| Scope boundary | China Cybersecurity Law covers China network operations, data security, review, app governance, CII, and MLPS evidence. | EU Cyber Resilience Act covers EU products with digital elements, manufacturer/importer/distributor duties, vulnerability handling, conformity assessment, and CE documentation. | Run separate scope decisions when the same launch can trigger both China Cybersecurity Law and EU Cyber Resilience Act. |
|---|
| Covered actors | China Cybersecurity Law work is usually owned by China operator, app provider, platform, CII, data, and security owners. | EU Cyber Resilience Act work is usually owned by EU manufacturer, importer, distributor, and product security owners. | Assign separate owners when the legal route, regulator, filing, assessment, permit, or evidence package is different. |
|---|
| Trigger event | China Cybersecurity Law screening starts with China operation, app launch, network procurement, review trigger, important data, or MLPS classification. | EU Cyber Resilience Act screening starts with placing a product with digital elements on the EU market. | Record the triggering event and launch date for each route before reusing technical evidence. |
|---|
| Core obligations | China Cybersecurity Law requires the team to translate its official articles or measures into concrete controls for China network operations, data security, review, app governance, CII, and MLPS evidence. | EU Cyber Resilience Act requires controls for EU products with digital elements, manufacturer/importer/distributor duties, vulnerability handling, conformity assessment, and CE documentation. | Shared facts can support both routes, but the legal conclusion and required action must be written separately. |
|---|
| Evidence package | A defensible China Cybersecurity Law file includes China role memo, controls, app/review filings, MLPS records, and incident process. | A defensible EU Cyber Resilience Act file includes technical documentation, cybersecurity risk assessment, vulnerability process, conformity evidence, declaration, and CE record. | Reuse common documents only after each file identifies why the document satisfies that route. |
|---|
| Timing and refresh points | China Cybersecurity Law timing should track effective dates, filing windows, review periods, renewals, or transition dates named in its sources. | EU Cyber Resilience Act timing should track its own effective dates, implementation windows, reporting periods, renewals, or market-entry deadlines. | Calendar each route independently; a date in one regime does not extend or replace a date in the other. |
|---|
| Enforcement exposure | China Cybersecurity Law exposure usually follows the actor, regulator, and failure mode tied to China operation, app launch, network procurement, review trigger, important data, or MLPS classification. | EU Cyber Resilience Act exposure usually follows the actor, regulator, and failure mode tied to placing a product with digital elements on the EU market. | Preserve the evidence trail before launch, filing, transfer, procurement, sale, or disposal because later remediation is weaker than a dated decision record. |
|---|
| Overlap and routing | China Cybersecurity Law and EU Cyber Resilience Act can use the same product, app, supplier, data-flow, or equipment facts, but China Cybersecurity Law owns the decision for China network operations, data security, review, app governance, CII, and MLPS evidence. | EU Cyber Resilience Act owns the decision for EU products with digital elements, manufacturer/importer/distributor duties, vulnerability handling, conformity assessment, and CE documentation. | Create linked records rather than copying one conclusion across both regimes. |
|---|
| Practical decision rule | Choose China Cybersecurity Law when the immediate blocker is China operation, app launch, network procurement, review trigger, important data, or MLPS classification. | Choose EU Cyber Resilience Act when the immediate blocker is placing a product with digital elements on the EU market. | Run both tracks when the same China or cross-market launch creates both China Cybersecurity Law and EU Cyber Resilience Act triggers. |
|---|