Cyber Security Management Act, Specific Non-Government Agency Cyber Security Management
Arts. 3(6)-(8) 7-8, 20-23 and 30 of the Cyber Security Management Act (資通安全管理法), full-text amendment promulgated Sept. 24, 2025 (Presidential Order Hua-Zong-Yi-Yi-Zi No. 11400095391), effective Dec. 1, 2025
A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.
What follows is LexLint's own research summary of this law, not legal advice.
In force 10 months, effective 1 December 2025.
A sector security regimes rule binding private bodies.
As of 19 September 2026.
What it requires
- This binds a critical infrastructure provider the government has individually designated under Article 20, or another specific non-government agency (a government-owned enterprise, a designated nationwide foundation, or an enterprise, organization or institution under government control) Article 3(6) defines; a business the competent authority has not placed in one of these designated classes carries no duty under this row.
- Report to the competent authority for approval or recordation of the agency's assigned cyber security responsibility level, based on the sensitivity, volume and nature of the information the agency holds and the scale and nature of its information and communication systems.
- Appoint a dedicated Chief Information Security Officer to promote and oversee the agency's cyber security affairs.
- Formulate, revise and implement a cyber security maintenance plan matching the agency's assigned responsibility level, and submit its implementation status and any corrective-action report to the central competent authority in charge of the relevant sector.
- Comply with the central competent authority's periodic or ad hoc audits of the maintenance plan's implementation; a designated critical infrastructure provider's audit results are forwarded to the Ministry of Digital Affairs.
- A failure to formulate, implement or report on the plan draws a fine of NT$100,000 to NT$5,000,000 per violation, after an unheeded order to correct within a specified period.
If you get it wrong
Criminal exposureNo
Private right of actionNo
Criminal exposure note
Article 30's sanction for a maintenance-plan, reporting or audit failure is an administrative fine with an order to correct; no provision reviewed here makes that failure, standing alone, a criminal offense.
Penalty structure
Article 30's shared range for any of six listed failures (maintenance-plan formulation or implementation, implementation-status reporting, corrective-action reporting, notification-mechanism formulation, incident-report submission, and drill or notification-content requirements) is NT$100,000 to NT$5,000,000 per violation, imposed after an order to correct within a specified period goes unheeded, escalating per violation for continued non-correction.
- Rule
- Fixed only
- As of
- 19 September 2026
- Currency
- TWD
- Fixed cap
- 5,000,000
Who enforces it
Enforcement body
The central competent authority in charge of the relevant sector for a designated critical infrastructure provider or other specific non-government agency (for example the Financial Supervisory Commission for a financial-sector critical infrastructure provider), which reports audit and corrective-action results to the Ministry of Digital Affairs, the Act's overall competent authority.
Settledness
- As of
- 19 September 2026
- Open questions
- The Cyber Security Management Act's own enforcement rules (資通安全管理法施行細則, pcode A0030303) were confirmed by name to exist during this research pass; does their substantive content add a threshold, timeline or procedure to the responsibility-level or audit duties recorded here?
What it reaches
Obligation class
Security, Governance
What this law does
Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.
Chapter III of the Cyber Security Management Act binds a 'Specific Non-Government Agency,' defined to mean 'a critical infrastructure provider, a government-owned enterprise, a designated foundation, or any enterprise, organization, or institution under control of the government' (Art. 3(6)).
A critical infrastructure provider's own class is defined by reference to 'physical or virtual assets, systems, or networks, the functions of which, once they cease to operate or their performance is reduced, may have a significant impact on national security, social and public interests, people's lives, or economic activities' (Art. 3(7)), a class the Executive Yuan periodically designates.
A critical infrastructure provider 'shall comply with the requirements of their assigned cyber security responsibility levels, appoint dedicated cyber security personnel, and ... formulate, revise, and implement cyber security maintenance plans' (Art. 20, Paragraph 2). Every other specific non-government agency carries the identical duty under Article 21, Paragraph 1.
Every specific non-government agency must also 'appoint a Chief Information Security Officer ... responsible for promoting and overseeing the specific non-government agency's cyber security-related affairs' (Art. 23). A failure to formulate, implement or report on the maintenance plan draws, under Article 30, 'a fine of not less than NT$100,000 and not more than NT$5,000,000 ... for each violation.'
When LexLint raises it
operates_essential_service
Read the law
Official English translation
Laws & Regulations Database of the Republic of China (law.moj.gov.tw), read through the kong0107/mojLawSplitJSON mirror per the corpus's #8858 fidelity determination MOJ UpdateDate 20260911
Every line above is drawn from the primary source linked here, read on the date shown. This is a research summary, not legal advice.