---
title: "China cybersecurity compliance checklist"
canonical_url: "https://www.sorena.io/artifacts/apac/china-cybersecurity-law/checklist"
source_url: "https://www.sorena.io/artifacts/apac/china-cybersecurity-law/checklist"
author: "Sorena AI"
description: "A China cybersecurity checklist for scoping network duties, data security, CII procurement review, app rules, MIIT filing, and supporting standards."
published_at: "2026-07-05"
updated_at: "2026-07-25"
keywords:
  - "China Cybersecurity Law"
  - "Data Security Law"
  - "Cybersecurity Review Measures"
  - "Mobile app filing"
  - "MLPS"
---
**[SORENA](https://www.sorena.io/)** - AI-Powered GRC Platform

[Home](https://www.sorena.io/) | [Solutions](https://www.sorena.io/solutions) | [Artifacts](https://www.sorena.io/artifacts) | [About Us](https://www.sorena.io/about-us) | [Contact](https://www.sorena.io/contact) | [Portal](https://app.sorena.io)

---

# China cybersecurity compliance checklist

A China cybersecurity checklist for scoping network duties, data security, CII procurement review, app rules, MIIT filing, and supporting standards.

*Cybersecurity* *China*

## China Cybersecurity Law cybersecurity compliance checklist

A decision checklist for teams that operate networks, process data, run apps or platforms, procure network products or services, and launch connected products.

Use this after scoping the activity. The checklist assigns network-operation, data, CII procurement, platform, app, and standards work to separate owners and evidence. Apply each route only when its own trigger is met.

Identify the regulated activity and the network operator for each network in China, apply the baseline duties, screen special review or filing triggers, and keep the actor, decision, evidence, approval, and reassessment trigger for each conclusion.

## Definitions

### Network operator

Under Article 78 of the current Cybersecurity Law, a network operator is the owner or administrator of a network or a network service provider. A network is a system of computers or other information terminals and related equipment that collects, stores, transmits, exchanges, or processes information under defined rules and procedures. The term can therefore cover more than a public telecommunications carrier or online platform.

**Why it matters here:** A network operator must apply the Article 23 classified-protection baseline and the Article 27 incident duties to the network it owns, manages, or uses to provide network services. Record the specific network and role instead of assigning the label to the company as a whole.

Sources:

- [PRC Cybersecurity Law, Articles 23, 27, and 78](https://www.cac.gov.cn/2025-12/29/c_1768735112911946.htm?ref=sorena.io)

### Critical information infrastructure operator

**Term:** CII operator

Critical information infrastructure, or CII, covers infrastructure in important sectors such as public communications and information services, energy, transport, water, finance, public services, and e-government, plus other infrastructure whose damage, loss of function, or data leakage could seriously harm national security, the national economy and people's livelihood, or the public interest. The competent protection department identifies CII under the governing rules; operating a network does not by itself establish CII status.

**Why it matters here:** A CII operator has duties beyond the network-operator baseline, including a dedicated security function, personnel checks, disaster-recovery backup, exercises, annual security assessment, and a cybersecurity-review screen for procurements that may affect national security.

Sources:

- [PRC Cybersecurity Law, Articles 33-40](https://www.cac.gov.cn/2025-12/29/c_1768735112911946.htm?ref=sorena.io)
- [Cybersecurity Review Measures, Articles 2 and 5](https://www.cac.gov.cn/2022-01/04/c_1642894602182845.htm?ref=sorena.io)

### Important data

The Data Security Law uses a classified and graded protection system based on the harm that alteration, destruction, leakage, illegal acquisition, or illegal use could cause to national security, the public interest, or lawful individual and organisational interests. National, regional, departmental, industry, and sector catalogues identify important data for enhanced protection; the label should be based on the applicable catalogue and facts, not on data volume alone.

**Why it matters here:** A processor of important data must name a data-security responsible person and management body, conduct periodic risk assessments, and submit reports covering the types and quantities of important data, processing activities, risks, and response measures. Export rules require a separate route analysis.

Sources:

- [PRC Data Security Law, Articles 21 and 27-31](https://www.cac.gov.cn/2021-06/11/c_1624994566919140.htm?ref=sorena.io)

### Cybersecurity review

Cybersecurity review is the national-security review under the Cybersecurity Review Measures. It applies to CII operators procuring network products or services, and to network platform operators conducting data-processing activities, when the activity affects or may affect national security. A network platform operator holding personal information of more than one million users must file before seeking a foreign listing.

