ComparisonChina

China Cybersecurity Law Comparison

Comparison showing China operator/security duties versus EU product cybersecurity duties under the CRA.

China Cybersecurity Law vs EU Cyber Resilience Act explains where two compliance regimes overlap, where they diverge, and how to keep decisions, owners, evidence, and timing separate.

Author
Sorena AI
Published
Jul 5, 2026
Updated
Jul 5, 2026
Sections
1

Structured answer sets in this page tree.

Primary sources
5

Cited legal and guidance references.

Publication metadata
Sorena AI
Published Jul 5, 2026
Updated Jul 5, 2026
Overview

Comparison showing China operator/security duties versus EU product cybersecurity duties under the CRA.

Comparison

China Cybersecurity Law vs EU Cyber Resilience Act

This comparison helps separate China Cybersecurity Law decisions from EU Cyber Resilience Act decisions without merging evidence, owners, or timing.

Review all sources
First framework
China Cybersecurity Law

Use for China network operations, data security, review, app governance, CII, and MLPS evidence. Keep its evidence and legal conclusion separate.

Second framework
EU Cyber Resilience Act

Use for EU products with digital elements, manufacturer/importer/distributor duties, vulnerability handling, conformity assessment, and CE documentation. Keep its evidence and legal conclusion separate.

Comparison row 1

Scope boundary

China Cybersecurity Law

China Cybersecurity Law covers China network operations, data security, review, app governance, CII, and MLPS evidence.

EU Cyber Resilience Act

EU Cyber Resilience Act covers EU products with digital elements, manufacturer/importer/distributor duties, vulnerability handling, conformity assessment, and CE documentation.

Operational implication

Run separate scope decisions when the same launch can trigger both China Cybersecurity Law and EU Cyber Resilience Act.

Comparison row 2

Covered actors

China Cybersecurity Law

China Cybersecurity Law work is usually owned by China operator, app provider, platform, CII, data, and security owners.

EU Cyber Resilience Act

EU Cyber Resilience Act work is usually owned by EU manufacturer, importer, distributor, and product security owners.

Operational implication

Assign separate owners when the legal route, regulator, filing, assessment, permit, or evidence package is different.

Comparison row 3

Trigger event

China Cybersecurity Law

China Cybersecurity Law screening starts with China operation, app launch, network procurement, review trigger, important data, or MLPS classification.

EU Cyber Resilience Act

EU Cyber Resilience Act screening starts with placing a product with digital elements on the EU market.

Operational implication

Record the triggering event and launch date for each route before reusing technical evidence.

Comparison row 4

Core obligations

China Cybersecurity Law

China Cybersecurity Law requires the team to translate its official articles or measures into concrete controls for China network operations, data security, review, app governance, CII, and MLPS evidence.

EU Cyber Resilience Act

EU Cyber Resilience Act requires controls for EU products with digital elements, manufacturer/importer/distributor duties, vulnerability handling, conformity assessment, and CE documentation.

Operational implication

Shared facts can support both routes, but the legal conclusion and required action must be written separately.

Comparison row 5

Evidence package

China Cybersecurity Law

A defensible China Cybersecurity Law file includes China role memo, controls, app/review filings, MLPS records, and incident process.

EU Cyber Resilience Act

A defensible EU Cyber Resilience Act file includes technical documentation, cybersecurity risk assessment, vulnerability process, conformity evidence, declaration, and CE record.

Operational implication

Reuse common documents only after each file identifies why the document satisfies that route.

Comparison row 6

Timing and refresh points

China Cybersecurity Law

China Cybersecurity Law timing should track effective dates, filing windows, review periods, renewals, or transition dates named in its sources.

EU Cyber Resilience Act

EU Cyber Resilience Act timing should track its own effective dates, implementation windows, reporting periods, renewals, or market-entry deadlines.

Operational implication

Calendar each route independently; a date in one regime does not extend or replace a date in the other.

Comparison row 7

Enforcement exposure

China Cybersecurity Law

China Cybersecurity Law exposure usually follows the actor, regulator, and failure mode tied to China operation, app launch, network procurement, review trigger, important data, or MLPS classification.

EU Cyber Resilience Act

EU Cyber Resilience Act exposure usually follows the actor, regulator, and failure mode tied to placing a product with digital elements on the EU market.

Operational implication

Preserve the evidence trail before launch, filing, transfer, procurement, sale, or disposal because later remediation is weaker than a dated decision record.

Comparison row 8

Overlap and routing

China Cybersecurity Law

China Cybersecurity Law and EU Cyber Resilience Act can use the same product, app, supplier, data-flow, or equipment facts, but China Cybersecurity Law owns the decision for China network operations, data security, review, app governance, CII, and MLPS evidence.

EU Cyber Resilience Act

EU Cyber Resilience Act owns the decision for EU products with digital elements, manufacturer/importer/distributor duties, vulnerability handling, conformity assessment, and CE documentation.

Operational implication

Create linked records rather than copying one conclusion across both regimes.

Comparison row 9

Practical decision rule

China Cybersecurity Law

Choose China Cybersecurity Law when the immediate blocker is China operation, app launch, network procurement, review trigger, important data, or MLPS classification.

EU Cyber Resilience Act

Choose EU Cyber Resilience Act when the immediate blocker is placing a product with digital elements on the EU market.

