---
title: "China Cybersecurity Law vs EU Cyber Resilience Act"
canonical_url: "https://www.sorena.io/artifacts/apac/china-cybersecurity-law/china-cybersecurity-law-vs-eu-cyber-resilience-act"
source_url: "https://www.sorena.io/artifacts/apac/china-cybersecurity-law/china-cybersecurity-law-vs-eu-cyber-resilience-act"
author: "Sorena AI"
description: "Compare China's network-operator rules with the EU CRA's product duties, including scope, actors, evidence, reporting dates, and launch decisions."
published_at: "2026-07-05"
updated_at: "2026-07-25"
keywords:
  - "China Cybersecurity Law"
  - "Data Security Law"
  - "Cybersecurity Review Measures"
  - "Mobile app filing"
  - "MLPS"
---
**[SORENA](https://www.sorena.io/)** - AI-Powered GRC Platform

[Home](https://www.sorena.io/) | [Solutions](https://www.sorena.io/solutions) | [Artifacts](https://www.sorena.io/artifacts) | [About Us](https://www.sorena.io/about-us) | [Contact](https://www.sorena.io/contact) | [Portal](https://app.sorena.io)

---

# China Cybersecurity Law vs EU Cyber Resilience Act

Compare China's network-operator rules with the EU CRA's product duties, including scope, actors, evidence, reporting dates, and launch decisions.

*Comparison* *China*

## China Cybersecurity Law vs EU Cyber Resilience Act

China's Cybersecurity Law regulates networks and network operators in China. The EU CRA regulates products with digital elements placed on the EU market.

A connected product can trigger both, but the regulated object, responsible actor, evidence, reporting route, and compliance date differ.

Use the China Cybersecurity Law track for a network built, operated, maintained, or used in China and for the entity that operates it. Use the EU Cyber Resilience Act track for hardware or software with a direct or indirect logical or physical data connection that is made available on the EU market. A connected device sold in the EU and supported by a China-operated service can require both tracks. The CRA's vulnerability-reporting duties apply from 11 September 2026; most other CRA obligations apply from 11 December 2027.

## Definitions

### EU Cyber Resilience Act

**Term:** CRA

The CRA is Regulation (EU) 2024/2847. It sets horizontal cybersecurity requirements for covered hardware and software products with digital elements made available on the EU market, with duties for manufacturers and other economic operators across design, conformity assessment, vulnerability handling, support, reporting, and market surveillance.

**Why it matters here:** The CRA is a product-market regulation, not an operator-security regime. Its Article 14 reporting duties apply from 11 September 2026, while most other obligations apply from 11 December 2027.

Sources:

- [EU Cyber Resilience Act](https://eur-lex.europa.eu/eli/reg/2024/2847/oj?ref=sorena.io)

### Product with digital elements

A product with digital elements is a software or hardware product and its remote data-processing solutions, including a software or hardware component placed on the market separately. CRA scope also requires the product's intended purpose or reasonably foreseeable use to include a direct or indirect logical or physical data connection to a device or network.

**Why it matters here:** Define the product boundary before classifying it or selecting a conformity route. A China-operated backend may be relevant remote data processing when the manufacturer designed it, or had it designed under its responsibility, and the product cannot perform one of its functions without it.

Sources:

- [EU Cyber Resilience Act](https://eur-lex.europa.eu/eli/reg/2024/2847/oj?ref=sorena.io)

### Making available on the EU market

**Term:** made available on the EU market

A product is made available on the EU market when it is supplied for distribution or use on that market in the course of a commercial activity, whether for payment or free of charge. Placing on the market is the first such supply; later supplies are also making available.

**Why it matters here:** A free download can still be commercial, while free and open-source software supplied outside a commercial activity falls outside the manufacturer regime. Record the supply model, responsible economic operator, territory, and first market event.

Sources:

- [EU Cyber Resilience Act](https://eur-lex.europa.eu/eli/reg/2024/2847/oj?ref=sorena.io)

### CRA support period

**Term:** support period

The support period is the time during which the manufacturer must handle product vulnerabilities effectively. It must reflect expected use, reasonable user expectations, product nature and purpose, relevant product-lifetime law, and other stated factors; it is normally at least five years, or the expected use time when that is shorter.

**Why it matters here:** Document the product-specific rationale and disclose at least the support end month and year at purchase. The period controls vulnerability handling and affects how long security updates, technical documentation, and user information remain available.

Sources:

- [EU Cyber Resilience Act](https://eur-lex.europa.eu/eli/reg/2024/2847/oj?ref=sorena.io)

### CRA conformity assessment

**Term:** conformity assessment

Conformity assessment is the process of verifying whether the CRA's essential cybersecurity requirements are met. The permitted route depends on the product category and any applicable harmonised standards, common specifications, or certification; some important or critical products cannot rely on unrestricted manufacturer self-assessment.

**Why it matters here:** Complete the applicable route before the product is placed on the EU market, then draw up the EU declaration of conformity and affix CE marking. A China security filing, MLPS assessment, or supplier certificate does not replace the CRA route.

Sources:

- [EU Cyber Resilience Act](https://eur-lex.europa.eu/eli/reg/2024/2847/oj?ref=sorena.io)

### Critical information infrastructure

**Term:** CII

CII is an important network facility or information system in a listed or other important sector whose destruction, loss of function, or data leakage could seriously harm national security, the national economy, people's livelihoods, or the public interest. The responsible protection department identifies CII under sector rules and notifies the operator.

