The Crosswalk

    NewPer-page social previews and this changelog

    SAHPRA

    Flag of South AfricaSouth Africa - SAHPRA

    GuidanceLast updated · 2023Verified · 2026-07-16

    Medicines and Related Substances Act + SAHPRA medical device guidance

    Share

    Authority

    South African Health Products Regulatory Authority

    Enforced

    2017 (licensing); cyber guidance 2022

    Legal framework

    Medicines Act + SAHPRA MD Regulations + POPIA

    FDA package reuse

    ~80%

    Scope

    All medical devices and IVDs requiring establishment licensing. Cybersecurity addressed via general safety and POPIA data-protection overlay.

    Pre-market

    Risk-based registration dossier; CE / FDA approvals accepted as supporting evidence.

    Post-market

    Vigilance reporting to SAHPRA; POPIA breach notifications to the Information Regulator.

    SBOM

    Recommended

    Not mandated; encouraged for SaMD aligned to FDA expectations.

    Vulnerability disclosure

    Encouraged via CSIRT.gov.za.

    Penalty

    Licence suspension; POPIA fines up to R10M; criminal liability.

    Unique requirements

    • 01South African Establishment Licence
    • 02Local Authorised Representative
    • 03POPIA compliance for any patient-data processing

    Highlights

    • Reference jurisdiction route for FDA / CE
    • POPIA data-protection overlay
    • Phased medical device licensing rollout

    Aligns with

    IMDRF N60 ISO 13485 FDA 2023 Guidance

    Timeline

    1. 2017

      Medical device licensing introduced

    2. Jul 2021

      POPIA full enforcement

    3. 2022

      SAHPRA cybersecurity guidance circulated

    Key documents

    How to submit in South Africa

    Playbook reviewed · 2026-07-16

    Submission route

    SAHPRA licence under the Medicines and Related Substances Act

    SAHPRA's medical device framework is maturing; cybersecurity expectations track IMDRF and are typically satisfied by an FDA or CE package.

    Authority portal

    Step-by-step

    1. Step 01

      Appoint local representation

      Most jurisdictions require a locally-established entity to hold the registration or act as authorised representative before submission.

    2. Step 02

      Reuse FDA or CE package as baseline

      Adapt the cybersecurity subsection you already prepared for FDA or CE; regulators here typically accept the structure and ask for local labeling additions.

    3. Step 03

      Translate and localise

      Local-language technical summary and labeling are usually mandatory; certified translation is safest.

    4. Step 04

      Submit + track queries

      Respond to clarification rounds promptly; each unanswered question can add 30-90 days to the clock.

    Evidence checklist

    Item Level FDA equivalent Notes
    Cybersecurity documentation (baseline FDA or CE) Required SPDF
    Local authorised representative agreement Required
    Local-language labeling and IFU Required
    SBOM Recommended Not mandatory but reduces clarification rounds.

    Common SAHPRA rejections

    Establishment licence not in place for local rep

    Common

    Fix · Local rep must hold a SAHPRA establishment licence before filing.

    Typical timeline

    End-to-end window: 9-18 months

    Phase 01

    Local rep + dossier prep

    2-4 months

    Phase 02

    Regulatory review

    9-18 months

    Phase 03

    Approval + market entry

    1-3 months

    Related markets

    Frequently asked about South Africa

    Is SBOM required for medical devices in South Africa?

    Recommended. Not mandated; encouraged for SaMD aligned to FDA expectations.

    What does SAHPRA require for pre-market cybersecurity?

    Risk-based registration dossier; CE / FDA approvals accepted as supporting evidence.

    What are the post-market cybersecurity obligations under SAHPRA?

    Vigilance reporting to SAHPRA; POPIA breach notifications to the Information Regulator.

    What is the penalty for non-compliance with SAHPRA cybersecurity rules?

    Licence suspension; POPIA fines up to R10M; criminal liability.

    How much of my FDA cybersecurity package is reusable in South Africa?

    Roughly 80% - an editorial estimate based on overlapping evidence requirements (threat model, SBOM, security risk assessment, pen-test report).