---
title: "United Kingdom MHRA - Cybersecurity Submission Playbook"
description: "How to submit a medical device to MHRA in United Kingdom: step-by-step route, evidence checklist, common rejections, and typical review timeline. Compared wit"
lang: en
json-ld: |
  [
    {
      "@context": "https://schema.org",
      "@type": "WebSite",
      "name": "The Medical Device Cybersecurity Crosswalk",
      "alternateName": "MDC Crosswalk",
      "url": "https://mdccrosswalk.com/",
      "description": "Compare FDA, EU MDR, MHRA, PMDA, NMPA, TGA, MFDS and Health Canada medical device cybersecurity requirements across 29 jurisdictions."
    },
    {
      "@context": "https://schema.org",
      "@type": "Organization",
      "name": "MDC Crosswalk",
      "url": "https://mdccrosswalk.com/",
      "logo": "https://mdccrosswalk.com/favicon.png",
      "sameAs": [
        "https://bluegoatcyber.com"
      ],
      "description": "An editorial reference comparing global medical-device cybersecurity regulations. Maintained by Blue Goat Cyber."
    },
    {
      "@context": "https://schema.org",
      "@type": "Article",
      "headline": "United Kingdom - UK MDR 2002 (as amended) + MHRA Cyber Guidance",
      "description": "How to submit a medical device to MHRA in United Kingdom: step-by-step route, evidence checklist, common rejections, and typical review timeline. Compared wit",
      "author": {
        "@type": "Organization",
        "name": "MDC Crosswalk"
      },
      "publisher": {
        "@type": "Organization",
        "name": "MDC Crosswalk"
      },
      "image": "https://mdccrosswalk.lovable.app/favicon.png",
      "datePublished": "2026 (Draft Medical Devices (Amendment) Regulations 2026 published; MHRA stakeholder impact survey underway alongside the Feb 2026 CE-recognition consultation)",
      "about": "Medicines and Healthcare products Regulatory Agency",
      "dateModified": "2026-07-16",
      "mainEntityOfPage": "https://mdccrosswalk.lovable.app/standards/uk"
    },
    {
      "@context": "https://schema.org",
      "@type": "FAQPage",
      "mainEntity": [
        {
          "@type": "Question",
          "name": "Is SBOM required for medical devices in United Kingdom?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "Recommended. Not mandated; encouraged via NCSC guidance and aligns with FDA expectations for dual-market devices."
          }
        },
        {
          "@type": "Question",
          "name": "What does MHRA require for pre-market cybersecurity?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "Risk-based, leverages BS EN 81001-5-1 and FDA-aligned evidence. UKCA marking with grace period for CE-marked devices."
          }
        },
        {
          "@type": "Question",
          "name": "What are the post-market cybersecurity obligations under MHRA?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "MORE vigilance reporting + DTAC for NHS deployment + DSPT for connected services."
          }
        },
        {
          "@type": "Question",
          "name": "What is the penalty for non-compliance with MHRA cybersecurity rules?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "Market removal, criminal liability under Consumer Protection Act."
          }
        },
        {
          "@type": "Question",
          "name": "How much of my FDA cybersecurity package is reusable in United Kingdom?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "Roughly 80% - an editorial estimate based on overlapping evidence requirements (threat model, SBOM, security risk assessment, pen-test report)."
          }
        },
        {
          "@type": "Question",
          "name": "Why do MHRA submissions get rejected for \"ukrp details missing from labeling\"?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "Add UKRP name and address to device labeling and IFU before AB audit."
          }
        },
        {
          "@type": "Question",
          "name": "Why do MHRA submissions get rejected for \"reliance on ce certificate near 2030 sunset\"?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "Start UKCA transition planning 18-24 months before June 2030 to avoid AB bottleneck."
          }
        }
      ]
    },
    {
      "@context": "https://schema.org",
      "@type": "HowTo",
      "name": "How to submit a medical device to MHRA",
      "description": "The UK continues to recognise CE-marked devices through 30 June 2030 while the post-Brexit framework catches up. MHRA's cybersecurity expectations mirror MDCG 2019-16 for now, with additional guidance on connected/AI devices published under the Software and AI as a Medical Device programme.",
      "totalTime": "0-4 weeks (CE recognition) or 10-16 months (UKCA).",
      "step": [
        {
          "@type": "HowToStep",
          "position": 1,
          "name": "Decide CE recognition vs UKCA",
          "text": "CE recognition is the low-friction path until 30 June 2030; UKCA is required afterwards and for Northern Ireland-only products."
        },
        {
          "@type": "HowToStep",
          "position": 2,
          "name": "Engage an Approved Body (UKCA path)",
          "text": "AB capacity in the UK is limited; book 6-12 months ahead for Class IIa+ devices."
        },
        {
          "@type": "HowToStep",
          "position": 3,
          "name": "Package cybersecurity evidence",
          "text": "MHRA accepts MDCG 2019-16-style documentation as-is; add UK-specific labeling for the UKRP."
        },
        {
          "@type": "HowToStep",
          "position": 4,
          "name": "Register with MHRA",
          "text": "All devices placed on the GB market must be registered by the UKRP within grace-period deadlines."
        }
      ]
    },
    {
      "@context": "https://schema.org",
      "@type": "BreadcrumbList",
      "itemListElement": [
        {
          "@type": "ListItem",
          "position": 1,
          "name": "Home",
          "item": "https://mdccrosswalk.lovable.app/"
        },
        {
          "@type": "ListItem",
          "position": 2,
          "name": "Standards"
        },
        {
          "@type": "ListItem",
          "position": 3,
          "name": "United Kingdom"
        }
      ]
    }
  ]
---

