Law / Taiwan

Cyber Security Management Act, Cyber Security Incident Reporting

Arts. 24 and 29 of the Cyber Security Management Act (資通安全管理法) full-text amendment promulgated Sept. 24, 2025 (Presidential Order Hua-Zong-Yi-Yi-Zi No. 11400095391), effective Dec. 1, 2025

A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.

What follows is LexLint's own research summary of this law, not legal advice.

In force 10 months, effective 1 December 2025.

A vulnerability and incident reporting rule binding private bodies.

As of 19 September 2026.

What it requires

  • This binds the same specific non-government agency class as the Act's Chapter III sector-regime duties (a designated critical infrastructure provider, government-owned enterprise, designated nationwide foundation, or government-controlled enterprise); no revenue, user-count or other threshold narrows the class further.
  • Establish a notification and response mechanism for a cyber security incident before one occurs.
  • Notify the central competent authority in charge of the relevant sector as soon as the agency becomes aware of a cyber security incident.
  • Submit an investigation, handling and corrective-action report on the incident to that authority, and to the Ministry of Digital Affairs as well where the incident is a major one.
  • A failure to report an incident under this duty draws a fine of NT$300,000 to NT$10,000,000, with additional fines imposed for each period the agency remains uncorrected past the ordered deadline.

If you get it wrong

Criminal exposureNo

Private right of actionNo

Criminal exposure note

Article 29's sanction for a failure to report a cyber security incident is an administrative fine with an order to correct; no provision reviewed here makes that failure, standing alone, a criminal offense.

Penalty structure

Article 29's range for a specific non-government agency's failure to report a cyber security incident under Article 24, Paragraph 2 is NT$300,000 to NT$10,000,000, with additional fines imposed if correction is not made within the prescribed period.

Rule
Fixed only
As of
19 September 2026
Currency
TWD
Fixed cap
10,000,000

Who enforces it

Enforcement body

The central competent authority in charge of the relevant sector, which also receives assistance from and may escalate a major incident to the Ministry of Digital Affairs.

Settledness

As of
19 September 2026
Open questions
Does the Cyber Security Management Act's enforcement rules (資通安全管理法施行細則, pcode A0030303), confirmed by name but not read in full during this research pass, set a specific reporting clock (a number of hours or days) for Article 24's incident-notification duty, which the Act's own text leaves to rules the competent authority prescribes?

What it reaches

Obligation class

Security, Reporting

What this law does

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

Article 24 requires every specific non-government agency to 'establish notification and response mechanisms for cyber security incidents,' and, 'When specific non-government agencies become aware of a cyber security incident, they shall notify the central competent authority in charge of the relevant sector of the incident'.

Failing that notification duty draws, under Article 29, 'a fine of not less than NT$300,000 and not more than NT$10,000,000,' escalating for continued non-correction past the ordered deadline.

When LexLint raises it

  • operates_essential_service

Read the law

Official English translation
Laws & Regulations Database of the Republic of China (law.moj.gov.tw), read through the kong0107/mojLawSplitJSON mirror per the corpus's #8858 fidelity determination MOJ UpdateDate 20260911

Every line above is drawn from the primary source linked here, read on the date shown. This is a research summary, not legal advice.

Back to the example  ·  Lint your app