Start with the specific network, system, service, app, product, procurement, or data activity in China. Then identify the legal entity acting as network operator, provider, data processor, platform operator, app sponsor, or purchaser under each controlling instrument.
Recommended order: scope the activity and role, classify the system and data, screen special review or filing routes, implement controls, then schedule recurring and change-triggered work.
The Cybersecurity Law applies to constructing, operating, maintaining, and using networks in China. It first took effect on 1 June 2017; amendments adopted on 28 October 2025 took effect on 1 January 2026 and renumbered the operating duties. Critical information infrastructure (CII) status depends on identification and notice by the responsible sector protection department. Important-data status depends on the applicable national, regional, departmental, industry, or sector catalogue or an authority identification. Neither status follows automatically from being a network operator. The review measures, app rules, filing notice, and recommended GB/T standards have separate actors and triggers.
Separate law and measure effective dates from app-filing implementation phases and recommended-standard implementation dates. A historical effective date is not a new annual deadline.
New to the regime? Start by scoping the activity and regulated role. If those facts are already documented, move directly to review triggers, evidence, deadlines, enforcement, or a focused comparison.
Identify the specific China network, data activity, app, platform, procurement, or connected product before assigning duties. CII status requires sector recognition and operator notice; network-operator status alone is not enough.
Classify systems and data, then document whether classified protection or cybersecurity review is relevant and what evidence supports the conclusion.
Keep app-provider, app-distribution-platform, MIIT filing, the smart-home standard, and the voluntary cybersecurity label scheme separate while linking shared product and security facts.
Distinguish one-time historical effective dates from filing phases, event-driven deadlines, recurring controls, and actor-specific enforcement exposure.
Use a comparison when one launch crosses legal regimes, or go to the focused FAQ when the immediate trigger is already known.
Sorena AI helps map official China Cybersecurity Law requirements to scoped decisions, evidence records, owners, and change-triggered reviews.
