---
title: "Thailand Thai FDA - Cybersecurity Submission Playbook"
description: "How to submit a medical device to Thai FDA in Thailand: step-by-step route, evidence checklist, common rejections, and typical review timeline. Compared with"
lang: en
json-ld: |
  [
    {
      "@context": "https://schema.org",
      "@type": "WebSite",
      "name": "The Medical Device Cybersecurity Crosswalk",
      "alternateName": "MDC Crosswalk",
      "url": "https://mdccrosswalk.com/",
      "description": "Compare FDA, EU MDR, MHRA, PMDA, NMPA, TGA, MFDS and Health Canada medical device cybersecurity requirements across 29 jurisdictions."
    },
    {
      "@context": "https://schema.org",
      "@type": "Organization",
      "name": "MDC Crosswalk",
      "url": "https://mdccrosswalk.com/",
      "logo": "https://mdccrosswalk.com/favicon.png",
      "sameAs": [
        "https://bluegoatcyber.com"
      ],
      "description": "An editorial reference comparing global medical-device cybersecurity regulations. Maintained by Blue Goat Cyber."
    },
    {
      "@context": "https://schema.org",
      "@type": "Article",
      "headline": "Thailand - Medical Device Act B.E. 2562 + Thai FDA cybersecurity expectations",
      "description": "How to submit a medical device to Thai FDA in Thailand: step-by-step route, evidence checklist, common rejections, and typical review timeline. Compared with ",
      "author": {
        "@type": "Organization",
        "name": "MDC Crosswalk"
      },
      "publisher": {
        "@type": "Organization",
        "name": "MDC Crosswalk"
      },
      "image": "https://mdccrosswalk.lovable.app/favicon.png",
      "datePublished": "2023",
      "about": "Food and Drug Administration, Thailand, Medical Device Control Division",
      "dateModified": "2026-07-16",
      "mainEntityOfPage": "https://mdccrosswalk.lovable.app/standards/th"
    },
    {
      "@context": "https://schema.org",
      "@type": "FAQPage",
      "mainEntity": [
        {
          "@type": "Question",
          "name": "Is SBOM required for medical devices in Thailand?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "Recommended. Encouraged but not mandated."
          }
        },
        {
          "@type": "Question",
          "name": "What does Thai FDA require for pre-market cybersecurity?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "Risk-class proportional dossier following ASEAN CSDT; FDA / CE approvals accepted as supporting evidence."
          }
        },
        {
          "@type": "Question",
          "name": "What are the post-market cybersecurity obligations under Thai FDA?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "Adverse-event reporting, software change notifications."
          }
        },
        {
          "@type": "Question",
          "name": "What is the penalty for non-compliance with Thai FDA cybersecurity rules?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "Licence suspension, fines, criminal liability under MD Act and PDPA."
          }
        },
        {
          "@type": "Question",
          "name": "How much of my FDA cybersecurity package is reusable in Thailand?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "Roughly 75% - an editorial estimate based on overlapping evidence requirements (threat model, SBOM, security risk assessment, pen-test report)."
          }
        },
        {
          "@type": "Question",
          "name": "Why do Thai FDA submissions get rejected for \"no thai licence holder appointed\"?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "Contract a Thai entity holding an importer or manufacturer licence."
          }
        }
      ]
    },
    {
      "@context": "https://schema.org",
      "@type": "HowTo",
      "name": "How to submit a medical device to Thai FDA",
      "description": "Thai FDA accepts GHTF founding-member approvals. Cybersecurity documentation is not separately mandated but recommended for connected devices.",
      "totalTime": "4-8 months",
      "step": [
        {
          "@type": "HowToStep",
          "position": 1,
          "name": "Appoint local representation",
          "text": "Most jurisdictions require a locally-established entity to hold the registration or act as authorised representative before submission."
        },
        {
          "@type": "HowToStep",
          "position": 2,
          "name": "Reuse FDA or CE package as baseline",
          "text": "Adapt the cybersecurity subsection you already prepared for FDA or CE; regulators here typically accept the structure and ask for local labeling additions."
        },
        {
          "@type": "HowToStep",
          "position": 3,
          "name": "Translate and localise",
          "text": "Local-language technical summary and labeling are usually mandatory; certified translation is safest."
        },
        {
          "@type": "HowToStep",
          "position": 4,
          "name": "Submit + track queries",
          "text": "Respond to clarification rounds promptly; each unanswered question can add 30-90 days to the clock."
        }
      ]
    },
    {
      "@context": "https://schema.org",
      "@type": "BreadcrumbList",
      "itemListElement": [
        {
          "@type": "ListItem",
          "position": 1,
          "name": "Home",
          "item": "https://mdccrosswalk.lovable.app/"
        },
        {
          "@type": "ListItem",
          "position": 2,
          "name": "Standards"
        },
        {
          "@type": "ListItem",
          "position": 3,
          "name": "Thailand"
        }
      ]
    }
  ]
---

[

The Crosswalk



](/)

[Overview](/)[Playbook](/playbook)CompareReference

[New Per-page social previews and this changelog ](/changelog "Per-page social previews and this changelog") Search⌘K

1.  [Home ](/)
2.  Standards 
3.  Thailand 

Thai FDA

# ![Flag of Thailand](/flags/th.svg)Thailand - Thai FDA 

Guidance Last updated · 2023 Verified · 2026-07-16 

Medical Device Act B.E. 2562 + Thai FDA cybersecurity expectations

Share Copy link X LinkedIn Email

Sources verified · 2026-07-16

Thai FDA cybersecurity expectations are guidance; PDPA/ETDA overlays confirmed.