[

The Crosswalk



](/)

[Overview](/)[Playbook](/playbook)CompareReference

[New Per-page social previews and this changelog ](/changelog "Per-page social previews and this changelog") Search⌘K

1.  [Home ](/)
2.  Standards 
3.  United Kingdom 

MHRA

# ![Flag of United Kingdom](/flags/gb.svg)United Kingdom - MHRA 

Guidance Last updated · 2026 (Draft Medical Devices (Amendment) Regulations 2026 published; MHRA stakeholder impact survey underway alongside the Feb 2026 CE-recognition consultation) Verified · 2026-07-16 

UK MDR 2002 (as amended) + MHRA Cyber Guidance

Share Copy link X LinkedIn Email

Sources verified · 2026-07-16

Cross-checked against MHRA roadmap and DTAC/DSPT references.

Authority

Medicines and Healthcare products Regulatory Agency

Enforced

Reform program 2024–26

Legal framework

UK MDR 2002 + DTAC + NHS DSPT

FDA package reuse

~80%

[Editorial estimate · how →](/methodology#fda-reuse)

## Scope

Devices marketed in Great Britain (Northern Ireland follows EU MDR via the Windsor Framework). Software as a Medical Device addressed by separate MHRA Change Programme.

Pre-market

Risk-based, leverages BS EN 81001-5-1 and FDA-aligned evidence. UKCA marking with grace period for CE-marked devices.

Post-market

MORE vigilance reporting + DTAC for NHS deployment + DSPT for connected services.

SBOM

Recommended 

Not mandated; encouraged via NCSC guidance and aligns with FDA expectations for dual-market devices.

Vulnerability disclosure

Encouraged via the NCSC Vulnerability Disclosure Toolkit.

Penalty

Market removal, criminal liability under Consumer Protection Act.

## Unique requirements

-   01 DTAC clinical safety, data protection, technical assurance for NHS 
-   02 DSPT compliance for hosted services 
-   03 International recognition route for FDA/Health Canada/TGA approvals (Draft 2026 Regulations codify the pathway; MHRA impact survey open) 

## Highlights

-   Pragmatic FDA/EU dual-recognition 
-   DTAC required for NHS deployment 
-   Future divergence from EU MDR 

## Aligns with

IMDRF N60  BS EN 81001-5-1  NCSC CAF 

## Timeline

1.  Jan 2021
    
    Brexit transition ends, UKCA introduced
    
2.  Sep 2021
    
    MHRA SaMD Change Programme launched
    
3.  2024
    
    International Recognition route consultation
    
4.  Feb 16 2026
    
    MHRA consultation on indefinite recognition of CE-marked devices launched (closed; analysis underway)
    
5.  2026
    
    Draft Medical Devices (Amendment) Regulations 2026 published for consultation; MHRA impact survey open
    

## Key documents

[

MHRA Software & AI as a Medical Device Change Programme

https://www.gov.uk/government/publications/software-and-ai-as-a-medical-device-change-programme



](https://www.gov.uk/government/publications/software-and-ai-as-a-medical-device-change-programme)[

NHS Digital Technology Assessment Criteria (DTAC)

https://transform.england.nhs.uk/key-tools-and-info/digital-technology-assessment-criteria-dtac/



](https://transform.england.nhs.uk/key-tools-and-info/digital-technology-assessment-criteria-dtac/)[

NCSC Vulnerability Disclosure Toolkit

https://www.ncsc.gov.uk/information/vulnerability-disclosure-toolkit



](https://www.ncsc.gov.uk/information/vulnerability-disclosure-toolkit)

## How to submit in United Kingdom

Playbook reviewed · 2026-07-16

Submission route

UKCA marking (or CE recognition through 30 June 2030) with an Approved Body, plus MHRA registration

The UK continues to recognise CE-marked devices through 30 June 2030 while the post-Brexit framework catches up. MHRA's cybersecurity expectations mirror MDCG 2019-16 for now, with additional guidance on connected/AI devices published under the Software and AI as a Medical Device programme.

