Governance & Sustainability
Sercomm regards sound corporate governance as the foundation of sustainable operations. Through the Board of Directors and functional committees such as the Audit Committee, the Company reinforces the oversight role of its independent directors while enhancing decision-making and risk management. Sercomm is committed to accurate, transparent, and timely disclosure, maintains ongoing communication with stakeholders, and incorporates environmental, social, and governance considerations into its business decisions and management practices to support long-term resilience and responsible growth.
Chairman and President
Message from Management

In 2025, the networking industry faced exchange-rate volatility, U.S. tariffs and rising component costs. Sercomm continued to invest in R&D and pursue prudent market strategies. As customer inventories normalized and demand recovered, shipments of next-generation broadband products gained momentum. Consolidated revenue reached NT$54 billion, with a gross margin of 15.7% and EPS of NT$4.04.

We strengthened coordination across five manufacturing centers in Chunan, Suzhou, Calamba, New Delhi and Mexico. Our second Philippine facility began mass production, with further expansion planned in Mexico. We also continued to develop markets in Southeast Asia, Latin America and the Middle East.

Sercomm continued its ESG efforts and low-carbon transition. We ranked in the top 6%–20% of Taiwan's Corporate Governance Evaluation and earned the EcoVadis Platinum Medal, placing us in the global top 1%.

In 2026, we will continue developing Wi-Fi 7, 5G FWA, enterprise networking, AI-powered IoT and distributed access products. Through innovation, cost discipline and closer customer partnerships, we aim to create long-term value for shareholders, customers and employees.

Sustainability Management at Sercomm
SUSTAINABILITY FRAMEWORK

To address stakeholder expectations and establish a consistent path for sustainability initiatives across environmental, social, and governance dimensions, Sercomm reviews and adjusts its sustainability strategy based on the core principles of the United Nations Sustainable Development Goals (SDGs), identified sustainability risks and opportunities, and the results of its annual material topic assessment.

Together, these elements form a unified framework that guides sustainability action plans and the setting of short-, medium-, and long-term goals.

STRATEGIC ALIGNMENT
United Nations Sustainable Development Goals (SDGs) symbol
Goal 3
Goal 4
Goal 5
Goal 6
Goal 7
Goal 8
Goal 9
Goal 10
Goal 11
Goal 12
Goal 13
Goal 14
Goal 15
Goal 16
Goal 17
SDGs Logo
Sustainability Vision and Direction
Sercomm strives to be a trusted technology partner to telecommunications customers worldwide. The Company responds to evolving market needs through product and service innovation while deepening collaboration with customers and value chain partners. In its business decisions, Sercomm considers the long-term interests of shareholders, customers, employees, and other stakeholders. Guided by integrity and regulatory compliance, Sercomm seeks to build a greener, safer, more equitable, diverse, and inclusive company while creating lasting value with its stakeholders.
Sustainability Management in Practice
RBA, JAC and ISO
International Standards and System Certifications

Sercomm incorporates the Responsible Business Alliance (RBA) Code of Conduct and international standards such as ISO into its responsible operations framework. Based on the nature of each site’s operations, the Company maintains management and verification mechanisms covering quality, occupational health and safety, environment, energy, greenhouse gas inventories, information security, and supply chain security. Implementation is reviewed through self-assessments, internal audits, third-party certification or verification, and management review, with corrective actions tracked to improve management effectiveness.

Management in Practice
Standards Alignment

Identify applicable regulations, customer requirements, and international standards, and incorporate them into management policies and systems.

System Implementation

Responsible units implement training, risk controls, and routine management activities in accordance with established procedures.

Assessment and Assurance

Review implementation and effectiveness through self-assessments, internal and external audits, and third-party certification or verification.

Continual Improvement

Track audit findings and corrective actions, and update management objectives and practices through management reviews.

