ComparisonChina

China Cybersecurity Law vs EU Cyber Resilience Act

China's Cybersecurity Law regulates networks and network operators in China. The EU CRA regulates products with digital elements placed on the EU market.

A connected product can trigger both, but the regulated object, responsible actor, evidence, reporting route, and compliance date differ.

Author
Sorena AI
Published
Jul 5, 2026
Updated
Jul 25, 2026
Sections
1

Structured answer sets in this page tree.

Primary sources
6

Cited legal and guidance references.

Publication metadata
Sorena AI
Published Jul 5, 2026
Updated Jul 25, 2026
Overview

Use the China Cybersecurity Law track for a network built, operated, maintained, or used in China and for the entity that operates it. Use the EU Cyber Resilience Act track for hardware or software with a direct or indirect logical or physical data connection that is . A connected device sold in the EU and supported by a China-operated service can require both tracks. The 's vulnerability-reporting duties apply from 11 September 2026; most other CRA obligations apply from 11 December 2027.

Comparison

China Cybersecurity Law vs EU Cyber Resilience Act

Compare a China network-operator compliance track with an EU product-conformity track. Reuse engineering facts, but make separate scope, actor, evidence, reporting, and release decisions.

Review all sources
First framework
China Cybersecurity Law

Use for networks and network operators in China, including baseline network-security duties and separate screening for graded protection, , review, and data rules.

Second framework
EU Cyber Resilience Act

Use for products with digital elements , including lifecycle security, vulnerability handling, , documentation, and CE marking.

Comparison row 1

Scope boundary

China Cybersecurity Law

The Cybersecurity Law applies to the construction, operation, maintenance, and use of networks in China. It sets baseline duties for network operators and additional duties for separately identified critical information infrastructure operators.

EU Cyber Resilience Act

The covers software and hardware products with direct or indirect logical or physical data connections when they are . It contains exclusions and special rules, so product type and commercial supply must be checked.

Operational implication

A device, app, or service can be part of a China-operated network and also be an EU . Make both scope decisions from the actual architecture and supply model.

Comparison row 2

Covered actors

China Cybersecurity Law

The network operator owns the baseline China duties. A operator has additional obligations only when the network and operator meet the applicable identification framework; CII status should not be assumed from company size alone.

EU Cyber Resilience Act

The manufacturer owns product design, risk assessment, vulnerability handling, , technical documentation, declaration, and CE marking. Importers and distributors have separate verification and corrective-action duties.

Operational implication

Assign a China network owner and an EU manufacturer compliance owner. Product-security engineering may support both, but it does not replace either legal owner.

Comparison row 3

Trigger event

China Cybersecurity Law

Screen when an entity builds, operates, maintains, or uses a network in China, then determine the operator and whether enhanced , procurement-review, data, or app rules also apply.

EU Cyber Resilience Act

Screen when a is first placed on or later , including substantial modifications that can cause the modifier to assume manufacturer duties.

Operational implication

Record the China service or network start and the EU market event separately. A cloud deployment date and a hardware sale date may trigger different tracks.

Comparison row 4

Core obligations

China Cybersecurity Law

Network operators must follow the graded cybersecurity-protection framework and take technical and organizational measures for secure operation, incident response, and protection of network data. Additional duties depend on the network and data involved.

EU Cyber Resilience Act

Manufacturers must design, develop, and produce the product to meet the 's essential cybersecurity requirements, assess cybersecurity risks, handle vulnerabilities during the , provide security information and updates, and complete the applicable .

Operational implication

Map shared controls once, then show separately how they satisfy the China network duty and the product requirement.

Comparison row 5

Evidence package

China Cybersecurity Law

Retain the network boundary, operator decision, graded-protection classification and implementation records, security policies, supplier controls, monitoring, logs, incident plans, exercises, incidents, and remediation evidence.

EU Cyber Resilience Act

Retain the product scope and classification rationale, cybersecurity risk assessment, technical documentation, secure-development and update evidence, vulnerability records, conformity-assessment output, EU declaration of conformity, CE record, and support-period rationale.

Operational implication

Link common test reports to both files, but preserve the product version, network deployment, responsible actor, and legal conclusion for each.

Comparison row 6

Timing and refresh points

China Cybersecurity Law

The Cybersecurity Law first took effect on 1 June 2017. The 2025 amendment took effect on 1 January 2026. Network-security duties continue during operation; those dates are not annual filing deadlines.

