The Crosswalk

    NewPer-page social previews and this changelog

    Thai FDA

    Flag of ThailandThailand - Thai FDA

    GuidanceLast updated · 2023Verified · 2026-07-16

    Medical Device Act B.E. 2562 + Thai FDA cybersecurity expectations

    Share

    Authority

    Food and Drug Administration, Thailand, Medical Device Control Division

    Enforced

    2021 (revised MD Act)

    Legal framework

    Medical Device Act B.E. 2562 + PDPA Thailand + ETDA guidance

    FDA package reuse

    ~75%

    Scope

    All medical devices marketed in Thailand. Cybersecurity guidance applies to SaMD and connected devices.

    Pre-market

    Risk-class proportional dossier following ASEAN CSDT; FDA / CE approvals accepted as supporting evidence.

    Post-market

    Adverse-event reporting, software change notifications.

    SBOM

    Recommended

    Encouraged but not mandated.

    Vulnerability disclosure

    ThaiCERT coordinated disclosure encouraged.

    Penalty

    Licence suspension, fines, criminal liability under MD Act and PDPA.

    Unique requirements

    • 01Thai Authorised Representative
    • 02Thai-language labelling and IFU
    • 03Establishment licence prerequisite

    Highlights

    • ASEAN CSDT template alignment
    • PDPA Thailand effective 2022
    • FDA / CE approvals accepted

    Aligns with

    ASEAN MDD IMDRF N60 ISO 13485

    Timeline

    1. 2019

      Medical Device Act B.E. 2562 enacted

    2. Jun 2022

      PDPA full enforcement

    3. 2023

      Cybersecurity expectations clarified

    Key documents

    How to submit in Thailand

    Playbook reviewed · 2026-07-16

    Submission route

    Thai FDA licence under the Medical Device Act B.E. 2562

    Thai FDA accepts GHTF founding-member approvals. Cybersecurity documentation is not separately mandated but recommended for connected devices.

    Authority portal

    Step-by-step

    1. Step 01

      Appoint local representation

      Most jurisdictions require a locally-established entity to hold the registration or act as authorised representative before submission.

    2. Step 02

      Reuse FDA or CE package as baseline

      Adapt the cybersecurity subsection you already prepared for FDA or CE; regulators here typically accept the structure and ask for local labeling additions.

    3. Step 03

      Translate and localise

      Local-language technical summary and labeling are usually mandatory; certified translation is safest.

    4. Step 04

      Submit + track queries

      Respond to clarification rounds promptly; each unanswered question can add 30-90 days to the clock.

    Evidence checklist

    Item Level FDA equivalent Notes
    Cybersecurity documentation (baseline FDA or CE) Required SPDF
    Local authorised representative agreement Required
    Local-language labeling and IFU Required
    SBOM Recommended Not mandatory but reduces clarification rounds.

    Common Thai FDA rejections

    No Thai licence holder appointed

    Common

    Fix · Contract a Thai entity holding an importer or manufacturer licence.

    Typical timeline

    End-to-end window: 4-8 months

    Phase 01

    Local rep + dossier prep

    2-4 months

    Phase 02

    Regulatory review

    4-8 months

    Phase 03

    Approval + market entry

    1-3 months

    Related markets

    Frequently asked about Thailand

    Is SBOM required for medical devices in Thailand?

    Recommended. Encouraged but not mandated.

    What does Thai FDA require for pre-market cybersecurity?

    Risk-class proportional dossier following ASEAN CSDT; FDA / CE approvals accepted as supporting evidence.

    What are the post-market cybersecurity obligations under Thai FDA?

    Adverse-event reporting, software change notifications.

    What is the penalty for non-compliance with Thai FDA cybersecurity rules?

    Licence suspension, fines, criminal liability under MD Act and PDPA.

    How much of my FDA cybersecurity package is reusable in Thailand?

    Roughly 75% - an editorial estimate based on overlapping evidence requirements (threat model, SBOM, security risk assessment, pen-test report).