ComparisonChina

China Cybersecurity Law vs EU NIS2 Directive

China's Cybersecurity Law starts with a network and its operator in China. NIS2 starts with an entity in a covered EU sector under the applicable Member State law.

The same group can need both programs, but entity scope, authority, reporting route, management duties, and evidence remain jurisdiction-specific.

Author
Sorena AI
Published
Jul 5, 2026
Updated
Jul 25, 2026
Sections
1

Structured answer sets in this page tree.

Primary sources
7

Cited legal and guidance references.

Publication metadata
Sorena AI
Published Jul 5, 2026
Updated Jul 25, 2026
Overview

Use the China Cybersecurity Law track for networks built, operated, maintained, or used in China. Use the track when a legal entity falls within a covered sector and the applicable Member State implementation law. NIS2 generally captures and larger entities in Annex I or II sectors, but it also includes specific entities regardless of size and allows national additions. A multinational may need both tracks for the same systems without being able to reuse one legal conclusion.

Comparison

China Cybersecurity Law vs EU NIS2 Directive

Compare a China network-operator regime with an EU entity-governance regime. Shared security controls can support both, but scope, management approval, incident reporting, and supervision require separate decisions.

Review all sources
First framework
China Cybersecurity Law

Use for networks and network operators in China, with separate screening for graded protection, CII, cybersecurity review, app, personal-information, and data duties.

Second framework
EU NIS2 Directive

Use for covered entities under Member State law, including management accountability, risk-management measures, supply-chain security, incident reporting, and supervision.

Comparison row 1

Scope boundary

China Cybersecurity Law

The Cybersecurity Law applies to the construction, operation, maintenance, and use of networks in China. Baseline network-operator duties and enhanced CII duties are separate layers.

EU NIS2 Directive

applies through Member State law to entities in the sectors and categories set by the Directive. The general size-cap rule captures and larger Annex I or II entities, subject to size-independent inclusions, exclusions, and national additions.

Operational implication

Assess the China network and each EU legal entity separately. A corporate group, product, or system is not itself the complete unit of analysis for both regimes.

Comparison row 2

Covered actors

China Cybersecurity Law

The network operator owns baseline duties. A CII operator has enhanced obligations only when the network and operator meet the applicable identification framework; CII status does not follow from company size alone.

EU NIS2 Directive

The covered legal entity owns compliance. Its management body must approve and oversee the Article 21 measures and receive training; operational security and supplier owners support that accountability.

Operational implication

Name the China network operator, the legal entity, and the accountable management body. Do not assign the whole program only to a central security team.

Comparison row 3

Trigger event

China Cybersecurity Law

Screen when an entity builds, operates, maintains, or uses a network in China, then identify the operator and any enhanced CII, review, app, personal-information, important-data, or export duty.

EU NIS2 Directive

Screen each entity against its sector, services, size, establishment, jurisdiction, national registration rules, and Member State transposition. Certain public communications, trust, top-level-domain, DNS, and other listed entities can be covered regardless of size.

Operational implication

Repeat the scope review after acquisitions, legal-entity changes, new sectors or services, new Member State establishments, and material China network changes.

Comparison row 4

Core obligations

China Cybersecurity Law

Network operators must follow the graded cybersecurity-protection framework and take technical and organizational measures for secure operation, incident response, and protection of network data. Further duties depend on CII and data status.

EU NIS2 Directive

Article 21 requires proportionate technical, operational, and organizational measures covering risk analysis, incident handling, continuity and crisis management, supply-chain security, secure acquisition and development, vulnerability handling, effectiveness assessment, cyber hygiene and training, cryptography, access control, asset and HR security, and multi-factor or continuous authentication where appropriate.

Operational implication

A common control library can support both tracks, but each mapping must identify the regulated operator or entity, the system boundary, and the applicable legal text.

Comparison row 5

Evidence package

China Cybersecurity Law

Retain the network boundary, operator and CII decisions, graded-protection classification and implementation, policies, supplier controls, monitoring, logs, incident plans, exercises, incidents, and remediation.

EU NIS2 Directive

Retain the entity-scope rationale, essential or important classification, national registration, management approvals and training, Article 21 control mapping, supplier evidence, tests, incidents, staged reports, and authority correspondence.

Operational implication

Link shared technical evidence to separate legal records. A group policy without entity approval, system ownership, and implementation evidence is incomplete.