**Why it matters here:** The intake record must identify the actor and trigger. For a filing, retain the application, national-security impact analysis, relevant procurement or listing documents, supplemental material, written notices, supplier commitments, and the final decision.

Sources:

- [Cybersecurity Review Measures, Articles 2 and 5-10](https://www.cac.gov.cn/2022-01/04/c_1642894602182845.htm?ref=sorena.io)

### MIIT mobile app filing

**Term:** MIIT app filing

The MIIT app-filing process applies to sponsors providing app-based internet information services in China. The sponsor files with its provincial communications administration through a network access provider or app distribution platform. The authority issues a filing number when the submitted material is complete and accurate; the sponsor displays that number in the app and handles later changes or cancellation.

**Why it matters here:** MIIT app filing is separate from the filing that an app distribution platform makes with the provincial cyberspace administration under the 2022 app provisions. Keep both records when the organisation holds both roles.

Sources:

- [MIIT notice on mobile app filing work](https://www.miit.gov.cn/zwgk/zcwj/wjfb/tz/art/2023/art_920db564162e4312916a01bed6540ad8.html?ref=sorena.io)
- [Mobile Internet Application Information Service Management Provisions, Article 17](https://www.cac.gov.cn/2022-06/14/c_1656821626455324.htm?ref=sorena.io)

### Mobile app distribution platform

**Term:** app distribution platform

Under the 2022 app provisions, an app distribution platform is an internet information service provider that publishes mobile apps or provides download or dynamic-loading distribution services. Examples include app stores, quick-app centres, internet mini-program platforms, and browser plug-in platforms. The platform verifies providers, reviews new and updated apps, manages listed apps, and handles complaints and violations.

**Why it matters here:** An app distribution platform must file with its provincial cyberspace administration within 30 days after going online. This filing and the platform's governance duties are separate from the MIIT filing made for an app-based internet information service.

Sources:

- [Mobile Internet Application Information Service Management Provisions, Articles 2 and 17-22](https://www.cac.gov.cn/2022-06/14/c_1656821626455324.htm?ref=sorena.io)

### Multi-Level Protection Scheme

**Term:** MLPS

MLPS is a common English label for China's network security classified-protection system. Article 23 of the current Cybersecurity Law imposes baseline classified-protection duties on network operators. GB/T 22239-2019 is a recommended national baseline standard used within the wider system, not a standalone statute or one universal certification requirement.

**Why it matters here:** The checklist record should identify the exact network, operator, system boundary, classification method and level, applicable rules and standard edition, controls, tests, findings, remediation, and reassessment triggers. MLPS classification does not determine CII, important-data, review, privacy, or app status.

Sources:

- [PRC Cybersecurity Law, Articles 23 and 78](https://www.cac.gov.cn/2025-12/29/c_1768735112911946.htm?ref=sorena.io)
- [Official national standards record for GB/T 22239-2019](https://openstd.samr.gov.cn/bzgk/gb/newGbInfo?hcno=BAFB47E8874764186BDB7865E8344DAF&ref=sorena.io)

### App sponsor for MIIT filing

**Term:** app sponsor

The app sponsor is the organisation or individual providing the app-based internet information service and named in the MIIT filing. It supplies truthful identity, network-resource, service, approval, and contact information, displays the filing number and query link, and files changes or cancellation.

**Why it matters here:** Confirm the filed legal entity instead of assuming that the developer, brand owner, app provider, access provider, or distribution platform is the sponsor. One entity may hold several roles, but each role needs its own evidence.

Sources:

- [MIIT notice on mobile app filing work](https://www.miit.gov.cn/zwgk/zcwj/wjfb/tz/art/2023/art_920db564162e4312916a01bed6540ad8.html?ref=sorena.io)

### Network product or service provider

A network product or service provider is the provider subject to Article 24 of the current Cybersecurity Law. Its product or service must meet applicable mandatory national-standard requirements, must not contain malicious programs, and must receive prompt remediation, user notice, authority reporting, and continuing security maintenance when security defects or vulnerabilities are found.

**Why it matters here:** This role is separate from the network operator, although one entity may hold both roles. Keep the product security and support-period file separate from the operator's Article 23 controls and Article 27 incident record.

