---
title: "Singapore HSA - Cybersecurity Submission Playbook"
description: "How to submit a medical device to HSA in Singapore: step-by-step route, evidence checklist, common rejections, and typical review timeline. Compared with FDA"
lang: en
json-ld: |
  [
    {
      "@context": "https://schema.org",
      "@type": "WebSite",
      "name": "The Medical Device Cybersecurity Crosswalk",
      "alternateName": "MDC Crosswalk",
      "url": "https://mdccrosswalk.com/",
      "description": "Compare FDA, EU MDR, MHRA, PMDA, NMPA, TGA, MFDS and Health Canada medical device cybersecurity requirements across 29 jurisdictions."
    },
    {
      "@context": "https://schema.org",
      "@type": "Organization",
      "name": "MDC Crosswalk",
      "url": "https://mdccrosswalk.com/",
      "logo": "https://mdccrosswalk.com/favicon.png",
      "sameAs": [
        "https://bluegoatcyber.com"
      ],
      "description": "An editorial reference comparing global medical-device cybersecurity regulations. Maintained by Blue Goat Cyber."
    },
    {
      "@context": "https://schema.org",
      "@type": "Article",
      "headline": "Singapore - Regulatory Guidelines for Software Medical Devices incl. ML-Enabled Devices (GL-04 Rev.4, Dec 2025) + Cybersecurity",
      "description": "How to submit a medical device to HSA in Singapore: step-by-step route, evidence checklist, common rejections, and typical review timeline. Compared with FDA ",
      "author": {
        "@type": "Organization",
        "name": "MDC Crosswalk"
      },
      "publisher": {
        "@type": "Organization",
        "name": "MDC Crosswalk"
      },
      "image": "https://mdccrosswalk.lovable.app/favicon.png",
      "datePublished": "Dec 2025 (HSA GL-04 Revision 4: Regulatory Guidelines for Software Medical Devices including ML-Enabled Medical Devices)",
      "about": "Health Sciences Authority, Medical Devices Cluster",
      "dateModified": "2026-07-16",
      "mainEntityOfPage": "https://mdccrosswalk.lovable.app/standards/sg"
    },
    {
      "@context": "https://schema.org",
      "@type": "FAQPage",
      "mainEntity": [
        {
          "@type": "Question",
          "name": "Is SBOM required for medical devices in Singapore?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "Recommended. Aligned to IMDRF N60; expected for higher-risk devices."
          }
        },
        {
          "@type": "Question",
          "name": "What does HSA require for pre-market cybersecurity?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "Cybersecurity by design, risk assessment, labelling, MDS supporting docs at registration; abridged route if cleared by FDA/EU/TGA/HC/PMDA."
          }
        },
        {
          "@type": "Question",
          "name": "What are the post-market cybersecurity obligations under HSA?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "Field Safety Corrective Action (FSCA) reporting, vigilance, periodic security updates."
          }
        },
        {
          "@type": "Question",
          "name": "What is the penalty for non-compliance with HSA cybersecurity rules?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "Suspension or cancellation of registration; CSA penalties for critical info infrastructure."
          }
        },
        {
          "@type": "Question",
          "name": "How much of my FDA cybersecurity package is reusable in Singapore?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "Roughly 90% - an editorial estimate based on overlapping evidence requirements (threat model, SBOM, security risk assessment, pen-test report)."
          }
        },
        {
          "@type": "Question",
          "name": "Why do HSA submissions get rejected for \"reference agency letter is expired or scope mismatch\"?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "Refresh the reference approval or use the Full evaluation route."
          }
        }
      ]
    },
    {
      "@context": "https://schema.org",
      "@type": "HowTo",
      "name": "How to submit a medical device to HSA",
      "description": "HSA operates one of Asia's most reciprocity-friendly pathways: an FDA-cleared or CE-marked device qualifies for an abridged or expedited route with substantially reduced review time.",
      "totalTime": "1-15 months depending on route.",
      "step": [
        {
          "@type": "HowToStep",
          "position": 1,
          "name": "Select evaluation route",
          "text": "Full, Abridged, Expedited, or Immediate based on prior approvals from reference agencies (FDA, EU, TGA, Health Canada, PMDA)."
        },
        {
          "@type": "HowToStep",
          "position": 2,
          "name": "Prepare cybersecurity documentation",
          "text": "Reuse the FDA or CE evidence; add HSA-specific labeling and Singaporean licence holder details."
        },
        {
          "@type": "HowToStep",
          "position": 3,
          "name": "Submit via MEDICS",
          "text": "HSA's online submission portal; cybersecurity documentation is part of the technical file."
        }
      ]
    },
    {
      "@context": "https://schema.org",
      "@type": "BreadcrumbList",
      "itemListElement": [
        {
          "@type": "ListItem",
          "position": 1,
          "name": "Home",
          "item": "https://mdccrosswalk.lovable.app/"
        },
        {
          "@type": "ListItem",
          "position": 2,
          "name": "Standards"
        },
        {
          "@type": "ListItem",
          "position": 3,
          "name": "Singapore"
        }
      ]
    }
  ]
---

