SAHPRA
South Africa - SAHPRA
Medicines and Related Substances Act + SAHPRA medical device guidance
Authority
South African Health Products Regulatory Authority
Enforced
2017 (licensing); cyber guidance 2022
Legal framework
Medicines Act + SAHPRA MD Regulations + POPIA
Scope
All medical devices and IVDs requiring establishment licensing. Cybersecurity addressed via general safety and POPIA data-protection overlay.
Pre-market
Risk-based registration dossier; CE / FDA approvals accepted as supporting evidence.
Post-market
Vigilance reporting to SAHPRA; POPIA breach notifications to the Information Regulator.
SBOM
RecommendedNot mandated; encouraged for SaMD aligned to FDA expectations.
Vulnerability disclosure
Encouraged via CSIRT.gov.za.
Penalty
Licence suspension; POPIA fines up to R10M; criminal liability.
Unique requirements
- 01South African Establishment Licence
- 02Local Authorised Representative
- 03POPIA compliance for any patient-data processing
Highlights
- Reference jurisdiction route for FDA / CE
- POPIA data-protection overlay
- Phased medical device licensing rollout
Aligns with
Timeline
-
2017
Medical device licensing introduced
-
Jul 2021
POPIA full enforcement
-
2022
SAHPRA cybersecurity guidance circulated
Key documents
How to submit in South Africa
Playbook reviewed · 2026-07-16
Submission route
SAHPRA licence under the Medicines and Related Substances Act
SAHPRA's medical device framework is maturing; cybersecurity expectations track IMDRF and are typically satisfied by an FDA or CE package.
Authority portalStep-by-step
-
Step 01
Appoint local representation
Most jurisdictions require a locally-established entity to hold the registration or act as authorised representative before submission.
-
Step 02
Reuse FDA or CE package as baseline
Adapt the cybersecurity subsection you already prepared for FDA or CE; regulators here typically accept the structure and ask for local labeling additions.
-
Step 03
Translate and localise
Local-language technical summary and labeling are usually mandatory; certified translation is safest.
-
Step 04
Submit + track queries
Respond to clarification rounds promptly; each unanswered question can add 30-90 days to the clock.
Evidence checklist
| Item | Level | FDA equivalent | Notes |
|---|---|---|---|
| Cybersecurity documentation (baseline FDA or CE) | Required | SPDF | |
| Local authorised representative agreement | Required | — | |
| Local-language labeling and IFU | Required | — | |
| SBOM | Recommended | — | Not mandatory but reduces clarification rounds. |
Common SAHPRA rejections
Establishment licence not in place for local rep
CommonFix · Local rep must hold a SAHPRA establishment licence before filing.
Typical timeline
End-to-end window: 9-18 months
Phase 01
Local rep + dossier prep
2-4 months
Phase 02
Regulatory review
9-18 months
Phase 03
Approval + market entry
1-3 months
Related markets
Frequently asked about South Africa
Is SBOM required for medical devices in South Africa?
Recommended. Not mandated; encouraged for SaMD aligned to FDA expectations.
What does SAHPRA require for pre-market cybersecurity?
Risk-based registration dossier; CE / FDA approvals accepted as supporting evidence.
What are the post-market cybersecurity obligations under SAHPRA?
Vigilance reporting to SAHPRA; POPIA breach notifications to the Information Regulator.
What is the penalty for non-compliance with SAHPRA cybersecurity rules?
Licence suspension; POPIA fines up to R10M; criminal liability.
How much of my FDA cybersecurity package is reusable in South Africa?
Roughly 80% - an editorial estimate based on overlapping evidence requirements (threat model, SBOM, security risk assessment, pen-test report).