Authority

Food and Drug Administration, Thailand, Medical Device Control Division

Enforced

2021 (revised MD Act)

Legal framework

Medical Device Act B.E. 2562 + PDPA Thailand + ETDA guidance

FDA package reuse

~75%

[Editorial estimate · how →](/methodology#fda-reuse)

## Scope

All medical devices marketed in Thailand. Cybersecurity guidance applies to SaMD and connected devices.

Pre-market

Risk-class proportional dossier following ASEAN CSDT; FDA / CE approvals accepted as supporting evidence.

Post-market

Adverse-event reporting, software change notifications.

SBOM

Recommended 

Encouraged but not mandated.

Vulnerability disclosure

ThaiCERT coordinated disclosure encouraged.

Penalty

Licence suspension, fines, criminal liability under MD Act and PDPA.

## Unique requirements

-   01 Thai Authorised Representative 
-   02 Thai-language labelling and IFU 
-   03 Establishment licence prerequisite 

## Highlights

-   ASEAN CSDT template alignment 
-   PDPA Thailand effective 2022 
-   FDA / CE approvals accepted 

## Aligns with

ASEAN MDD  IMDRF N60  ISO 13485 

## Timeline

1.  2019
    
    Medical Device Act B.E. 2562 enacted
    
2.  Jun 2022
    
    PDPA full enforcement
    
3.  2023
    
    Cybersecurity expectations clarified
    

## Key documents

[

Thai FDA - Software as a Medical Device (SaMD) registration

https://medical.fda.moph.go.th/samd-head/category/samd-03



](https://medical.fda.moph.go.th/samd-head/category/samd-03)[

Thai FDA Medical Device Control Division

https://medical.fda.moph.go.th/



](https://medical.fda.moph.go.th/)

## How to submit in Thailand

Playbook reviewed · 2026-07-16

Submission route

Thai FDA licence under the Medical Device Act B.E. 2562

Thai FDA accepts GHTF founding-member approvals. Cybersecurity documentation is not separately mandated but recommended for connected devices.

[Authority portal](https://www.fda.moph.go.th/sites/Medical/EN/SitePages/Home.aspx)

### Step-by-step

1.  Step 01
    
    Appoint local representation
    
    Most jurisdictions require a locally-established entity to hold the registration or act as authorised representative before submission.
    
2.  Step 02
    
    Reuse FDA or CE package as baseline
    
    Adapt the cybersecurity subsection you already prepared for FDA or CE; regulators here typically accept the structure and ask for local labeling additions.
    
3.  Step 03
    
    Translate and localise
    
    Local-language technical summary and labeling are usually mandatory; certified translation is safest.
    
4.  Step 04
    
    Submit + track queries
    
    Respond to clarification rounds promptly; each unanswered question can add 30-90 days to the clock.
    

### Evidence checklist

Item

Level

FDA equivalent

Notes

Cybersecurity documentation (baseline FDA or CE)

Required 

SPDF

Local authorised representative agreement

Required 

—

Local-language labeling and IFU

Required 

—

SBOM

Recommended 

—

Not mandatory but reduces clarification rounds.

### Common Thai FDA rejections

No Thai licence holder appointed

Common 

Fix ·  Contract a Thai entity holding an importer or manufacturer licence.

### Typical timeline

End-to-end window: 4-8 months 

Phase 01

Local rep + dossier prep

2-4 months

Phase 02

Regulatory review

4-8 months

Phase 03

Approval + market entry

1-3 months

[Previous ![Flag of Malaysia](/flags/my.svg)Malaysia ](/standards/my)[Next  ![Flag of Indonesia](/flags/id.svg)Indonesia ](/standards/id)

## Related markets

[![Flag of Egypt](/flags/eg.svg)

Egypt

~75% FDA reuse

](/standards/eg)[![Flag of United Kingdom](/flags/gb.svg)

United Kingdom

~80% FDA reuse

](/standards/uk)[![Flag of Taiwan](/flags/tw.svg)

Taiwan

~80% FDA reuse

](/standards/tw)[![Flag of South Africa](/flags/za.svg)

South Africa

~80% FDA reuse

](/standards/za)

## Frequently asked about Thailand

### Is SBOM required for medical devices in Thailand?

Recommended. Encouraged but not mandated.

### What does Thai FDA require for pre-market cybersecurity?

Risk-class proportional dossier following ASEAN CSDT; FDA / CE approvals accepted as supporting evidence.

### What are the post-market cybersecurity obligations under Thai FDA?

Adverse-event reporting, software change notifications.

### What is the penalty for non-compliance with Thai FDA cybersecurity rules?

Licence suspension, fines, criminal liability under MD Act and PDPA.

### How much of my FDA cybersecurity package is reusable in Thailand?

Roughly 75% - an editorial estimate based on overlapping evidence requirements (threat model, SBOM, security risk assessment, pen-test report).

Sponsored note · Blue Goat Cyber

Submitting to Thai FDA? Get a second pair of eyes before you file. Blue Goat Cyber has packaged cybersecurity evidence for Thailand alongside 37 other markets. We'll tell you what to keep, what to rework, and what's missing, in 30 minutes.  [Talk through your Thai FDA submission](https://go.bluegoatcyber.com/meetings/blue-goat-cyber/discovery-session)

The Crosswalk

An independent reference for global medical device cybersecurity standards. A field guide for MedTech innovators and RA/QA teams charting an international path.

Resource

-   [Comparison matrix](/compare)
-   [Global playbook](/playbook)
-   [Glossary](/glossary)
-   [FAQ](/faq)

Sponsored by

[Blue Goat Cyber ↗](https://bluegoatcyber.com)

Editorially independent. Sponsorship keeps it free.

© 2026 The Crosswalk. Not legal advice.

Validate every requirement against current regulator publications.