China Cybersecurity Law cybersecurity compliance checklist
A decision checklist for teams that operate networks, process data, run apps or platforms, procure network products or services, and launch connected products.
Use this after scoping the activity. The checklist assigns network-operation, data, CII procurement, platform, app, and standards work to separate owners and evidence. Apply each route only when its own trigger is met.
Identify the regulated activity and the for each network in China, apply the baseline duties, screen special review or filing triggers, and keep the actor, decision, evidence, approval, and reassessment trigger for each conclusion.
1
Section 1
Scope the regulated activity before checking duties
Start with the particular network, information system, app, platform, procurement, product, and data activity in China. One organisation may hold several regulated roles, and a network-operator conclusion does not by itself establish CII status or a filing duty.
Under the Cybersecurity Law text effective from 1 January 2026, Article 23 states the baseline network-operator duties, including internal rules, a responsible person, protective measures, network monitoring, at least six months of network-log retention, and data classification, backup, and encryption. Article 27 requires an incident plan, prompt handling of security risks, activation and remediation when an incident occurs, and reporting as required. Articles 33-40 add CII-specific duties. Data Security Law Articles 21, 27, 29, and 30 cover data classification, management duties, incident response, and periodic risk assessments for processors of .
Legal and security owners: define each China network, app, platform, connected product, data activity, and procurement boundary; record the , provider, processor, sponsor, or platform role for each.
Map Article 23 duties: internal rules and accountability, malware and intrusion protection, network monitoring, at least six months of network logs, and data classification, backup, and encryption.
Security owner: maintain the Article 27 network-security incident plan, vulnerability and threat response records, exercise evidence, incident decisions, remediation, and required reports.
: document the Article 24 check for mandatory national standards, malicious-code prevention, vulnerability remediation and reporting, user notice, and security maintenance for the required or agreed period.
Screen whether data could be and whether export, sharing, or incident handling needs a separate legal route.
For apps, separate MIIT filing and app governance evidence from Personal Information Protection Law notice, consent, rights, and security work.
For smart-home or connected products, link product security evidence to telecom, privacy, and radio records without merging the legal conclusions.
Assign each applicable duty to a product, legal, compliance, security, data, app, procurement, or supplier owner.
For every item, record the regulated actor, source and article, condition tested, conclusion, evidence, approval date, and event that reopens the conclusion. Use an explicit result such as applicable, not applicable, pending authority input, or blocked by missing facts. Mark an item not applicable only with a reason and approver.
Confirm the network or system boundary and document why the operator is in scope.
Security owner: map Article 23 controls and retain operating evidence, including the configured network-log retention period and samples showing logs are available for at least six months.
Product or service provider: identify each network product or service supplied in China and retain the applicable mandatory-standard check, malicious-code controls, vulnerability intake and remediation records, user and authority notices, and the promised or required security-maintenance period.
Data owner: classify processed data; if may be involved, identify the applicable catalogue or competent authority and document the responsible person, management body, periodic risk assessment, report, incident route, and export screen.
and procurement owner: retain the protection department's recognition notice and match it to the facility, system boundary, operator, and current configuration; before use, assess whether a network product or service procurement may affect national security, include the supplier cooperation commitments required by Article 6 of the Measures, and retain any filing and written review result.
CII security function: retain the dedicated security organisation and responsible person, key-personnel background checks, training, disaster-recovery backup, incident exercises, and the annual security assessment and report required by Articles 36 and 40.
Listing and data owners: if a holds personal information of more than one million users and seeks a foreign listing, file for and preserve the application, national-security impact analysis, listing application documents, supplemental materials, notices, and decision.
: complete before a new app begins service, display and link the filing number as required, and process changes or cancellation. App platform owner: separately file the within 30 days after it goes online and retain provider verification, listing review, monitoring, complaint, and takedown records.
Standards owner: for or mappings, record the applicable edition, system or product boundary, clauses, evidence, and basis for use; do not present a recommended standard as a standalone law or automatic certification duty.
Keep evidence showing that the China decision was made before the launch, transfer, filing, procurement, disposal, or product change went live.
Keep the record understandable to an external reviewer: decision owner, official source citation, product, app, data-flow, or vendor identifier, approval date, and the trigger for reopening the decision.
Network and role inventory with diagrams, owners, users, services, dependencies, and the approved network-operator conclusion.
Article 23 control map with policies, technical configurations, monitoring records, backup and encryption evidence, and samples showing at least six months of network-log retention.
Article 27 incident plan, exercise results, vulnerability and incident tickets, notifications, reports, remediation, and closure approval.
Data inventory and classification rationale, important-data catalogue analysis, responsible person, risk assessment and report, incident evidence, and export-route decision.
CII status record, additional CII controls, annual assessment and report, procurement screen, supplier commitments, cybersecurity-review submission, notices, and decision where applicable.
and distribution-platform governance records, number and display evidence, change or cancellation record, and the separate provincial cyberspace filing for a distribution platform.
or scope, edition, clause map, test evidence, exceptions, remediation, and retest results where either standard is used.
Keep Personal Information Protection Law processing rights and personal-information export route selection in the privacy guide; keep telecom network access, radio approval, and mobile terminal app removal rules in the telecom and wireless guide.
When one launch triggers several regimes, link the shared facts such as model number, app package, data flow, supplier, or release date, but keep the legal conclusions separate.
Assuming every China technology launch is only a privacy project; network security, app filing, , and review questions may sit outside the Personal Information Protection Law.
Calling a supplier review complete before checking triggers for CII procurement or large platform scenarios.
Using one generic security policy as proof of classified protection, important-data, and app-governance compliance.
Articles 5-10 support the CII procurement screen, supplier commitments, foreign-listing trigger, filing materials, written intake decision, and national-security risk factors.
Supports filing before a new app begins service, the 20-working-day authority process for complete and accurate material, filing-number display and link requirements, and change or cancellation handling.
Articles 17-22 support the separate app-distribution-platform filing, verification, review, monitoring, complaint, enforcement-record, and reporting checks.
Use for data classification and graded protection, important-data risk assessment, security management, incident response, outbound important-data context, penalties, and 1 September 2021 effective date.