Cybersecurity 2026

TAIWAN Trends and Developments Contributed by: Ken-Ying Tseng, Winona Chen and Roger Kai, Lee and Li Attorneys-at-Law

enhancements are warranted. Additionally, it explores best practices from jurisdictions recognised for their advanced cybersecurity efforts, offering Taiwanese regulators insights to enhance the current regulatory landscape. Through this analysis, the article aims to inform stakeholders, including legal practitioners, cor - porate compliance officers and policymakers, about the evolving obligations and strategic considerations that are essential for navigating Taiwan’s cybersecurity environment. Regulatory expectations Regulatory expectations in Taiwan increasingly emphasise cybersecurity and national security con - siderations in vendor and supply chain management, particularly for suppliers participating in government, critical infrastructure and financial-sector procure - ment projects. Under the Cybersecurity Management Act (CMA), government agencies, critical infrastruc - tures and critical infrastructure providers are required, in principle, to avoid or restrict from procuring or using information and communications technology (ICT) products that are deemed to endanger national cybersecurity. In practice, ICT products formally iden - tified as endangering national cybersecurity are pre - dominantly those originating from, manufactured by or substantially involving elements from China (PRC). Consequently, suppliers are expected to proactively reduce or eliminate PRC-related elements through - out their supply chains, including hardware com - ponents, embedded software, firmware, cloud ser - vices, technical support and maintenance services. This expectation extends beyond first-tier vendors to upstream suppliers and subcontractors, requiring comprehensive supply chain due diligence, transpar - ent disclosure of product origin and contractual com - mitments to maintain a PRC-free or PRC-reduced supply chain. Vendors are further expected to imple - ment internal governance mechanisms, such as peri - odic risk assessments, supplier qualification reviews and change-management procedures, to ensure that subsequent modifications to product design, sourcing strategies or ownership structures do not undermine compliance or introduce new security risks. Furthermore, standard government procurement tem - plates impose strict information security obligations on suppliers, requiring full compliance with the CMA

and its subordinate regulations, the Classified Nation - al Security Information Protection Act, the Personal Data Protection Act (PDPA), the Copyright Act and all cybersecurity standards and policies promulgated by the Executive Yuan. In the event that a supplier vio - lates the requirements and causes harm to the rights or interests of others due to its negligence, the sup - plier shall bear legal liabilities and is required to fully co-operate in the subsequent remediation measures, including incident investigation, containment, notifica - tion, evidence preservation and corrective actions. If such violations result in losses to the procuring agen - cy, the supplier is also liable for damages. Further - more, government agencies have the right to conduct cybersecurity audits, supervision, document reviews or other appropriate verification measures, which reinforces the principle that suppliers are subject to continuous oversight throughout the entire contract life cycle rather than only at the procurement stage. Similar regulatory logic applies within the financial industry under the oversight of the Financial Super - visory Commission (FSC), which imposes stringent outsourcing rules to safeguard the security, confi - dentiality and operational resilience of financial infor - mation systems. Financial institutions are generally prohibited from engaging outsourcing vendors with PRC capital backgrounds, and outsourced systems, platforms or products must not be manufactured in PRC, reflecting heightened concerns regarding data leakage, systemic risk, cross-border data access and potential foreign influence over critical financial infra - structure. In addition to binding regulatory require - ments, Taiwan’s Bankers Association has established self-regulatory guidelines governing information sys - tem outsourcing, further strengthening expectations for vendor risk assessment, contractual safeguards, service continuity planning and ongoing supervision. These guidelines require financial institutions to retain audit rights over outsourced vendors, enabling on-site inspections, documentation reviews, security test - ing, source-code or architecture assessments where appropriate, and incident response drills to ensure continued compliance. Government procurement cybersecurity requirements similarly emphasise supplier accountability, audit - ability, timely incident reporting and strict adherence

408 CHAMBERS.COM

Powered by