China's Cybersecurity Law starts with a network and its operator in China. NIS2 starts with an entity in a covered EU sector under the applicable Member State law.
The same group can need both programs, but entity scope, authority, reporting route, management duties, and evidence remain jurisdiction-specific.
Use the China Cybersecurity Law track for networks built, operated, maintained, or used in China. Use the track when a legal entity falls within a covered sector and the applicable Member State implementation law. NIS2 generally captures and larger entities in Annex I or II sectors, but it also includes specific entities regardless of size and allows national additions. A multinational may need both tracks for the same systems without being able to reuse one legal conclusion.
Comparison
China Cybersecurity Law vs EU NIS2 Directive
Compare a China network-operator regime with an EU entity-governance regime. Shared security controls can support both, but scope, management approval, incident reporting, and supervision require separate decisions.
Use for networks and network operators in China, with separate screening for graded protection, CII, cybersecurity review, app, personal-information, and data duties.
Second framework
EU NIS2 Directive
Use for covered entities under Member State law, including management accountability, risk-management measures, supply-chain security, incident reporting, and supervision.
The Cybersecurity Law applies to the construction, operation, maintenance, and use of networks in China. Baseline network-operator duties and enhanced CII duties are separate layers.
applies through Member State law to entities in the sectors and categories set by the Directive. The general size-cap rule captures and larger Annex I or II entities, subject to size-independent inclusions, exclusions, and national additions.
Assess the China network and each EU legal entity separately. A corporate group, product, or system is not itself the complete unit of analysis for both regimes.
The network operator owns baseline duties. A CII operator has enhanced obligations only when the network and operator meet the applicable identification framework; CII status does not follow from company size alone.
The covered legal entity owns compliance. Its management body must approve and oversee the Article 21 measures and receive training; operational security and supplier owners support that accountability.
Name the China network operator, the legal entity, and the accountable management body. Do not assign the whole program only to a central security team.
Screen when an entity builds, operates, maintains, or uses a network in China, then identify the operator and any enhanced CII, review, app, personal-information, important-data, or export duty.
Screen each entity against its sector, services, size, establishment, jurisdiction, national registration rules, and Member State transposition. Certain public communications, trust, top-level-domain, DNS, and other listed entities can be covered regardless of size.
Repeat the scope review after acquisitions, legal-entity changes, new sectors or services, new Member State establishments, and material China network changes.
Network operators must follow the graded cybersecurity-protection framework and take technical and organizational measures for secure operation, incident response, and protection of network data. Further duties depend on CII and data status.
A common control library can support both tracks, but each mapping must identify the regulated operator or entity, the system boundary, and the applicable legal text.
Retain the entity-scope rationale, essential or important classification, national registration, management approvals and training, Article 21 control mapping, supplier evidence, tests, incidents, staged reports, and authority correspondence.
Link shared technical evidence to separate legal records. A group policy without entity approval, system ownership, and implementation evidence is incomplete.
The Cybersecurity Law first took effect on 1 June 2017, and the 2025 amendment took effect on 1 January 2026. Security duties continue during network operation; neither date is an annual filing deadline.
Member States were required to transpose by 17 October 2024. For a significant incident, the Directive sets an early warning within 24 hours of awareness, an incident notification within 72 hours, and a final report no later than one month after the incident notification. An ongoing incident instead requires a progress report at that point and a final report within one month after the incident is handled.
Use the current national law and authority channel for the clock. Maintain a separate China incident matrix because thresholds, recipients, and timing can differ.
China consequences depend on the current amended provision, actor, conduct, severity, and linked laws. The 2025 amendment revised several liability provisions, so the 2016 penalty numbering is no longer current.
are generally subject to proactive supervision, while are generally supervised after evidence of non-compliance. requires national maximum fines of at least EUR 10 million or 2% of worldwide annual turnover for essential entities and EUR 7 million or 1.4% for important entities, whichever is higher.
Confirm the national enforcement text before stating exposure. Preserve management, scope, control, reporting, and remediation records for each entity.
The file must still show entity scope, management approval, Article 21 mapping, significant-incident analysis, national reporting, and supervision status.
Link the evidence but write two conclusions. A China network classification does not establish scope, and NIS2 registration does not establish China compliance.
Run the China track when the organization operates or uses a network in China, then determine baseline, graded-protection, CII, review, and data obligations.
Run both when an EU covered entity depends on systems or operations in China. Keep entity scope, network scope, approvals, and incident reporting separate.
The Cybersecurity Law applies to the construction, operation, maintenance, and use of networks in China. Baseline network-operator duties and enhanced CII duties are separate layers.
applies through Member State law to entities in the sectors and categories set by the Directive. The general size-cap rule captures and larger Annex I or II entities, subject to size-independent inclusions, exclusions, and national additions.
Assess the China network and each EU legal entity separately. A corporate group, product, or system is not itself the complete unit of analysis for both regimes.
The network operator owns baseline duties. A CII operator has enhanced obligations only when the network and operator meet the applicable identification framework; CII status does not follow from company size alone.
