CybersecurityChina

China Cybersecurity Law cybersecurity compliance checklist

A decision checklist for teams that operate networks, process data, run apps or platforms, procure network products or services, and launch connected products.

Use this after scoping the activity. The checklist assigns network-operation, data, CII procurement, platform, app, and standards work to separate owners and evidence. Apply each route only when its own trigger is met.

Author
Sorena AI
Published
Jul 5, 2026
Updated
Jul 25, 2026
Sections
4

Structured answer sets in this page tree.

Primary sources
7

Cited legal and guidance references.

Publication metadata
Sorena AI
Published Jul 5, 2026
Updated Jul 25, 2026
Overview

Identify the regulated activity and the for each network in China, apply the baseline duties, screen special review or filing triggers, and keep the actor, decision, evidence, approval, and reassessment trigger for each conclusion.

Section 1

Scope the regulated activity before checking duties

Start with the particular network, information system, app, platform, procurement, product, and data activity in China. One organisation may hold several regulated roles, and a network-operator conclusion does not by itself establish CII status or a filing duty.

Under the Cybersecurity Law text effective from 1 January 2026, Article 23 states the baseline network-operator duties, including internal rules, a responsible person, protective measures, network monitoring, at least six months of network-log retention, and data classification, backup, and encryption. Article 27 requires an incident plan, prompt handling of security risks, activation and remediation when an incident occurs, and reporting as required. Articles 33-40 add CII-specific duties. Data Security Law Articles 21, 27, 29, and 30 cover data classification, management duties, incident response, and periodic risk assessments for processors of .

  • Legal and security owners: define each China network, app, platform, connected product, data activity, and procurement boundary; record the , provider, processor, sponsor, or platform role for each.
  • Map Article 23 duties: internal rules and accountability, malware and intrusion protection, network monitoring, at least six months of network logs, and data classification, backup, and encryption.
  • Security owner: maintain the Article 27 network-security incident plan, vulnerability and threat response records, exercise evidence, incident decisions, remediation, and required reports.
  • : document the Article 24 check for mandatory national standards, malicious-code prevention, vulnerability remediation and reporting, user notice, and security maintenance for the required or agreed period.
  • Screen whether data could be and whether export, sharing, or incident handling needs a separate legal route.
  • For apps, separate MIIT filing and app governance evidence from Personal Information Protection Law notice, consent, rights, and security work.
  • For smart-home or connected products, link product security evidence to telecom, privacy, and radio records without merging the legal conclusions.
Section 2

Checklist steps that should produce evidence

Assign each applicable duty to a product, legal, compliance, security, data, app, procurement, or supplier owner.

For every item, record the regulated actor, source and article, condition tested, conclusion, evidence, approval date, and event that reopens the conclusion. Use an explicit result such as applicable, not applicable, pending authority input, or blocked by missing facts. Mark an item not applicable only with a reason and approver.

  • Confirm the network or system boundary and document why the operator is in scope.
  • Security owner: map Article 23 controls and retain operating evidence, including the configured network-log retention period and samples showing logs are available for at least six months.
  • Product or service provider: identify each network product or service supplied in China and retain the applicable mandatory-standard check, malicious-code controls, vulnerability intake and remediation records, user and authority notices, and the promised or required security-maintenance period.
  • Data owner: classify processed data; if may be involved, identify the applicable catalogue or competent authority and document the responsible person, management body, periodic risk assessment, report, incident route, and export screen.
  • and procurement owner: retain the protection department's recognition notice and match it to the facility, system boundary, operator, and current configuration; before use, assess whether a network product or service procurement may affect national security, include the supplier cooperation commitments required by Article 6 of the Measures, and retain any filing and written review result.
  • CII security function: retain the dedicated security organisation and responsible person, key-personnel background checks, training, disaster-recovery backup, incident exercises, and the annual security assessment and report required by Articles 36 and 40.
  • Listing and data owners: if a holds personal information of more than one million users and seeks a foreign listing, file for and preserve the application, national-security impact analysis, listing application documents, supplemental materials, notices, and decision.
  • : complete before a new app begins service, display and link the filing number as required, and process changes or cancellation. App platform owner: separately file the within 30 days after it goes online and retain provider verification, listing review, monitoring, complaint, and takedown records.
  • Standards owner: for or mappings, record the applicable edition, system or product boundary, clauses, evidence, and basis for use; do not present a recommended standard as a standalone law or automatic certification duty.
Section 3

Evidence to keep before launch or change approval

Keep evidence showing that the China decision was made before the launch, transfer, filing, procurement, disposal, or product change went live.

Keep the record understandable to an external reviewer: decision owner, official source citation, product, app, data-flow, or vendor identifier, approval date, and the trigger for reopening the decision.

  • Network and role inventory with diagrams, owners, users, services, dependencies, and the approved network-operator conclusion.
  • Article 23 control map with policies, technical configurations, monitoring records, backup and encryption evidence, and samples showing at least six months of network-log retention.
  • Article 27 incident plan, exercise results, vulnerability and incident tickets, notifications, reports, remediation, and closure approval.
  • Data inventory and classification rationale, important-data catalogue analysis, responsible person, risk assessment and report, incident evidence, and export-route decision.
  • CII status record, additional CII controls, annual assessment and report, procurement screen, supplier commitments, cybersecurity-review submission, notices, and decision where applicable.
  • and distribution-platform governance records, number and display evidence, change or cancellation record, and the separate provincial cyberspace filing for a distribution platform.
  • or scope, edition, clause map, test evidence, exceptions, remediation, and retest results where either standard is used.
Section 4

Boundary with nearby China regimes

Keep Personal Information Protection Law processing rights and personal-information export route selection in the privacy guide; keep telecom network access, radio approval, and mobile terminal app removal rules in the telecom and wireless guide.

