CybersecurityChina

China Cybersecurity Law Compliance Guide

Start with the specific network, system, service, app, product, procurement, or data activity in China. Then identify the legal entity acting as network operator, provider, data processor, platform operator, app sponsor, or purchaser under each controlling instrument.

By Sorena AIOfficial citationsPractical launch evidence
Quick scan
Cybersecurity
Identify the regulated role
Scope the particular China network, system, app, platform, and data activity; do not label the whole company with one role.
Screen review and filing triggers
Run the notified-CII procurement, network-platform national-security and foreign-listing, important-data catalogue, app governance, and filing screens independently.
Build security evidence
Retain dated role and applicability decisions, Article 23 and 27 operating evidence, Article 24 product-support records, filings, review materials, incidents, remediation, and change triggers.

Recommended order: scope the activity and role, classify the system and data, screen special review or filing routes, implement controls, then schedule recurring and change-triggered work.

Key dates
1 Jan 2026
amended Cybersecurity Law effective
1 Sep 2021
Data Security Law effective
15 Feb 2022
review measures effective
1 Aug 2022
app provisions effective
What this hub helps you decide
Identify the regulated role
Define the specific network, system, app, platform, product, procurement, or data activity first. One organisation may be a network operator for one system, a network product or service provider for another, a data processor, a notified CII operator, a network platform operator, an app sponsor, or an app distribution platform.
Screen review and filing triggers
Check whether notified CII procurement or a network platform operator's data processing affects or may affect national security. Separately apply the mandatory pre-listing filing where a network platform operator holds personal information of more than one million users and seeks a foreign listing. Keep these reviews apart from app governance, Ministry of Industry and Information Technology (MIIT) app filing, and outbound-data routes.
Build security evidence
Keep the legal trigger, actor, official source, control owner, operating evidence, filing or review result, incident process, and reassessment trigger together. A GB/T designation identifies a recommended Chinese national standard, not a statute. Standards mappings and the voluntary China Cybersecurity Label route do not replace binding network, data, app, telecom, radio, or privacy duties.
Identify the regulated role
Screen review and filing triggers
Build security evidence
Publication details
Editorial metadata for this artifact
Author
Sorena AI
Published
Jul 5, 2026
Updated
Jul 16, 2026

The Cybersecurity Law applies to constructing, operating, maintaining, and using networks in China. It first took effect on 1 June 2017; amendments adopted on 28 October 2025 took effect on 1 January 2026 and renumbered the operating duties. Critical information infrastructure (CII) status depends on identification and notice by the responsible sector protection department. Important-data status depends on the applicable national, regional, departmental, industry, or sector catalogue or an authority identification. Neither status follows automatically from being a network operator. The review measures, app rules, filing notice, and recommended GB/T standards have separate actors and triggers.

China Timeline

Key dates for China Cybersecurity Law

Separate law and measure effective dates from app-filing implementation phases and recommended-standard implementation dates. A historical effective date is not a new annual deadline.

Loading timeline...
Recommended reading path

Choose the next China cybersecurity decision

New to the regime? Start by scoping the activity and regulated role. If those facts are already documented, move directly to review triggers, evidence, deadlines, enforcement, or a focused comparison.

1

Start here: scope, roles, and baseline duties

Identify the specific China network, data activity, app, platform, procurement, or connected product before assigning duties. CII status requires sector recognition and operator notice; network-operator status alone is not enough.

5

Compare routes or answer a specific question

Use a comparison when one launch crosses legal regimes, or go to the focused FAQ when the immediate trigger is already known.

Next step

Build the China network security evidence file

Sorena AI helps map official China Cybersecurity Law requirements to scoped decisions, evidence records, owners, and change-triggered reviews.

What this unlocks
  • Start with the official trigger and the product, app, data flow, equipment, supplier, or lifecycle role that creates the China Cybersecurity Law question.
  • Research Copilot keeps the official citation, decision owner, evidence record, and approval history connected.
  • SSOT preserves official citations, launch facts, evidence files, and refresh history when product, supplier, app, data, equipment, or disposal facts change.
China Cybersecurity Law artifact preview
Share it internally
Download the timeline export to align legal, product, engineering, and commercial teams on milestones and deadlines.