Sources:

- [PRC Cybersecurity Law, Article 24](https://www.cac.gov.cn/2025-12/29/c_1768735112911946.htm?ref=sorena.io)

### Network platform operator under the Cybersecurity Review Measures

**Term:** network platform operator

The Cybersecurity Review Measures use network platform operator for the operator whose data-processing activity affects or may affect national security. The measures also require such an operator to file before a foreign listing when it holds personal information of more than one million users. The term is not another name for every network operator, online service, or CII operator.

**Why it matters here:** Record the platform role, data-processing activity, user count, listing destination, and national-security analysis. The measures use the phrase foreign listing; check the current official interpretation for a specific destination or transaction.

Sources:

- [Cybersecurity Review Measures, Articles 2 and 7-10](https://www.cac.gov.cn/2022-01/04/c_1642894602182845.htm?ref=sorena.io)

### GB/T 22239-2019 classified-protection baseline

**Term:** GB/T 22239-2019

GB/T 22239-2019 is a current recommended Chinese national standard titled Baseline for classified protection of cybersecurity. The official record states that it was published on 10 May 2019 and implemented on 1 December 2019 but does not expose the full clauses.

**Why it matters here:** Use the complete applicable standard and governing classification rules before assigning a level, mapping controls, or claiming conformity. Its implementation date is not an annual deadline.

Sources:

- [Official national standards record for GB/T 22239-2019](https://openstd.samr.gov.cn/bzgk/gb/newGbInfo?hcno=BAFB47E8874764186BDB7865E8344DAF&ref=sorena.io)

### GB/T 41387-2022 smart-home security specification

**Term:** GB/T 41387-2022

GB/T 41387-2022 is a current recommended Chinese national standard titled Smart home general security specification. The official record states that it was published on 15 April 2022 and implemented on 1 November 2022 but does not expose the full clauses or establish automatic certification for every connected product.

**Why it matters here:** Use the complete applicable standard for a product-level mapping. Keep telecom, radio, app, privacy, network-operation, and any voluntary China Cybersecurity Label route as separate decisions.

Sources:

- [Official national standards record for GB/T 41387-2022](https://openstd.samr.gov.cn/bzgk/gb/newGbInfo?hcno=B1C14E854C0BA30D1C29FC376299761A&ref=sorena.io)

### Mobile app provider

**Term:** App-provider

A mobile app provider is the owner or operator of a mobile app that provides information services. Under the 2022 app provisions, the provider has duties for content, user identity in specified services, required licences, security defects, data and personal information, minors, management rules, user enforcement, complaints, and cooperation with supervision.

**Why it matters here:** This operating role is separate from the app sponsor named in the MIIT filing and from the app distribution platform. One entity may hold more than one role and needs evidence for each.

Sources:

- [Mobile Internet Application Information Service Management Provisions, Articles 5-16 and 26](https://www.cac.gov.cn/2022-06/14/c_1656821626455324.htm?ref=sorena.io)

## Scope the regulated activity before checking duties

Start with the particular network, information system, app, platform, procurement, product, and data activity in China. One organisation may hold several regulated roles, and a network-operator conclusion does not by itself establish CII status or a cybersecurity review filing duty.

Under the Cybersecurity Law text effective from 1 January 2026, Article 23 states the baseline network-operator duties, including internal rules, a responsible person, protective measures, network monitoring, at least six months of network-log retention, and data classification, backup, and encryption. Article 27 requires an incident plan, prompt handling of security risks, activation and remediation when an incident occurs, and reporting as required. Articles 33-40 add CII-specific duties. Data Security Law Articles 21, 27, 29, and 30 cover data classification, management duties, incident response, and periodic risk assessments for processors of important data.

- Legal and security owners: define each China network, app, platform, connected product, data activity, and procurement boundary; record the network operator, provider, processor, sponsor, or platform role for each.
- Map Article 23 duties: internal rules and accountability, malware and intrusion protection, network monitoring, at least six months of network logs, and data classification, backup, and encryption.
- Security owner: maintain the Article 27 network-security incident plan, vulnerability and threat response records, exercise evidence, incident decisions, remediation, and required reports.
- Network product or service provider: document the Article 24 check for mandatory national standards, malicious-code prevention, vulnerability remediation and reporting, user notice, and security maintenance for the required or agreed period.
- Screen whether data could be important data and whether export, sharing, or incident handling needs a separate legal route.
- For apps, separate MIIT filing and app governance evidence from Personal Information Protection Law notice, consent, rights, and security work.
- For smart-home or connected products, link product security evidence to telecom, privacy, and radio records without merging the legal conclusions.