Management System Certifications
Quality, Occupational Health and Safety, and Responsible Operations
ISO 9001:2015 Quality Management System
Taipei Headquarters (DNV) | Chunan (DNV) | Suzhou (DNV) | Philippines (DNV)
TL 9000:2016 Telecommunications Quality Management System
Taipei Headquarters (DNV) | Chunan (DNV) | Suzhou (DNV)
ISO 45001:2018 Occupational Health and Safety Management System
Taipei Headquarters (BSI) | Chunan (DNV) | Suzhou (DNV) | Philippines (DNV)
RBA Validated Assessment Program (VAP)
Chunan (RBA) | Suzhou (RBA) | Philippines (RBA)
Environmental, Climate, and Energy Management
ISO 14001:2015 Environmental Management System
Chunan (DNV) | Suzhou (DNV) | Philippines (DNV)
ISO 14064-1:2018 GHG Inventory
Taipei Headquarters (DNV) | Chunan (DNV) | Suzhou (TÜV SÜD) | Philippines (TÜV SÜD)
ISO 14067:2018 Carbon Footprint Verification
Chunan (DNV) | Suzhou (DNV, SGS)
Green Mark
Philippines (TÜV Rheinland)
LEED Green Building Certification
Chunan (USGBC)
ISO 50001:2018 Energy Management System
Chunan (DNV) | Suzhou (TÜV SÜD) | Philippines (DNV)
FSC-STD-40-004 V3-1 Chain of Custody Certification
Philippines (BV)
Information and Supply Chain Security
ISO/IEC 27001:2022 Information Security Management System
Taipei Headquarters (SGS) | Chunan (SGS) | Suzhou (TÜV SÜD) | Philippines (TÜV SÜD)
C-TPAT U.S. Customs Trade Partnership Against Terrorism
Chunan (GSV) | Philippines (GSV)

For the scope of management system certifications and the certification bodies for each site, please refer to page 127 of the Sercomm 2025 Sustainability Report.

Climate Governance and Strategic Action

Sercomm integrates climate change into its corporate governance and enterprise risk management. The Board of Directors is the highest oversight body for climate governance and oversees the management framework, strategic direction, and targets for climate-related risks and opportunities. Chaired by the President, the Sustainable Development Committee meets quarterly to review climate risk assessments, SBTi targets, and related action plans, and periodically reports implementation progress to the Board.

Linking governance and strategy
Risk-informed decisions
The sustainability function coordinates with manufacturing, supply chain, finance, and other functions to identify and assess climate-related risks and opportunities. The results inform operational management, investment decisions, strategic planning, and financial planning.
Targets into action
Science-based targets and climate scenario analysis guide planning for low-carbon investment, energy transition, supply chain decarbonization, and low-carbon products, with implementation progress reviewed regularly.
How international frameworks support management
CDP
Disclosure and external review

Sercomm participates in CDP assessments and discloses its GHG emissions, climate risks, and management responses. Assessment results are used to review data quality and disclosure gaps.

TCFD
Governance and risk integration

Sercomm applies the TCFD pillars of governance, strategy, risk management, and metrics and targets to integrate climate issues into enterprise risk management and progressively align with IFRS S2.

Science Based Targets initiative (SBTi)
Targets guiding transition

Sercomm's SBTi targets were validated in 2025. From a 2023 base year, the Company targets a 42% reduction in absolute Scope 1 and Scope 2 emissions and a 25% reduction in Scope 3 emissions by 2030.

2025 management actions

In 2025, the Sustainable Development Committee reviewed and tracked SBTi target and scenario modeling, internal carbon pricing planning, Scope 3 tracking and supply chain decarbonization, renewable energy and energy management, and customer product life cycle assessment and product carbon footprint methodologies. Regular reporting and follow-up connect climate strategy with business operations and customer needs.

For detailed climate risks and opportunities, scenario analysis, metrics, targets, and performance, see Environment & Innovation.

CDP TCFD SBTi
Sustainable Supply Chain Management

Under its Sustainable Procurement Policy and Supplier Management Procedure, Sercomm integrates environmental protection, occupational health and safety, labor and human rights, business ethics, information security, and personal data protection into supplier management. Suppliers are required to comply with applicable laws, the Responsible Business Alliance (RBA) Code of Conduct, and green product requirements including RoHS, REACH, and WEEE. Sercomm manages environmental and social risks through supplier commitments, risk assessments, audits, and corrective action follow-up.