**Why it matters here:** CII status changes the China track by adding enhanced security, annual assessment, personnel, procurement, and other duties. A product's CRA class, CE marking, company size, or importance to a customer does not establish CII status.

Sources:

- [Regulations on the Security Protection of Critical Information Infrastructure](https://www.cac.gov.cn/2021-08/17/c_1630785976988160.htm?ref=sorena.io)
- [PRC Cybersecurity Law, consolidated after the 2025 amendment](https://www.cac.gov.cn/2025-12/29/c_1768735112911946.htm?ref=sorena.io)

### Open-source software steward

An open-source software steward is a legal person, other than a manufacturer, that systematically supports the sustained development of specific free and open-source products intended for commercial activities and helps ensure their viability. The CRA gives this role a lighter set of duties than a manufacturer.

**Why it matters here:** A foundation or other supporting organization does not become a manufacturer merely because it maintains open-source development, but it may need the steward route. A commercial manufacturer that markets the software under its name remains subject to the manufacturer analysis.

Sources:

- [EU Cyber Resilience Act](https://eur-lex.europa.eu/eli/reg/2024/2847/oj?ref=sorena.io)

## China Cybersecurity Law vs EU Cyber Resilience Act

Compare a China network-operator compliance track with an EU product-conformity track. Reuse engineering facts, but make separate scope, actor, evidence, reporting, and release decisions.

- **China Cybersecurity Law**: Use for networks and network operators in China, including baseline network-security duties and separate screening for graded protection, CII, review, and data rules.
- **EU Cyber Resilience Act**: Use for products with digital elements made available on the EU market, including lifecycle security, vulnerability handling, conformity assessment, documentation, and CE marking.