[

The Crosswalk



](/)

[Overview](/)[Playbook](/playbook)CompareReference

[New Per-page social previews and this changelog ](/changelog "Per-page social previews and this changelog") Search⌘K

1.  [Home ](/)
2.  Standards 
3.  Singapore 

HSA

# ![Flag of Singapore](/flags/sg.svg)Singapore - HSA 

Guidance Last updated · Dec 2025 (HSA GL-04 Revision 4: Regulatory Guidelines for Software Medical Devices including ML-Enabled Medical Devices) Verified · 2026-07-16 

Regulatory Guidelines for Software Medical Devices incl. ML-Enabled Devices (GL-04 Rev.4, Dec 2025) + Cybersecurity

Share Copy link X LinkedIn Email

Sources verified · 2026-07-16

HSA cybersecurity expectations are issued as guidance, not standalone statute.

Authority

Health Sciences Authority, Medical Devices Cluster

Enforced

Apr 2022 (rev.)

Legal framework

Health Products Act + HSA Cybersecurity Guidance + CSA Cybersecurity Act

FDA package reuse

~90%

[Editorial estimate · how →](/methodology#fda-reuse)

## Scope

Standalone software medical devices and devices with software components. Reference jurisdiction route accelerates approval.

Pre-market

Cybersecurity by design, risk assessment, labelling, MDS supporting docs at registration; abridged route if cleared by FDA/EU/TGA/HC/PMDA.

Post-market

Field Safety Corrective Action (FSCA) reporting, vigilance, periodic security updates.

SBOM

Recommended 

Aligned to IMDRF N60; expected for higher-risk devices.

Vulnerability disclosure

Encouraged via CSA SingCERT.

Penalty

Suspension or cancellation of registration; CSA penalties for critical info infrastructure.

## Unique requirements

-   01 Singapore Registrant required 
-   02 Reference jurisdiction route (FDA/EU/TGA/HC/PMDA approvals accepted) 
-   03 Critical Info Infrastructure (CII) designation may apply 

## Highlights

-   Aligned to IMDRF N60 & FDA 
-   Reference jurisdiction abridged route 
-   Strong overlap with CSA Cybersecurity Act 

## Aligns with

IMDRF N60  FDA 2023 Guidance  IEC 81001-5-1 

## Timeline

1.  Dec 2019
    
    First SaMD guidelines
    
2.  Apr 2022
    
    Cybersecurity guidance revision
    
3.  Dec 2025
    
    HSA GL-04 Revision 4 published: updated SaMD/ML-enabled device lifecycle guidance with expanded cybersecurity definitions and AI-specific requirements
    

## Key documents

[

HSA Regulatory Guidelines for Software Medical Devices

https://www.hsa.gov.sg/medical-devices/guidance-documents



](https://www.hsa.gov.sg/medical-devices/guidance-documents)[

CSA Singapore Cybersecurity Act

https://www.csa.gov.sg/legislation/cybersecurity-act



](https://www.csa.gov.sg/legislation/cybersecurity-act)

## How to submit in Singapore

Playbook reviewed · 2026-07-16

Submission route

HSA product registration under the Health Products Act, with cybersecurity per HSA Regulatory Guidelines for Software Medical Devices (2022)

HSA operates one of Asia's most reciprocity-friendly pathways: an FDA-cleared or CE-marked device qualifies for an abridged or expedited route with substantially reduced review time.

