Buying Security Testing in Taiwan's Public Sector
5 min read
When a government agency or a public school sets aside budget for security testing, the first obstacle is usually not technical. It is procurement: do you run your own tender, or buy through a common-supply contract? The administrative cost of the two routes differs enormously, and choosing wrong costs weeks. This piece sets out the mechanism so the decision gets made while the budget is still being drafted. Two things to say upfront. This describes Taiwan's public procurement system; if you buy for a public body elsewhere, your own framework agreements rest on a similar idea under different rules. And LaiSecure is not on any common-supply contract award list, so nothing here is a pitch. It is the difference between the two routes, written down. General background only: the announcements of the competent authority and the rules in force are what govern.
1. What a common-supply contract is for
A common-supply contract is Taiwan's framework agreement for public buying. If every agency ran its own tender for the same thing, the administrative cost across government would be enormous. Instead one agency acts on behalf of the rest: it runs a single tender and signs contracts with the suppliers that win. Every other eligible body then orders directly under that contract, with no tender of its own to run.
Eligibility usually covers government agencies at every level, public schools and state-owned enterprises, with the exact scope set by each individual contract. Ordering runs through the common-supply contract system on the government e-procurement site, where the line items, specifications and prices are all visible. That visibility helps at the budgeting stage, because you can see roughly what something costs without sending out a request for quotes first.
For the officer handling the purchase, the gain is skipping the tender, which can compress weeks into days. The price is that you can only buy the items and specifications the contract holds, with very little room to customise. If your requirement lands neatly on a standard item, this route is fast and easy. If it does not, you will read the contract end to end and find nothing that matches.
2. What the security line items look like
Inside the information services common-supply contracts, security work is normally split into separate services, each with its own pricing unit. Decide which one you are buying first, because the outputs are not interchangeable. Nobody refunds a wrong choice; you simply receive a report answering a question you did not ask.
| Service | Priced by | What you get |
|---|---|---|
| Web application vulnerability scan | Number of URLs or systems | A list of weaknesses classified against the OWASP Top 10, with remediation advice |
| Host vulnerability scan | Number of IP addresses | A list of weaknesses with severity scored by CVSS |
| Security health check | Number of hosts | Results from going inside the system to inventory processes, accounts, open services and scheduled tasks |
| Penetration test | Number of targets and depth of testing | The process and result of actually attempting to exploit weaknesses, normally a price tier above a scan |
| Social engineering exercise | Number of people tested | Response statistics for the people tested, plus follow-up training recommendations |
Line items, specifications and awarded suppliers change with each contract term, so do not copy a specification document somebody wrote a few years ago. Check the current contract on the e-procurement site before drafting the budget, because both prices and pricing units may have moved. The usual result of copying an old specification is that the budget is set and the request has already gone up the chain before anyone notices the item no longer exists.
3. The order the work actually happens in
From deciding to test to a supplier turning up, the steps run roughly as follows. Things stall at step two and step five most often. Step two is the amount band: pick the wrong path and you start over. Step five is the authorisation letter, without which the supplier will not begin on the day.
Six steps for the officer handling it
- Fix the scope. How many sites, how many hosts, how many IP addresses. That drives the amount, which drives the procurement route.
- Work out which amount band you are in. Small purchases follow a simpler procedure and do not necessarily need a common-supply contract. Larger amounts follow the prescribed process, and the threshold figures get adjusted, so check the current announcement.
- Look up the current contract on the government e-procurement site. Confirm your item and specification exist, and see which suppliers hold the award.
- If the item matches, order through the system. If nothing matches your specification, assess running your own procurement instead.
- Sign the testing authorisation letter before anything runs. This step cannot be skipped. Without written authorisation the supplier should not proceed, and you carry risk you did not need to.
- Read the report at sign-off. Does it include manual verification, is there a remediation priority order, and do the false positives come with the reasoning behind the judgement.
4. When the amount is small, there are other options
Not every piece of security testing has to go through a common-supply contract. A vulnerability scan of one website, or a health check on a handful of hosts, often falls inside the simpler small-purchase procedure. Going straight to a supplier for a quote is faster in that case, and you can buy things the contract specifications do not cover. The actual thresholds and procedures follow the rules in force and your own organisation's internal policy, so ask your finance or accounting office once before the budget is drafted.
The real benefit of sourcing your own quotes is that the scope becomes negotiable. Contract items are standard specifications. If your requirement is unusual, a custom scope is often cheaper. Say you have one system but want it tested more thoroughly: through the contract you would have to buy a whole bundle of specifications you will not use, while a direct quote can cover only the part you want.
Ask for a redacted sample report when you request quotes. The report is the only thing this money leaves behind, so checking the format against what your sign-off requires beats discovering afterwards that the content is thin.
One thing to be plain about. Suppliers on a common-supply contract have to go through the tender process and meet the qualification conditions, which leaves out individual contractors and studios without a commercial registration. So if your organisation is required to buy through a common-supply contract, work with the suppliers listed on the system. LaiSecure is not one of them. Direct engagement is only an option where the amount falls inside the range you can source yourself, and where your accounting office accepts a signed service payment record rather than a unified invoice, which is Taiwan's government-issued VAT invoice. Saying that at the outset saves both sides a meeting that ends in a dead end.
The value of a common-supply contract is skipping the tender. The cost is a fixed specification with little room to customise. Settle the scope and the amount before the budget is drafted, then decide between the contract and your own sourcing. That is far less work than finding out afterwards that the procedure was wrong. Whichever route you take, two things stay non-negotiable: written authorisation before testing starts, and report quality at sign-off.
Common questions
- Is a common-supply contract always cheaper?
- Not necessarily. The contract price is a negotiated standard rate for a standard specification, and its advantages are procedural simplicity and price transparency rather than being the lowest price on the market for every item. On a small, straightforward job, your own quotes can come back closer to what you actually need, because you are not paying for specifications you will never use.
- Can a private company buy through a common-supply contract?
- No. In Taiwan the system covers government agencies at every level, public schools and state-owned enterprises, and private companies fall outside it. A private buyer simply negotiates with a supplier directly. The precise eligibility is set by each individual contract.
- Can an independent supplier take on work for an agency or a school?
- Within the small-purchase range there is a chance, but it depends on your organisation's internal rules. The sticking point is usually documentation. An individual taking the work as professional practice income provides a signed service payment record with tax withheld by the agency, not a unified invoice. Some accounting offices accept that, others insist on an invoice. Ask before the budget is drafted and you get an answer quickly.
- The contract has no specification matching what we need. What then?
- Assess running your own procurement. The common version of this is an agency wanting an unusual scope, for example one system tested more thoroughly than the standard item allows, or a specific report format. Forcing that into a standard item usually buys something unusable, so follow the prescribed process for sourcing it yourself.