Cybersecurity 2026

TAIWAN Law and Practice Contributed by: Ken-Ying Tseng, Winona Chen and Roger Kai, Lee and Li Attorneys-at-Law

ards, with Chinese National Standard (CNS) 27001 or the International Organization for Standardization (ISO) 27001 standard given as examples. Other sys - tems or standards with equal or stronger effect, or other standards developed by the government agency itself and approved by the competent authority, are also acceptable. Entities at levels A–C are also required to assign dedi - cated cybersecurity personnel. Moreover, both non- government agency and government agency staff can hold the position of chief information security officer (CISO) under Articles 12 and 23 of the CSMA. Also, entities at every level shall conduct cybersecurity edu - cation and training regularly. In addition to the CSMA, entities may have different requirements under other regulations. Requirements for Conducting Risk Assessment or Specific Cyber-Testing, Scanning and Analysis Operations For entities subject to the CSMA, the Regulations on Classification of Cyber Security Responsibility Levels provide different levels of entities with technical meas - ures for adoption. For example, for level A entities, security detection, cybersecurity health diagnosis, cybersecurity monitoring management mechanisms, vulnerability management and cybersecurity defence are required. The specific personal data security maintenance plans stipulated by the competent authorities of certain industries may also demand that entities establish an audit mechanism for the security maintenance of personal data, and designate appropriate personnel to inspect the implementation status of the plan and its process. Required Standards for Recovery and Resiliency of Business Operations and Necessary Data After Cyber-Attacks The CSMA does not provides a specific standard for recovery and resiliency after cyber-attacks, provid - ing only general obligations to plan for recovery and resiliency.

Government agencies and private entities subject to the CSMA should comply with the Regulations on Classification of Cyber Security Responsibility Levels. As explained, the entities are required to file and submit a report on the investigation, response and improvement of cybersecurity under the CSMA after cyber-attacks. Article 12 of the Enforcement Rules of the CSMA explicates the items that should be includ - ed in the report, but it specifies no standards for the same. 2.3 Incident Response and Notification Obligations Under the CSMA, a cybersecurity incident refers to any event where the status of a system, service or network is identified as having a potential violation of the cybersecurity policy, or a failure of protective measures, which affects the functionality of the infor - mation and communication system. Pursuant to the CSMA, government agencies and pri - vate entities subject to the CSMA shall report to their supervisory agencies and MODA when they become aware of a cybersecurity incident. The Regulations for Reporting and Responding Cyber - security Incidents set forth further details about the reporting of cybersecurity incidents, as required under the CSMA. A specific non-government agency shall report to its regulator at the central government within one hour after it becomes aware of a cybersecurity incident, and the regulator shall respond within two to eight hours depending on the classification of the cybersecurity incident. Meanwhile, the specific non- government agency shall complete damage control or recovery of the system within 36–72 hours. 2.4 State Responsibilities and Obligations Responsibilities for Promoting National Cybersecurity Resilience Pursuant to Article 4 of the CSMA, the government should bolster national cyber resilience by actively integrating private industry capabilities and provid - ing essential resources to safeguard public interests. In this regard, MODA, as the competent authority of the CSMA, is responsible for establishing the Nation - al Cyber Security Development Program to advance

395 CHAMBERS.COM

Powered by