---
title: "Ukraine SES - Cybersecurity Submission Playbook"
description: "How to submit a medical device to SES in Ukraine: step-by-step route, evidence checklist, common rejections, and typical review timeline. Compared with FDA &amp;"
lang: en
json-ld: |
  [
    {
      "@context": "https://schema.org",
      "@type": "WebSite",
      "name": "The Medical Device Cybersecurity Crosswalk",
      "alternateName": "MDC Crosswalk",
      "url": "https://mdccrosswalk.com/",
      "description": "Compare FDA, EU MDR, MHRA, PMDA, NMPA, TGA, MFDS and Health Canada medical device cybersecurity requirements across 29 jurisdictions."
    },
    {
      "@context": "https://schema.org",
      "@type": "Organization",
      "name": "MDC Crosswalk",
      "url": "https://mdccrosswalk.com/",
      "logo": "https://mdccrosswalk.com/favicon.png",
      "sameAs": [
        "https://bluegoatcyber.com"
      ],
      "description": "An editorial reference comparing global medical-device cybersecurity regulations. Maintained by Blue Goat Cyber."
    },
    {
      "@context": "https://schema.org",
      "@type": "Article",
      "headline": "Ukraine - Technical Regulation on Medical Devices (Resolution 753) - MDR-aligned",
      "description": "How to submit a medical device to SES in Ukraine: step-by-step route, evidence checklist, common rejections, and typical review timeline. Compared with FDA & ",
      "author": {
        "@type": "Organization",
        "name": "MDC Crosswalk"
      },
      "publisher": {
        "@type": "Organization",
        "name": "MDC Crosswalk"
      },
      "image": "https://mdccrosswalk.lovable.app/favicon.png",
      "datePublished": "2024",
      "about": "State Service of Ukraine on Medicines and Drug Control",
      "dateModified": "2026-07-16",
      "mainEntityOfPage": "https://mdccrosswalk.lovable.app/standards/ua"
    },
    {
      "@context": "https://schema.org",
      "@type": "FAQPage",
      "mainEntity": [
        {
          "@type": "Question",
          "name": "Is SBOM required for medical devices in Ukraine?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "Recommended. Not statutorily required; expected by designated bodies for connected devices in line with MDR practice."
          }
        },
        {
          "@type": "Question",
          "name": "What does SES require for pre-market cybersecurity?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "Essential safety and performance requirements mirror MDR Annex I; software safety implicit. Technical file plus risk management (ISO 14971) and software lifecycle (IEC 62304) accepted."
          }
        },
        {
          "@type": "Question",
          "name": "What are the post-market cybersecurity obligations under SES?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "Vigilance reporting to SES; serious incidents within 15 days. SSSCIP coordinates cyber-incident response for hospital-deployed devices."
          }
        },
        {
          "@type": "Question",
          "name": "What is the penalty for non-compliance with SES cybersecurity rules?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "Withdrawal from market, administrative fines under TR753."
          }
        },
        {
          "@type": "Question",
          "name": "How much of my FDA cybersecurity package is reusable in Ukraine?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "Roughly 70% - an editorial estimate based on overlapping evidence requirements (threat model, SBOM, security risk assessment, pen-test report)."
          }
        },
        {
          "@type": "Question",
          "name": "Why do SES submissions get rejected for \"local ar appointment missing\"?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "Appoint a Ukrainian AR before filing."
          }
        }
      ]
    },
    {
      "@context": "https://schema.org",
      "@type": "HowTo",
      "name": "How to submit a medical device to SES",
      "description": "Ukraine's device regulation is aligned with EU MDR. Wartime enforcement is uneven; check current DLS advisories before planning submissions.",
      "totalTime": "3-6 months post-CE",
      "step": [
        {
          "@type": "HowToStep",
          "position": 1,
          "name": "Appoint local representation",
          "text": "Most jurisdictions require a locally-established entity to hold the registration or act as authorised representative before submission."
        },
        {
          "@type": "HowToStep",
          "position": 2,
          "name": "Reuse FDA or CE package as baseline",
          "text": "Adapt the cybersecurity subsection you already prepared for FDA or CE; regulators here typically accept the structure and ask for local labeling additions."
        },
        {
          "@type": "HowToStep",
          "position": 3,
          "name": "Translate and localise",
          "text": "Local-language technical summary and labeling are usually mandatory; certified translation is safest."
        },
        {
          "@type": "HowToStep",
          "position": 4,
          "name": "Submit + track queries",
          "text": "Respond to clarification rounds promptly; each unanswered question can add 30-90 days to the clock."
        }
      ]
    },
    {
      "@context": "https://schema.org",
      "@type": "BreadcrumbList",
      "itemListElement": [
        {
          "@type": "ListItem",
          "position": 1,
          "name": "Home",
          "item": "https://mdccrosswalk.lovable.app/"
        },
        {
          "@type": "ListItem",
          "position": 2,
          "name": "Standards"
        },
        {
          "@type": "ListItem",
          "position": 3,
          "name": "Ukraine"
        }
      ]
    }
  ]
---