EU Cyber Resilience Act

The entered into force on 10 December 2024. Article 14 reporting applies from 11 September 2026: early warning within 24 hours, fuller notification within 72 hours, and a final report within 14 days after a corrective or mitigating measure is available for an actively exploited vulnerability or within one month after a severe-incident notification. Article 14 also reaches products placed on the market before the main application date. Most other obligations apply from 11 December 2027, while some conformity-assessment-body provisions apply earlier.

Operational implication

Build the reporting and user-notice process before September 2026, including coverage for earlier products, and complete full product conformity before December 2027. Maintain the China controls throughout network operation.

Comparison row 7

Enforcement exposure

China Cybersecurity Law

China consequences depend on the current amended provision, actor, conduct, severity, and any linked law. The 2025 amendment revised and increased several liability provisions, so the original 2016 penalty numbering is not current.

EU Cyber Resilience Act

EU market-surveillance authorities can require corrective action, restrict or prohibit products, order withdrawal or recall, and impose penalties under the and national rules. Exposure depends on the breached obligation and economic operator.

Operational implication

Keep dated scope, risk, test, vulnerability, update, and release records. Do not present a certification or China security filing as blanket immunity in either market.

Comparison row 8

Overlap and routing

China Cybersecurity Law

China and teams can share the bill of materials, architecture, supplier reviews, vulnerability intake, patch records, security tests, and incident evidence.

EU Cyber Resilience Act

The file must still establish the product boundary, responsible economic operator, , essential-requirements assessment, conformity route, reporting, and CE documentation.

Operational implication

Use linked evidence with separate conclusions. A China network assessment does not establish conformity, and CE marking does not establish China network compliance.

Comparison row 9

Practical decision rule

China Cybersecurity Law

Run the China track when the product or service forms part of a network in China or the organization operates that network.

EU Cyber Resilience Act

Run the track when covered hardware or software will be , whether for payment or through another commercial supply model.

Operational implication

Run both for an EU-connected product supported by China network operations. If one track is excluded, retain the facts and legal basis for that conclusion.

Practical decision rule

When to run one track or both

  • Use the China track for the China network and operator; separately screen graded protection, , cybersecurity review, app, personal-information, important-data, and export rules.
  • Use the track for a covered ; determine the product classification, , conformity route, documentation, reporting, and CE steps.
  • Run both when the same architecture and supply chain create both triggers, but retain separate scope decisions and release approvals.
Section 1

How to use this comparison

Start by separating the regulated objects. The China decision concerns the network, its operator, and any enhanced status such as critical information infrastructure. The decision concerns a and the manufacturer, importer, or distributor that makes it available in the EU.

For the , confirm the , commercial placement on the EU market, exclusions, product classification, route, and . Free and open-source software supplied outside a commercial activity is outside the manufacturer regime, although an can have separate duties. The CRA also excludes products covered by the EU medical-device, in vitro diagnostic-device, motor-vehicle type-approval, civil-aviation certification, and marine-equipment regimes; identical-specification replacement spare parts; and products developed or modified exclusively for national-security or defence purposes. A remote data-processing solution is included when the manufacturer designed it, or had it designed under its responsibility, and the product cannot perform one of its functions without it.

From 11 September 2026, a manufacturer that becomes aware of an actively exploited vulnerability or a severe incident affecting product security must send an early warning within 24 hours and a fuller notification within 72 hours through the reporting route. The final report is due no later than 14 days after a corrective or mitigating measure becomes available for an actively exploited vulnerability, or within one month after the incident notification for a severe incident. The manufacturer must also inform impacted users and, where appropriate, all users about the event and available corrective or mitigating measures. Article 14 applies to covered products placed on the market before 11 December 2027 as well as later products, even though the CRA's other obligations generally apply to an earlier product only if it is substantially modified after that date.

For China, identify the network boundary and operator, apply the applicable graded-protection and network-security duties, and separately screen , cybersecurity review, personal-information, important-data, and cross-border-transfer rules. The 2025 amendment to the Cybersecurity Law took effect on 1 January 2026 and strengthened and reorganized liability provisions; do not rely on the 2016 article numbering for current enforcement analysis.

  • Shared engineering evidence can include architecture, asset inventory, supplier controls, vulnerability handling, logging, incident response, and security updates.
  • China evidence must tie those controls to the relevant network, operator, graded-protection level, and any or review decision.
  • evidence must tie them to the product, supported versions, cybersecurity risk assessment, technical documentation, conformity route, EU declaration of conformity, CE marking, and reporting process.
Next step

Keep the network and product decisions separate

Map shared security evidence to the China network and the EU product without merging scope, actor, conformity, or reporting conclusions.