The covered legal entity owns compliance. Its management body must approve and oversee the Article 21 measures and receive training; operational security and supplier owners support that accountability.
Name the China network operator, the legal entity, and the accountable management body. Do not assign the whole program only to a central security team.
Screen when an entity builds, operates, maintains, or uses a network in China, then identify the operator and any enhanced CII, review, app, personal-information, important-data, or export duty.
Screen each entity against its sector, services, size, establishment, jurisdiction, national registration rules, and Member State transposition. Certain public communications, trust, top-level-domain, DNS, and other listed entities can be covered regardless of size.
Repeat the scope review after acquisitions, legal-entity changes, new sectors or services, new Member State establishments, and material China network changes.
Network operators must follow the graded cybersecurity-protection framework and take technical and organizational measures for secure operation, incident response, and protection of network data. Further duties depend on CII and data status.
A common control library can support both tracks, but each mapping must identify the regulated operator or entity, the system boundary, and the applicable legal text.
Retain the entity-scope rationale, essential or important classification, national registration, management approvals and training, Article 21 control mapping, supplier evidence, tests, incidents, staged reports, and authority correspondence.
Link shared technical evidence to separate legal records. A group policy without entity approval, system ownership, and implementation evidence is incomplete.
The Cybersecurity Law first took effect on 1 June 2017, and the 2025 amendment took effect on 1 January 2026. Security duties continue during network operation; neither date is an annual filing deadline.
Member States were required to transpose by 17 October 2024. For a significant incident, the Directive sets an early warning within 24 hours of awareness, an incident notification within 72 hours, and a final report no later than one month after the incident notification. An ongoing incident instead requires a progress report at that point and a final report within one month after the incident is handled.
Use the current national law and authority channel for the clock. Maintain a separate China incident matrix because thresholds, recipients, and timing can differ.
China consequences depend on the current amended provision, actor, conduct, severity, and linked laws. The 2025 amendment revised several liability provisions, so the 2016 penalty numbering is no longer current.
are generally subject to proactive supervision, while are generally supervised after evidence of non-compliance. requires national maximum fines of at least EUR 10 million or 2% of worldwide annual turnover for essential entities and EUR 7 million or 1.4% for important entities, whichever is higher.
Confirm the national enforcement text before stating exposure. Preserve management, scope, control, reporting, and remediation records for each entity.
The file must still show entity scope, management approval, Article 21 mapping, significant-incident analysis, national reporting, and supervision status.
Link the evidence but write two conclusions. A China network classification does not establish scope, and NIS2 registration does not establish China compliance.
Run the China track when the organization operates or uses a network in China, then determine baseline, graded-protection, CII, review, and data obligations.
Run both when an EU covered entity depends on systems or operations in China. Keep entity scope, network scope, approvals, and incident reporting separate.
Use the China track for the China network and operator; separately screen graded protection, CII, cybersecurity review, app, personal-information, important-data, and export rules.
Use the track entity by entity, applying the relevant Member State law, sector, size, jurisdiction, essential or important classification, management, risk-management, and reporting requirements.
Run both when the same systems support both operations, but retain separate scope rationales, authority routes, management approvals, and incident clocks.
For China, identify the network, its operator, the applicable graded-protection duties, and any separate CII, cybersecurity-review, app, personal-information, important-data, or data-export trigger. The 2025 amendment to the Cybersecurity Law took effect on 1 January 2026 and revised liability provisions and article numbering.
For , assess each legal entity against Annex I and Annex II sectors, the EU size rules, size-independent categories, Member State additions, establishment and jurisdiction rules, and the relevant national transposition law. Under the general size test, an SME has fewer than 250 employees and no more than EUR 50 million in annual turnover or EUR 43 million on its annual balance sheet; a small enterprise has fewer than 50 employees and no more than EUR 10 million in turnover or on its balance sheet. NIS2 generally captures enterprises and entities above the SME ceilings, but partner and linked enterprises can change the staff and financial totals, and specified categories apply regardless of size. and have different supervision and maximum-fine requirements, but both follow the Article 21 risk-management baseline.
If applies, must approve and oversee the cybersecurity measures and receive training. follow a staged process: early warning within 24 hours of awareness, incident notification within 72 hours, and a final report no later than one month after that notification. If the incident is still ongoing when the final report is due, the entity submits a progress report and then a final report within one month after handling the incident. The relevant national procedure controls the filing channel.
Keep one system and supplier inventory, but identify the China network operator and the entity separately.
Map shared risk, incident, continuity, vulnerability, cryptography, access-control, and supply-chain evidence to each regime's legal requirement.
Maintain separate authority contacts, incident thresholds, clocks, reporting forms, management approvals, and enforcement records.
Official source for the employee, turnover, balance-sheet, partner-enterprise, linked-enterprise, and accounting-period rules used in the general NIS2 size test.
Use for cybersecurity review scope, CII procurement filing, platform operator review triggers, review materials, special review, and 15 February 2022 effective date.
Use for data classification and graded protection, important-data risk assessment, security management, incident response, outbound important-data context, penalties, and 1 September 2021 effective date.