---
title: "Taiwan TFDA - Cybersecurity Submission Playbook"
description: "How to submit a medical device to TFDA in Taiwan: step-by-step route, evidence checklist, common rejections, and typical review timeline. Compared with FDA &amp;"
lang: en
json-ld: |
  [
    {
      "@context": "https://schema.org",
      "@type": "WebSite",
      "name": "The Medical Device Cybersecurity Crosswalk",
      "alternateName": "MDC Crosswalk",
      "url": "https://mdccrosswalk.com/",
      "description": "Compare FDA, EU MDR, MHRA, PMDA, NMPA, TGA, MFDS and Health Canada medical device cybersecurity requirements across 29 jurisdictions."
    },
    {
      "@context": "https://schema.org",
      "@type": "Organization",
      "name": "MDC Crosswalk",
      "url": "https://mdccrosswalk.com/",
      "logo": "https://mdccrosswalk.com/favicon.png",
      "sameAs": [
        "https://bluegoatcyber.com"
      ],
      "description": "An editorial reference comparing global medical-device cybersecurity regulations. Maintained by Blue Goat Cyber."
    },
    {
      "@context": "https://schema.org",
      "@type": "Article",
      "headline": "Taiwan - Cybersecurity Guidance for Medical Devices (2021, rev. 2023)",
      "description": "How to submit a medical device to TFDA in Taiwan: step-by-step route, evidence checklist, common rejections, and typical review timeline. Compared with FDA & ",
      "author": {
        "@type": "Organization",
        "name": "MDC Crosswalk"
      },
      "publisher": {
        "@type": "Organization",
        "name": "MDC Crosswalk"
      },
      "image": "https://mdccrosswalk.lovable.app/favicon.png",
      "datePublished": "2023",
      "about": "Taiwan Food and Drug Administration",
      "dateModified": "2026-07-16",
      "mainEntityOfPage": "https://mdccrosswalk.lovable.app/standards/tw"
    },
    {
      "@context": "https://schema.org",
      "@type": "FAQPage",
      "mainEntity": [
        {
          "@type": "Question",
          "name": "Is SBOM required for medical devices in Taiwan?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "Required. Expected at submission for Class II/III network-connected devices; SPDX or CycloneDX accepted."
          }
        },
        {
          "@type": "Question",
          "name": "What does TFDA require for pre-market cybersecurity?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "Threat modelling, secure design, verification & validation; SBOM expected for higher-risk devices."
          }
        },
        {
          "@type": "Question",
          "name": "What are the post-market cybersecurity obligations under TFDA?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "Vulnerability monitoring, software change reporting, periodic security updates."
          }
        },
        {
          "@type": "Question",
          "name": "What is the penalty for non-compliance with TFDA cybersecurity rules?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "Licence revocation, recall, fines under Medical Devices Act."
          }
        },
        {
          "@type": "Question",
          "name": "How much of my FDA cybersecurity package is reusable in Taiwan?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "Roughly 80% - an editorial estimate based on overlapping evidence requirements (threat model, SBOM, security risk assessment, pen-test report)."
          }
        },
        {
          "@type": "Question",
          "name": "Why do TFDA submissions get rejected for \"no taiwanese licence holder\"?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "Appoint a Taiwanese entity holding a device permit."
          }
        }
      ]
    },
    {
      "@context": "https://schema.org",
      "@type": "HowTo",
      "name": "How to submit a medical device to TFDA",
      "description": "TFDA aligns with IMDRF and accepts FDA / PMDA content with Chinese translation. Cybersecurity guideline mirrors FDA 2018 pre-market with local adaptations.",
      "totalTime": "6-12 months",
      "step": [
        {
          "@type": "HowToStep",
          "position": 1,
          "name": "Appoint local representation",
          "text": "Most jurisdictions require a locally-established entity to hold the registration or act as authorised representative before submission."
        },
        {
          "@type": "HowToStep",
          "position": 2,
          "name": "Reuse FDA or CE package as baseline",
          "text": "Adapt the cybersecurity subsection you already prepared for FDA or CE; regulators here typically accept the structure and ask for local labeling additions."
        },
        {
          "@type": "HowToStep",
          "position": 3,
          "name": "Translate and localise",
          "text": "Local-language technical summary and labeling are usually mandatory; certified translation is safest."
        },
        {
          "@type": "HowToStep",
          "position": 4,
          "name": "Submit + track queries",
          "text": "Respond to clarification rounds promptly; each unanswered question can add 30-90 days to the clock."
        }
      ]
    },
    {
      "@context": "https://schema.org",
      "@type": "BreadcrumbList",
      "itemListElement": [
        {
          "@type": "ListItem",
          "position": 1,
          "name": "Home",
          "item": "https://mdccrosswalk.lovable.app/"
        },
        {
          "@type": "ListItem",
          "position": 2,
          "name": "Standards"
        },
        {
          "@type": "ListItem",
          "position": 3,
          "name": "Taiwan"
        }
      ]
    }
  ]
---

[

The Crosswalk



](/)

[Overview](/)[Playbook](/playbook)CompareReference

[New Per-page social previews and this changelog ](/changelog "Per-page social previews and this changelog") Search⌘K

1.  [Home ](/)
2.  Standards 
3.  Taiwan 

TFDA

# ![Flag of Taiwan](/flags/tw.svg)Taiwan - TFDA 

Guidance Last updated · 2023 Verified · 2026-07-16 

Cybersecurity Guidance for Medical Devices (2021, rev. 2023)

Share Copy link X LinkedIn Email

Sources verified · 2026-07-16

TFDA 2021/2023 guidance is non-binding; SBOM expectation reflects guidance, not a hard statutory rule.

