---
title: "Vietnam DMEC - Cybersecurity Submission Playbook"
description: "How to submit a medical device to DMEC / MoH in Vietnam: step-by-step route, evidence checklist, common rejections, and typical review timeline. Compared with"
lang: en
json-ld: |
  [
    {
      "@context": "https://schema.org",
      "@type": "WebSite",
      "name": "The Medical Device Cybersecurity Crosswalk",
      "alternateName": "MDC Crosswalk",
      "url": "https://mdccrosswalk.com/",
      "description": "Compare FDA, EU MDR, MHRA, PMDA, NMPA, TGA, MFDS and Health Canada medical device cybersecurity requirements across 29 jurisdictions."
    },
    {
      "@context": "https://schema.org",
      "@type": "Organization",
      "name": "MDC Crosswalk",
      "url": "https://mdccrosswalk.com/",
      "logo": "https://mdccrosswalk.com/favicon.png",
      "sameAs": [
        "https://bluegoatcyber.com"
      ],
      "description": "An editorial reference comparing global medical-device cybersecurity regulations. Maintained by Blue Goat Cyber."
    },
    {
      "@context": "https://schema.org",
      "@type": "Article",
      "headline": "Vietnam - Decree 98/2021/ND-CP + Decree 07/2023 + cybersecurity overlay",
      "description": "How to submit a medical device to DMEC / MoH in Vietnam: step-by-step route, evidence checklist, common rejections, and typical review timeline. Compared with",
      "author": {
        "@type": "Organization",
        "name": "MDC Crosswalk"
      },
      "publisher": {
        "@type": "Organization",
        "name": "MDC Crosswalk"
      },
      "image": "https://mdccrosswalk.lovable.app/favicon.png",
      "datePublished": "2024",
      "about": "Department of Medical Equipment and Construction, Ministry of Health",
      "dateModified": "2026-07-16",
      "mainEntityOfPage": "https://mdccrosswalk.lovable.app/standards/vn"
    },
    {
      "@context": "https://schema.org",
      "@type": "FAQPage",
      "mainEntity": [
        {
          "@type": "Question",
          "name": "Is SBOM required for medical devices in Vietnam?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "Recommended. Encouraged for SaMD; mirrors IMDRF N60."
          }
        },
        {
          "@type": "Question",
          "name": "What does DMEC / MoH require for pre-market cybersecurity?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "Risk-class registration dossier; ASEAN CSDT template; FDA / CE accepted as supporting evidence."
          }
        },
        {
          "@type": "Question",
          "name": "What are the post-market cybersecurity obligations under DMEC / MoH?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "Adverse-event reporting to MoH; cyber-incident reporting under Cybersecurity Law."
          }
        },
        {
          "@type": "Question",
          "name": "What is the penalty for non-compliance with DMEC / MoH cybersecurity rules?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "Registration cancellation; PDPD fines; criminal liability under Cybersecurity Law."
          }
        },
        {
          "@type": "Question",
          "name": "How much of my FDA cybersecurity package is reusable in Vietnam?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "Roughly 70% - an editorial estimate based on overlapping evidence requirements (threat model, SBOM, security risk assessment, pen-test report)."
          }
        },
        {
          "@type": "Question",
          "name": "Why do DMEC submissions get rejected for \"local classification disputed\"?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "Provide the manufacturer's classification rationale with references to ASEAN/IMDRF rules."
          }
        }
      ]
    },
    {
      "@context": "https://schema.org",
      "@type": "HowTo",
      "name": "How to submit a medical device to DMEC / MoH",
      "description": "Vietnam requires local registration with a Vietnamese entity. Cybersecurity documentation, when submitted, aids review for Class C/D connected devices.",
      "totalTime": "6-12 months",
      "step": [
        {
          "@type": "HowToStep",
          "position": 1,
          "name": "Appoint local representation",
          "text": "Most jurisdictions require a locally-established entity to hold the registration or act as authorised representative before submission."
        },
        {
          "@type": "HowToStep",
          "position": 2,
          "name": "Reuse FDA or CE package as baseline",
          "text": "Adapt the cybersecurity subsection you already prepared for FDA or CE; regulators here typically accept the structure and ask for local labeling additions."
        },
        {
          "@type": "HowToStep",
          "position": 3,
          "name": "Translate and localise",
          "text": "Local-language technical summary and labeling are usually mandatory; certified translation is safest."
        },
        {
          "@type": "HowToStep",
          "position": 4,
          "name": "Submit + track queries",
          "text": "Respond to clarification rounds promptly; each unanswered question can add 30-90 days to the clock."
        }
      ]
    },
    {
      "@context": "https://schema.org",
      "@type": "BreadcrumbList",
      "itemListElement": [
        {
          "@type": "ListItem",
          "position": 1,
          "name": "Home",
          "item": "https://mdccrosswalk.lovable.app/"
        },
        {
          "@type": "ListItem",
          "position": 2,
          "name": "Standards"
        },
        {
          "@type": "ListItem",
          "position": 3,
          "name": "Vietnam"
        }
      ]
    }
  ]
---

