---
title: "South Africa SAHPRA - Cybersecurity Submission Playbook"
description: "How to submit a medical device to SAHPRA in South Africa: step-by-step route, evidence checklist, common rejections, and typical review timeline. Compared wit"
lang: en
json-ld: |
  [
    {
      "@context": "https://schema.org",
      "@type": "WebSite",
      "name": "The Medical Device Cybersecurity Crosswalk",
      "alternateName": "MDC Crosswalk",
      "url": "https://mdccrosswalk.com/",
      "description": "Compare FDA, EU MDR, MHRA, PMDA, NMPA, TGA, MFDS and Health Canada medical device cybersecurity requirements across 29 jurisdictions."
    },
    {
      "@context": "https://schema.org",
      "@type": "Organization",
      "name": "MDC Crosswalk",
      "url": "https://mdccrosswalk.com/",
      "logo": "https://mdccrosswalk.com/favicon.png",
      "sameAs": [
        "https://bluegoatcyber.com"
      ],
      "description": "An editorial reference comparing global medical-device cybersecurity regulations. Maintained by Blue Goat Cyber."
    },
    {
      "@context": "https://schema.org",
      "@type": "Article",
      "headline": "South Africa - Medicines and Related Substances Act + SAHPRA medical device guidance",
      "description": "How to submit a medical device to SAHPRA in South Africa: step-by-step route, evidence checklist, common rejections, and typical review timeline. Compared wit",
      "author": {
        "@type": "Organization",
        "name": "MDC Crosswalk"
      },
      "publisher": {
        "@type": "Organization",
        "name": "MDC Crosswalk"
      },
      "image": "https://mdccrosswalk.lovable.app/favicon.png",
      "datePublished": "2023",
      "about": "South African Health Products Regulatory Authority",
      "dateModified": "2026-07-16",
      "mainEntityOfPage": "https://mdccrosswalk.lovable.app/standards/za"
    },
    {
      "@context": "https://schema.org",
      "@type": "FAQPage",
      "mainEntity": [
        {
          "@type": "Question",
          "name": "Is SBOM required for medical devices in South Africa?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "Recommended. Not mandated; encouraged for SaMD aligned to FDA expectations."
          }
        },
        {
          "@type": "Question",
          "name": "What does SAHPRA require for pre-market cybersecurity?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "Risk-based registration dossier; CE / FDA approvals accepted as supporting evidence."
          }
        },
        {
          "@type": "Question",
          "name": "What are the post-market cybersecurity obligations under SAHPRA?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "Vigilance reporting to SAHPRA; POPIA breach notifications to the Information Regulator."
          }
        },
        {
          "@type": "Question",
          "name": "What is the penalty for non-compliance with SAHPRA cybersecurity rules?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "Licence suspension; POPIA fines up to R10M; criminal liability."
          }
        },
        {
          "@type": "Question",
          "name": "How much of my FDA cybersecurity package is reusable in South Africa?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "Roughly 80% - an editorial estimate based on overlapping evidence requirements (threat model, SBOM, security risk assessment, pen-test report)."
          }
        },
        {
          "@type": "Question",
          "name": "Why do SAHPRA submissions get rejected for \"establishment licence not in place for local rep\"?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "Local rep must hold a SAHPRA establishment licence before filing."
          }
        }
      ]
    },
    {
      "@context": "https://schema.org",
      "@type": "HowTo",
      "name": "How to submit a medical device to SAHPRA",
      "description": "SAHPRA's medical device framework is maturing; cybersecurity expectations track IMDRF and are typically satisfied by an FDA or CE package.",
      "totalTime": "9-18 months",
      "step": [
        {
          "@type": "HowToStep",
          "position": 1,
          "name": "Appoint local representation",
          "text": "Most jurisdictions require a locally-established entity to hold the registration or act as authorised representative before submission."
        },
        {
          "@type": "HowToStep",
          "position": 2,
          "name": "Reuse FDA or CE package as baseline",
          "text": "Adapt the cybersecurity subsection you already prepared for FDA or CE; regulators here typically accept the structure and ask for local labeling additions."
        },
        {
          "@type": "HowToStep",
          "position": 3,
          "name": "Translate and localise",
          "text": "Local-language technical summary and labeling are usually mandatory; certified translation is safest."
        },
        {
          "@type": "HowToStep",
          "position": 4,
          "name": "Submit + track queries",
          "text": "Respond to clarification rounds promptly; each unanswered question can add 30-90 days to the clock."
        }
      ]
    },
    {
      "@context": "https://schema.org",
      "@type": "BreadcrumbList",
      "itemListElement": [
        {
          "@type": "ListItem",
          "position": 1,
          "name": "Home",
          "item": "https://mdccrosswalk.lovable.app/"
        },
        {
          "@type": "ListItem",
          "position": 2,
          "name": "Standards"
        },
        {
          "@type": "ListItem",
          "position": 3,
          "name": "South Africa"
        }
      ]
    }
  ]
---

[

The Crosswalk



](/)

[Overview](/)[Playbook](/playbook)CompareReference

[New Per-page social previews and this changelog ](/changelog "Per-page social previews and this changelog") Search⌘K

1.  [Home ](/)
2.  Standards 
3.  South Africa 

SAHPRA

# ![Flag of South Africa](/flags/za.svg)South Africa - SAHPRA 

Guidance Last updated · 2023 Verified · 2026-07-16 

Medicines and Related Substances Act + SAHPRA medical device guidance

Share Copy link X LinkedIn Email

Sources verified · 2026-07-16

SAHPRA cybersecurity content is guidance; POPIA overlay confirmed.