| Dimension | China Cybersecurity Law | EU Cyber Resilience Act | Operational implication | Sources |
| --- | --- | --- | --- | --- |
| Scope boundary | The Cybersecurity Law applies to the construction, operation, maintenance, and use of networks in China. It sets baseline duties for network operators and additional duties for separately identified critical information infrastructure operators. | The CRA covers software and hardware products with direct or indirect logical or physical data connections when they are made available on the EU market. It contains exclusions and special rules, so product type and commercial supply must be checked. | A device, app, or service can be part of a China-operated network and also be an EU product with digital elements. Make both scope decisions from the actual architecture and supply model. | [PRC Cybersecurity Law](https://www.cac.gov.cn/2016-11/07/c_1119867116.htm?ref=sorena.io) - Use for network operator security duties, network product/service security, CII provisions, personal-information security articles, penalties, and 1 June 2017 effective date.<br>[EU Cyber Resilience Act](https://eur-lex.europa.eu/eli/reg/2024/2847/oj?ref=sorena.io) - Use for EU Cyber Resilience Act product scope, vulnerability handling, conformity assessment, CE marking, and manufacturer obligation comparison points.<br>[PRC Data Security Law](https://www.cac.gov.cn/2021-06/11/c_1624994566919140.htm?ref=sorena.io) - Use for data classification and graded protection, important-data risk assessment, security management, incident response, outbound important-data context, penalties, and 1 September 2021 effective date. |
| Covered actors | The network operator owns the baseline China duties. A CII operator has additional obligations only when the network and operator meet the applicable identification framework; CII status should not be assumed from company size alone. | The manufacturer owns product design, risk assessment, vulnerability handling, conformity assessment, technical documentation, declaration, and CE marking. Importers and distributors have separate verification and corrective-action duties. | Assign a China network owner and an EU manufacturer compliance owner. Product-security engineering may support both, but it does not replace either legal owner. | [PRC Cybersecurity Law](https://www.cac.gov.cn/2016-11/07/c_1119867116.htm?ref=sorena.io) - Use for network operator security duties, network product/service security, CII provisions, personal-information security articles, penalties, and 1 June 2017 effective date.<br>[EU Cyber Resilience Act](https://eur-lex.europa.eu/eli/reg/2024/2847/oj?ref=sorena.io) - Use for EU Cyber Resilience Act product scope, vulnerability handling, conformity assessment, CE marking, and manufacturer obligation comparison points.<br>[PRC Data Security Law](https://www.cac.gov.cn/2021-06/11/c_1624994566919140.htm?ref=sorena.io) - Use for data classification and graded protection, important-data risk assessment, security management, incident response, outbound important-data context, penalties, and 1 September 2021 effective date. |
| Trigger event | Screen when an entity builds, operates, maintains, or uses a network in China, then determine the operator and whether enhanced CII, procurement-review, data, or app rules also apply. | Screen when a product with digital elements is first placed on or later made available on the EU market, including substantial modifications that can cause the modifier to assume manufacturer duties. | Record the China service or network start and the EU market event separately. A cloud deployment date and a hardware sale date may trigger different tracks. | [PRC Cybersecurity Law](https://www.cac.gov.cn/2016-11/07/c_1119867116.htm?ref=sorena.io) - Use for network operator security duties, network product/service security, CII provisions, personal-information security articles, penalties, and 1 June 2017 effective date.<br>[EU Cyber Resilience Act](https://eur-lex.europa.eu/eli/reg/2024/2847/oj?ref=sorena.io) - Use for EU Cyber Resilience Act product scope, vulnerability handling, conformity assessment, CE marking, and manufacturer obligation comparison points.<br>[PRC Data Security Law](https://www.cac.gov.cn/2021-06/11/c_1624994566919140.htm?ref=sorena.io) - Use for data classification and graded protection, important-data risk assessment, security management, incident response, outbound important-data context, penalties, and 1 September 2021 effective date. |
| Core obligations | Network operators must follow the graded cybersecurity-protection framework and take technical and organizational measures for secure operation, incident response, and protection of network data. Additional duties depend on the network and data involved. | Manufacturers must design, develop, and produce the product to meet the CRA's essential cybersecurity requirements, assess cybersecurity risks, handle vulnerabilities during the support period, provide security information and updates, and complete the applicable conformity assessment. | Map shared controls once, then show separately how they satisfy the China network duty and the CRA product requirement. | [PRC Cybersecurity Law](https://www.cac.gov.cn/2016-11/07/c_1119867116.htm?ref=sorena.io) - Use for network operator security duties, network product/service security, CII provisions, personal-information security articles, penalties, and 1 June 2017 effective date.<br>[EU Cyber Resilience Act](https://eur-lex.europa.eu/eli/reg/2024/2847/oj?ref=sorena.io) - Use for EU Cyber Resilience Act product scope, vulnerability handling, conformity assessment, CE marking, and manufacturer obligation comparison points.<br>[PRC Data Security Law](https://www.cac.gov.cn/2021-06/11/c_1624994566919140.htm?ref=sorena.io) - Use for data classification and graded protection, important-data risk assessment, security management, incident response, outbound important-data context, penalties, and 1 September 2021 effective date. |
| Evidence package | Retain the network boundary, operator decision, graded-protection classification and implementation records, security policies, supplier controls, monitoring, logs, incident plans, exercises, incidents, and remediation evidence. | Retain the product scope and classification rationale, cybersecurity risk assessment, technical documentation, secure-development and update evidence, vulnerability records, conformity-assessment output, EU declaration of conformity, CE record, and support-period rationale. | Link common test reports to both files, but preserve the product version, network deployment, responsible actor, and legal conclusion for each. | [PRC Cybersecurity Law](https://www.cac.gov.cn/2016-11/07/c_1119867116.htm?ref=sorena.io) - Use for network operator security duties, network product/service security, CII provisions, personal-information security articles, penalties, and 1 June 2017 effective date.<br>[EU Cyber Resilience Act](https://eur-lex.europa.eu/eli/reg/2024/2847/oj?ref=sorena.io) - Use for EU Cyber Resilience Act product scope, vulnerability handling, conformity assessment, CE marking, and manufacturer obligation comparison points.<br>[PRC Data Security Law](https://www.cac.gov.cn/2021-06/11/c_1624994566919140.htm?ref=sorena.io) - Use for data classification and graded protection, important-data risk assessment, security management, incident response, outbound important-data context, penalties, and 1 September 2021 effective date. |
| Timing and refresh points | The Cybersecurity Law first took effect on 1 June 2017. The 2025 amendment took effect on 1 January 2026. Network-security duties continue during operation; those dates are not annual filing deadlines. | The CRA entered into force on 10 December 2024. Article 14 reporting applies from 11 September 2026: early warning within 24 hours, fuller notification within 72 hours, and a final report within 14 days after a corrective or mitigating measure is available for an actively exploited vulnerability or within one month after a severe-incident notification. Article 14 also reaches products placed on the market before the main application date. Most other obligations apply from 11 December 2027, while some conformity-assessment-body provisions apply earlier. | Build the CRA reporting and user-notice process before September 2026, including coverage for earlier products, and complete full product conformity before December 2027. Maintain the China controls throughout network operation. | [PRC Cybersecurity Law, consolidated after the 2025 amendment](https://www.cac.gov.cn/2025-12/29/c_1768735112911946.htm?ref=sorena.io) - Current official text for the original 1 June 2017 commencement and the amended provisions effective from 1 January 2026.<br>[EU Cyber Resilience Act](https://eur-lex.europa.eu/eli/reg/2024/2847/oj?ref=sorena.io) - Use for EU Cyber Resilience Act product scope, vulnerability handling, conformity assessment, CE marking, and manufacturer obligation comparison points.<br>[PRC Cybersecurity Law](https://www.cac.gov.cn/2016-11/07/c_1119867116.htm?ref=sorena.io) - Use for network operator security duties, network product/service security, CII provisions, personal-information security articles, penalties, and 1 June 2017 effective date.<br>[PRC Data Security Law](https://www.cac.gov.cn/2021-06/11/c_1624994566919140.htm?ref=sorena.io) - Use for data classification and graded protection, important-data risk assessment, security management, incident response, outbound important-data context, penalties, and 1 September 2021 effective date. |
| Enforcement exposure | China consequences depend on the current amended provision, actor, conduct, severity, and any linked law. The 2025 amendment revised and increased several liability provisions, so the original 2016 penalty numbering is not current. | EU market-surveillance authorities can require corrective action, restrict or prohibit products, order withdrawal or recall, and impose penalties under the CRA and national rules. Exposure depends on the breached obligation and economic operator. | Keep dated scope, risk, test, vulnerability, update, and release records. Do not present a certification or China security filing as blanket immunity in either market. | [PRC Cybersecurity Law, consolidated after the 2025 amendment](https://www.cac.gov.cn/2025-12/29/c_1768735112911946.htm?ref=sorena.io) - Current official text for actor-specific duties, revised liability provisions, penalty tiers, and other enforcement consequences.<br>[EU Cyber Resilience Act](https://eur-lex.europa.eu/eli/reg/2024/2847/oj?ref=sorena.io) - Use for EU Cyber Resilience Act product scope, vulnerability handling, conformity assessment, CE marking, and manufacturer obligation comparison points.<br>[PRC Cybersecurity Law](https://www.cac.gov.cn/2016-11/07/c_1119867116.htm?ref=sorena.io) - Use for network operator security duties, network product/service security, CII provisions, personal-information security articles, penalties, and 1 June 2017 effective date.<br>[PRC Data Security Law](https://www.cac.gov.cn/2021-06/11/c_1624994566919140.htm?ref=sorena.io) - Use for data classification and graded protection, important-data risk assessment, security management, incident response, outbound important-data context, penalties, and 1 September 2021 effective date. |
| Overlap and routing | China and CRA teams can share the bill of materials, architecture, supplier reviews, vulnerability intake, patch records, security tests, and incident evidence. | The CRA file must still establish the product boundary, responsible economic operator, support period, essential-requirements assessment, conformity route, reporting, and CE documentation. | Use linked evidence with separate conclusions. A China network assessment does not establish CRA conformity, and CE marking does not establish China network compliance. | [PRC Cybersecurity Law](https://www.cac.gov.cn/2016-11/07/c_1119867116.htm?ref=sorena.io) - Use for network operator security duties, network product/service security, CII provisions, personal-information security articles, penalties, and 1 June 2017 effective date.<br>[EU Cyber Resilience Act](https://eur-lex.europa.eu/eli/reg/2024/2847/oj?ref=sorena.io) - Use for EU Cyber Resilience Act product scope, vulnerability handling, conformity assessment, CE marking, and manufacturer obligation comparison points.<br>[PRC Data Security Law](https://www.cac.gov.cn/2021-06/11/c_1624994566919140.htm?ref=sorena.io) - Use for data classification and graded protection, important-data risk assessment, security management, incident response, outbound important-data context, penalties, and 1 September 2021 effective date. |
| Practical decision rule | Run the China track when the product or service forms part of a network in China or the organization operates that network. | Run the CRA track when covered hardware or software will be made available on the EU market, whether for payment or through another commercial supply model. | Run both for an EU-connected product supported by China network operations. If one track is excluded, retain the facts and legal basis for that conclusion. | [PRC Cybersecurity Law](https://www.cac.gov.cn/2016-11/07/c_1119867116.htm?ref=sorena.io) - Use for network operator security duties, network product/service security, CII provisions, personal-information security articles, penalties, and 1 June 2017 effective date.<br>[EU Cyber Resilience Act](https://eur-lex.europa.eu/eli/reg/2024/2847/oj?ref=sorena.io) - Use for EU Cyber Resilience Act product scope, vulnerability handling, conformity assessment, CE marking, and manufacturer obligation comparison points.<br>[PRC Data Security Law](https://www.cac.gov.cn/2021-06/11/c_1624994566919140.htm?ref=sorena.io) - Use for data classification and graded protection, important-data risk assessment, security management, incident response, outbound important-data context, penalties, and 1 September 2021 effective date. |