When one launch triggers several regimes, link the shared facts such as model number, app package, data flow, supplier, or release date, but keep the legal conclusions separate.

  • Assuming every China technology launch is only a privacy project; network security, app filing, , and review questions may sit outside the Personal Information Protection Law.
  • Calling a supplier review complete before checking triggers for CII procurement or large platform scenarios.
  • Using one generic security policy as proof of classified protection, important-data, and app-governance compliance.
Primary sources

References and citations

cac.gov.cn
Referenced sections
  • Articles 5-10 support the CII procurement screen, supplier commitments, foreign-listing trigger, filing materials, written intake decision, and national-security risk factors.
miit.gov.cn
Referenced sections
  • Supports filing before a new app begins service, the 20-working-day authority process for complete and accurate material, filing-number display and link requirements, and change or cancellation handling.
cac.gov.cn
Referenced sections
  • Current source for network, product, CII, and personal-information duties and their boundaries with the related regimes.
cac.gov.cn
Referenced sections
  • Use for data classification and graded protection, important-data risk assessment, security management, incident response, outbound important-data context, penalties, and 1 September 2021 effective date.
Related guides

Explore more topics

China App Filing vs Personal Information Rules
Decide whether a China mobile app needs MIIT filing, personal-information controls, or both, with current triggers, duties, dates, and evidence.
China cybersecurity and data security requirements
China cybersecurity requirements by actor: network operators, data processors, CII operators, platforms, app providers, and distribution platforms.
China cybersecurity deadlines and compliance calendar
Separate China cybersecurity commencement dates from recurring duties, filing lead times, review periods, and event-driven response deadlines.
China Cybersecurity Law FAQ
Practical answers on China network-operator scope, MLPS evidence, important data, cybersecurity review, app filing and governance, and smart-home standards under the law in force from 1 January 2026.
China Cybersecurity Law vs EU Cyber Resilience Act
Compare China's network-operator rules with the EU CRA's product duties, including scope, actors, evidence, reporting dates, and launch decisions.
China Cybersecurity Law vs EU NIS2 Directive
Compare China's network-operator duties with NIS2 entity duties, including scope, management accountability, incident reporting, evidence, and enforcement.
China cybersecurity penalties and fines
Compare current China Cybersecurity Law and Data Security Law fines by actor, breach, severity, and enforcement consequence.
China Cybersecurity Review vs Data Export Assessment
Separate China's cybersecurity-review triggers from CAC data-export assessment triggers, thresholds, filings, evidence, timing, and reapplication rules.
China cybersecurity review workflow
Determine whether CII procurement, platform data processing, or a qualifying foreign listing triggers China's Cybersecurity Review Measures.
China mobile app filing and app governance
Identify the China app sponsor, complete MIIT filing before service, and separate provider, platform, privacy, content, and security duties.
China Smart-Home Security vs Telecom and Radio Approval
Separate GB/T 41387-2022 smart-home security evidence from China telecom network-access and radio approval decisions for connected products.
CII and network operator role triage
How to separate ordinary network operator duties from CII, procurement, and review-risk questions under China cybersecurity sources.
Does an app need MIIT filing and CAC app governance review?
An app sponsor providing internet information services through an app in China must complete MIIT filing. CAC rules separately govern app providers and distribution platforms without creating one routine CAC approval for every app.
GB/T 22239-2019 classified protection baseline
How to scope and document a GB/T 22239-2019 classified protection baseline without treating the recommended standard as a standalone law.
GB/T 41387-2022 smart home security standard
How connected-device teams can scope and document GB/T 41387-2022 without treating it as an automatic certification or product-approval duty.
How do smart home security standards fit with China cybersecurity law?
GB/T 41387-2022 can organize smart-home security evidence, but it is a recommended standard, not a product approval. Check app, data, MLPS, telecom access, and radio requirements separately.
How does important data change China cybersecurity obligations?
Once data is officially identified as important data, the processor needs named governance, periodic risk assessments and reports, incident controls, and a separate export decision. An internal sensitivity label alone does not establish the legal category.
Is every company a network operator under China Cybersecurity Law?
No. Under China's Cybersecurity Law, a network operator is an owner or administrator of a network or a network service provider. Apply that definition to each China network or service, then test CII and other roles separately.
MLPS classified protection evidence map
Classify a China network under MLPS, complete level 2 or above filing, map controls, and retain assessment, remediation, and change evidence.
What is MLPS classified protection evidence?
MLPS evidence shows how a defined China network or system was graded and protected. Keep the scope, grading rationale, filing or assessment records where applicable, control mapping, test results, remediation, and reassessment history.
When does China cybersecurity review apply?
China cybersecurity review applies to CII procurement or network-platform data processing that affects or may affect national security, plus a mandatory pre-filing trigger for certain foreign listings involving more than one million users' personal information.