 2025) Verified · 2026-07-16 

SFDA Medical Device Cybersecurity Expectations (MDS-G027 Digital Health Products Guidance, Aug 2025)

Share Copy link X LinkedIn Email

Sources verified · 2026-07-16

SFDA MDS-G42 reviewed; binding force vs. guidance status awaiting RA SME review.

Authority

Saudi Food and Drug Authority

Enforced

2022

Legal framework

Medical Devices Law + MDS-G42 + NCA Essential Cybersecurity Controls

FDA package reuse

~85%

[Editorial estimate · how →](/methodology#fda-reuse)

## Scope

All medical devices with cybersecurity-relevant features. Reference jurisdiction model accelerates clearance.

Pre-market

Threat modelling, security risk management aligned to AAMI TIR57 / IEC 81001-5-1.

Post-market

Incident reporting to SFDA, coordinated disclosure expected.

SBOM

Recommended 

Encouraged, mirrors FDA approach.

Vulnerability disclosure

Recommended via Saudi NCA channels.

Penalty

Marketing authorisation withdrawal, sanctions under NCA framework.

## Unique requirements

-   01 Authorized Representative in KSA 
-   02 MDMA (Medical Device Marketing Authorization) 
-   03 NCA ECC overlap for healthcare entities 

## Highlights

-   Closely tracks IMDRF N60 & FDA 
-   Overlaps with NCA Essential Cybersecurity Controls 
-   Reference jurisdiction model 

## Aligns with

IMDRF N60  FDA Feb 2026 Final Guidance  IEC 81001-5-1  NCA ECC 

## Timeline

1.  2022
    
    MDS-G42 published
    
2.  Aug 11 2025
    
    SFDA MDS-G027 'Guidance on Digital Health Products' Version 1.0 published
    

## Key documents

[

SFDA Medical Devices Regulations Hub

https://www.sfda.gov.sa/en/regulations



](https://www.sfda.gov.sa/en/regulations)[

SFDA MDS-G027 Guidance on Digital Health Products (Aug 2025)

https://www.sfda.gov.sa/sites/default/files/2025-08/MDS-G027.pdf



](https://www.sfda.gov.sa/sites/default/files/2025-08/MDS-G027.pdf)

## How to submit in Saudi Arabia

Playbook reviewed · 2026-07-16

Submission route

SFDA Medical Device Marketing Authorisation (MDMA) under the Interim Regulation

SFDA accepts GHTF founding-member approvals as prior evidence. Cybersecurity documentation is expected as part of the technical file for connected devices.

[Authority portal](https://www.sfda.gov.sa/en/medicaldevices)

### Step-by-step

1.  Step 01
    
    Appoint local representation
    
    Most jurisdictions require a locally-established entity to hold the registration or act as authorised representative before submission.
    
2.  Step 02
    
    Reuse FDA or CE package as baseline
    
    Adapt the cybersecurity subsection you already prepared for FDA or CE; regulators here typically accept the structure and ask for local labeling additions.
    
3.  Step 03
    
    Translate and localise
    
    Local-language technical summary and labeling are usually mandatory; certified translation is safest.
    
4.  Step 04
    
    Submit + track queries
    
    Respond to clarification rounds promptly; each unanswered question can add 30-90 days to the clock.
    

### Evidence checklist

Item

Level

FDA equivalent

Notes

Cybersecurity documentation (baseline FDA or CE)

Required 

SPDF

Local authorised representative agreement

Required 

—

Local-language labeling and IFU

Required 

—

SBOM

Recommended 

—

Not mandatory but reduces clarification rounds.

### Common SFDA rejections

No Authorised Representative appointed

Common 

Fix ·  Contract an SFDA-listed AR before submission.

Reference GHTF approval not clearly cited

Occasional 

Fix ·  Attach the FDA/CE certificate with an explicit scope table.

### Typical timeline

End-to-end window: 4-9 months 

Phase 01

Local rep + dossier prep

2-4 months

Phase 02

Regulatory review

4-9 months

Phase 03

Approval + market entry

1-3 months

[Previous ![Flag of Brazil](/flags/br.svg)Brazil ](/standards/br)[Next  ![Flag of Switzerland](/flags/ch.svg)Switzerland ](/standards/ch)

## Related markets

[![Flag of Australia](/flags/au.svg)

Australia

~85% FDA reuse

](/standards/au)[![Flag of Argentina](/flags/ar.svg)

Argentina

~85% FDA reuse

](/standards/ar)[![Flag of Colombia](/flags/co.svg)

Colombia

~85% FDA reuse

](/standards/co)[![Flag of Taiwan](/flags/tw.svg)

Taiwan

~85% FDA reuse

](/standards/tw)

## Frequently asked about Saudi Arabia

### Is SBOM required for medical devices in Saudi Arabia?

Recommended. Encouraged, mirrors FDA approach.

### What does SFDA require for pre-market cybersecurity?

Threat modelling, security risk management aligned to AAMI TIR57 / IEC 81001-5-1.

### What are the post-market cybersecurity obligations under SFDA?

Incident reporting to SFDA, coordinated disclosure expected.

### What is the penalty for non-compliance with SFDA cybersecurity rules?

Marketing authorisation withdrawal, sanctions under NCA framework.

### How much of my FDA cybersecurity package is reusable in Saudi Arabia?

Roughly 85% - an editorial estimate based on overlapping evidence requirements (threat model, SBOM, security risk assessment, pen-test report).

Sponsored note · Blue Goat Cyber

Submitting to SFDA? Get a second pair of eyes before you file. Blue Goat Cyber has packaged cybersecurity evidence for Saudi Arabia alongside 37 other markets. We'll tell you what to keep, what to rework, and what's missing, in 30 minutes.  [Talk through your SFDA submission](https://go.bluegoatcyber.com/meetings/blue-goat-cyber/discovery-session)

The Crosswalk

An independent reference for global medical device cybersecurity standards. A field guide for MedTech innovators and RA/QA teams charting an international path.

Resource

-   [Comparison matrix](/compare)
-   [Global playbook](/playbook)
-   [Glossary](/glossary)
-   [FAQ](/faq)

Sponsored by

[Blue Goat Cyber ↗](https://bluegoatcyber.com)

Editorially independent. Sponsorship keeps it free.

© 2026 The Crosswalk. Not legal advice.

Validate every requirement against current regulator publications.