Sources for Scope boundary - China Cybersecurity Law:

- [PRC Cybersecurity Law](https://www.cac.gov.cn/2016-11/07/c_1119867116.htm?ref=sorena.io) - Use for network operator security duties, network product/service security, CII provisions, personal-information security articles, penalties, and 1 June 2017 effective date.

Sources for Scope boundary - EU Cyber Resilience Act:

- [EU Cyber Resilience Act](https://eur-lex.europa.eu/eli/reg/2024/2847/oj?ref=sorena.io) - Use for EU Cyber Resilience Act product scope, vulnerability handling, conformity assessment, CE marking, and manufacturer obligation comparison points.

Sources for Scope boundary - operational implication:

- [PRC Cybersecurity Law](https://www.cac.gov.cn/2016-11/07/c_1119867116.htm?ref=sorena.io) - Use for network operator security duties, network product/service security, CII provisions, personal-information security articles, penalties, and 1 June 2017 effective date.
- [PRC Data Security Law](https://www.cac.gov.cn/2021-06/11/c_1624994566919140.htm?ref=sorena.io) - Use for data classification and graded protection, important-data risk assessment, security management, incident response, outbound important-data context, penalties, and 1 September 2021 effective date.

Sources for Covered actors - China Cybersecurity Law:

- [PRC Cybersecurity Law](https://www.cac.gov.cn/2016-11/07/c_1119867116.htm?ref=sorena.io) - Use for network operator security duties, network product/service security, CII provisions, personal-information security articles, penalties, and 1 June 2017 effective date.

Sources for Covered actors - EU Cyber Resilience Act:

- [EU Cyber Resilience Act](https://eur-lex.europa.eu/eli/reg/2024/2847/oj?ref=sorena.io) - Use for EU Cyber Resilience Act product scope, vulnerability handling, conformity assessment, CE marking, and manufacturer obligation comparison points.

Sources for Covered actors - operational implication:

- [PRC Cybersecurity Law](https://www.cac.gov.cn/2016-11/07/c_1119867116.htm?ref=sorena.io) - Use for network operator security duties, network product/service security, CII provisions, personal-information security articles, penalties, and 1 June 2017 effective date.
- [PRC Data Security Law](https://www.cac.gov.cn/2021-06/11/c_1624994566919140.htm?ref=sorena.io) - Use for data classification and graded protection, important-data risk assessment, security management, incident response, outbound important-data context, penalties, and 1 September 2021 effective date.

