top of page

Taiwan BSMI Type Approval Update: New Cybersecurity Files

  • Jul 21
  • 6 min read

Taiwan's Bureau of Standards, Metrology and Inspection (BSMI) has issued a full revision of the Guidelines for Type Approval Operations of Electrical and Electronic Products (電機電子類商品型式認可作業要點), the operating instrument that specifies exactly which technical documents must accompany a type approval application in Taiwan.

The revision was promulgated on 20 May 2026 under Order No. 經標檢政字第11530001750號 and took effect immediately on the same date. It replaces the entire text, reducing the instrument from eleven points to ten.


The timing matters. The Guidelines were originally issued on 13 September 2002 and amended only once thereafter, on 23 October 2007. This is therefore the first substantive change to Taiwan's electrical and electronic type approval documentation set in nearly two decades and the substance of the change is cybersecurity, not administrative housekeeping.


What Changed in the Taiwan BSMI Type Approval Documentation Set


The headline change is the creation of a fourth technical documentation category: Information Security Requirements (資訊安全規範). The prior text recognised three categories only electrical safety, electromagnetic compatibility, and digital reception function. Where an information security inspection item applies to a product, the applicant must now file:


  1. A Chinese language user manual and specification sheet

  2. Colour photographs (4×6 inches or larger) of the exterior and internal structure, with a product catalogue permitted in place of the exterior shot where necessary

  3. Certification certificates, factory reports or specification sheets for security relevant software and key hardware components expressly including active chips, communication chips and communication modules

  4. Functional block diagrams for the security relevant hardware architecture, plus functional block or hierarchy diagrams for the software programs

  5. A software bill of materials (SBOM) covering security and ICT related software, together with a list of key hardware components and material composition specifications

  6. A completed information security self-check form (資訊安全自我檢查表)


Points 5 and 6 are the operationally significant additions. An SBOM is not a document most electrical and electronic manufacturers currently generate for Taiwanese certification purposes, and producing one to an auditable standard requires build pipeline tooling and supplier disclosure that many organisations have not yet put in place.


Deferred Application to Energy and Mobility Hardware


A dedicated transitional paragraph names four product families and gives them a fixed future start date. For electric vehicle charging equipment, power conversion systems, solar photovoltaic inverters, and stationary lithium energy storage devices, the information security technical documents become a required part of the type approval application from 1 January 2028.

This is the clearest signal in the instrument of where BSMI's supply chain security concern is concentrated: grid connected and grid adjacent power electronics.


Other Amendments


  • Certificate validity language softened. Point 6 previously stated that a type approval certificate is valid for three years. The revised text states that validity is three years in principle (原則為三年), introducing administrative discretion where none previously existed on the face of the instrument.

  • Import sampling provisions consolidated. The first declaration sampling rule formerly at Point 10 has been folded into Point 9. Substantively, the sampling probabilities are unchanged: one batch in twenty for information technology products and EMC only products, one batch in ten for everything else.

  • Re testing trigger clarified. Point 9 now specifies that where sampling fails, it is goods of the same type that must pass two consecutive declared batches before simplified inspection resumes.

  • English language allowance extended to cover the Chinese manual and specification item within the new information security category, subject to BSMI agreement.


An infographic summarizing the May 2026 revision to Taiwan's BSMI Type Approval Guidelines. It uses a "before and after" layout to show the addition of a fourth technical category "Information Security Requirements" alongside safety, EMC, and digital reception. The graphic outlines the new mandatory documentation set (including user manuals, component security evidence, and Software Bill of Materials/SBOM), points out affected product families like EV chargers and solar inverters with a January 2028 deadline, and notes administrative changes to certificate validity and product modification rules.

Correction: Product Modification Rules Were Removed, Not Tightened


One widely circulated characterisation of this revision states that product modification and change control protocols have been tightened. The primary text shows the opposite.

The 2007 version of the Guidelines contained a Point 7 setting out a three tier change regime: a changed basic design required a fresh type approval application; an unchanged basic design with variation in other inspected items required a series product approval; and a change affecting neither the certificate particulars nor product identification required only an application for approval.


That provision has been deleted from the revised Guidelines. The new Point 7 says only that BSMI and its branches may require supporting documents, technical documents or test reports when reviewing re applications, series applications or approval cases.