[

The Crosswalk



](/)

[Overview](/)[Playbook](/playbook)CompareReference

[New Per-page social previews and this changelog ](/changelog "Per-page social previews and this changelog") Search⌘K

1.  [Home ](/)
2.  Standards 
3.  Ukraine 

SES

# ![Flag of Ukraine](/flags/ua.svg)Ukraine - SES 

Mandatory Last updated · 2024 Verified · 2026-07-16 

Technical Regulation on Medical Devices (Resolution 753) - MDR-aligned

Share Copy link X LinkedIn Email

Sources verified · 2026-07-16

Cross-checked against CMU Resolution 753 and the EU–Ukraine ACAA pathway documentation.

Authority

State Service of Ukraine on Medicines and Drug Control

Enforced

2013 (Resolution 753), revised 2023

Legal framework

Technical Regulation on Medical Devices (CMU Resolution 753), aligned with EU MDR via the EU–Ukraine Association Agreement; NIS2-style obligations being transposed under EU candidate-status reforms.

FDA package reuse

~70%

[Editorial estimate · how →](/methodology#fda-reuse)

## Scope

Medical devices placed on the Ukrainian market via national TR753 conformity assessment, performed by designated bodies. Connected devices fall under SSSCIP critical-infrastructure rules where deployed in hospitals.

Pre-market

Essential safety and performance requirements mirror MDR Annex I; software safety implicit. Technical file plus risk management (ISO 14971) and software lifecycle (IEC 62304) accepted.

Post-market

Vigilance reporting to SES; serious incidents within 15 days. SSSCIP coordinates cyber-incident response for hospital-deployed devices.

SBOM

Recommended 

Not statutorily required; expected by designated bodies for connected devices in line with MDR practice.

Vulnerability disclosure

SSSCIP CERT-UA coordination; ENISA-style framework being adopted under EU accession reforms.

Penalty

Withdrawal from market, administrative fines under TR753.

## Unique requirements

-   01 Ukrainian Authorised Representative for non-resident manufacturers 
-   02 Wartime SSSCIP cyber notifications for hospital-deployed connected devices 

## Highlights

-   MDR-aligned essential requirements 
-   ACAA pathway in progress for direct CE recognition 
-   Designated bodies perform conformity assessment 

## Aligns with

EU MDR  IEC 62304  ISO 14971  ISO 13485 

## Timeline

1.  2013
    
    CMU Resolution 753 adopted (TR on medical devices)
    
2.  2023
    
    TR753 revisions to further align with EU MDR
    
3.  Ongoing
    
    ACAA pathway to direct EU CE recognition under negotiation
    

## Key documents

[

CMU Resolution 753 - Technical Regulation on Medical Devices

https://zakon.rada.gov.ua/laws/show/753-2013-%D0%BF



](https://zakon.rada.gov.ua/laws/show/753-2013-%D0%BF)[

SES - State Service of Ukraine on Medicines and Drug Control

https://www.dls.gov.ua/



](https://www.dls.gov.ua/)

## How to submit in Ukraine

Playbook reviewed · 2026-07-16

Submission route

State Service on Medicines and Drugs Control registration under EU MDR-aligned rules

Ukraine's device regulation is aligned with EU MDR. Wartime enforcement is uneven; check current DLS advisories before planning submissions.