Comparison row 6

Timing and refresh points

China Cybersecurity Law

The Cybersecurity Law first took effect on 1 June 2017, and the 2025 amendment took effect on 1 January 2026. Security duties continue during network operation; neither date is an annual filing deadline.

EU NIS2 Directive

Member States were required to transpose by 17 October 2024. For a significant incident, the Directive sets an early warning within 24 hours of awareness, an incident notification within 72 hours, and a final report no later than one month after the incident notification. An ongoing incident instead requires a progress report at that point and a final report within one month after the incident is handled.

Operational implication

Use the current national law and authority channel for the clock. Maintain a separate China incident matrix because thresholds, recipients, and timing can differ.

Comparison row 7

Enforcement exposure

China Cybersecurity Law

China consequences depend on the current amended provision, actor, conduct, severity, and linked laws. The 2025 amendment revised several liability provisions, so the 2016 penalty numbering is no longer current.

EU NIS2 Directive

are generally subject to proactive supervision, while are generally supervised after evidence of non-compliance. requires national maximum fines of at least EUR 10 million or 2% of worldwide annual turnover for essential entities and EUR 7 million or 1.4% for important entities, whichever is higher.

Operational implication

Confirm the national enforcement text before stating exposure. Preserve management, scope, control, reporting, and remediation records for each entity.

Comparison row 8

Overlap and routing

China Cybersecurity Law

Both tracks can use the same asset inventory, risk register, supplier reviews, vulnerability records, continuity plans, logs, and incident chronology.

EU NIS2 Directive

The file must still show entity scope, management approval, Article 21 mapping, significant-incident analysis, national reporting, and supervision status.

Operational implication

Link the evidence but write two conclusions. A China network classification does not establish scope, and NIS2 registration does not establish China compliance.

Comparison row 9

Practical decision rule

China Cybersecurity Law

Run the China track when the organization operates or uses a network in China, then determine baseline, graded-protection, CII, review, and data obligations.

EU NIS2 Directive

Run the track for each entity that provides a listed service or activity in the EU and meets a Directive or national scope rule.

Operational implication

Run both when an EU covered entity depends on systems or operations in China. Keep entity scope, network scope, approvals, and incident reporting separate.

Practical decision rule

When to run one track or both

  • Use the China track for the China network and operator; separately screen graded protection, CII, cybersecurity review, app, personal-information, important-data, and export rules.
  • Use the track entity by entity, applying the relevant Member State law, sector, size, jurisdiction, essential or important classification, management, risk-management, and reporting requirements.
  • Run both when the same systems support both operations, but retain separate scope rationales, authority routes, management approvals, and incident clocks.
Section 1

How to use this comparison

For China, identify the network, its operator, the applicable graded-protection duties, and any separate CII, cybersecurity-review, app, personal-information, important-data, or data-export trigger. The 2025 amendment to the Cybersecurity Law took effect on 1 January 2026 and revised liability provisions and article numbering.

For , assess each legal entity against Annex I and Annex II sectors, the EU size rules, size-independent categories, Member State additions, establishment and jurisdiction rules, and the relevant national transposition law. Under the general size test, an SME has fewer than 250 employees and no more than EUR 50 million in annual turnover or EUR 43 million on its annual balance sheet; a small enterprise has fewer than 50 employees and no more than EUR 10 million in turnover or on its balance sheet. NIS2 generally captures enterprises and entities above the SME ceilings, but partner and linked enterprises can change the staff and financial totals, and specified categories apply regardless of size. and have different supervision and maximum-fine requirements, but both follow the Article 21 risk-management baseline.

If applies, must approve and oversee the cybersecurity measures and receive training. follow a staged process: early warning within 24 hours of awareness, incident notification within 72 hours, and a final report no later than one month after that notification. If the incident is still ongoing when the final report is due, the entity submits a progress report and then a final report within one month after handling the incident. The relevant national procedure controls the filing channel.