Authority

Taiwan Food and Drug Administration

Enforced

Jul 2021

Legal framework

Medical Devices Act + TFDA Cybersecurity Guidance + IMDRF N60 alignment

FDA package reuse

~80%

[Editorial estimate · how →](/methodology#fda-reuse)

## Scope

Network-connected medical devices and SaMD. Risk-based depth of cybersecurity evidence at registration.

Pre-market

Threat modelling, secure design, verification & validation; SBOM expected for higher-risk devices.

Post-market

Vulnerability monitoring, software change reporting, periodic security updates.

SBOM

Required 

Expected at submission for Class II/III network-connected devices; SPDX or CycloneDX accepted.

Vulnerability disclosure

TWCERT/CC coordinated disclosure encouraged.

Penalty

Licence revocation, recall, fines under Medical Devices Act.

## Unique requirements

-   01 Taiwan Licence Holder required 
-   02 Traditional Chinese labelling and IFU 
-   03 QSD (Quality System Documentation) inspection 

## Highlights

-   Closely tracks IMDRF N60 
-   SBOM expected for Class II/III 
-   Reference jurisdiction route accepted for FDA approvals 

## Aligns with

IMDRF N60  FDA 2023 Guidance  IEC 81001-5-1 

## Timeline

1.  Jul 2021
    
    First cybersecurity guidance
    
2.  2023
    
    Revision aligned to IMDRF N60
    

## Key documents

[

TFDA Medical Device Cybersecurity Guidance

https://www.fda.gov.tw/eng/



](https://www.fda.gov.tw/eng/)

## How to submit in Taiwan

Playbook reviewed · 2026-07-16

Submission route

TFDA licence under the Medical Devices Act with cybersecurity per TFDA 2021 guideline

TFDA aligns with IMDRF and accepts FDA / PMDA content with Chinese translation. Cybersecurity guideline mirrors FDA 2018 pre-market with local adaptations.

[Authority portal](https://www.fda.gov.tw/ENG/)

### Step-by-step

1.  Step 01
    
    Appoint local representation
    
    Most jurisdictions require a locally-established entity to hold the registration or act as authorised representative before submission.
    
2.  Step 02
    
    Reuse FDA or CE package as baseline
    
    Adapt the cybersecurity subsection you already prepared for FDA or CE; regulators here typically accept the structure and ask for local labeling additions.
    
3.  Step 03
    
    Translate and localise
    
    Local-language technical summary and labeling are usually mandatory; certified translation is safest.
    
4.  Step 04
    
    Submit + track queries
    
    Respond to clarification rounds promptly; each unanswered question can add 30-90 days to the clock.
    

### Evidence checklist

Item

Level

FDA equivalent

Notes

Cybersecurity documentation (baseline FDA or CE)

Required 

SPDF

Local authorised representative agreement

Required 

—

Local-language labeling and IFU

Required 

—

SBOM

Recommended 

—

Not mandatory but reduces clarification rounds.

### Common TFDA rejections

No Taiwanese licence holder

Common 

Fix ·  Appoint a Taiwanese entity holding a device permit.

### Typical timeline

End-to-end window: 6-12 months 

Phase 01

Local rep + dossier prep

2-4 months

Phase 02

Regulatory review

6-12 months

Phase 03

Approval + market entry

1-3 months

[Previous ![Flag of Israel](/flags/il.svg)Israel ](/standards/il)[Next  ![Flag of Mexico](/flags/mx.svg)Mexico ](/standards/mx)

## Related markets

[![Flag of United Kingdom](/flags/gb.svg)

United Kingdom

~80% FDA reuse

](/standards/uk)[![Flag of South Africa](/flags/za.svg)

South Africa

~80% FDA reuse

](/standards/za)[![Flag of Malaysia](/flags/my.svg)

Malaysia

~80% FDA reuse

](/standards/my)[![Flag of Philippines](/flags/ph.svg)

Philippines

~80% FDA reuse

](/standards/ph)

## Frequently asked about Taiwan

### Is SBOM required for medical devices in Taiwan?

Required. Expected at submission for Class II/III network-connected devices; SPDX or CycloneDX accepted.

### What does TFDA require for pre-market cybersecurity?

Threat modelling, secure design, verification & validation; SBOM expected for higher-risk devices.

### What are the post-market cybersecurity obligations under TFDA?

Vulnerability monitoring, software change reporting, periodic security updates.

### What is the penalty for non-compliance with TFDA cybersecurity rules?

Licence revocation, recall, fines under Medical Devices Act.

### How much of my FDA cybersecurity package is reusable in Taiwan?

Roughly 80% - an editorial estimate based on overlapping evidence requirements (threat model, SBOM, security risk assessment, pen-test report).

Sponsored note · Blue Goat Cyber

Submitting to TFDA? Get a second pair of eyes before you file. Blue Goat Cyber has packaged cybersecurity evidence for Taiwan alongside 37 other markets. We'll tell you what to keep, what to rework, and what's missing, in 30 minutes.  [Talk through your TFDA submission](https://go.bluegoatcyber.com/meetings/blue-goat-cyber/discovery-session)

The Crosswalk

An independent reference for global medical device cybersecurity standards. A field guide for MedTech innovators and RA/QA teams charting an international path.

Resource

-   [Comparison matrix](/compare)
-   [Global playbook](/playbook)
-   [Glossary](/glossary)
-   [FAQ](/faq)

Sponsored by

[Blue Goat Cyber ↗](https://bluegoatcyber.com)

Editorially independent. Sponsorship keeps it free.

© 2026 The Crosswalk. Not legal advice.

Validate every requirement against current regulator publications.