Management approach
Policies and commitments
Management requirements are communicated through the Supplier's Code of Conduct Agreement, the Supplier Code of Conduct, and relevant contract clauses. New suppliers must complete the required assessments and sign these documents before becoming qualified suppliers.
Selection and assessment
Prospective suppliers undergo document reviews and, depending on their characteristics and risk level, on-site audits. CSR risk assessments cover regional, business, environmental, social, and governance factors, including labor and human rights, occupational safety, personal data protection, ethics, and responsible minerals.
Audits and improvement
Existing suppliers are managed by category based on monthly scoring and annual audits. Sustainability audits follow the five RBA areas and include zero-tolerance items. Sercomm requires corrective action and tracks progress; suppliers that fail the follow-up review lose their qualified status.
Capacity and decarbonization
Training and practical exchanges help suppliers understand regulatory, customer, and Sercomm sustainability requirements. Sercomm also collects emission factors and product carbon footprint information to improve the completeness and traceability of supply chain carbon data.
Responsible minerals and green procurement
Responsible minerals

Supplier due diligence follows the OECD guidance and the RMI's CMRT and EMRT. Sercomm reviews mineral origins and smelter qualification status, and requires a phase-out plan when an unqualified smelter is identified.

Sustainable and green procurement

Guided by ISO 20400, procurement decisions consider environmental and social factors. Sercomm prioritizes environmentally preferable, low-carbon, low-hazard, and recyclable materials, and encourages suppliers to establish environmental and energy management systems.

2025 results
100%
Signing rate for both required new-supplier commitments
54 suppliers
Tier 1 suppliers received on-site audits, including 31 key suppliers
88.33%
Corrective action rate for other non-conformances, with 333 findings corrected
291 suppliers
Participated in ESG training, totaling 503 attendances and 1,996.5 person-hours
503 suppliers
Covered by the responsible minerals survey, with a 100% response rate
269 smelters
Identified in the supply chain; all were qualified smelters

No suppliers were identified as having significant actual or potential negative environmental or social impacts in 2025. For the complete management system, audit scope, and performance data, see pages 30-37 of the Sercomm 2025 Sustainability Report.

Sustainable Supply Chain
Information Security Policy

Sercomm regards information security as essential to operational resilience and to protecting corporate, customer, and product information. Guided by its Information Security Policy and ISO/IEC 27001:2022 Information Security Management System (ISMS), the Company applies governance oversight, risk assessment, security controls, monitoring and audits, incident response, and continual improvement through the PDCA cycle. Privacy and personal data protection are managed as a related but distinct area covering the lawful use and security of personal data throughout its life cycle.

Governance and Management Structure
Governance and Oversight
Convened by the Chief Operating Officer, the Information Security Committee meets every six months to review information security and data protection policies, management performance, and material issues, and reports to the Board at least annually. The Information Security Promotion Team coordinates policy implementation, risk management, and compliance reviews across domestic and overseas operations.
Dedicated Function and System
In 2025, Sercomm established a dedicated information security department with two full-time personnel responsible for security architecture, governance systems, incident monitoring and response, and cross-functional risk assessment and improvement tracking. Taipei Headquarters and the Chunan, Suzhou, and Philippines sites are certified to ISO/IEC 27001:2022 and regularly undergo internal audits, management reviews, and third-party audits.
Corporate and Product Information Security
Corporate Information Security

Sercomm regularly conducts information asset inventories, risk assessments, vulnerability scans, and penetration tests. Intrusion detection, network access control, endpoint detection and response, and encryption of confidential information strengthen the security of networks, devices, applications, and data. Twenty-four-hour monitoring, tiered incident reporting, disaster recovery, social engineering, and breach-and-attack simulation exercises further enhance detection and response capabilities.