[Authority portal](https://www.hsa.gov.sg/medical-devices)

### Step-by-step

1.  Step 01
    
    Select evaluation route
    
    Full, Abridged, Expedited, or Immediate based on prior approvals from reference agencies (FDA, EU, TGA, Health Canada, PMDA).
    
2.  Step 02
    
    Prepare cybersecurity documentation
    
    Reuse the FDA or CE evidence; add HSA-specific labeling and Singaporean licence holder details.
    
3.  Step 03
    
    Submit via MEDICS
    
    HSA's online submission portal; cybersecurity documentation is part of the technical file.
    

### Evidence checklist

Item

Level

FDA equivalent

Notes

Cybersecurity documentation per HSA SaMD guidelines

Required 

—

Reference agency approval letter

Situational 

—

Unlocks Abridged / Expedited routes.

Singaporean registrant

Required 

—

### Common HSA rejections

Reference agency letter is expired or scope mismatch

Occasional 

Fix ·  Refresh the reference approval or use the Full evaluation route.

### Typical timeline

End-to-end window: 1-15 months depending on route. 

Phase 01

Immediate route

≤ 1 month

Phase 02

Expedited route

4-6 months

Phase 03

Full route

9-15 months

[Previous ![Flag of South Korea](/flags/kr.svg)South Korea ](/standards/kr)[Next  ![Flag of Brazil](/flags/br.svg)Brazil ](/standards/br)

## Related markets

[![Flag of Mexico](/flags/mx.svg)

Mexico

~90% FDA reuse

](/standards/mx)[![Flag of New Zealand](/flags/nz.svg)

New Zealand

~90% FDA reuse

](/standards/nz)[![Flag of Hong Kong](/flags/hk.svg)

Hong Kong

~90% FDA reuse

](/standards/hk)[![Flag of Australia](/flags/au.svg)

Australia

~85% FDA reuse

](/standards/au)

## Frequently asked about Singapore

### Is SBOM required for medical devices in Singapore?

Recommended. Aligned to IMDRF N60; expected for higher-risk devices.

### What does HSA require for pre-market cybersecurity?

Cybersecurity by design, risk assessment, labelling, MDS supporting docs at registration; abridged route if cleared by FDA/EU/TGA/HC/PMDA.

### What are the post-market cybersecurity obligations under HSA?

Field Safety Corrective Action (FSCA) reporting, vigilance, periodic security updates.

### What is the penalty for non-compliance with HSA cybersecurity rules?

Suspension or cancellation of registration; CSA penalties for critical info infrastructure.

### How much of my FDA cybersecurity package is reusable in Singapore?

Roughly 90% - an editorial estimate based on overlapping evidence requirements (threat model, SBOM, security risk assessment, pen-test report).

Sponsored note · Blue Goat Cyber

Submitting to HSA? Get a second pair of eyes before you file. Blue Goat Cyber has packaged cybersecurity evidence for Singapore alongside 37 other markets. We'll tell you what to keep, what to rework, and what's missing, in 30 minutes.  [Talk through your HSA submission](https://go.bluegoatcyber.com/meetings/blue-goat-cyber/discovery-session)

The Crosswalk

An independent reference for global medical device cybersecurity standards. A field guide for MedTech innovators and RA/QA teams charting an international path.

Resource

-   [Comparison matrix](/compare)
-   [Global playbook](/playbook)
-   [Glossary](/glossary)
-   [FAQ](/faq)

Sponsored by

[Blue Goat Cyber ↗](https://bluegoatcyber.com)

Editorially independent. Sponsorship keeps it free.

© 2026 The Crosswalk. Not legal advice.

Validate every requirement against current regulator publications.