---
title: "China Cybersecurity, Data Security, and Network Review Compliance Guide"
canonical_url: "https://www.sorena.io/artifacts/apac/china-cybersecurity-law"
source_url: "https://www.sorena.io/artifacts/apac/china-cybersecurity-law"
author: "Sorena AI"
description: "Identify China's network, data, CII, cybersecurity review, app, and connected-product duties under the current Cybersecurity Law and related rules."
published_at: "2026-07-05"
updated_at: "2026-07-16"
keywords:
  - "China Cybersecurity Law"
  - "Data Security Law"
  - "Cybersecurity Review Measures"
  - "Mobile app filing"
  - "MLPS"
---
**[SORENA](https://www.sorena.io/)** - AI-Powered GRC Platform

[Home](https://www.sorena.io/) | [Solutions](https://www.sorena.io/solutions) | [Artifacts](https://www.sorena.io/artifacts) | [About Us](https://www.sorena.io/about-us) | [Contact](https://www.sorena.io/contact) | [Portal](https://app.sorena.io)

---

# China Cybersecurity, Data Security, and Network Review Compliance Guide

Identify China's network, data, CII, cybersecurity review, app, and connected-product duties under the current Cybersecurity Law and related rules.

![China Cybersecurity Law artifact preview](https://cdn.sorena.io/cdn-cgi/image/format=auto/cheatsheets/prod/sorena-ai-china-cybersecurity-law-timeline-small.jpg?v=cheatsheets%2Fprod)

*Cybersecurity* *China*

## China Cybersecurity Law Compliance Guide

Start with the specific network, system, service, app, product, procurement, or data activity in China. Then identify the legal entity acting as network operator, provider, data processor, platform operator, app sponsor, or purchaser under each controlling instrument.

The Cybersecurity Law applies to constructing, operating, maintaining, and using networks in China. It first took effect on 1 June 2017; amendments adopted on 28 October 2025 took effect on 1 January 2026 and renumbered the operating duties. Critical information infrastructure (CII) status depends on identification and notice by the responsible sector protection department. Important-data status depends on the applicable national, regional, departmental, industry, or sector catalogue or an authority identification. Neither status follows automatically from being a network operator. The review measures, app rules, filing notice, and recommended GB/T standards have separate actors and triggers.

[Build the China network security evidence file](/contact.md)

## What this hub helps you decide

- **Identify the regulated role**: Define the specific network, system, app, platform, product, procurement, or data activity first. One organisation may be a network operator for one system, a network product or service provider for another, a data processor, a notified CII operator, a network platform operator, an app sponsor, or an app distribution platform.
- **Screen review and filing triggers**: Check whether notified CII procurement or a network platform operator's data processing affects or may affect national security. Separately apply the mandatory pre-listing filing where a network platform operator holds personal information of more than one million users and seeks a foreign listing. Keep these reviews apart from app governance, Ministry of Industry and Information Technology (MIIT) app filing, and outbound-data routes.
- **Build security evidence**: Keep the legal trigger, actor, official source, control owner, operating evidence, filing or review result, incident process, and reassessment trigger together. A GB/T designation identifies a recommended Chinese national standard, not a statute. Standards mappings and the voluntary China Cybersecurity Label route do not replace binding network, data, app, telecom, radio, or privacy duties.

By Sorena AI | Official citations | Practical launch evidence

### Quick scan

*Cybersecurity*

- **Identify the regulated role**: Scope the particular China network, system, app, platform, and data activity; do not label the whole company with one role.
- **Screen review and filing triggers**: Run the notified-CII procurement, network-platform national-security and foreign-listing, important-data catalogue, app governance, and filing screens independently.
- **Build security evidence**: Retain dated role and applicability decisions, Article 23 and 27 operating evidence, Article 24 product-support records, filings, review materials, incidents, remediation, and change triggers.

