China Cybersecurity Law vs EU Cyber Resilience Act
China's Cybersecurity Law regulates networks and network operators in China. The EU CRA regulates products with digital elements placed on the EU market.
A connected product can trigger both, but the regulated object, responsible actor, evidence, reporting route, and compliance date differ.
Use the China Cybersecurity Law track for a network built, operated, maintained, or used in China and for the entity that operates it. Use the EU Cyber Resilience Act track for hardware or software with a direct or indirect logical or physical data connection that is . A connected device sold in the EU and supported by a China-operated service can require both tracks. The 's vulnerability-reporting duties apply from 11 September 2026; most other CRA obligations apply from 11 December 2027.
Comparison
China Cybersecurity Law vs EU Cyber Resilience Act
Compare a China network-operator compliance track with an EU product-conformity track. Reuse engineering facts, but make separate scope, actor, evidence, reporting, and release decisions.
Use for networks and network operators in China, including baseline network-security duties and separate screening for graded protection, , review, and data rules.
Second framework
EU Cyber Resilience Act
Use for products with digital elements , including lifecycle security, vulnerability handling, , documentation, and CE marking.
China Cybersecurity Law vs EU Cyber Resilience Act
The Cybersecurity Law applies to the construction, operation, maintenance, and use of networks in China. It sets baseline duties for network operators and additional duties for separately identified critical information infrastructure operators.
The covers software and hardware products with direct or indirect logical or physical data connections when they are . It contains exclusions and special rules, so product type and commercial supply must be checked.
A device, app, or service can be part of a China-operated network and also be an EU . Make both scope decisions from the actual architecture and supply model.
The network operator owns the baseline China duties. A operator has additional obligations only when the network and operator meet the applicable identification framework; CII status should not be assumed from company size alone.
The manufacturer owns product design, risk assessment, vulnerability handling, , technical documentation, declaration, and CE marking. Importers and distributors have separate verification and corrective-action duties.
Assign a China network owner and an EU manufacturer compliance owner. Product-security engineering may support both, but it does not replace either legal owner.
Screen when an entity builds, operates, maintains, or uses a network in China, then determine the operator and whether enhanced , procurement-review, data, or app rules also apply.
Record the China service or network start and the EU market event separately. A cloud deployment date and a hardware sale date may trigger different tracks.
Network operators must follow the graded cybersecurity-protection framework and take technical and organizational measures for secure operation, incident response, and protection of network data. Additional duties depend on the network and data involved.
Manufacturers must design, develop, and produce the product to meet the 's essential cybersecurity requirements, assess cybersecurity risks, handle vulnerabilities during the , provide security information and updates, and complete the applicable .
Retain the product scope and classification rationale, cybersecurity risk assessment, technical documentation, secure-development and update evidence, vulnerability records, conformity-assessment output, EU declaration of conformity, CE record, and support-period rationale.
The Cybersecurity Law first took effect on 1 June 2017. The 2025 amendment took effect on 1 January 2026. Network-security duties continue during operation; those dates are not annual filing deadlines.
The entered into force on 10 December 2024. Article 14 reporting applies from 11 September 2026: early warning within 24 hours, fuller notification within 72 hours, and a final report within 14 days after a corrective or mitigating measure is available for an actively exploited vulnerability or within one month after a severe-incident notification. Article 14 also reaches products placed on the market before the main application date. Most other obligations apply from 11 December 2027, while some conformity-assessment-body provisions apply earlier.
Build the reporting and user-notice process before September 2026, including coverage for earlier products, and complete full product conformity before December 2027. Maintain the China controls throughout network operation.
China consequences depend on the current amended provision, actor, conduct, severity, and any linked law. The 2025 amendment revised and increased several liability provisions, so the original 2016 penalty numbering is not current.
EU market-surveillance authorities can require corrective action, restrict or prohibit products, order withdrawal or recall, and impose penalties under the and national rules. Exposure depends on the breached obligation and economic operator.
Keep dated scope, risk, test, vulnerability, update, and release records. Do not present a certification or China security filing as blanket immunity in either market.
China and teams can share the bill of materials, architecture, supplier reviews, vulnerability intake, patch records, security tests, and incident evidence.
The file must still establish the product boundary, responsible economic operator, , essential-requirements assessment, conformity route, reporting, and CE documentation.
Use linked evidence with separate conclusions. A China network assessment does not establish conformity, and CE marking does not establish China network compliance.
Run both for an EU-connected product supported by China network operations. If one track is excluded, retain the facts and legal basis for that conclusion.
The Cybersecurity Law applies to the construction, operation, maintenance, and use of networks in China. It sets baseline duties for network operators and additional duties for separately identified critical information infrastructure operators.
The covers software and hardware products with direct or indirect logical or physical data connections when they are . It contains exclusions and special rules, so product type and commercial supply must be checked.
A device, app, or service can be part of a China-operated network and also be an EU . Make both scope decisions from the actual architecture and supply model.
The network operator owns the baseline China duties. A operator has additional obligations only when the network and operator meet the applicable identification framework; CII status should not be assumed from company size alone.
The manufacturer owns product design, risk assessment, vulnerability handling, , technical documentation, declaration, and CE marking. Importers and distributors have separate verification and corrective-action duties.