Product Information Security

The Product Security Incident Response Team (PSIRT) integrates the Secure Development Lifecycle (SDLC) into product design, development, verification, and post-launch management. Products are tested for malware, backdoors, network vulnerabilities, and potential attacks, with identified issues tracked through JIRA. Researchers, industry organizations, and suppliers may report a product vulnerability, including the affected product and version, issue details, and exploitation status, to PSIRT@sercomm.com.

Privacy and Personal Data Protection

Sercomm incorporates privacy and personal data protection requirements for employees, suppliers, customers, and consumers into its Sustainable Development Best Practice Principles, Employee Handbook, Supplier's Code of Conduct Agreement, Information Security Management Manual, and other management documents. These requirements apply across branches, operating sites, and subsidiaries. In accordance with the Personal Data Protection Act and applicable requirements, the Company applies controls to the collection, storage, processing, transmission, and sharing of personal data. Confidentiality agreements, access controls, system and equipment safeguards, and training further protect employee and customer data.

2025 Management Results
2
Dedicated information security personnel
3
Three reviews completed: one internal audit, one management review, and one external audit
24-hour
Security monitoring and incident tracking
9
System recovery and information security exercises
72.56%
Training implementation rate, totaling 585.62 person-hours
Zero
Major information security incidents; complaints involving customer privacy breaches or data loss were also zero

For the complete governance structure, management mechanisms, incident reporting process, exercises, and secure product development process, please refer to pages 111-114 of the Sercomm 2025 Sustainability Report.

Sercomm turns review findings and incident lessons into corrective actions and management updates.

  • Management reviews assess KPIs, risk changes, audits, incidents, and resource needs.
  • Assign owners and deadlines for deficiencies, then verify corrective action effectiveness.
  • Apply incident lessons to improve reporting, response, recovery, and security awareness training.
  • Update policies, procedures, risk treatments, and controls for regulatory, threat, technology, or business changes.
  • Track improvements through governance reporting until effective closure.

Sercomm plans its information security management in line with its policy, ISO/IEC 27001:2022, and applicable requirements.

  • Set annual objectives, KPIs, and action plans based on operational, regulatory, customer, and contractual needs.
  • Inventory information assets, assess impacts, threats, and vulnerabilities, and define risk treatment.
  • Assign responsibilities and reporting lines across governance and implementation teams.
  • Define incident levels, reporting timelines, response and recovery goals, including privacy and personal data protection.

Sercomm reviews control effectiveness and performance through monitoring, testing, exercises, and audits.

  • Use endpoint detection and the security operations center for 24-hour monitoring and incident tracking.
  • Scan vulnerabilities, update information asset inventories, and perform business impact analysis.
  • Conduct penetration tests and BAS exercises to validate detection and response.
  • Perform internal audits, management reviews, and third-party audits against ISO/IEC 27001:2022.
  • Review KPIs, incidents, exercises, and findings, then track corrective actions and report results.

Sercomm implements risk treatment plans across people, systems, data, and suppliers.

  • Manage accounts, authentication, and system access by job requirements, with regular permission reviews.
  • Protect confidential, customer, and personal data through classification, encryption, backup, and secure handling.
  • Provide onboarding, security awareness training, and social engineering exercises.
  • Apply security requirements and periodic assessments to IT contractors and suppliers.
  • Classify and report incidents, then respond, recover, and track improvements under established procedures.
Sustainability Governance and Materiality
Sustainability Governance Structure

Sercomm links Board oversight with management decisions and cross-functional execution through a four-level sustainability governance structure.

Board of Directors|Oversight and Approval

Approves and oversees Sercomm's sustainability vision, strategy, and direction. The Committee reports key progress and issues to the Board at least annually.

Sustainable Development Committee|Decision and Review

Chaired by the President and composed of directors and senior executives, the Committee reviews policies, strategies, targets, action plans, and performance. It meets quarterly and held four meetings in 2025 with 100% attendance.

Sustainability Task Force|Coordination and Integration

Coordinates sustainability plans and responsibilities, consolidates targets, annual actions, and results each month, and reports to the Committee. Written updates are provided in months without an in-person meeting.