Recommended order: scope the activity and role, classify the system and data, screen special review or filing routes, implement controls, then schedule recurring and change-triggered work.

| Value | Metric |
| --- | --- |
| 1 Jan 2026 | amended Cybersecurity Law effective |
| 1 Sep 2021 | Data Security Law effective |
| 15 Feb 2022 | review measures effective |
| 1 Aug 2022 | app provisions effective |

**Key highlights:** Identify the regulated role | Screen review and filing triggers | Build security evidence

## Primary sources

- [PRC Cybersecurity Law, current text](https://www.cac.gov.cn/2025-12/29/c_1768735112911946.htm?ref=sorena.io) - Official consolidated text reflecting the 28 October 2025 amendment. Use Articles 2, 23-27, 33-40, and 78 for territorial scope, baseline duties, product and incident duties, CII obligations, and definitions.
- [NPC report on adoption of the PRC Cybersecurity Law amendment](https://www.npc.gov.cn/npc/c2/c30834/202510/t20251028_449076.html?ref=sorena.io) - Official report confirming adoption on 28 October 2025 and entry into force on 1 January 2026.
- [PRC Data Security Law](https://www.cac.gov.cn/2021-06/11/c_1624994566919140.htm?ref=sorena.io) - Use for data classification and graded protection, important-data risk assessment, security management, incident response, outbound important-data context, penalties, and 1 September 2021 effective date.
- [Cybersecurity Review Measures](https://www.cac.gov.cn/2022-01/04/c_1642894602182845.htm?ref=sorena.io) - Use for cybersecurity review scope, CII procurement filing, platform operator review triggers, review materials, special review, and 15 February 2022 effective date.
- [Mobile Internet Application Information Service Management Provisions](https://www.cac.gov.cn/2022-06/14/c_1656821626455324.htm?ref=sorena.io) - Use for app provider and app distribution platform governance, content/security/data duties, platform filing and verification, and 1 August 2022 effective date.
- [MIIT notice on mobile app filing work](https://www.miit.gov.cn/zwgk/zcwj/wjfb/tz/art/2023/art_920db564162e4312916a01bed6540ad8.html?ref=sorena.io) - Use for MIIT mobile app filing phases, registration, supervision, normalization, and operational filing evidence.
- [GB/T 22239 classified protection baseline requirements](https://openstd.samr.gov.cn/bzgk/gb/newGbInfo?hcno=BAFB47E8874764186BDB7865E8344DAF&ref=sorena.io) - Use as the MLPS/classified protection baseline standard reference for control evidence mapping and the 1 December 2019 implementation date.
- [GB/T smart home general security specification](https://openstd.samr.gov.cn/bzgk/gb/newGbInfo?hcno=B1C14E854C0BA30D1C29FC376299761A&ref=sorena.io) - Use as the smart-home security specification reference for connected appliance evidence mapping and the 1 November 2022 implementation date.
- [Cybersecurity Label Administrative Measures](https://www.cac.gov.cn/2026-04/10/c_1777558393316312.htm?ref=sorena.io) - Official measures effective 1 July 2026. Participation is voluntary, products with internet connectivity are handled through product directories and implementation rules, and network critical equipment and specialized cybersecurity products remain under their separate regime.

*Recommended reading path*

## Choose the next China cybersecurity decision

New to the regime? Start by scoping the activity and regulated role. If those facts are already documented, move directly to review triggers, evidence, deadlines, enforcement, or a focused comparison.

### 1. Start here: scope, roles, and baseline duties

Identify the specific China network, data activity, app, platform, procurement, or connected product before assigning duties. CII status requires sector recognition and operator notice; network-operator status alone is not enough.

1. [CII and network operator role triage](/artifacts/apac/china-cybersecurity-law/critical-information-infrastructure-and-network-operators.md): How to separate ordinary network operator duties from CII, procurement, and review-risk questions under China cybersecurity sources.
2. [China cybersecurity and data security requirements](/artifacts/apac/china-cybersecurity-law/requirements.md): China cybersecurity requirements by actor: network operators, data processors, CII operators, platforms, app providers, and distribution platforms.
3. [China cybersecurity compliance checklist](/artifacts/apac/china-cybersecurity-law/checklist.md): A China cybersecurity checklist for scoping network duties, data security, CII procurement review, app rules, MIIT filing, and supporting standards.

### 2. Classification, review, and evidence

Classify systems and data, then document whether classified protection or cybersecurity review is relevant and what evidence supports the conclusion.