[

The Crosswalk



](/)

[Overview](/)[Playbook](/playbook)CompareReference

[New Per-page social previews and this changelog ](/changelog "Per-page social previews and this changelog") Search⌘K

1.  [Home ](/)
2.  Standards 
3.  Vietnam 

DMEC / MoH

# ![Flag of Vietnam](/flags/vn.svg)Vietnam - DMEC / MoH 

Mandatory Last updated · 2024 Verified · 2026-07-16 

Decree 98/2021/ND-CP + Decree 07/2023 + cybersecurity overlay

Share Copy link X LinkedIn Email

Sources verified · 2026-07-16

Decree 98/2021 governs device registration broadly; cybersecurity expectations layered via Cybersecurity Law 2018 and PDPD 2023, not a device-specific cyber rule.

Authority

Department of Medical Equipment and Construction, Ministry of Health

Enforced

Jan 2022

Legal framework

Decree 98/2021 + Decree 07/2023 + Cybersecurity Law 2018 + PDPD 2023

FDA package reuse

~70%

[Editorial estimate · how →](/methodology#fda-reuse)

## Scope

All medical devices in Vietnam; risk-class A/B/C/D registration regime.

Pre-market

Risk-class registration dossier; ASEAN CSDT template; FDA / CE accepted as supporting evidence.

Post-market

Adverse-event reporting to MoH; cyber-incident reporting under Cybersecurity Law.

SBOM

Recommended 

Encouraged for SaMD; mirrors IMDRF N60.

Vulnerability disclosure

VNCERT/CC coordinated disclosure recommended.

Penalty

Registration cancellation; PDPD fines; criminal liability under Cybersecurity Law.

## Unique requirements

-   01 Vietnamese Registration Holder 
-   02 Vietnamese-language IFU and labelling 
-   03 Data localisation for personal data 

## Highlights

-   PDPD 2023 introduced GDPR-style data rules 
-   Data localisation for connected devices 
-   ASEAN CSDT template alignment 

## Aligns with

ASEAN MDD  IMDRF N60  ISO 13485 

## Timeline

1.  Jan 2022
    
    Decree 98/2021 effective
    
2.  Mar 2023
    
    Decree 07/2023 amends transition rules
    
3.  Jul 2023
    
    PDPD 2023 effective
    

## Key documents

[

Decree 98/2021/ND-CP

https://moh.gov.vn/



](https://moh.gov.vn/)[

PDPD 2023, Personal Data Protection Decree

https://www.mic.gov.vn/



](https://www.mic.gov.vn/)

## How to submit in Vietnam

Playbook reviewed · 2026-07-16

Submission route

Ministry of Health circular 8/2023 registration

Vietnam requires local registration with a Vietnamese entity. Cybersecurity documentation, when submitted, aids review for Class C/D connected devices.

