TFDA
Taiwan - TFDA
Cybersecurity Guidance for Medical Devices (2021, rev. 2023)
Authority
Taiwan Food and Drug Administration
Enforced
Jul 2021
Legal framework
Medical Devices Act + TFDA Cybersecurity Guidance + IMDRF N60 alignment
Scope
Network-connected medical devices and SaMD. Risk-based depth of cybersecurity evidence at registration.
Pre-market
Threat modelling, secure design, verification & validation; SBOM expected for higher-risk devices.
Post-market
Vulnerability monitoring, software change reporting, periodic security updates.
SBOM
RequiredExpected at submission for Class II/III network-connected devices; SPDX or CycloneDX accepted.
Vulnerability disclosure
TWCERT/CC coordinated disclosure encouraged.
Penalty
Licence revocation, recall, fines under Medical Devices Act.
Unique requirements
- 01Taiwan Licence Holder required
- 02Traditional Chinese labelling and IFU
- 03QSD (Quality System Documentation) inspection
Highlights
- Closely tracks IMDRF N60
- SBOM expected for Class II/III
- Reference jurisdiction route accepted for FDA approvals
Aligns with
Timeline
-
Jul 2021
First cybersecurity guidance
-
2023
Revision aligned to IMDRF N60
Key documents
How to submit in Taiwan
Playbook reviewed · 2026-07-16
Submission route
TFDA licence under the Medical Devices Act with cybersecurity per TFDA 2021 guideline
TFDA aligns with IMDRF and accepts FDA / PMDA content with Chinese translation. Cybersecurity guideline mirrors FDA 2018 pre-market with local adaptations.
Authority portalStep-by-step
-
Step 01
Appoint local representation
Most jurisdictions require a locally-established entity to hold the registration or act as authorised representative before submission.
-
Step 02
Reuse FDA or CE package as baseline
Adapt the cybersecurity subsection you already prepared for FDA or CE; regulators here typically accept the structure and ask for local labeling additions.
-
Step 03
Translate and localise
Local-language technical summary and labeling are usually mandatory; certified translation is safest.
-
Step 04
Submit + track queries
Respond to clarification rounds promptly; each unanswered question can add 30-90 days to the clock.
Evidence checklist
| Item | Level | FDA equivalent | Notes |
|---|---|---|---|
| Cybersecurity documentation (baseline FDA or CE) | Required | SPDF | |
| Local authorised representative agreement | Required | — | |
| Local-language labeling and IFU | Required | — | |
| SBOM | Recommended | — | Not mandatory but reduces clarification rounds. |
Common TFDA rejections
No Taiwanese licence holder
CommonFix · Appoint a Taiwanese entity holding a device permit.
Typical timeline
End-to-end window: 6-12 months
Phase 01
Local rep + dossier prep
2-4 months
Phase 02
Regulatory review
6-12 months
Phase 03
Approval + market entry
1-3 months
Related markets
Frequently asked about Taiwan
Is SBOM required for medical devices in Taiwan?
Required. Expected at submission for Class II/III network-connected devices; SPDX or CycloneDX accepted.
What does TFDA require for pre-market cybersecurity?
Threat modelling, secure design, verification & validation; SBOM expected for higher-risk devices.
What are the post-market cybersecurity obligations under TFDA?
Vulnerability monitoring, software change reporting, periodic security updates.
What is the penalty for non-compliance with TFDA cybersecurity rules?
Licence revocation, recall, fines under Medical Devices Act.
How much of my FDA cybersecurity package is reusable in Taiwan?
Roughly 80% - an editorial estimate based on overlapping evidence requirements (threat model, SBOM, security risk assessment, pen-test report).