  • Keep one system and supplier inventory, but identify the China network operator and the entity separately.
  • Map shared risk, incident, continuity, vulnerability, cryptography, access-control, and supply-chain evidence to each regime's legal requirement.
  • Maintain separate authority contacts, incident thresholds, clocks, reporting forms, management approvals, and enforcement records.
Primary sources

References and citations

eur-lex.europa.eu
Referenced sections
  • Official source for the employee, turnover, balance-sheet, partner-enterprise, linked-enterprise, and accounting-period rules used in the general NIS2 size test.
cac.gov.cn
Referenced sections
  • Use for cybersecurity review scope, CII procurement filing, platform operator review triggers, review materials, special review, and 15 February 2022 effective date.
eur-lex.europa.eu
Referenced sections
  • Binding source for entity scope, management accountability, Article 21 measures, incident reporting, supervision, enforcement, and transposition.
cac.gov.cn
Referenced sections
  • Use for network operator security duties, network product/service security, CII provisions, personal-information security articles, penalties, and 1 June 2017 effective date.
cac.gov.cn
Referenced sections
  • Use for data classification and graded protection, important-data risk assessment, security management, incident response, outbound important-data context, penalties, and 1 September 2021 effective date.
Related guides

Explore more topics

China App Filing vs Personal Information Rules
Decide whether a China mobile app needs MIIT filing, personal-information controls, or both, with current triggers, duties, dates, and evidence.
China cybersecurity and data security requirements
China cybersecurity requirements by actor: network operators, data processors, CII operators, platforms, app providers, and distribution platforms.
China cybersecurity compliance checklist
A China cybersecurity checklist for scoping network duties, data security, CII procurement review, app rules, MIIT filing, and supporting standards.
China cybersecurity deadlines and compliance calendar
Separate China cybersecurity commencement dates from recurring duties, filing lead times, review periods, and event-driven response deadlines.
China Cybersecurity Law FAQ
Practical answers on China network-operator scope, MLPS evidence, important data, cybersecurity review, app filing and governance, and smart-home standards under the law in force from 1 January 2026.
China Cybersecurity Law vs EU Cyber Resilience Act
Compare China's network-operator rules with the EU CRA's product duties, including scope, actors, evidence, reporting dates, and launch decisions.
China cybersecurity penalties and fines
Compare current China Cybersecurity Law and Data Security Law fines by actor, breach, severity, and enforcement consequence.
China Cybersecurity Review vs Data Export Assessment
Separate China's cybersecurity-review triggers from CAC data-export assessment triggers, thresholds, filings, evidence, timing, and reapplication rules.
China cybersecurity review workflow
Determine whether CII procurement, platform data processing, or a qualifying foreign listing triggers China's Cybersecurity Review Measures.
China mobile app filing and app governance
Identify the China app sponsor, complete MIIT filing before service, and separate provider, platform, privacy, content, and security duties.
China Smart-Home Security vs Telecom and Radio Approval
Separate GB/T 41387-2022 smart-home security evidence from China telecom network-access and radio approval decisions for connected products.
CII and network operator role triage
How to separate ordinary network operator duties from CII, procurement, and review-risk questions under China cybersecurity sources.
Does an app need MIIT filing and CAC app governance review?
An app sponsor providing internet information services through an app in China must complete MIIT filing. CAC rules separately govern app providers and distribution platforms without creating one routine CAC approval for every app.
GB/T 22239-2019 classified protection baseline
How to scope and document a GB/T 22239-2019 classified protection baseline without treating the recommended standard as a standalone law.
GB/T 41387-2022 smart home security standard
How connected-device teams can scope and document GB/T 41387-2022 without treating it as an automatic certification or product-approval duty.
How do smart home security standards fit with China cybersecurity law?
GB/T 41387-2022 can organize smart-home security evidence, but it is a recommended standard, not a product approval. Check app, data, MLPS, telecom access, and radio requirements separately.
How does important data change China cybersecurity obligations?
Once data is officially identified as important data, the processor needs named governance, periodic risk assessments and reports, incident controls, and a separate export decision. An internal sensitivity label alone does not establish the legal category.
Is every company a network operator under China Cybersecurity Law?
No. Under China's Cybersecurity Law, a network operator is an owner or administrator of a network or a network service provider. Apply that definition to each China network or service, then test CII and other roles separately.
MLPS classified protection evidence map
Classify a China network under MLPS, complete level 2 or above filing, map controls, and retain assessment, remediation, and change evidence.
What is MLPS classified protection evidence?
MLPS evidence shows how a defined China network or system was graded and protected. Keep the scope, grading rationale, filing or assessment records where applicable, control mapping, test results, remediation, and reassessment history.
When does China cybersecurity review apply?
China cybersecurity review applies to CII procurement or network-platform data processing that affects or may affect national security, plus a mandatory pre-filing trigger for certain foreign listings involving more than one million users' personal information.