[Authority portal](https://moh.gov.vn/)

### Step-by-step

1.  Step 01
    
    Appoint local representation
    
    Most jurisdictions require a locally-established entity to hold the registration or act as authorised representative before submission.
    
2.  Step 02
    
    Reuse FDA or CE package as baseline
    
    Adapt the cybersecurity subsection you already prepared for FDA or CE; regulators here typically accept the structure and ask for local labeling additions.
    
3.  Step 03
    
    Translate and localise
    
    Local-language technical summary and labeling are usually mandatory; certified translation is safest.
    
4.  Step 04
    
    Submit + track queries
    
    Respond to clarification rounds promptly; each unanswered question can add 30-90 days to the clock.
    

### Evidence checklist

Item

Level

FDA equivalent

Notes

Cybersecurity documentation (baseline FDA or CE)

Required 

SPDF

Local authorised representative agreement

Required 

—

Local-language labeling and IFU

Required 

—

SBOM

Recommended 

—

Not mandatory but reduces clarification rounds.

### Common DMEC rejections

Local classification disputed

Common 

Fix ·  Provide the manufacturer's classification rationale with references to ASEAN/IMDRF rules.

### Typical timeline

End-to-end window: 6-12 months 

Phase 01

Local rep + dossier prep

2-4 months

Phase 02

Regulatory review

6-12 months

Phase 03

Approval + market entry

1-3 months

[Previous ![Flag of Chile](/flags/cl.svg)Chile ](/standards/cl)[Next  ![Flag of Philippines](/flags/ph.svg)Philippines ](/standards/ph)

## Related markets

[![Flag of Japan](/flags/jp.svg)

Japan

~70% FDA reuse

](/standards/jp)[![Flag of Ukraine](/flags/ua.svg)

Ukraine

~70% FDA reuse

](/standards/ua)[![Flag of South Korea](/flags/kr.svg)

South Korea

~65% FDA reuse

](/standards/kr)[![Flag of European Union](/flags/eu.svg)

European Union

~60% FDA reuse

](/standards/eu)

## Frequently asked about Vietnam

### Is SBOM required for medical devices in Vietnam?

Recommended. Encouraged for SaMD; mirrors IMDRF N60.

### What does DMEC / MoH require for pre-market cybersecurity?

Risk-class registration dossier; ASEAN CSDT template; FDA / CE accepted as supporting evidence.

### What are the post-market cybersecurity obligations under DMEC / MoH?

Adverse-event reporting to MoH; cyber-incident reporting under Cybersecurity Law.

### What is the penalty for non-compliance with DMEC / MoH cybersecurity rules?

Registration cancellation; PDPD fines; criminal liability under Cybersecurity Law.

### How much of my FDA cybersecurity package is reusable in Vietnam?

Roughly 70% - an editorial estimate based on overlapping evidence requirements (threat model, SBOM, security risk assessment, pen-test report).

Sponsored note · Blue Goat Cyber

Submitting to DMEC / MoH? Get a second pair of eyes before you file. Blue Goat Cyber has packaged cybersecurity evidence for Vietnam alongside 37 other markets. We'll tell you what to keep, what to rework, and what's missing, in 30 minutes.  [Talk through your DMEC submission](https://go.bluegoatcyber.com/meetings/blue-goat-cyber/discovery-session)

The Crosswalk

An independent reference for global medical device cybersecurity standards. A field guide for MedTech innovators and RA/QA teams charting an international path.

Resource

-   [Comparison matrix](/compare)
-   [Global playbook](/playbook)
-   [Glossary](/glossary)
-   [FAQ](/faq)

Sponsored by

[Blue Goat Cyber ↗](https://bluegoatcyber.com)

Editorially independent. Sponsorship keeps it free.

© 2026 The Crosswalk. Not legal advice.

Validate every requirement against current regulator publications.