4. [GB/T 22239-2019 classified protection baseline](/artifacts/apac/china-cybersecurity-law/classified-protection-baseline.md): How to scope and document a GB/T 22239-2019 classified protection baseline without treating the recommended standard as a standalone law.
5. [MLPS classified protection evidence map](/artifacts/apac/china-cybersecurity-law/mlps-classified-protection-evidence-map.md): Classify a China network under MLPS, complete level 2 or above filing, map controls, and retain assessment, remediation, and change evidence.
6. [China cybersecurity review workflow](/artifacts/apac/china-cybersecurity-law/cybersecurity-review-workflow.md): Determine whether CII procurement, platform data processing, or a qualifying foreign listing triggers China's Cybersecurity Review Measures.

### 3. Apps and connected products

Keep app-provider, app-distribution-platform, MIIT filing, the smart-home standard, and the voluntary cybersecurity label scheme separate while linking shared product and security facts.

7. [China mobile app filing and app governance](/artifacts/apac/china-cybersecurity-law/mobile-app-filing-and-app-governance.md): Identify the China app sponsor, complete MIIT filing before service, and separate provider, platform, privacy, content, and security duties.
8. [GB/T 41387-2022 smart home security standard](/artifacts/apac/china-cybersecurity-law/smart-home-security-standard.md): How connected-device teams can scope and document GB/T 41387-2022 without treating it as an automatic certification or product-approval duty.

### 4. Deadlines and enforcement

Distinguish one-time historical effective dates from filing phases, event-driven deadlines, recurring controls, and actor-specific enforcement exposure.

9. [China cybersecurity deadlines and compliance calendar](/artifacts/apac/china-cybersecurity-law/deadlines-and-compliance-calendar.md): Separate China cybersecurity commencement dates from recurring duties, filing lead times, review periods, and event-driven response deadlines.
10. [China cybersecurity penalties and fines](/artifacts/apac/china-cybersecurity-law/penalties-and-fines.md): Compare current China Cybersecurity Law and Data Security Law fines by actor, breach, severity, and enforcement consequence.

### 5. Compare routes or answer a specific question

Use a comparison when one launch crosses legal regimes, or go to the focused FAQ when the immediate trigger is already known.

11. [China Cybersecurity Review vs Data Export Assessment](/artifacts/apac/china-cybersecurity-law/cybersecurity-review-vs-data-export-security-assessment.md): Separate China's cybersecurity-review triggers from CAC data-export assessment triggers, thresholds, filings, evidence, timing, and reapplication rules.
12. [China App Filing vs Personal Information Rules](/artifacts/apac/china-cybersecurity-law/mobile-app-filing-vs-app-personal-information-rules.md): Decide whether a China mobile app needs MIIT filing, personal-information controls, or both, with current triggers, duties, dates, and evidence.
13. [China Smart-Home Security vs Telecom and Radio Approval](/artifacts/apac/china-cybersecurity-law/smart-home-security-vs-telecom-wireless-launch.md): Separate GB/T 41387-2022 smart-home security evidence from China telecom network-access and radio approval decisions for connected products.
14. [China Cybersecurity Law vs EU Cyber Resilience Act](/artifacts/apac/china-cybersecurity-law/china-cybersecurity-law-vs-eu-cyber-resilience-act.md): Compare China's network-operator rules with the EU CRA's product duties, including scope, actors, evidence, reporting dates, and launch decisions.
15. [China Cybersecurity Law vs EU NIS2 Directive](/artifacts/apac/china-cybersecurity-law/china-cybersecurity-law-vs-nis2.md): Compare China's network-operator duties with NIS2 entity duties, including scope, management accountability, incident reporting, evidence, and enforcement.
16. [China Cybersecurity Law FAQ](/artifacts/apac/china-cybersecurity-law/faq.md): Practical answers on China network-operator scope, MLPS evidence, important data, cybersecurity review, app filing and governance, and smart-home standards under the law in force from 1 January 2026.

### 6. More guides

Additional guidance related to this artifact.