[Authority portal](https://www.gov.uk/topic/medicines-medical-devices-blood/medical-devices-regulation-safety)

### Step-by-step

1.  Step 01
    
    Decide CE recognition vs UKCA
    
    CE recognition is the low-friction path until 30 June 2030; UKCA is required afterwards and for Northern Ireland-only products.
    
2.  Step 02
    
    Engage an Approved Body (UKCA path)
    
    AB capacity in the UK is limited; book 6-12 months ahead for Class IIa+ devices.
    
3.  Step 03
    
    Package cybersecurity evidence
    
    MHRA accepts MDCG 2019-16-style documentation as-is; add UK-specific labeling for the UKRP.
    
4.  Step 04
    
    Register with MHRA
    
    All devices placed on the GB market must be registered by the UKRP within grace-period deadlines.
    

### Evidence checklist

Item

Level

FDA equivalent

Notes

MDCG 2019-16-style cyber documentation

Required 

SPDF

UKRP appointment (non-UK manufacturers)

Required 

—

IEC 81001-5-1 evidence

Recommended 

—

PSTI-aligned vulnerability disclosure policy

Recommended 

—

Not legally required for medical devices but expected best practice.

### Common MHRA rejections

UKRP details missing from labeling

Common 

Fix ·  Add UKRP name and address to device labeling and IFU before AB audit.

Reliance on CE certificate near 2030 sunset

Occasional 

Fix ·  Start UKCA transition planning 18-24 months before June 2030 to avoid AB bottleneck.

### Typical timeline

End-to-end window: 0-4 weeks (CE recognition) or 10-16 months (UKCA). 

Phase 01

CE recognition path

0-4 weeks

MHRA registration only, if you already hold a valid CE certificate.

Phase 02

UKCA path (Class IIa+)

10-16 months

Includes AB queue + review.

[Previous ![Flag of European Union](/flags/eu.svg)European Union ](/standards/eu)[Next  ![Flag of Japan](/flags/jp.svg)Japan ](/standards/jp)

## MHRA head-to-head

[

Compare

![Flag of United Kingdom](/flags/gb.svg)MHRAvs ![Flag of United States](/flags/us.svg)FDA 524B

Open comparison ](/compare/fda-vs-mhra)[

Compare

![Flag of United Kingdom](/flags/gb.svg)MHRAvs ![Flag of European Union](/flags/eu.svg)EU MDR

Open comparison ](/compare/eu-mdr-vs-uk-mhra)

## Related markets

[![Flag of Taiwan](/flags/tw.svg)

Taiwan

~80% FDA reuse

](/standards/tw)[![Flag of South Africa](/flags/za.svg)

South Africa

~80% FDA reuse

](/standards/za)[![Flag of Malaysia](/flags/my.svg)

Malaysia

~80% FDA reuse

](/standards/my)[![Flag of Philippines](/flags/ph.svg)

Philippines

~80% FDA reuse

](/standards/ph)

## Frequently asked about United Kingdom

### Is SBOM required for medical devices in United Kingdom?

Recommended. Not mandated; encouraged via NCSC guidance and aligns with FDA expectations for dual-market devices.

### What does MHRA require for pre-market cybersecurity?

Risk-based, leverages BS EN 81001-5-1 and FDA-aligned evidence. UKCA marking with grace period for CE-marked devices.

### What are the post-market cybersecurity obligations under MHRA?

MORE vigilance reporting + DTAC for NHS deployment + DSPT for connected services.

### What is the penalty for non-compliance with MHRA cybersecurity rules?

Market removal, criminal liability under Consumer Protection Act.

### How much of my FDA cybersecurity package is reusable in United Kingdom?

Roughly 80% - an editorial estimate based on overlapping evidence requirements (threat model, SBOM, security risk assessment, pen-test report).

Sponsored note · Blue Goat Cyber

Submitting to MHRA? Get a second pair of eyes before you file. Blue Goat Cyber has packaged cybersecurity evidence for United Kingdom alongside 37 other markets. We'll tell you what to keep, what to rework, and what's missing, in 30 minutes.  [Talk through your MHRA submission](https://go.bluegoatcyber.com/meetings/blue-goat-cyber/discovery-session)

The Crosswalk

An independent reference for global medical device cybersecurity standards. A field guide for MedTech innovators and RA/QA teams charting an international path.

Resource

-   [Comparison matrix](/compare)
-   [Global playbook](/playbook)
-   [Glossary](/glossary)
-   [FAQ](/faq)

Sponsored by

[Blue Goat Cyber ↗](https://bluegoatcyber.com)

Editorially independent. Sponsorship keeps it free.

© 2026 The Crosswalk. Not legal advice.

Validate every requirement against current regulator publications.