Thai FDA
Thailand - Thai FDA
Medical Device Act B.E. 2562 + Thai FDA cybersecurity expectations
Authority
Food and Drug Administration, Thailand, Medical Device Control Division
Enforced
2021 (revised MD Act)
Legal framework
Medical Device Act B.E. 2562 + PDPA Thailand + ETDA guidance
Scope
All medical devices marketed in Thailand. Cybersecurity guidance applies to SaMD and connected devices.
Pre-market
Risk-class proportional dossier following ASEAN CSDT; FDA / CE approvals accepted as supporting evidence.
Post-market
Adverse-event reporting, software change notifications.
SBOM
RecommendedEncouraged but not mandated.
Vulnerability disclosure
ThaiCERT coordinated disclosure encouraged.
Penalty
Licence suspension, fines, criminal liability under MD Act and PDPA.
Unique requirements
- 01Thai Authorised Representative
- 02Thai-language labelling and IFU
- 03Establishment licence prerequisite
Highlights
- ASEAN CSDT template alignment
- PDPA Thailand effective 2022
- FDA / CE approvals accepted
Aligns with
Timeline
-
2019
Medical Device Act B.E. 2562 enacted
-
Jun 2022
PDPA full enforcement
-
2023
Cybersecurity expectations clarified
Key documents
How to submit in Thailand
Playbook reviewed · 2026-07-16
Submission route
Thai FDA licence under the Medical Device Act B.E. 2562
Thai FDA accepts GHTF founding-member approvals. Cybersecurity documentation is not separately mandated but recommended for connected devices.
Authority portalStep-by-step
-
Step 01
Appoint local representation
Most jurisdictions require a locally-established entity to hold the registration or act as authorised representative before submission.
-
Step 02
Reuse FDA or CE package as baseline
Adapt the cybersecurity subsection you already prepared for FDA or CE; regulators here typically accept the structure and ask for local labeling additions.
-
Step 03
Translate and localise
Local-language technical summary and labeling are usually mandatory; certified translation is safest.
-
Step 04
Submit + track queries
Respond to clarification rounds promptly; each unanswered question can add 30-90 days to the clock.
Evidence checklist
| Item | Level | FDA equivalent | Notes |
|---|---|---|---|
| Cybersecurity documentation (baseline FDA or CE) | Required | SPDF | |
| Local authorised representative agreement | Required | — | |
| Local-language labeling and IFU | Required | — | |
| SBOM | Recommended | — | Not mandatory but reduces clarification rounds. |
Common Thai FDA rejections
No Thai licence holder appointed
CommonFix · Contract a Thai entity holding an importer or manufacturer licence.
Typical timeline
End-to-end window: 4-8 months
Phase 01
Local rep + dossier prep
2-4 months
Phase 02
Regulatory review
4-8 months
Phase 03
Approval + market entry
1-3 months
Related markets
Frequently asked about Thailand
Is SBOM required for medical devices in Thailand?
Recommended. Encouraged but not mandated.
What does Thai FDA require for pre-market cybersecurity?
Risk-class proportional dossier following ASEAN CSDT; FDA / CE approvals accepted as supporting evidence.
What are the post-market cybersecurity obligations under Thai FDA?
Adverse-event reporting, software change notifications.
What is the penalty for non-compliance with Thai FDA cybersecurity rules?
Licence suspension, fines, criminal liability under MD Act and PDPA.
How much of my FDA cybersecurity package is reusable in Thailand?
Roughly 75% - an editorial estimate based on overlapping evidence requirements (threat model, SBOM, security risk assessment, pen-test report).