SES
Ukraine - SES
Technical Regulation on Medical Devices (Resolution 753) - MDR-aligned
Authority
State Service of Ukraine on Medicines and Drug Control
Enforced
2013 (Resolution 753), revised 2023
Legal framework
Technical Regulation on Medical Devices (CMU Resolution 753), aligned with EU MDR via the EU–Ukraine Association Agreement; NIS2-style obligations being transposed under EU candidate-status reforms.
Scope
Medical devices placed on the Ukrainian market via national TR753 conformity assessment, performed by designated bodies. Connected devices fall under SSSCIP critical-infrastructure rules where deployed in hospitals.
Pre-market
Essential safety and performance requirements mirror MDR Annex I; software safety implicit. Technical file plus risk management (ISO 14971) and software lifecycle (IEC 62304) accepted.
Post-market
Vigilance reporting to SES; serious incidents within 15 days. SSSCIP coordinates cyber-incident response for hospital-deployed devices.
SBOM
RecommendedNot statutorily required; expected by designated bodies for connected devices in line with MDR practice.
Vulnerability disclosure
SSSCIP CERT-UA coordination; ENISA-style framework being adopted under EU accession reforms.
Penalty
Withdrawal from market, administrative fines under TR753.
Unique requirements
- 01Ukrainian Authorised Representative for non-resident manufacturers
- 02Wartime SSSCIP cyber notifications for hospital-deployed connected devices
Highlights
- MDR-aligned essential requirements
- ACAA pathway in progress for direct CE recognition
- Designated bodies perform conformity assessment
Aligns with
Timeline
-
2013
CMU Resolution 753 adopted (TR on medical devices)
-
2023
TR753 revisions to further align with EU MDR
-
Ongoing
ACAA pathway to direct EU CE recognition under negotiation
Key documents
How to submit in Ukraine
Playbook reviewed · 2026-07-16
Submission route
State Service on Medicines and Drugs Control registration under EU MDR-aligned rules
Ukraine's device regulation is aligned with EU MDR. Wartime enforcement is uneven; check current DLS advisories before planning submissions.
Authority portalStep-by-step
-
Step 01
Appoint local representation
Most jurisdictions require a locally-established entity to hold the registration or act as authorised representative before submission.
-
Step 02
Reuse FDA or CE package as baseline
Adapt the cybersecurity subsection you already prepared for FDA or CE; regulators here typically accept the structure and ask for local labeling additions.
-
Step 03
Translate and localise
Local-language technical summary and labeling are usually mandatory; certified translation is safest.
-
Step 04
Submit + track queries
Respond to clarification rounds promptly; each unanswered question can add 30-90 days to the clock.
Evidence checklist
| Item | Level | FDA equivalent | Notes |
|---|---|---|---|
| Cybersecurity documentation (baseline FDA or CE) | Required | SPDF | |
| Local authorised representative agreement | Required | — | |
| Local-language labeling and IFU | Required | — | |
| SBOM | Recommended | — | Not mandatory but reduces clarification rounds. |
Common SES rejections
Local AR appointment missing
OccasionalFix · Appoint a Ukrainian AR before filing.
Typical timeline
End-to-end window: 3-6 months post-CE
Phase 01
Local rep + dossier prep
2-4 months
Phase 02
Regulatory review
3-6 months post-CE
Phase 03
Approval + market entry
1-3 months
Related markets
Frequently asked about Ukraine
Is SBOM required for medical devices in Ukraine?
Recommended. Not statutorily required; expected by designated bodies for connected devices in line with MDR practice.
What does SES require for pre-market cybersecurity?
Essential safety and performance requirements mirror MDR Annex I; software safety implicit. Technical file plus risk management (ISO 14971) and software lifecycle (IEC 62304) accepted.
What are the post-market cybersecurity obligations under SES?
Vigilance reporting to SES; serious incidents within 15 days. SSSCIP coordinates cyber-incident response for hospital-deployed devices.
What is the penalty for non-compliance with SES cybersecurity rules?
Withdrawal from market, administrative fines under TR753.
How much of my FDA cybersecurity package is reusable in Ukraine?
Roughly 70% - an editorial estimate based on overlapping evidence requirements (threat model, SBOM, security risk assessment, pen-test report).