HSA
Singapore - HSA
Regulatory Guidelines for Software Medical Devices incl. ML-Enabled Devices (GL-04 Rev.4, Dec 2025) + Cybersecurity
Authority
Health Sciences Authority, Medical Devices Cluster
Enforced
Apr 2022 (rev.)
Legal framework
Health Products Act + HSA Cybersecurity Guidance + CSA Cybersecurity Act
Scope
Standalone software medical devices and devices with software components. Reference jurisdiction route accelerates approval.
Pre-market
Cybersecurity by design, risk assessment, labelling, MDS supporting docs at registration; abridged route if cleared by FDA/EU/TGA/HC/PMDA.
Post-market
Field Safety Corrective Action (FSCA) reporting, vigilance, periodic security updates.
SBOM
RecommendedAligned to IMDRF N60; expected for higher-risk devices.
Vulnerability disclosure
Encouraged via CSA SingCERT.
Penalty
Suspension or cancellation of registration; CSA penalties for critical info infrastructure.
Unique requirements
- 01Singapore Registrant required
- 02Reference jurisdiction route (FDA/EU/TGA/HC/PMDA approvals accepted)
- 03Critical Info Infrastructure (CII) designation may apply
Highlights
- Aligned to IMDRF N60 & FDA
- Reference jurisdiction abridged route
- Strong overlap with CSA Cybersecurity Act
Aligns with
Timeline
-
Dec 2019
First SaMD guidelines
-
Apr 2022
Cybersecurity guidance revision
-
Dec 2025
HSA GL-04 Revision 4 published: updated SaMD/ML-enabled device lifecycle guidance with expanded cybersecurity definitions and AI-specific requirements
Key documents
How to submit in Singapore
Playbook reviewed · 2026-07-16
Submission route
HSA product registration under the Health Products Act, with cybersecurity per HSA Regulatory Guidelines for Software Medical Devices (2022)
HSA operates one of Asia's most reciprocity-friendly pathways: an FDA-cleared or CE-marked device qualifies for an abridged or expedited route with substantially reduced review time.
Authority portalStep-by-step
-
Step 01
Select evaluation route
Full, Abridged, Expedited, or Immediate based on prior approvals from reference agencies (FDA, EU, TGA, Health Canada, PMDA).
-
Step 02
Prepare cybersecurity documentation
Reuse the FDA or CE evidence; add HSA-specific labeling and Singaporean licence holder details.
-
Step 03
Submit via MEDICS
HSA's online submission portal; cybersecurity documentation is part of the technical file.
Evidence checklist
| Item | Level | FDA equivalent | Notes |
|---|---|---|---|
| Cybersecurity documentation per HSA SaMD guidelines | Required | — | |
| Reference agency approval letter | Situational | — | Unlocks Abridged / Expedited routes. |
| Singaporean registrant | Required | — |
Common HSA rejections
Reference agency letter is expired or scope mismatch
OccasionalFix · Refresh the reference approval or use the Full evaluation route.
Typical timeline
End-to-end window: 1-15 months depending on route.
Phase 01
Immediate route
≤ 1 month
Phase 02
Expedited route
4-6 months
Phase 03
Full route
9-15 months
Related markets
Frequently asked about Singapore
Is SBOM required for medical devices in Singapore?
Recommended. Aligned to IMDRF N60; expected for higher-risk devices.
What does HSA require for pre-market cybersecurity?
Cybersecurity by design, risk assessment, labelling, MDS supporting docs at registration; abridged route if cleared by FDA/EU/TGA/HC/PMDA.
What are the post-market cybersecurity obligations under HSA?
Field Safety Corrective Action (FSCA) reporting, vigilance, periodic security updates.
What is the penalty for non-compliance with HSA cybersecurity rules?
Suspension or cancellation of registration; CSA penalties for critical info infrastructure.
How much of my FDA cybersecurity package is reusable in Singapore?
Roughly 90% - an editorial estimate based on overlapping evidence requirements (threat model, SBOM, security risk assessment, pen-test report).