Sources for this answer:

- [PRC Cybersecurity Law, current text](https://www.cac.gov.cn/2025-12/29/c_1768735112911946.htm?ref=sorena.io) - Official consolidated text; Articles 23, 24, 27, 33-40, and 78 support the baseline, product, incident, CII, procurement-review, and network-operator checks.
- [PRC Data Security Law](https://www.cac.gov.cn/2021-06/11/c_1624994566919140.htm?ref=sorena.io) - Use for data classification and graded protection, important-data risk assessment, security management, incident response, outbound important-data context, penalties, and 1 September 2021 effective date.
- [Cybersecurity Review Measures](https://www.cac.gov.cn/2022-01/04/c_1642894602182845.htm?ref=sorena.io) - Use for cybersecurity review scope, CII procurement filing, platform operator review triggers, review materials, special review, and 15 February 2022 effective date.
- [Mobile Internet Application Information Service Management Provisions](https://www.cac.gov.cn/2022-06/14/c_1656821626455324.htm?ref=sorena.io) - Supports app-provider duties and the requirement for an app distribution platform to file within 30 days after going online.
- [MIIT notice on mobile app filing work](https://www.miit.gov.cn/zwgk/zcwj/wjfb/tz/art/2023/art_920db564162e4312916a01bed6540ad8.html?ref=sorena.io) - Supports app-sponsor filing, verification by access providers and distribution platforms, display of filing numbers, and change or cancellation handling.

## Checklist steps that should produce evidence

Assign each applicable duty to a product, legal, compliance, security, data, app, procurement, or supplier owner.

For every item, record the regulated actor, source and article, condition tested, conclusion, evidence, approval date, and event that reopens the conclusion. Use an explicit result such as applicable, not applicable, pending authority input, or blocked by missing facts. Mark an item not applicable only with a reason and approver.

- Confirm the network or system boundary and document why the operator is in scope.
- Security owner: map Article 23 controls and retain operating evidence, including the configured network-log retention period and samples showing logs are available for at least six months.
- Product or service provider: identify each network product or service supplied in China and retain the applicable mandatory-standard check, malicious-code controls, vulnerability intake and remediation records, user and authority notices, and the promised or required security-maintenance period.
- Data owner: classify processed data; if important data may be involved, identify the applicable catalogue or competent authority and document the responsible person, management body, periodic risk assessment, report, incident route, and export screen.
- CII operator and procurement owner: retain the protection department's recognition notice and match it to the facility, system boundary, operator, and current configuration; before use, assess whether a network product or service procurement may affect national security, include the supplier cooperation commitments required by Article 6 of the Cybersecurity Review Measures, and retain any filing and written review result.
- CII security function: retain the dedicated security organisation and responsible person, key-personnel background checks, training, disaster-recovery backup, incident exercises, and the annual security assessment and report required by Articles 36 and 40.
- Listing and data owners: if a network platform operator holds personal information of more than one million users and seeks a foreign listing, file for cybersecurity review and preserve the application, national-security impact analysis, listing application documents, supplemental materials, notices, and decision.
- App sponsor: complete MIIT app filing before a new app begins service, display and link the filing number as required, and process changes or cancellation. App platform owner: separately file the app distribution platform within 30 days after it goes online and retain provider verification, listing review, monitoring, complaint, and takedown records.
- Standards owner: for GB/T 22239-2019 or GB/T 41387-2022 mappings, record the applicable edition, system or product boundary, clauses, evidence, and basis for use; do not present a recommended standard as a standalone law or automatic certification duty.