Sources for Trigger event - China Cybersecurity Law:

- [PRC Cybersecurity Law](https://www.cac.gov.cn/2016-11/07/c_1119867116.htm?ref=sorena.io) - Use for network operator security duties, network product/service security, CII provisions, personal-information security articles, penalties, and 1 June 2017 effective date.

Sources for Trigger event - EU Cyber Resilience Act:

- [EU Cyber Resilience Act](https://eur-lex.europa.eu/eli/reg/2024/2847/oj?ref=sorena.io) - Use for EU Cyber Resilience Act product scope, vulnerability handling, conformity assessment, CE marking, and manufacturer obligation comparison points.

Sources for Trigger event - operational implication:

- [PRC Cybersecurity Law](https://www.cac.gov.cn/2016-11/07/c_1119867116.htm?ref=sorena.io) - Use for network operator security duties, network product/service security, CII provisions, personal-information security articles, penalties, and 1 June 2017 effective date.
- [PRC Data Security Law](https://www.cac.gov.cn/2021-06/11/c_1624994566919140.htm?ref=sorena.io) - Use for data classification and graded protection, important-data risk assessment, security management, incident response, outbound important-data context, penalties, and 1 September 2021 effective date.

Sources for Core obligations - China Cybersecurity Law:

- [PRC Cybersecurity Law](https://www.cac.gov.cn/2016-11/07/c_1119867116.htm?ref=sorena.io) - Use for network operator security duties, network product/service security, CII provisions, personal-information security articles, penalties, and 1 June 2017 effective date.

Sources for Core obligations - EU Cyber Resilience Act:

- [EU Cyber Resilience Act](https://eur-lex.europa.eu/eli/reg/2024/2847/oj?ref=sorena.io) - Use for EU Cyber Resilience Act product scope, vulnerability handling, conformity assessment, CE marking, and manufacturer obligation comparison points.

Sources for Core obligations - operational implication:

- [PRC Cybersecurity Law](https://www.cac.gov.cn/2016-11/07/c_1119867116.htm?ref=sorena.io) - Use for network operator security duties, network product/service security, CII provisions, personal-information security articles, penalties, and 1 June 2017 effective date.
- [PRC Data Security Law](https://www.cac.gov.cn/2021-06/11/c_1624994566919140.htm?ref=sorena.io) - Use for data classification and graded protection, important-data risk assessment, security management, incident response, outbound important-data context, penalties, and 1 September 2021 effective date.

Sources for Evidence package - China Cybersecurity Law:

- [PRC Cybersecurity Law](https://www.cac.gov.cn/2016-11/07/c_1119867116.htm?ref=sorena.io) - Use for network operator security duties, network product/service security, CII provisions, personal-information security articles, penalties, and 1 June 2017 effective date.

Sources for Evidence package - EU Cyber Resilience Act:

- [EU Cyber Resilience Act](https://eur-lex.europa.eu/eli/reg/2024/2847/oj?ref=sorena.io) - Use for EU Cyber Resilience Act product scope, vulnerability handling, conformity assessment, CE marking, and manufacturer obligation comparison points.

Sources for Evidence package - operational implication:

- [PRC Cybersecurity Law](https://www.cac.gov.cn/2016-11/07/c_1119867116.htm?ref=sorena.io) - Use for network operator security duties, network product/service security, CII provisions, personal-information security articles, penalties, and 1 June 2017 effective date.
- [PRC Data Security Law](https://www.cac.gov.cn/2021-06/11/c_1624994566919140.htm?ref=sorena.io) - Use for data classification and graded protection, important-data risk assessment, security management, incident response, outbound important-data context, penalties, and 1 September 2021 effective date.

Sources for Timing and refresh points - China Cybersecurity Law:

- [PRC Cybersecurity Law, consolidated after the 2025 amendment](https://www.cac.gov.cn/2025-12/29/c_1768735112911946.htm?ref=sorena.io) - Current official text for the original 1 June 2017 commencement and the amended provisions effective from 1 January 2026.

Sources for Timing and refresh points - EU Cyber Resilience Act:

- [EU Cyber Resilience Act](https://eur-lex.europa.eu/eli/reg/2024/2847/oj?ref=sorena.io) - Use for EU Cyber Resilience Act product scope, vulnerability handling, conformity assessment, CE marking, and manufacturer obligation comparison points.

Sources for Timing and refresh points - operational implication:

- [PRC Cybersecurity Law](https://www.cac.gov.cn/2016-11/07/c_1119867116.htm?ref=sorena.io) - Use for network operator security duties, network product/service security, CII provisions, personal-information security articles, penalties, and 1 June 2017 effective date.
- [PRC Data Security Law](https://www.cac.gov.cn/2021-06/11/c_1624994566919140.htm?ref=sorena.io) - Use for data classification and graded protection, important-data risk assessment, security management, incident response, outbound important-data context, penalties, and 1 September 2021 effective date.

Sources for Enforcement exposure - China Cybersecurity Law:

- [PRC Cybersecurity Law, consolidated after the 2025 amendment](https://www.cac.gov.cn/2025-12/29/c_1768735112911946.htm?ref=sorena.io) - Current official text for actor-specific duties, revised liability provisions, penalty tiers, and other enforcement consequences.

Sources for Enforcement exposure - EU Cyber Resilience Act:

- [EU Cyber Resilience Act](https://eur-lex.europa.eu/eli/reg/2024/2847/oj?ref=sorena.io) - Use for EU Cyber Resilience Act product scope, vulnerability handling, conformity assessment, CE marking, and manufacturer obligation comparison points.