Authority

South African Health Products Regulatory Authority

Enforced

2017 (licensing); cyber guidance 2022

Legal framework

Medicines Act + SAHPRA MD Regulations + POPIA

FDA package reuse

~80%

[Editorial estimate · how →](/methodology#fda-reuse)

## Scope

All medical devices and IVDs requiring establishment licensing. Cybersecurity addressed via general safety and POPIA data-protection overlay.

Pre-market

Risk-based registration dossier; CE / FDA approvals accepted as supporting evidence.

Post-market

Vigilance reporting to SAHPRA; POPIA breach notifications to the Information Regulator.

SBOM

Recommended 

Not mandated; encouraged for SaMD aligned to FDA expectations.

Vulnerability disclosure

Encouraged via CSIRT.gov.za.

Penalty

Licence suspension; POPIA fines up to R10M; criminal liability.

## Unique requirements

-   01 South African Establishment Licence 
-   02 Local Authorised Representative 
-   03 POPIA compliance for any patient-data processing 

## Highlights

-   Reference jurisdiction route for FDA / CE 
-   POPIA data-protection overlay 
-   Phased medical device licensing rollout 

## Aligns with

IMDRF N60  ISO 13485  FDA 2023 Guidance 

## Timeline

1.  2017
    
    Medical device licensing introduced
    
2.  Jul 2021
    
    POPIA full enforcement
    
3.  2022
    
    SAHPRA cybersecurity guidance circulated
    

## Key documents

[

SAHPRA Medical Devices

https://www.sahpra.org.za/medical-devices/



](https://www.sahpra.org.za/medical-devices/)[

POPIA

https://popia.co.za/



](https://popia.co.za/)

## How to submit in South Africa

Playbook reviewed · 2026-07-16

Submission route

SAHPRA licence under the Medicines and Related Substances Act

SAHPRA's medical device framework is maturing; cybersecurity expectations track IMDRF and are typically satisfied by an FDA or CE package.

[Authority portal](https://www.sahpra.org.za/medical-devices/)

### Step-by-step

1.  Step 01
    
    Appoint local representation
    
    Most jurisdictions require a locally-established entity to hold the registration or act as authorised representative before submission.
    
2.  Step 02
    
    Reuse FDA or CE package as baseline
    
    Adapt the cybersecurity subsection you already prepared for FDA or CE; regulators here typically accept the structure and ask for local labeling additions.
    
3.  Step 03
    
    Translate and localise
    
    Local-language technical summary and labeling are usually mandatory; certified translation is safest.
    
4.  Step 04
    
    Submit + track queries
    
    Respond to clarification rounds promptly; each unanswered question can add 30-90 days to the clock.
    

### Evidence checklist

Item

Level

FDA equivalent

Notes

Cybersecurity documentation (baseline FDA or CE)

Required 

SPDF

Local authorised representative agreement

Required 

—

Local-language labeling and IFU

Required 

—

SBOM

Recommended 

—

Not mandatory but reduces clarification rounds.

### Common SAHPRA rejections

Establishment licence not in place for local rep

Common 

Fix ·  Local rep must hold a SAHPRA establishment licence before filing.

### Typical timeline

End-to-end window: 9-18 months 

Phase 01

Local rep + dossier prep

2-4 months

Phase 02

Regulatory review

9-18 months

Phase 03

Approval + market entry

1-3 months

[Previous ![Flag of United Arab Emirates](/flags/ae.svg)United Arab Emirates ](/standards/ae)[Next  ![Flag of Malaysia](/flags/my.svg)Malaysia ](/standards/my)

## Related markets

[![Flag of United Kingdom](/flags/gb.svg)

United Kingdom

~80% FDA reuse

](/standards/uk)[![Flag of Taiwan](/flags/tw.svg)

Taiwan

~80% FDA reuse

](/standards/tw)[![Flag of Malaysia](/flags/my.svg)

Malaysia

~80% FDA reuse

](/standards/my)[![Flag of Philippines](/flags/ph.svg)

Philippines

~80% FDA reuse

](/standards/ph)

## Frequently asked about South Africa

### Is SBOM required for medical devices in South Africa?

Recommended. Not mandated; encouraged for SaMD aligned to FDA expectations.

### What does SAHPRA require for pre-market cybersecurity?

Risk-based registration dossier; CE / FDA approvals accepted as supporting evidence.

### What are the post-market cybersecurity obligations under SAHPRA?

Vigilance reporting to SAHPRA; POPIA breach notifications to the Information Regulator.

### What is the penalty for non-compliance with SAHPRA cybersecurity rules?

Licence suspension; POPIA fines up to R10M; criminal liability.

### How much of my FDA cybersecurity package is reusable in South Africa?

Roughly 80% - an editorial estimate based on overlapping evidence requirements (threat model, SBOM, security risk assessment, pen-test report).

Sponsored note · Blue Goat Cyber

Submitting to SAHPRA? Get a second pair of eyes before you file. Blue Goat Cyber has packaged cybersecurity evidence for South Africa alongside 37 other markets. We'll tell you what to keep, what to rework, and what's missing, in 30 minutes.  [Talk through your SAHPRA submission](https://go.bluegoatcyber.com/meetings/blue-goat-cyber/discovery-session)

The Crosswalk

An independent reference for global medical device cybersecurity standards. A field guide for MedTech innovators and RA/QA teams charting an international path.

Resource

-   [Comparison matrix](/compare)
-   [Global playbook](/playbook)
-   [Glossary](/glossary)
-   [FAQ](/faq)

Sponsored by

[Blue Goat Cyber ↗](https://bluegoatcyber.com)

Editorially independent. Sponsorship keeps it free.

© 2026 The Crosswalk. Not legal advice.

Validate every requirement against current regulator publications.