Sources for this answer:

- [PRC Cybersecurity Law, current text](https://www.cac.gov.cn/2025-12/29/c_1768735112911946.htm?ref=sorena.io) - Use Articles 23, 27, 36-40, and 78 for network-operator controls, incident response, additional CII duties, procurement review, annual assessment, and the actor definition.
- [PRC Data Security Law](https://www.cac.gov.cn/2021-06/11/c_1624994566919140.htm?ref=sorena.io) - Use for data classification and graded protection, important-data risk assessment, security management, incident response, outbound important-data context, penalties, and 1 September 2021 effective date.
- [Cybersecurity Review Measures](https://www.cac.gov.cn/2022-01/04/c_1642894602182845.htm?ref=sorena.io) - Articles 5-10 support the CII procurement screen, supplier commitments, foreign-listing trigger, filing materials, written intake decision, and national-security risk factors.
- [Mobile Internet Application Information Service Management Provisions](https://www.cac.gov.cn/2022-06/14/c_1656821626455324.htm?ref=sorena.io) - Articles 17-22 support the separate app-distribution-platform filing, verification, review, monitoring, complaint, enforcement-record, and reporting checks.
- [MIIT notice on mobile app filing work](https://www.miit.gov.cn/zwgk/zcwj/wjfb/tz/art/2023/art_920db564162e4312916a01bed6540ad8.html?ref=sorena.io) - Supports filing before a new app begins service, the 20-working-day authority process for complete and accurate material, filing-number display and link requirements, and change or cancellation handling.

## Evidence to keep before launch or change approval

Keep evidence showing that the China decision was made before the launch, transfer, filing, procurement, disposal, or product change went live.

Keep the record understandable to an external reviewer: decision owner, official source citation, product, app, data-flow, or vendor identifier, approval date, and the trigger for reopening the decision.

- Network and role inventory with diagrams, owners, users, services, dependencies, and the approved network-operator conclusion.
- Article 23 control map with policies, technical configurations, monitoring records, backup and encryption evidence, and samples showing at least six months of network-log retention.
- Article 27 incident plan, exercise results, vulnerability and incident tickets, notifications, reports, remediation, and closure approval.
- Data inventory and classification rationale, important-data catalogue analysis, responsible person, risk assessment and report, incident evidence, and export-route decision.
- CII status record, additional CII controls, annual assessment and report, procurement screen, supplier commitments, cybersecurity-review submission, notices, and decision where applicable.
- App-provider and distribution-platform governance records, MIIT app filing number and display evidence, change or cancellation record, and the separate provincial cyberspace filing for a distribution platform.
- GB/T 22239-2019 or GB/T 41387-2022 scope, edition, clause map, test evidence, exceptions, remediation, and retest results where either standard is used.

Sources for this answer:

- [PRC Cybersecurity Law, current text](https://www.cac.gov.cn/2025-12/29/c_1768735112911946.htm?ref=sorena.io) - Current source for the network-operation, product, incident, CII, annual-assessment, and procurement evidence listed here.
- [PRC Data Security Law](https://www.cac.gov.cn/2021-06/11/c_1624994566919140.htm?ref=sorena.io) - Use for data classification and graded protection, important-data risk assessment, security management, incident response, outbound important-data context, penalties, and 1 September 2021 effective date.

## Boundary with nearby China regimes

Keep Personal Information Protection Law processing rights and personal-information export route selection in the privacy guide; keep telecom network access, radio approval, and mobile terminal app removal rules in the telecom and wireless guide.

When one launch triggers several regimes, link the shared facts such as model number, app package, data flow, supplier, or release date, but keep the legal conclusions separate.

- Assuming every China technology launch is only a privacy project; network security, app filing, MLPS, and review questions may sit outside the Personal Information Protection Law.
- Calling a supplier review complete before checking cybersecurity review triggers for CII procurement or large platform scenarios.
- Using one generic security policy as proof of classified protection, important-data, and app-governance compliance.

Sources for this answer:

- [PRC Cybersecurity Law, current text](https://www.cac.gov.cn/2025-12/29/c_1768735112911946.htm?ref=sorena.io) - Current source for network, product, CII, and personal-information duties and their boundaries with the related regimes.
- [PRC Data Security Law](https://www.cac.gov.cn/2021-06/11/c_1624994566919140.htm?ref=sorena.io) - Use for data classification and graded protection, important-data risk assessment, security management, incident response, outbound important-data context, penalties, and 1 September 2021 effective date.

*Apply the requirement*

*Placement: Before primary sources*

## Build the China network security evidence file

Track network, data, CII, review, app, and standards checklist results with the exact actor, trigger, evidence, and change event.