Primary sources

References and citations

cac.gov.cn
Referenced sections
  • Use for cybersecurity review scope, CII procurement filing, platform operator review triggers, review materials, special review, and 15 February 2022 effective date.
eur-lex.europa.eu
Referenced sections
  • Binding source for product scope, duties, conformity assessment, reporting, CE marking, and application dates.
cac.gov.cn
Referenced sections
  • Use for network operator security duties, network product/service security, CII provisions, personal-information security articles, penalties, and 1 June 2017 effective date.
cac.gov.cn
Referenced sections
  • Use for data classification and graded protection, important-data risk assessment, security management, incident response, outbound important-data context, penalties, and 1 September 2021 effective date.
Related guides

Explore more topics

China App Filing vs Personal Information Rules
Decide whether a China mobile app needs MIIT filing, personal-information controls, or both, with current triggers, duties, dates, and evidence.
China cybersecurity and data security requirements
China cybersecurity requirements by actor: network operators, data processors, CII operators, platforms, app providers, and distribution platforms.
China cybersecurity compliance checklist
A China cybersecurity checklist for scoping network duties, data security, CII procurement review, app rules, MIIT filing, and supporting standards.
China cybersecurity deadlines and compliance calendar
Separate China cybersecurity commencement dates from recurring duties, filing lead times, review periods, and event-driven response deadlines.
China Cybersecurity Law FAQ
Practical answers on China network-operator scope, MLPS evidence, important data, cybersecurity review, app filing and governance, and smart-home standards under the law in force from 1 January 2026.
China Cybersecurity Law vs EU NIS2 Directive
Compare China's network-operator duties with NIS2 entity duties, including scope, management accountability, incident reporting, evidence, and enforcement.
China cybersecurity penalties and fines
Compare current China Cybersecurity Law and Data Security Law fines by actor, breach, severity, and enforcement consequence.
China Cybersecurity Review vs Data Export Assessment
Separate China's cybersecurity-review triggers from CAC data-export assessment triggers, thresholds, filings, evidence, timing, and reapplication rules.
China cybersecurity review workflow
Determine whether CII procurement, platform data processing, or a qualifying foreign listing triggers China's Cybersecurity Review Measures.
China mobile app filing and app governance
Identify the China app sponsor, complete MIIT filing before service, and separate provider, platform, privacy, content, and security duties.
China Smart-Home Security vs Telecom and Radio Approval
Separate GB/T 41387-2022 smart-home security evidence from China telecom network-access and radio approval decisions for connected products.
CII and network operator role triage
How to separate ordinary network operator duties from CII, procurement, and review-risk questions under China cybersecurity sources.
Does an app need MIIT filing and CAC app governance review?
An app sponsor providing internet information services through an app in China must complete MIIT filing. CAC rules separately govern app providers and distribution platforms without creating one routine CAC approval for every app.
GB/T 22239-2019 classified protection baseline
How to scope and document a GB/T 22239-2019 classified protection baseline without treating the recommended standard as a standalone law.
GB/T 41387-2022 smart home security standard
How connected-device teams can scope and document GB/T 41387-2022 without treating it as an automatic certification or product-approval duty.
How do smart home security standards fit with China cybersecurity law?
GB/T 41387-2022 can organize smart-home security evidence, but it is a recommended standard, not a product approval. Check app, data, MLPS, telecom access, and radio requirements separately.
How does important data change China cybersecurity obligations?
Once data is officially identified as important data, the processor needs named governance, periodic risk assessments and reports, incident controls, and a separate export decision. An internal sensitivity label alone does not establish the legal category.
Is every company a network operator under China Cybersecurity Law?
No. Under China's Cybersecurity Law, a network operator is an owner or administrator of a network or a network service provider. Apply that definition to each China network or service, then test CII and other roles separately.
MLPS classified protection evidence map
Classify a China network under MLPS, complete level 2 or above filing, map controls, and retain assessment, remediation, and change evidence.
What is MLPS classified protection evidence?
MLPS evidence shows how a defined China network or system was graded and protected. Keep the scope, grading rationale, filing or assessment records where applicable, control mapping, test results, remediation, and reassessment history.
When does China cybersecurity review apply?
China cybersecurity review applies to CII procurement or network-platform data processing that affects or may affect national security, plus a mandatory pre-filing trigger for certain foreign listings involving more than one million users' personal information.