The deletion is a de duplication exercise rather than a liberalisation. The same three-tier change regime appears in Article 12 of the parent Regulations Governing Type Approval of Commodities (商品型式認可管理辦法, FL011450), where it remains fully in force. The substantive obligation on manufacturers is unchanged; only its location has moved. Manufacturers assessing a design change should now cite the Regulations, not the Guidelines.


What This Means for Manufacturers


Your existing documentation package is not automatically sufficient. If any of your product's declared inspection items includes an information security element, the technical file you assembled under the 2007 rules is incomplete. The gap is not formatting it is the absence of an SBOM, component-level security attestation, and a completed self check form.


SBOM capability is now a market access dependency, not a best practice. Generating an SBOM that will survive review means knowing, at component and library level, what is in your firmware and who supplied it. For manufacturers relying on third party communication modules or turnkey chipset firmware, this requires contractual disclosure from suppliers that may not currently exist. Supplier engagement should start well ahead of any filing.


Energy and EV hardware makers have a hard deadline and a long lead time. The 1 January 2028 date for EV chargers, power conversion systems, solar inverters and lithium storage devices looks distant. It is not, once you account for supplier negotiation, tooling deployment, firmware documentation and a first pass BSMI review cycle. Treat 2027 as the build year.


Do not read the modification rules as relaxed. The change control tiers still bind you through the parent Regulations. A design change affecting basic design still triggers a fresh application; a variant still requires series approval supported by a type test report identifying the differences from the original type.


Certificate renewal planning should assume less certainty. With validity now stated as three years "in principle", renewal timing may become case dependent. Build buffer into renewal schedules rather than assuming a fixed 36 month cycle.


Importers and local representatives carry the filing burden. Under the parent Regulations, where the producer is not domiciled in Taiwan, the applicant is the local agent or importer. That entity will be the one asked to produce an SBOM it did not create. Clarify responsibility and document flow contractually before filing.


Certification Impact Summary


Area

Position Before 20 May 2026

Position After 20 May 2026

Impact Level

Technical documentation categories

Three: safety, EMC, digital reception

Four: safety, EMC, digital reception, information security

High

SBOM requirement

None

Required for security/ICT-related software

High

Component security evidence

None

Certificates, factory reports or spec sheets for active chips, comm chips, comm modules

High

Information security self-check form

None

Mandatory submission

Medium

EV chargers, power conversion systems, PV inverters, lithium ESS

No security documentation

Security documentation required from 1 Jan 2028

High

Certificate validity

Three years

Three years in principle

Low

Product modification tiers

Stated in Guidelines Point 7

Deleted from Guidelines; governed by Regulations Art. 12

None

Import sampling probability

1/20 IT & EMC-only; 1/10 others

Unchanged

None

Safety, EMC and digital reception document lists

As per 2007 text

Unchanged

None

English-language documents

Permitted for specified items with BSMI consent

Extended to new information security manual item

Low


Timeline and Required Actions


Date

Event

Required Action

13 Sep 2002

Guidelines originally issued

23 Oct 2007

First full revision (11 points)

20 May 2026

Full revision issued and effective (10 points), Order No. 11530001750

Audit all active and pipeline Taiwan filings against the revised Point 3 document list

Q3 2026

Immediate transition period

Confirm with your Taiwanese agent or a designated laboratory whether your product's declared inspection items include an information security element

Q4 2026

Supplier engagement

Secure SBOM data, component certificates and firmware disclosure commitments from chip, module and firmware suppliers; amend supply contracts where needed

2027

Build year for deferred categories

Deploy SBOM generation tooling; complete the information security self-check form as a dry run; budget for extended review cycles

Q4 2027

Pre-deadline filing window

Submit EV charger, power conversion system, PV inverter and lithium ESS applications with a full security file to absorb any deficiency-notice cycle

1 Jan 2028

Information security documents become mandatory for EV chargers, power conversion systems, solar PV inverters and stationary lithium energy storage devices

No application in these categories may be filed without the Point 3(4) technical documents


Verify Your Taiwan Certification Position


Documentation gaps surface at the worst possible moment after a shipment has been declared and is sitting at the border. If you place electrical, electronic, EV charging or energy storage products on the Taiwanese market, now is the point to confirm whether your technical file meets the revised BSMI requirements.

bottom of page