Sources for Enforcement exposure - operational implication:

- [PRC Cybersecurity Law](https://www.cac.gov.cn/2016-11/07/c_1119867116.htm?ref=sorena.io) - Use for network operator security duties, network product/service security, CII provisions, personal-information security articles, penalties, and 1 June 2017 effective date.
- [PRC Data Security Law](https://www.cac.gov.cn/2021-06/11/c_1624994566919140.htm?ref=sorena.io) - Use for data classification and graded protection, important-data risk assessment, security management, incident response, outbound important-data context, penalties, and 1 September 2021 effective date.

Sources for Overlap and routing - China Cybersecurity Law:

- [PRC Cybersecurity Law](https://www.cac.gov.cn/2016-11/07/c_1119867116.htm?ref=sorena.io) - Use for network operator security duties, network product/service security, CII provisions, personal-information security articles, penalties, and 1 June 2017 effective date.

Sources for Overlap and routing - EU Cyber Resilience Act:

- [EU Cyber Resilience Act](https://eur-lex.europa.eu/eli/reg/2024/2847/oj?ref=sorena.io) - Use for EU Cyber Resilience Act product scope, vulnerability handling, conformity assessment, CE marking, and manufacturer obligation comparison points.

Sources for Overlap and routing - operational implication:

- [PRC Cybersecurity Law](https://www.cac.gov.cn/2016-11/07/c_1119867116.htm?ref=sorena.io) - Use for network operator security duties, network product/service security, CII provisions, personal-information security articles, penalties, and 1 June 2017 effective date.
- [PRC Data Security Law](https://www.cac.gov.cn/2021-06/11/c_1624994566919140.htm?ref=sorena.io) - Use for data classification and graded protection, important-data risk assessment, security management, incident response, outbound important-data context, penalties, and 1 September 2021 effective date.

Sources for Practical decision rule - China Cybersecurity Law:

- [PRC Cybersecurity Law](https://www.cac.gov.cn/2016-11/07/c_1119867116.htm?ref=sorena.io) - Use for network operator security duties, network product/service security, CII provisions, personal-information security articles, penalties, and 1 June 2017 effective date.

Sources for Practical decision rule - EU Cyber Resilience Act:

- [EU Cyber Resilience Act](https://eur-lex.europa.eu/eli/reg/2024/2847/oj?ref=sorena.io) - Use for EU Cyber Resilience Act product scope, vulnerability handling, conformity assessment, CE marking, and manufacturer obligation comparison points.

Sources for Practical decision rule - operational implication:

- [PRC Cybersecurity Law](https://www.cac.gov.cn/2016-11/07/c_1119867116.htm?ref=sorena.io) - Use for network operator security duties, network product/service security, CII provisions, personal-information security articles, penalties, and 1 June 2017 effective date.
- [PRC Data Security Law](https://www.cac.gov.cn/2021-06/11/c_1624994566919140.htm?ref=sorena.io) - Use for data classification and graded protection, important-data risk assessment, security management, incident response, outbound important-data context, penalties, and 1 September 2021 effective date.

### When to run one track or both

- Use the China track for the China network and operator; separately screen graded protection, CII, cybersecurity review, app, personal-information, important-data, and export rules.
- Use the CRA track for a covered product with digital elements made available on the EU market; determine the product classification, support period, conformity route, documentation, reporting, and CE steps.
- Run both when the same architecture and supply chain create both triggers, but retain separate scope decisions and release approvals.

Sources for the practical decision rule:

- [PRC Cybersecurity Law](https://www.cac.gov.cn/2016-11/07/c_1119867116.htm?ref=sorena.io) - Use for network operator security duties, network product/service security, CII provisions, personal-information security articles, penalties, and 1 June 2017 effective date.
- [PRC Data Security Law](https://www.cac.gov.cn/2021-06/11/c_1624994566919140.htm?ref=sorena.io) - Use for data classification and graded protection, important-data risk assessment, security management, incident response, outbound important-data context, penalties, and 1 September 2021 effective date.
- [2025 Decision amending the PRC Cybersecurity Law](https://www.npc.gov.cn/npc/c1773/c1848/c21114/wlaqfxz/wlaqfxz002/202511/t20251103_449242.html?ref=sorena.io) - Binding amendment effective on 1 January 2026; use for current article numbering and revised liability provisions.
- [EU Cyber Resilience Act](https://eur-lex.europa.eu/eli/reg/2024/2847/oj?ref=sorena.io) - Binding source for product scope, duties, conformity assessment, reporting, CE marking, and application dates.

## How to use this comparison

Start by separating the regulated objects. The China decision concerns the network, its operator, and any enhanced status such as critical information infrastructure. The CRA decision concerns a product with digital elements and the manufacturer, importer, or distributor that makes it available in the EU.

For the CRA, confirm the product with digital elements, commercial placement on the EU market, exclusions, product classification, conformity assessment route, and support period. Free and open-source software supplied outside a commercial activity is outside the manufacturer regime, although an open-source software steward can have separate duties. The CRA also excludes products covered by the EU medical-device, in vitro diagnostic-device, motor-vehicle type-approval, civil-aviation certification, and marine-equipment regimes; identical-specification replacement spare parts; and products developed or modified exclusively for national-security or defence purposes. A remote data-processing solution is included when the manufacturer designed it, or had it designed under its responsibility, and the product cannot perform one of its functions without it.