Five Thematic Task Forces|Implementation

Sustainable Development, Responsible Products, Responsible Operations, Employee Relations and Sustainability Engagement, and Corporate Governance set targets and action plans, implement initiatives, and report progress as required.

Sustainable Development Committee
Risk Management

Approved by the Board in 2020, Sercomm's Risk Management Policies and Procedures guide enterprise risk management.

Governance

The Board holds ultimate accountability, supported by the Audit Committee and Executive Management Committee. Risk units implement controls. The Audit Office reviews self-assessments and corrective actions.

Process

Following ISO 31000, Sercomm manages risks through identification, analysis, assessment, response, and tracking, with regular reporting and monitoring.

Risk Scope

Assessments cover strategic, operational, financial, and event risks, including supply chains, information security, intellectual property, customer credit, climate change, and occupational safety. Material risks are reported to the Board with response plans and targets.

Business Continuity

Business Impact Analysis identifies critical processes and recovery priorities. At least one test or drill is conducted annually, and continuity plans are updated as needed.

Sercomm Risk Management Organization
Stakeholder Engagement
Key Stakeholders

Sercomm identifies key stakeholders with reference to the AA1000 Stakeholder Engagement Standard 2015 (AA1000 SES), its industry context, and operating characteristics. The 2025 assessment identified five groups: employees, customers, suppliers, investors/financial institutions, and government agencies.

Identification and Governance

The assessment considers operational interaction, issue impact, and communication frequency. External expert input on industry trends, regulatory requirements, and stakeholder expectations is also incorporated to support a complete and objective result.

Communication and Response

Responsible units use meetings, surveys, training, grievance and service channels, public disclosures, and project engagement to understand concerns and drive responses and improvement. Engagement status is reported to the Board at least annually; the 2025 results were reported on August 11, 2026. For stakeholder concerns, communication channels and frequency, and key 2025 outcomes, please refer to pages 27–28 of the 2025 Sustainability Report.

2025 Key Engagement Outcomes

  • Employees: 32 OHS Committee meetings, four labor-management meetings, four new employee sessions with 114 participants, and four welfare committee meetings; average training time was 5.10 hours per employee; Taiwan training and activity feedback averaged 92.50%.
  • Customers: Satisfaction score of 77.87, responses to over 150 sustainability requests and surveys, and participation in nine industry exhibitions.
  • Suppliers: Two training sessions involving 291 suppliers and 503 participants, plus one supplier recognition conference.
  • Investors/Financial Institutions: Ten investor conferences and one shareholders' meeting.
  • Government Agencies: No material violations or grievances; responses submitted to 20 Taiwan Stock Exchange questionnaires.
Stakeholder Engagement
Material Topic Analysis

Following the GRI Universal Standards 2021, Sercomm applies double materiality to identify and prioritize sustainability topics. The assessment considers both Sercomm's actual and potential impacts on the economy, environment, and people, including human rights, and the effects of sustainability matters on financial performance, operations, and long-term development. It also supports preparations for IFRS S1 and S2.

Double Materiality

Impact materiality: Actual or potential positive and negative impacts on the economy, environment, and people, considering severity and likelihood.

Financial materiality: Potential effects of sustainability matters on Sercomm's financial performance, operations, and long-term development.

2025 Assessment Process

01 Understand the context: Starting with 23 topics, Sercomm collected 30 internal questionnaires to identify five stakeholder groups and 70 stakeholder concern surveys.

02 Identify impacts: The Company analyzed 23 positive and 23 negative impact factors.

03 Assess significance: Nineteen impact surveys and seven financial materiality surveys were collected.

04 Prioritize reporting: Topics were ranked by stakeholder views, impact significance, strategic relevance, and financial materiality. The Sustainable Development Committee approved 13 material topics.

2025 Material Topics

Environmental: Climate Change Mitigation and Adaptation; Greenhouse Gas and Energy Management.

Social: Human Resource Management; Occupational Health and Safety; Human Rights Management.

