Taiwan's primary cyber-resilience statute, the Cyber Security Management Act (資通安全管理法, Cyber Security Management Act, pcode A0030297), was replaced in full on Sept. 24, 2025 and took effect Dec. 1, 2025 under the Ministry of Digital Affairs (MODA) as competent authority.
Chapter III binds a 'Specific Non-Government Agency,' a term the Act defines to mean 'a critical infrastructure provider, a government-owned enterprise, a designated foundation, or any enterprise, organization, or institution under control of the government' (Art. 3(6)), with a critical infrastructure provider's own class turning on the Executive Yuan's periodic designation of a physical or virtual asset, system or network whose disruption would significantly affect national security, the public interest, daily life or economic activity (Art. 3(7)-(8)).
Every such agency must formulate, implement and report on a cyber security maintenance plan matched to a government-assigned responsibility level, appoint a dedicated Chief Information Security Officer, and submit to periodic audits (Arts. 7-8, 20-23, 30), and must separately maintain a notification and response mechanism and report a cyber security incident to the sector's own central competent authority as soon as it becomes aware of one (Arts. 24, 29).
Because a designated critical infrastructure provider is precisely the cross-sector essential-infrastructure-operator shape this corpus's activity vocabulary expresses through its general essential-service-operator role rather than through any single sector flag, both duties are flagged here; the Act's other named classes, a government-owned enterprise, a nationwide foundation, or a government-controlled enterprise, are named in each instrument's own description of who is bound rather than flagged, because government ownership as such is not an activity or role this corpus's vocabulary currently expresses.
Articles 11 and 27 separately bar a government agency, or a specific non-government agency the central competent authority so restricts, from downloading, installing or using a product the competent authority has determined poses a risk of harm to national cyber security; this is a procurement and use restriction running to the operator itself rather than a design, support-period or vulnerability-handling duty running to a product's manufacturer, so it is named here rather than treated as a product-security-requirements instrument.
Article 33 confirms that where a cyber security incident under this Act involves a personal data breach, the matter is additionally governed by the Personal Data Protection Act (個人資料保護法, pcode I0050021); that Act's own Article 20-1 duty, that 'Non-government agencies possessing personal data files shall implement security and maintenance measures to prevent the theft, alteration, damage, loss, or leakage of personal data,' is this jurisdiction's privacy-topic finding rather than restated here, and has not yet been researched under that topic as of this writing.
A second, sector-specific duty sits in the Telecommunications Management Act (電信管理法, pcode K0060111, enacted 2019, most provisions effective July 1, 2020): Article 15 requires a telecommunications enterprise that has established a public network using allocated telecommunications resources, or another enterprise the competent authority separately announces, to draw up and implement an info-communications security maintenance plan, and Article 42 separately lets the competent authority designate all or part of that network as critical telecommunications infrastructure, whose establisher must then draw up and implement a critical telecommunications infrastructure protection plan the competent authority evaluates and may audit.
Both duties transferred from the National Communications Commission to the Ministry of Digital Affairs on Aug. 27, 2022, and both carry their own escalating fine on non-compliance (Arts. 76, 79).
A third, financial-sector duty sits in a Financial Supervisory Commission (FSC) regulation issued under the Banking Act and four sibling statutes, the Implementation Rules of Internal Audit and Internal Control System of Financial Holding Companies and Banking Industries (金融控股公司及銀行業內部控制及稽核制度實施辦法, pcode G0380218), whose current full-text version was promulgated May 6, 2026: Article 24 requires a financial holding company or a bank, credit cooperative, bills finance company or trust enterprise to establish a dedicated information security unit under a Chief Information Security Officer ranked deputy general manager or above, and Article 25 sets that unit's minimum functions, including cyber security protection and incident-response mechanisms.
This regulation sets no fine of its own; a violation is enforced through the administrative-sanction provisions of the parent statutes it is issued under, not independently traced to a specific article.
Taiwan has no enacted law setting security requirements a software product or connected device must meet before or after it is placed on the market; the product-restriction provisions named above run to a designated operator's own use of a product, not to the product's manufacturer, so a product-security-requirements duty is a researched absence.
Taiwan also has no general reasonable-security or information-security-programme statute reaching a business simply because it holds data with no sector or designation gate; the nearest analogue, the Personal Data Protection Act's Article 20-1 security-safeguards duty, is a comprehensive-regime provision that belongs to the privacy topic under this profile's own seam rule, so a general security-baseline duty is likewise a researched absence.
The Cyber Security Management Act's own enforcement rules (資通安全管理法施行細則, pcode A0030303) are confirmed to exist by name, but their substantive content was not independently reviewed, and that gap is recorded as an open question on the affected instruments below.