The Crosswalk

    NewPer-page social previews and this changelog

    HSA

    Flag of SingaporeSingapore - HSA

    GuidanceLast updated · Dec 2025 (HSA GL-04 Revision 4: Regulatory Guidelines for Software Medical Devices including ML-Enabled Medical Devices)Verified · 2026-07-16

    Regulatory Guidelines for Software Medical Devices incl. ML-Enabled Devices (GL-04 Rev.4, Dec 2025) + Cybersecurity

    Share

    Authority

    Health Sciences Authority, Medical Devices Cluster

    Enforced

    Apr 2022 (rev.)

    Legal framework

    Health Products Act + HSA Cybersecurity Guidance + CSA Cybersecurity Act

    FDA package reuse

    ~90%

    Scope

    Standalone software medical devices and devices with software components. Reference jurisdiction route accelerates approval.

    Pre-market

    Cybersecurity by design, risk assessment, labelling, MDS supporting docs at registration; abridged route if cleared by FDA/EU/TGA/HC/PMDA.

    Post-market

    Field Safety Corrective Action (FSCA) reporting, vigilance, periodic security updates.

    SBOM

    Recommended

    Aligned to IMDRF N60; expected for higher-risk devices.

    Vulnerability disclosure

    Encouraged via CSA SingCERT.

    Penalty

    Suspension or cancellation of registration; CSA penalties for critical info infrastructure.

    Unique requirements

    • 01Singapore Registrant required
    • 02Reference jurisdiction route (FDA/EU/TGA/HC/PMDA approvals accepted)
    • 03Critical Info Infrastructure (CII) designation may apply

    Highlights

    • Aligned to IMDRF N60 & FDA
    • Reference jurisdiction abridged route
    • Strong overlap with CSA Cybersecurity Act

    Aligns with

    IMDRF N60 FDA 2023 Guidance IEC 81001-5-1

    Timeline

    1. Dec 2019

      First SaMD guidelines

    2. Apr 2022

      Cybersecurity guidance revision

    3. Dec 2025

      HSA GL-04 Revision 4 published: updated SaMD/ML-enabled device lifecycle guidance with expanded cybersecurity definitions and AI-specific requirements

    Key documents

    How to submit in Singapore

    Playbook reviewed · 2026-07-16

    Submission route

    HSA product registration under the Health Products Act, with cybersecurity per HSA Regulatory Guidelines for Software Medical Devices (2022)

    HSA operates one of Asia's most reciprocity-friendly pathways: an FDA-cleared or CE-marked device qualifies for an abridged or expedited route with substantially reduced review time.

    Authority portal

    Step-by-step

    1. Step 01

      Select evaluation route

      Full, Abridged, Expedited, or Immediate based on prior approvals from reference agencies (FDA, EU, TGA, Health Canada, PMDA).

    2. Step 02

      Prepare cybersecurity documentation

      Reuse the FDA or CE evidence; add HSA-specific labeling and Singaporean licence holder details.

    3. Step 03

      Submit via MEDICS

      HSA's online submission portal; cybersecurity documentation is part of the technical file.

    Evidence checklist

    Item Level FDA equivalent Notes
    Cybersecurity documentation per HSA SaMD guidelines Required
    Reference agency approval letter Situational Unlocks Abridged / Expedited routes.
    Singaporean registrant Required

    Common HSA rejections

    Reference agency letter is expired or scope mismatch

    Occasional

    Fix · Refresh the reference approval or use the Full evaluation route.

    Typical timeline

    End-to-end window: 1-15 months depending on route.

    Phase 01

    Immediate route

    ≤ 1 month

    Phase 02

    Expedited route

    4-6 months

    Phase 03

    Full route

    9-15 months

    Related markets

    Frequently asked about Singapore

    Is SBOM required for medical devices in Singapore?

    Recommended. Aligned to IMDRF N60; expected for higher-risk devices.

    What does HSA require for pre-market cybersecurity?

    Cybersecurity by design, risk assessment, labelling, MDS supporting docs at registration; abridged route if cleared by FDA/EU/TGA/HC/PMDA.

    What are the post-market cybersecurity obligations under HSA?

    Field Safety Corrective Action (FSCA) reporting, vigilance, periodic security updates.

    What is the penalty for non-compliance with HSA cybersecurity rules?

    Suspension or cancellation of registration; CSA penalties for critical info infrastructure.

    How much of my FDA cybersecurity package is reusable in Singapore?

    Roughly 90% - an editorial estimate based on overlapping evidence requirements (threat model, SBOM, security risk assessment, pen-test report).