Governance: Economic Performance; Information Security; Sustainable Supply Chain Management; Business Ethics.

Products and Services: Product Innovation and R&D; Customer Relationship Management; Product and Service Responsibility; Green Products.

Reading the Matrix and Governance

The horizontal axis shows impacts on the economy, environment, and people; the vertical axis shows financial materiality. Bubble size indicates the materiality level, while filled labels identify the 2025 material topics.

Following Committee approval, the results are incorporated into the annual Sustainability Report and submitted to the Board for approval before publication. See pages 22-26 of the 2025 Sustainability Report for the full methodology, impact descriptions, matrix, and ranking.

Material Topics
Business Ethics
Integrity Management Framework

Sercomm manages business ethics through policies, Board oversight, risk assessment, preventive controls, and internal audit. The framework covers directors, managers, employees, and supplier partners through applicable rules and commitments.

Policies and Scope

Key policies include the Ethical Corporate Management Best Practice Principles, Procedures for Ethical Management and Guidelines for Conduct, the Code of Ethical Conduct for Directors and Managers, and insider trading controls. They prohibit bribery, improper donations, illegal political contributions, conflicts of interest, unfair trade, and other improper benefits. Supplier commitments extend these requirements to business partners.

Governance and Board Oversight

The Internal Audit Office, reporting to the Board, oversees implementation. Management and relevant units perform internal control self-assessments, while Internal Audit reviews integrity risks, establishes checks for high-risk matters, and reports implementation to the Board annually.

Risk Assessment and Prevention

Annual assessments consider revenue, procurement, production capacity, and prior high-risk audit findings. Controls include Code of Ethical Conduct acknowledgment, mandatory training, onboarding communication, and insider trading reminders.

Internal Audit and Follow-up

The annual audit plan is approved by the Board. Audit progress and corrective actions are reported quarterly to the Audit Committee and the Board, with continued follow-up on key locations and high-risk processes.

2025 Performance

  • Integrity risk assessments covered the headquarters and major manufacturing centers in Chunan, Suzhou, and the Philippines, achieving 100% coverage.
  • All new employees signed the Code of Ethical Conduct. Business ethics training totaled 199.26 man-hours and 5,091 attendances, with a 71.93% implementation rate.
  • All 94 internal audit findings were corrected.
  • No corruption involving Sercomm or internal personnel was identified. One outsourced security worker in Suzhou falsified attendance records. The worker was blacklisted, the service provider was fined and not renewed, relevant managers were disciplined, and controls were strengthened.
Regulatory Compliance
Regulatory Compliance
Sercomm monitors legal and regulatory developments across its operating locations. A dedicated legal function supports business units in updating internal requirements and maintaining compliance. No material instances of non-compliance occurred in 2025; other disclosed cases were addressed through corrective actions.
Anti-Corruption
Anti-Corruption
Sercomm prohibits bribery, improper donations or sponsorships, illegal political contributions, conflicts of interest, unfair trade, and other improper benefits. In 2025, no corruption involving Sercomm or internal personnel was identified. One outsourced security worker in Suzhou falsified attendance records; the worker was blacklisted, the vendor was fined and not renewed, relevant managers were disciplined, and controls were strengthened.
Whistleblowing
Whistleblowing
Sercomm provides an independent reporting channel for employees, suppliers, customers, and other stakeholders. Named and anonymous reports are accepted with strict confidentiality and protection from retaliation. Appropriate action is taken based on investigation results. Report concerns to audit@sercomm.com. For the full policy, grievance channels, and procedures, see “Reporting, Grievance, and Whistleblower Protection” on the “People & Community” page.
Ethics Training
Ethics Training
All new employees sign the Code of Ethical Conduct, while employees complete annual mandatory business ethics training covering ethical management, insider trading, anti-money laundering, anti-corruption, conflicts of interest, and fair trade. In 2025, the signing rate was 100%; training totaled 199.26 man-hours and 5,091 attendances, with a 71.93% implementation rate.
Learn More About Sercomm’s Sustainability Efforts