- [Map official sources to evidence](/solutions/research-copilot.md): Connect each checklist result to the current article, responsible actor, retained evidence, approval, and event that reopens it.
- [Review the China route](/contact.md): Check the China Cybersecurity Law scope decision and unresolved launch questions with Sorena.

## Primary sources

- [PRC Cybersecurity Law, current text](https://www.cac.gov.cn/2025-12/29/c_1768735112911946.htm?ref=sorena.io) - Official consolidated text; use Articles 23-27, 33-40, and 78 for baseline, product, incident, CII, procurement, annual-assessment, and network-operator requirements.
- [PRC Data Security Law](https://www.cac.gov.cn/2021-06/11/c_1624994566919140.htm?ref=sorena.io) - Use for data classification and graded protection, important-data risk assessment, security management, incident response, outbound important-data context, penalties, and 1 September 2021 effective date.
- [Cybersecurity Review Measures](https://www.cac.gov.cn/2022-01/04/c_1642894602182845.htm?ref=sorena.io) - Use for cybersecurity review scope, CII procurement filing, platform operator review triggers, review materials, special review, and 15 February 2022 effective date.
- [Mobile Internet Application Information Service Management Provisions](https://www.cac.gov.cn/2022-06/14/c_1656821626455324.htm?ref=sorena.io) - Use for app provider and app distribution platform governance, content/security/data duties, platform filing and verification, and 1 August 2022 effective date.
- [MIIT notice on mobile app filing work](https://www.miit.gov.cn/zwgk/zcwj/wjfb/tz/art/2023/art_920db564162e4312916a01bed6540ad8.html?ref=sorena.io) - Use for MIIT mobile app filing phases, registration, supervision, normalization, and operational filing evidence.
- [GB/T 22239 classified protection baseline requirements](https://openstd.samr.gov.cn/bzgk/gb/newGbInfo?hcno=BAFB47E8874764186BDB7865E8344DAF&ref=sorena.io) - Use as the MLPS/classified protection baseline standard reference for control evidence mapping and the 1 December 2019 implementation date.
- [GB/T smart home general security specification](https://openstd.samr.gov.cn/bzgk/gb/newGbInfo?hcno=B1C14E854C0BA30D1C29FC376299761A&ref=sorena.io) - Use as the smart-home security specification reference for connected appliance evidence mapping and the 1 November 2022 implementation date.

