Getting your device licensed in Canada, with the cybersecurity work you've already done

Health Canada and FDA ask for much of the same evidence. We show you what carries over, fill the gaps, and prepare your submission.

How we help

  1. Gap check
  2. Fill the gaps
  3. Submission review

What Health Canada asks for

Health Canada's Pre-market Requirements for Medical Device Cybersecurity has applied since June 2019.

It covers any medical device that contains software, from Class I to Class IV. Class III and IV Medical Device Licence (MDL) applications and amendments have to include the evidence below.

Usually reusable from your FDA file?
Yes

Usually reusable from your FDA file?
Yes, mostly. May need re-framing to Canadian references such as AAMI TIR57

Usually reusable from your FDA file?
Yes

Usually reusable from your FDA file?
Yes. Check it names Canadian users and reporting routes

Usually reusable from your FDA file?
Partly. Your SBOM carries over, but the labelling text may not

Usually reusable from your FDA file?
New for most US-first teams

How we help

Step 1 of 3

See what carries over

We compare your FDA cybersecurity file with Health Canada's list and show you what's missing.

Gap check

Your FDA cybersecurity file

  • Secure design
  • Risk management
  • Verification and validation

Health Canada requirements

  • Postmarket plan
  • Labelling
  • Marketing history
A clear view of what's missing

Illustrative evidence workflow

Step 2 of 3

Close the evidence gaps

We write or fix the missing pieces: risk file updates, labelling and your postmarket plan.

Fill the gaps

Update your cybersecurity file

  • Risk-management documentation
  • Device labelling
  • Postmarket cybersecurity plan
Missing evidence written or corrected

Illustrative evidence workflow

Step 3 of 3

Get a reviewer's read before you file

Former FDA reviewers read the cybersecurity section the way a Health Canada reviewer would, before you file.

Submission review

Review the cybersecurity section

  • Secure design and risk management
  • Verification and validation evidence
  • Postmarket plan and labelling
Reviewer feedback before you submit

Illustrative evidence workflow

Who you'll work with

The same team that runs our FDA work, including former FDA CDRH premarket reviewers.

Naomi Schwartz

Naomi Schwartz

VP of Regulatory Strategy

Naomi is a regulatory, compliance, and standards expert. She employs gap analyses, proposes mitigation strategies, and optimizes cybersecurity frameworks to address risk and uncertainty for device commercialization and to meet regulatory requirements and guidelines. Naomi has 20+ years of systems engineering experience. Prior to Medcrypt, she was a premarket reviewer and consumer safety officer in CDRH for 6+ years, focusing on software, interoperability, and cybersecurity for connected diabetes devices. Her industry leadership and strategic direction include crafting standards and recommended practices for wireless diabetes device security, managing postmarket triage for cybersecurity vulnerability disclosure. She holds an MS in Electrical and Computer Engineering from Carnegie Mellon University and is a Certified Quality Auditor.

Seth Carmody

Seth Carmody

VP of Sales

Seth has 10 years of medical device experience and provides strategic direction for cybersecurity products and services for the regulated device market. Prior to Medcrypt, he spent 8 years at the FDA, architecting technology policy and laws that impact software-enabled medical devices, including the FDA’s medical device cybersecurity policies. His industry leadership and strategic direction extends to several high-profile industry frameworks including the Joint Security Plan (HSCC), MITRE’s Rubric for Applying CVSS to Medical Devices, and MDIC’s Playbook for Threat Modeling Medical Devices. He has authored several medical device cybersecurity papers and won several information security awards. He holds a PhD in Chemistry from Indiana University.

AJ Reiter

AJ Reiter

VP of Services

AJ started his career as a management consultant specializing in Digital Transformation and Business Optimization for the enterprise space. His expertise includes directing high-impact, enterprise-wide transformations, such as the global redesign of supplier risk management for a publicly traded manufacturer and leading comprehensive supply chain process and risk maturity assessments for major government and healthcare clients, translating leading practices into resource-ready implementation roadmaps and driving substantial organizational standardization. AJ holds a degree from Georgetown where he majored in Economics.

Nick Atwell

Nick Atwell

Director of Cybersecurity

Nick is a cybersecurity expert with extensive experience in PKI, Risk Management, and regulatory compliance. At MedCrypt, he focuses on aligning security architectures and Quality Management Systems (QMS) with FDA and industry standards while ensuring solutions are practical and user-friendly. Previously, Nick led PKI initiatives at Cerner, managing enterprise cryptographic infrastructure and implementing automation to streamline security processes. His work emphasizes both enhancing security posture and delivering solutions that balance compliance with usability.

Proof

"Medcrypt's structured approach to document review was very helpful. We liked their guidance and enjoyed working with their team."
Presidio Medical

FAQ

Much of it, yes. Design, risk and testing evidence usually carries over. Labelling, marketing history and Canada-specific postmarket details often need work.

Health Canada expects all software-containing devices to follow good cybersecurity practice. The detailed application requirements apply to Class III and IV.

It asks for a cybersecurity bill of materials: the commercial, open-source and off-the-shelf software and hardware components that could become vulnerable.

Typically 2 to 4 weeks from the gap check to an application-ready cybersecurity file.

Already cleared by FDA?

Find out in one call how much of that work counts in Canada.

Talk to an expert