17. [Does an app need MIIT filing and CAC app governance review?](/artifacts/apac/china-cybersecurity-law/faq/does-an-app-need-miit-filing-and-cac-app-governance-review.md): An app sponsor providing internet information services through an app in China must complete MIIT filing. CAC rules separately govern app providers and distribution platforms without creating one routine CAC approval for every app.
18. [How do smart home security standards fit with China cybersecurity law?](/artifacts/apac/china-cybersecurity-law/faq/how-do-smart-home-security-standards-fit-with-china-cybersecurity-law.md): GB/T 41387-2022 can organize smart-home security evidence, but it is a recommended standard, not a product approval. Check app, data, MLPS, telecom access, and radio requirements separately.
19. [How does important data change China cybersecurity obligations?](/artifacts/apac/china-cybersecurity-law/faq/how-does-important-data-change-cybersecurity-obligations.md): Once data is officially identified as important data, the processor needs named governance, periodic risk assessments and reports, incident controls, and a separate export decision. An internal sensitivity label alone does not establish the legal category.
20. [Is every company a network operator under China Cybersecurity Law?](/artifacts/apac/china-cybersecurity-law/faq/is-every-company-a-network-operator-under-china-cybersecurity-law.md): No. Under China's Cybersecurity Law, a network operator is an owner or administrator of a network or a network service provider. Apply that definition to each China network or service, then test CII and other roles separately.
21. [What is MLPS classified protection evidence?](/artifacts/apac/china-cybersecurity-law/faq/what-is-mlps-classified-protection-evidence.md): MLPS evidence shows how a defined China network or system was graded and protected. Keep the scope, grading rationale, filing or assessment records where applicable, control mapping, test results, remediation, and reassessment history.
22. [When does China cybersecurity review apply?](/artifacts/apac/china-cybersecurity-law/faq/when-does-china-cybersecurity-review-apply.md): China cybersecurity review applies to CII procurement or network-platform data processing that affects or may affect national security, plus a mandatory pre-filing trigger for certain foreign listings involving more than one million users' personal information.

## Key dates for China Cybersecurity Law

*China Timeline*

Separate law and measure effective dates from app-filing implementation phases and recommended-standard implementation dates. A historical effective date is not a new annual deadline.

*Next step*

## Build the China network security evidence file

Sorena AI helps map official China Cybersecurity Law requirements to scoped decisions, evidence records, owners, and change-triggered reviews.

- Start with the official trigger and the product, app, data flow, equipment, supplier, or lifecycle role that creates the China Cybersecurity Law question.
- Research Copilot keeps the official citation, decision owner, evidence record, and approval history connected.
- SSOT preserves official citations, launch facts, evidence files, and refresh history when product, supplier, app, data, equipment, or disposal facts change.

- [Open Research Copilot](/solutions/research-copilot.md): Map network operator duties, CII, data security, cybersecurity review, app filing, MLPS, and security-operation records to official citations, owners, and review checkpoints.
- [Open SSOT](/solutions/ssot.md): Keep official citations, decisions, approvals, and evidence records connected to governed product and compliance files.
- [Review unresolved triggers](/contact.md): Check edge cases before launch, filing, transfer, import, sale, or disposal.

## Compliance Timeline

| Date | Event | Category | Reference |
| --- | --- | --- | --- |
| 2016-11-07 | Cybersecurity Law adopted | Law | [Source](https://www.cac.gov.cn/2016-11/07/c_1119867116.htm?ref=sorena.io) |
| 2017-06-01 | Cybersecurity Law takes effect | Law | [Source](https://www.cac.gov.cn/2016-11/07/c_1119867116.htm?ref=sorena.io) |
| 2019-12-01 | Classified protection baseline standard implemented | Standards | [Source](https://openstd.samr.gov.cn/bzgk/gb/newGbInfo?hcno=BAFB47E8874764186BDB7865E8344DAF&ref=sorena.io) |
| 2021-06-10 | Data Security Law adopted | Law | [Source](https://www.cac.gov.cn/2021-06/11/c_1624994566919140.htm?ref=sorena.io) |
| 2021-09-01 | Data Security Law takes effect | Law | [Source](https://www.cac.gov.cn/2021-06/11/c_1624994566919140.htm?ref=sorena.io) |
| 2021-11-16 | Cybersecurity Review Measures approved | Review | [Source](https://www.cac.gov.cn/2022-01/04/c_1642894602182845.htm?ref=sorena.io) |
| 2022-02-15 | Cybersecurity Review Measures take effect | Review | [Source](https://www.cac.gov.cn/2022-01/04/c_1642894602182845.htm?ref=sorena.io) |
| 2022-06-14 | Mobile App Information Service Provisions published | App governance | [Source](https://www.cac.gov.cn/2022-06/14/c_1656821626455324.htm?ref=sorena.io) |
| 2022-08-01 | Mobile App Information Service Provisions take effect | App governance | [Source](https://www.cac.gov.cn/2022-06/14/c_1656821626455324.htm?ref=sorena.io) |
| 2022-11-01 | Smart home security specification implemented | Standards | [Source](https://openstd.samr.gov.cn/bzgk/gb/newGbInfo?hcno=B1C14E854C0BA30D1C29FC376299761A&ref=sorena.io) |
| 2023-08-09 | MIIT app filing notice published | App governance | [Source](https://www.miit.gov.cn/zwgk/zcwj/wjfb/tz/art/2023/art_920db564162e4312916a01bed6540ad8.html?ref=sorena.io) |
| 2023-09-01 | Existing-app filing phase begins | App governance | [Source](https://www.miit.gov.cn/zwgk/zcwj/wjfb/tz/art/2023/art_920db564162e4312916a01bed6540ad8.html?ref=sorena.io) |
| 2024-03-31 | Existing-app filing phase ends | App governance | [Source](https://www.miit.gov.cn/zwgk/zcwj/wjfb/tz/art/2023/art_920db564162e4312916a01bed6540ad8.html?ref=sorena.io) |
| 2024-04-01 | App filing supervision phase begins | App governance | [Source](https://www.miit.gov.cn/zwgk/zcwj/wjfb/tz/art/2023/art_920db564162e4312916a01bed6540ad8.html?ref=sorena.io) |
| 2024-07-01 | Normalized app filing work begins | App governance | [Source](https://www.miit.gov.cn/zwgk/zcwj/wjfb/tz/art/2023/art_920db564162e4312916a01bed6540ad8.html?ref=sorena.io) |