## Related Topic Guides

- [China App Filing vs Personal Information Rules](/artifacts/apac/china-cybersecurity-law/mobile-app-filing-vs-app-personal-information-rules.md): Decide whether a China mobile app needs MIIT filing, personal-information controls, or both, with current triggers, duties, dates, and evidence.
- [China cybersecurity and data security requirements](/artifacts/apac/china-cybersecurity-law/requirements.md): China cybersecurity requirements by actor: network operators, data processors, CII operators, platforms, app providers, and distribution platforms.
- [China cybersecurity deadlines and compliance calendar](/artifacts/apac/china-cybersecurity-law/deadlines-and-compliance-calendar.md): Separate China cybersecurity commencement dates from recurring duties, filing lead times, review periods, and event-driven response deadlines.
- [China Cybersecurity Law FAQ](/artifacts/apac/china-cybersecurity-law/faq.md): Practical answers on China network-operator scope, MLPS evidence, important data, cybersecurity review, app filing and governance, and smart-home standards under the law in force from 1 January 2026.
- [China Cybersecurity Law vs EU Cyber Resilience Act](/artifacts/apac/china-cybersecurity-law/china-cybersecurity-law-vs-eu-cyber-resilience-act.md): Compare China's network-operator rules with the EU CRA's product duties, including scope, actors, evidence, reporting dates, and launch decisions.
- [China Cybersecurity Law vs EU NIS2 Directive](/artifacts/apac/china-cybersecurity-law/china-cybersecurity-law-vs-nis2.md): Compare China's network-operator duties with NIS2 entity duties, including scope, management accountability, incident reporting, evidence, and enforcement.
- [China cybersecurity penalties and fines](/artifacts/apac/china-cybersecurity-law/penalties-and-fines.md): Compare current China Cybersecurity Law and Data Security Law fines by actor, breach, severity, and enforcement consequence.
- [China Cybersecurity Review vs Data Export Assessment](/artifacts/apac/china-cybersecurity-law/cybersecurity-review-vs-data-export-security-assessment.md): Separate China's cybersecurity-review triggers from CAC data-export assessment triggers, thresholds, filings, evidence, timing, and reapplication rules.
- [China cybersecurity review workflow](/artifacts/apac/china-cybersecurity-law/cybersecurity-review-workflow.md): Determine whether CII procurement, platform data processing, or a qualifying foreign listing triggers China's Cybersecurity Review Measures.
- [China mobile app filing and app governance](/artifacts/apac/china-cybersecurity-law/mobile-app-filing-and-app-governance.md): Identify the China app sponsor, complete MIIT filing before service, and separate provider, platform, privacy, content, and security duties.
- [China Smart-Home Security vs Telecom and Radio Approval](/artifacts/apac/china-cybersecurity-law/smart-home-security-vs-telecom-wireless-launch.md): Separate GB/T 41387-2022 smart-home security evidence from China telecom network-access and radio approval decisions for connected products.
- [CII and network operator role triage](/artifacts/apac/china-cybersecurity-law/critical-information-infrastructure-and-network-operators.md): How to separate ordinary network operator duties from CII, procurement, and review-risk questions under China cybersecurity sources.
- [Does an app need MIIT filing and CAC app governance review?](/artifacts/apac/china-cybersecurity-law/faq/does-an-app-need-miit-filing-and-cac-app-governance-review.md): An app sponsor providing internet information services through an app in China must complete MIIT filing. CAC rules separately govern app providers and distribution platforms without creating one routine CAC approval for every app.
- [GB/T 22239-2019 classified protection baseline](/artifacts/apac/china-cybersecurity-law/classified-protection-baseline.md): How to scope and document a GB/T 22239-2019 classified protection baseline without treating the recommended standard as a standalone law.
- [GB/T 41387-2022 smart home security standard](/artifacts/apac/china-cybersecurity-law/smart-home-security-standard.md): How connected-device teams can scope and document GB/T 41387-2022 without treating it as an automatic certification or product-approval duty.
- [How do smart home security standards fit with China cybersecurity law?](/artifacts/apac/china-cybersecurity-law/faq/how-do-smart-home-security-standards-fit-with-china-cybersecurity-law.md): GB/T 41387-2022 can organize smart-home security evidence, but it is a recommended standard, not a product approval. Check app, data, MLPS, telecom access, and radio requirements separately.
- [How does important data change China cybersecurity obligations?](/artifacts/apac/china-cybersecurity-law/faq/how-does-important-data-change-cybersecurity-obligations.md): Once data is officially identified as important data, the processor needs named governance, periodic risk assessments and reports, incident controls, and a separate export decision. An internal sensitivity label alone does not establish the legal category.
- [Is every company a network operator under China Cybersecurity Law?](/artifacts/apac/china-cybersecurity-law/faq/is-every-company-a-network-operator-under-china-cybersecurity-law.md): No. Under China's Cybersecurity Law, a network operator is an owner or administrator of a network or a network service provider. Apply that definition to each China network or service, then test CII and other roles separately.
- [MLPS classified protection evidence map](/artifacts/apac/china-cybersecurity-law/mlps-classified-protection-evidence-map.md): Classify a China network under MLPS, complete level 2 or above filing, map controls, and retain assessment, remediation, and change evidence.
- [What is MLPS classified protection evidence?](/artifacts/apac/china-cybersecurity-law/faq/what-is-mlps-classified-protection-evidence.md): MLPS evidence shows how a defined China network or system was graded and protected. Keep the scope, grading rationale, filing or assessment records where applicable, control mapping, test results, remediation, and reassessment history.
- [When does China cybersecurity review apply?](/artifacts/apac/china-cybersecurity-law/faq/when-does-china-cybersecurity-review-apply.md): China cybersecurity review applies to CII procurement or network-platform data processing that affects or may affect national security, plus a mandatory pre-filing trigger for certain foreign listings involving more than one million users' personal information.


---

[Privacy Policy](https://www.sorena.io/privacy.md) | [Terms of Use](https://www.sorena.io/terms-of-use.md) | [DMCA](https://www.sorena.io/dmca.md) | [About Us](https://www.sorena.io/about-us.md)

(c) 2026 Sorena AB (559573-7338). All rights reserved.

Source: https://www.sorena.io/artifacts/apac/china-cybersecurity-law/checklist.md