Operational implication

Run both tracks when the same China or cross-market launch creates both China Cybersecurity Law and EU Cyber Resilience Act triggers.

Practical decision rule

When to run one track or both

  • Use China Cybersecurity Law when the facts match China operation, app launch, network procurement, review trigger, important data, or MLPS classification.
  • Use EU Cyber Resilience Act when the facts match placing a product with digital elements on the EU market.
  • Run both when the same launch creates both triggers, but keep separate approvals and official citations.
Section 1

How to use this comparison

China Cybersecurity Law vs EU Cyber Resilience Act compares the practical trigger, owner, timing, and evidence record for each regime so visitors can avoid collapsing two different compliance decisions into one checklist.

Start with the trigger and accountable owner, then build the evidence package for each route. A filing, assessment, permit, or policy under one regime is not proof that the other regime is complete.

  • Use the left column for the China-specific legal route and evidence package.
  • Use the right column for the compared regime or adjacent China route.
  • Keep shared facts linked, but preserve separate legal conclusions, owners, and official citations.
Operationalize the requirement

Build the China network security evidence file

Sorena AI helps turn the China Cybersecurity Law vs EU Cyber Resilience Act decision into owners, controls, and reviewer-ready records.

Primary sources

References and citations

cac.gov.cn
Referenced sections
  • Use for cybersecurity review scope, CII procurement filing, platform operator review triggers, review materials, special review, and 15 February 2022 effective date.
eur-lex.europa.eu
Referenced sections
  • Use for EU Cyber Resilience Act product scope, vulnerability handling, conformity assessment, CE marking, and manufacturer obligation comparison points.
cac.gov.cn
Referenced sections
  • Use for network operator security duties, network product/service security, CII provisions, personal-information security articles, penalties, and 1 June 2017 effective date.
cac.gov.cn
Referenced sections
  • Use for data classification and graded protection, important-data risk assessment, security management, incident response, outbound important-data context, penalties, and 1 September 2021 effective date.
Related guides

Explore more topics

China cybersecurity and data security requirements
Network operator, data security, cybersecurity review, app governance, MLPS, and smart-home security requirements under China sources.
China cybersecurity compliance checklist
Checklist for network operators, app providers, connected-device teams, review screening, app filing, MLPS evidence, and smart-home security related review.
China cybersecurity deadlines and compliance calendar
Official cybersecurity, data security, review, app governance, filing, and standards dates.
China Cybersecurity Law FAQ
Answers to practical China Cybersecurity Law questions for scope, official source triggers, evidence records, and related China scope decisions.
China Cybersecurity Law vs EU NIS2
Comparison of China network/data security duties with EU NIS2 entity cybersecurity duties.
China cybersecurity penalties and enforcement exposure
China cybersecurity, data security, review, and app-governance enforcement exposure.
China cybersecurity review workflow
Intake workflow for procurement, platform, CII, and national-security risk review triggers.
China mobile app filing and app governance
How MIIT app filing and CAC app information service duties affect app providers and distribution workflows.
CII and network operator role triage
How to separate ordinary network operator duties from CII, procurement, and review-risk questions under China cybersecurity sources.
Cybersecurity review vs data export security assessment
Crosswalk for review triggers and data export assessment triggers so teams do not mix procurement/platform review with outbound data transfer review.
Does an app need MIIT filing and CAC app governance review?
Treat app filing and app information service governance as related but separate checks. MIIT filing evidence should not replace CAC app-provider governance, privacy minimization, or cybersecurity duties.
How do smart home security standards fit with China cybersecurity law?
The smart home security standard can support connected appliance security evidence, but it does not replace app privacy, network access, radio, or cybersecurity review analysis. Use it as one control map tied to the cited standard.
How does important data change China cybersecurity obligations?
Important data changes the risk analysis because the Data Security Law establishes data classification and graded protection. The practical record is an important-data screening note, plus export or security-assessment routing where applicable.
Is every company a network operator under China Cybersecurity Law?
Do not start with a generic company label. Start with the network, system, app, platform, data processing, and China operation facts, then map them to network operator, app provider, data processor, CII, or review triggers in the cited sources.
MLPS classified protection baseline evidence
How to use the classified protection baseline standard as evidence mapping without treating the standard itself as a standalone law.
MLPS classified protection evidence map
Evidence map for classified protection baseline controls, source status, owners, and security records.
Mobile app filing vs app personal information rules
Practical overlap guide for MIIT app filing, app information service governance, and app minimum personal-information duties.
Smart home security standard evidence
How connected-device teams can use the smart home security specification and cross-link telecom, privacy, and cybersecurity evidence.
Smart home security vs telecom and wireless launch
Cross-link page for smart connected appliance teams separating cybersecurity standard evidence from radio and network access evidence.
What is MLPS classified protection evidence?
MLPS evidence is a control and classification evidence set, not a standalone substitute for the Cybersecurity Law. Keep system scope, classification rationale, baseline requirement mapping, remediation, and review records.
When does China cybersecurity review apply?
Cybersecurity review analysis is needed when procurement, platform operation, CII, or national security risk facts match the Cybersecurity Review Measures. Keep an intake note with product/service, buyer/operator role, data/system impact, and official source trigger.