**Event details:**

- **2016-11-07 - Cybersecurity Law adopted**: The PRC Cybersecurity Law was adopted on 7 November 2016.
- **2017-06-01 - Cybersecurity Law takes effect**: The Cybersecurity Law took effect on 1 June 2017.
- **2019-12-01 - Classified protection baseline standard implemented**: GB/T 22239-2019 baseline requirements for classified protection of cybersecurity took effect on 1 December 2019.
- **2021-06-10 - Data Security Law adopted**: The PRC Data Security Law was adopted on 10 June 2021 before taking effect on 1 September 2021.
- **2021-09-01 - Data Security Law takes effect**: The PRC Data Security Law took effect on 1 September 2021.
- **2021-11-16 - Cybersecurity Review Measures approved**: The Cybersecurity Review Measures were approved on 16 November 2021 before taking effect on 15 February 2022.
- **2022-02-15 - Cybersecurity Review Measures take effect**: The Cybersecurity Review Measures took effect on 15 February 2022.
- **2022-06-14 - Mobile App Information Service Provisions published**: The revised mobile app information service provisions were published on 14 June 2022 before taking effect on 1 August 2022.
- **2022-08-01 - Mobile App Information Service Provisions take effect**: The revised Mobile Internet Application Information Service Management Provisions took effect on 1 August 2022.
- **2022-11-01 - Smart home security specification implemented**: The smart home general security specification took effect on 1 November 2022.
- **2023-08-09 - MIIT app filing notice published**: MIIT published its 21 July 2023 notice on 9 August 2023. The notice set implementation phases for existing apps, new apps, supervision, and normalized filing work.
- **2023-09-01 - Existing-app filing phase begins**: The MIIT notice set September 2023 through March 2024 as the filing phase for apps already operating in China. New apps were expected to complete filing before commencing service.
- **2024-03-31 - Existing-app filing phase ends**: The implementation window stated in the MIIT notice for existing apps ended after March 2024; this was a transition date, not a recurring annual deadline.
- **2024-04-01 - App filing supervision phase begins**: The MIIT notice designated April through June 2024 for supervision and inspection after the existing-app filing phase.
- **2024-07-01 - Normalized app filing work begins**: From July 2024, the MIIT notice moved app filing into an ongoing normalized phase. App changes and cancellations remain operational triggers rather than fixed yearly events.


---

[Privacy Policy](https://www.sorena.io/privacy.md) | [Terms of Use](https://www.sorena.io/terms-of-use.md) | [DMCA](https://www.sorena.io/dmca.md) | [About Us](https://www.sorena.io/about-us.md)

(c) 2026 Sorena AB (559573-7338). All rights reserved.

Source: https://www.sorena.io/artifacts/apac/china-cybersecurity-law.md