From 11 September 2026, a manufacturer that becomes aware of an actively exploited vulnerability or a severe incident affecting product security must send an early warning within 24 hours and a fuller notification within 72 hours through the CRA reporting route. The final report is due no later than 14 days after a corrective or mitigating measure becomes available for an actively exploited vulnerability, or within one month after the incident notification for a severe incident. The manufacturer must also inform impacted users and, where appropriate, all users about the event and available corrective or mitigating measures. Article 14 applies to covered products placed on the market before 11 December 2027 as well as later products, even though the CRA's other obligations generally apply to an earlier product only if it is substantially modified after that date.

For China, identify the network boundary and operator, apply the applicable graded-protection and network-security duties, and separately screen CII, cybersecurity review, personal-information, important-data, and cross-border-transfer rules. The 2025 amendment to the Cybersecurity Law took effect on 1 January 2026 and strengthened and reorganized liability provisions; do not rely on the 2016 article numbering for current enforcement analysis.

- Shared engineering evidence can include architecture, asset inventory, supplier controls, vulnerability handling, logging, incident response, and security updates.
- China evidence must tie those controls to the relevant network, operator, graded-protection level, and any CII or review decision.
- CRA evidence must tie them to the product, supported versions, cybersecurity risk assessment, technical documentation, conformity route, EU declaration of conformity, CE marking, and reporting process.

Sources for this answer:

- [PRC Cybersecurity Law, consolidated after the 2025 amendment](https://www.cac.gov.cn/2025-12/29/c_1768735112911946.htm?ref=sorena.io) - Current official text for network scope, operator duties, CII provisions, product and service security, and liability after 1 January 2026.
- [PRC Data Security Law](https://www.cac.gov.cn/2021-06/11/c_1624994566919140.htm?ref=sorena.io) - Use for data classification and graded protection, important-data risk assessment, security management, incident response, outbound important-data context, penalties, and 1 September 2021 effective date.
- [2025 Decision amending the PRC Cybersecurity Law](https://www.npc.gov.cn/npc/c1773/c1848/c21114/wlaqfxz/wlaqfxz002/202511/t20251103_449242.html?ref=sorena.io) - Binding amendment adopted on 28 October 2025 and effective on 1 January 2026; use for current article renumbering and revised liability provisions.
- [EU Cyber Resilience Act](https://eur-lex.europa.eu/eli/reg/2024/2847/oj?ref=sorena.io) - Binding Regulation (EU) 2024/2847; use for product scope and exclusions, economic-operator duties, reporting, conformity assessment, technical documentation, CE marking, and application dates.

*Next step*

*Placement: Before primary sources*

## Keep the network and product decisions separate

Map shared security evidence to the China network and the EU product without merging scope, actor, conformity, or reporting conclusions.

- [Map official sources to evidence](/solutions/research-copilot.md): Link each China and CRA decision to its official source, owner, evidence, and change history.
- [Review the China route](/contact.md): Review unresolved China network and EU product-scope questions.

## Primary sources

- [PRC Cybersecurity Law, consolidated after the 2025 amendment](https://www.cac.gov.cn/2025-12/29/c_1768735112911946.htm?ref=sorena.io) - Current official text for actor-specific duties, revised liability provisions, penalty tiers, and other enforcement consequences.
- [PRC Data Security Law](https://www.cac.gov.cn/2021-06/11/c_1624994566919140.htm?ref=sorena.io) - Use for data classification and graded protection, important-data risk assessment, security management, incident response, outbound important-data context, penalties, and 1 September 2021 effective date.
- [Cybersecurity Review Measures](https://www.cac.gov.cn/2022-01/04/c_1642894602182845.htm?ref=sorena.io) - Use for cybersecurity review scope, CII procurement filing, platform operator review triggers, review materials, special review, and 15 February 2022 effective date.
- [2025 Decision amending the PRC Cybersecurity Law](https://www.npc.gov.cn/npc/c1773/c1848/c21114/wlaqfxz/wlaqfxz002/202511/t20251103_449242.html?ref=sorena.io) - Binding amendment effective on 1 January 2026; use for current article numbering and revised liability provisions.
- [EU Cyber Resilience Act](https://eur-lex.europa.eu/eli/reg/2024/2847/oj?ref=sorena.io) - Binding source for product scope, duties, conformity assessment, reporting, CE marking, and application dates.
- [PRC Cybersecurity Law](https://www.cac.gov.cn/2016-11/07/c_1119867116.htm?ref=sorena.io) - Use for network operator security duties, network product/service security, CII provisions, personal-information security articles, penalties, and 1 June 2017 effective date.