Assign a China network owner and an EU manufacturer compliance owner. Product-security engineering may support both, but it does not replace either legal owner.
Screen when an entity builds, operates, maintains, or uses a network in China, then determine the operator and whether enhanced , procurement-review, data, or app rules also apply.
Record the China service or network start and the EU market event separately. A cloud deployment date and a hardware sale date may trigger different tracks.
Network operators must follow the graded cybersecurity-protection framework and take technical and organizational measures for secure operation, incident response, and protection of network data. Additional duties depend on the network and data involved.
Manufacturers must design, develop, and produce the product to meet the 's essential cybersecurity requirements, assess cybersecurity risks, handle vulnerabilities during the , provide security information and updates, and complete the applicable .
Retain the product scope and classification rationale, cybersecurity risk assessment, technical documentation, secure-development and update evidence, vulnerability records, conformity-assessment output, EU declaration of conformity, CE record, and support-period rationale.
The Cybersecurity Law first took effect on 1 June 2017. The 2025 amendment took effect on 1 January 2026. Network-security duties continue during operation; those dates are not annual filing deadlines.
The entered into force on 10 December 2024. Article 14 reporting applies from 11 September 2026: early warning within 24 hours, fuller notification within 72 hours, and a final report within 14 days after a corrective or mitigating measure is available for an actively exploited vulnerability or within one month after a severe-incident notification. Article 14 also reaches products placed on the market before the main application date. Most other obligations apply from 11 December 2027, while some conformity-assessment-body provisions apply earlier.
Build the reporting and user-notice process before September 2026, including coverage for earlier products, and complete full product conformity before December 2027. Maintain the China controls throughout network operation.
China consequences depend on the current amended provision, actor, conduct, severity, and any linked law. The 2025 amendment revised and increased several liability provisions, so the original 2016 penalty numbering is not current.
EU market-surveillance authorities can require corrective action, restrict or prohibit products, order withdrawal or recall, and impose penalties under the and national rules. Exposure depends on the breached obligation and economic operator.
Keep dated scope, risk, test, vulnerability, update, and release records. Do not present a certification or China security filing as blanket immunity in either market.
China and teams can share the bill of materials, architecture, supplier reviews, vulnerability intake, patch records, security tests, and incident evidence.
The file must still establish the product boundary, responsible economic operator, , essential-requirements assessment, conformity route, reporting, and CE documentation.
Use linked evidence with separate conclusions. A China network assessment does not establish conformity, and CE marking does not establish China network compliance.
Run both for an EU-connected product supported by China network operations. If one track is excluded, retain the facts and legal basis for that conclusion.
Use the China track for the China network and operator; separately screen graded protection, , cybersecurity review, app, personal-information, important-data, and export rules.
Use the track for a covered ; determine the product classification, , conformity route, documentation, reporting, and CE steps.
Run both when the same architecture and supply chain create both triggers, but retain separate scope decisions and release approvals.
Start by separating the regulated objects. The China decision concerns the network, its operator, and any enhanced status such as critical information infrastructure. The decision concerns a and the manufacturer, importer, or distributor that makes it available in the EU.
For the , confirm the , commercial placement on the EU market, exclusions, product classification, route, and . Free and open-source software supplied outside a commercial activity is outside the manufacturer regime, although an can have separate duties. The CRA also excludes products covered by the EU medical-device, in vitro diagnostic-device, motor-vehicle type-approval, civil-aviation certification, and marine-equipment regimes; identical-specification replacement spare parts; and products developed or modified exclusively for national-security or defence purposes. A remote data-processing solution is included when the manufacturer designed it, or had it designed under its responsibility, and the product cannot perform one of its functions without it.
From 11 September 2026, a manufacturer that becomes aware of an actively exploited vulnerability or a severe incident affecting product security must send an early warning within 24 hours and a fuller notification within 72 hours through the reporting route. The final report is due no later than 14 days after a corrective or mitigating measure becomes available for an actively exploited vulnerability, or within one month after the incident notification for a severe incident. The manufacturer must also inform impacted users and, where appropriate, all users about the event and available corrective or mitigating measures. Article 14 applies to covered products placed on the market before 11 December 2027 as well as later products, even though the CRA's other obligations generally apply to an earlier product only if it is substantially modified after that date.
For China, identify the network boundary and operator, apply the applicable graded-protection and network-security duties, and separately screen , cybersecurity review, personal-information, important-data, and cross-border-transfer rules. The 2025 amendment to the Cybersecurity Law took effect on 1 January 2026 and strengthened and reorganized liability provisions; do not rely on the 2016 article numbering for current enforcement analysis.
Shared engineering evidence can include architecture, asset inventory, supplier controls, vulnerability handling, logging, incident response, and security updates.
China evidence must tie those controls to the relevant network, operator, graded-protection level, and any or review decision.
evidence must tie them to the product, supported versions, cybersecurity risk assessment, technical documentation, conformity route, EU declaration of conformity, CE marking, and reporting process.
Use for cybersecurity review scope, CII procurement filing, platform operator review triggers, review materials, special review, and 15 February 2022 effective date.
Use for data classification and graded protection, important-data risk assessment, security management, incident response, outbound important-data context, penalties, and 1 September 2021 effective date.