[Authority portal](https://www.dls.gov.ua/)

### Step-by-step

1.  Step 01
    
    Appoint local representation
    
    Most jurisdictions require a locally-established entity to hold the registration or act as authorised representative before submission.
    
2.  Step 02
    
    Reuse FDA or CE package as baseline
    
    Adapt the cybersecurity subsection you already prepared for FDA or CE; regulators here typically accept the structure and ask for local labeling additions.
    
3.  Step 03
    
    Translate and localise
    
    Local-language technical summary and labeling are usually mandatory; certified translation is safest.
    
4.  Step 04
    
    Submit + track queries
    
    Respond to clarification rounds promptly; each unanswered question can add 30-90 days to the clock.
    

### Evidence checklist

Item

Level

FDA equivalent

Notes

Cybersecurity documentation (baseline FDA or CE)

Required 

SPDF

Local authorised representative agreement

Required 

—

Local-language labeling and IFU

Required 

—

SBOM

Recommended 

—

Not mandatory but reduces clarification rounds.

### Common SES rejections

Local AR appointment missing

Occasional 

Fix ·  Appoint a Ukrainian AR before filing.

### Typical timeline

End-to-end window: 3-6 months post-CE 

Phase 01

Local rep + dossier prep

2-4 months

Phase 02

Regulatory review

3-6 months post-CE

Phase 03

Approval + market entry

1-3 months

[Previous ![Flag of Philippines](/flags/ph.svg)Philippines ](/standards/ph)[Next  ![Flag of Kazakhstan](/flags/kz.svg)Kazakhstan ](/standards/kz)

## Related markets

[![Flag of Japan](/flags/jp.svg)

Japan

~70% FDA reuse

](/standards/jp)[![Flag of Vietnam](/flags/vn.svg)

Vietnam

~70% FDA reuse

](/standards/vn)[![Flag of South Korea](/flags/kr.svg)

South Korea

~65% FDA reuse

](/standards/kr)[![Flag of European Union](/flags/eu.svg)

European Union

~60% FDA reuse

](/standards/eu)

## Frequently asked about Ukraine

### Is SBOM required for medical devices in Ukraine?

Recommended. Not statutorily required; expected by designated bodies for connected devices in line with MDR practice.

### What does SES require for pre-market cybersecurity?

Essential safety and performance requirements mirror MDR Annex I; software safety implicit. Technical file plus risk management (ISO 14971) and software lifecycle (IEC 62304) accepted.

### What are the post-market cybersecurity obligations under SES?

Vigilance reporting to SES; serious incidents within 15 days. SSSCIP coordinates cyber-incident response for hospital-deployed devices.

### What is the penalty for non-compliance with SES cybersecurity rules?

Withdrawal from market, administrative fines under TR753.

### How much of my FDA cybersecurity package is reusable in Ukraine?

Roughly 70% - an editorial estimate based on overlapping evidence requirements (threat model, SBOM, security risk assessment, pen-test report).

Sponsored note · Blue Goat Cyber

Submitting to SES? Get a second pair of eyes before you file. Blue Goat Cyber has packaged cybersecurity evidence for Ukraine alongside 37 other markets. We'll tell you what to keep, what to rework, and what's missing, in 30 minutes.  [Talk through your SES submission](https://go.bluegoatcyber.com/meetings/blue-goat-cyber/discovery-session)

The Crosswalk

An independent reference for global medical device cybersecurity standards. A field guide for MedTech innovators and RA/QA teams charting an international path.

Resource

-   [Comparison matrix](/compare)
-   [Global playbook](/playbook)
-   [Glossary](/glossary)
-   [FAQ](/faq)

Sponsored by

[Blue Goat Cyber ↗](https://bluegoatcyber.com)

Editorially independent. Sponsorship keeps it free.

© 2026 The Crosswalk. Not legal advice.

Validate every requirement against current regulator publications.