## Related Topic Guides

- [China App Filing vs Personal Information Rules](/artifacts/apac/china-cybersecurity-law/mobile-app-filing-vs-app-personal-information-rules.md): Decide whether a China mobile app needs MIIT filing, personal-information controls, or both, with current triggers, duties, dates, and evidence.
- [China cybersecurity and data security requirements](/artifacts/apac/china-cybersecurity-law/requirements.md): China cybersecurity requirements by actor: network operators, data processors, CII operators, platforms, app providers, and distribution platforms.
- [China cybersecurity compliance checklist](/artifacts/apac/china-cybersecurity-law/checklist.md): A China cybersecurity checklist for scoping network duties, data security, CII procurement review, app rules, MIIT filing, and supporting standards.
- [China cybersecurity deadlines and compliance calendar](/artifacts/apac/china-cybersecurity-law/deadlines-and-compliance-calendar.md): Separate China cybersecurity commencement dates from recurring duties, filing lead times, review periods, and event-driven response deadlines.
- [China Cybersecurity Law FAQ](/artifacts/apac/china-cybersecurity-law/faq.md): Practical answers on China network-operator scope, MLPS evidence, important data, cybersecurity review, app filing and governance, and smart-home standards under the law in force from 1 January 2026.
- [China Cybersecurity Law vs EU NIS2 Directive](/artifacts/apac/china-cybersecurity-law/china-cybersecurity-law-vs-nis2.md): Compare China's network-operator duties with NIS2 entity duties, including scope, management accountability, incident reporting, evidence, and enforcement.
- [China cybersecurity penalties and fines](/artifacts/apac/china-cybersecurity-law/penalties-and-fines.md): Compare current China Cybersecurity Law and Data Security Law fines by actor, breach, severity, and enforcement consequence.
- [China Cybersecurity Review vs Data Export Assessment](/artifacts/apac/china-cybersecurity-law/cybersecurity-review-vs-data-export-security-assessment.md): Separate China's cybersecurity-review triggers from CAC data-export assessment triggers, thresholds, filings, evidence, timing, and reapplication rules.
- [China cybersecurity review workflow](/artifacts/apac/china-cybersecurity-law/cybersecurity-review-workflow.md): Determine whether CII procurement, platform data processing, or a qualifying foreign listing triggers China's Cybersecurity Review Measures.
- [China mobile app filing and app governance](/artifacts/apac/china-cybersecurity-law/mobile-app-filing-and-app-governance.md): Identify the China app sponsor, complete MIIT filing before service, and separate provider, platform, privacy, content, and security duties.
- [China Smart-Home Security vs Telecom and Radio Approval](/artifacts/apac/china-cybersecurity-law/smart-home-security-vs-telecom-wireless-launch.md): Separate GB/T 41387-2022 smart-home security evidence from China telecom network-access and radio approval decisions for connected products.
- [CII and network operator role triage](/artifacts/apac/china-cybersecurity-law/critical-information-infrastructure-and-network-operators.md): How to separate ordinary network operator duties from CII, procurement, and review-risk questions under China cybersecurity sources.
- [Does an app need MIIT filing and CAC app governance review?](/artifacts/apac/china-cybersecurity-law/faq/does-an-app-need-miit-filing-and-cac-app-governance-review.md): An app sponsor providing internet information services through an app in China must complete MIIT filing. CAC rules separately govern app providers and distribution platforms without creating one routine CAC approval for every app.
- [GB/T 22239-2019 classified protection baseline](/artifacts/apac/china-cybersecurity-law/classified-protection-baseline.md): How to scope and document a GB/T 22239-2019 classified protection baseline without treating the recommended standard as a standalone law.
- [GB/T 41387-2022 smart home security standard](/artifacts/apac/china-cybersecurity-law/smart-home-security-standard.md): How connected-device teams can scope and document GB/T 41387-2022 without treating it as an automatic certification or product-approval duty.
- [How do smart home security standards fit with China cybersecurity law?](/artifacts/apac/china-cybersecurity-law/faq/how-do-smart-home-security-standards-fit-with-china-cybersecurity-law.md): GB/T 41387-2022 can organize smart-home security evidence, but it is a recommended standard, not a product approval. Check app, data, MLPS, telecom access, and radio requirements separately.
- [How does important data change China cybersecurity obligations?](/artifacts/apac/china-cybersecurity-law/faq/how-does-important-data-change-cybersecurity-obligations.md): Once data is officially identified as important data, the processor needs named governance, periodic risk assessments and reports, incident controls, and a separate export decision. An internal sensitivity label alone does not establish the legal category.
- [Is every company a network operator under China Cybersecurity Law?](/artifacts/apac/china-cybersecurity-law/faq/is-every-company-a-network-operator-under-china-cybersecurity-law.md): No. Under China's Cybersecurity Law, a network operator is an owner or administrator of a network or a network service provider. Apply that definition to each China network or service, then test CII and other roles separately.
- [MLPS classified protection evidence map](/artifacts/apac/china-cybersecurity-law/mlps-classified-protection-evidence-map.md): Classify a China network under MLPS, complete level 2 or above filing, map controls, and retain assessment, remediation, and change evidence.
- [What is MLPS classified protection evidence?](/artifacts/apac/china-cybersecurity-law/faq/what-is-mlps-classified-protection-evidence.md): MLPS evidence shows how a defined China network or system was graded and protected. Keep the scope, grading rationale, filing or assessment records where applicable, control mapping, test results, remediation, and reassessment history.
- [When does China cybersecurity review apply?](/artifacts/apac/china-cybersecurity-law/faq/when-does-china-cybersecurity-review-apply.md): China cybersecurity review applies to CII procurement or network-platform data processing that affects or may affect national security, plus a mandatory pre-filing trigger for certain foreign listings involving more than one million users' personal information.


---

[Privacy Policy](https://www.sorena.io/privacy.md) | [Terms of Use](https://www.sorena.io/terms-of-use.md) | [DMCA](https://www.sorena.io/dmca.md) | [About Us](https://www.sorena.io/about-us.md)

(c) 2026 Sorena AB (559573-7338). All rights reserved.

Source: https://www.sorena.io/artifacts/apac/china-cybersecurity-law/china-cybersecurity-law-vs-eu-cyber-resilience-act.md
