---
title: "China Cybersecurity Law vs EU NIS2 Directive"
canonical_url: "https://www.sorena.io/artifacts/apac/china-cybersecurity-law/china-cybersecurity-law-vs-nis2"
source_url: "https://www.sorena.io/artifacts/apac/china-cybersecurity-law/china-cybersecurity-law-vs-nis2"
author: "Sorena AI"
description: "Compare China's network-operator duties with NIS2 entity duties, including scope, management accountability, incident reporting, evidence, and enforcement."
published_at: "2026-07-05"
updated_at: "2026-07-25"
keywords:
  - "China Cybersecurity Law"
  - "Data Security Law"
  - "Cybersecurity Review Measures"
  - "Mobile app filing"
  - "MLPS"
---
**[SORENA](https://www.sorena.io/)** - AI-Powered GRC Platform

[Home](https://www.sorena.io/) | [Solutions](https://www.sorena.io/solutions) | [Artifacts](https://www.sorena.io/artifacts) | [About Us](https://www.sorena.io/about-us) | [Contact](https://www.sorena.io/contact) | [Portal](https://app.sorena.io)

---

# China Cybersecurity Law vs EU NIS2 Directive

Compare China's network-operator duties with NIS2 entity duties, including scope, management accountability, incident reporting, evidence, and enforcement.

*Comparison* *China*

## China Cybersecurity Law vs EU NIS2 Directive

China's Cybersecurity Law starts with a network and its operator in China. NIS2 starts with an entity in a covered EU sector under the applicable Member State law.

The same group can need both programs, but entity scope, authority, reporting route, management duties, and evidence remain jurisdiction-specific.

Use the China Cybersecurity Law track for networks built, operated, maintained, or used in China. Use the NIS2 track when a legal entity falls within a covered sector and the applicable Member State implementation law. NIS2 generally captures medium-sized and larger entities in Annex I or II sectors, but it also includes specific entities regardless of size and allows national additions. A multinational may need both tracks for the same systems without being able to reuse one legal conclusion.

## Definitions

### NIS2 Directive

**Term:** NIS2

NIS2 is Directive (EU) 2022/2555. It requires Member States to impose cybersecurity risk-management, incident-reporting, governance, supervision, and enforcement rules on covered entities, mainly in the sectors listed in Annexes I and II. The Directive works through each Member State's implementing law rather than as one self-executing EU compliance code.

**Why it matters here:** Determine the applicable national law, competent authority, reporting channel, and any national additions before using this comparison operationally. The Directive's 17 October 2024 transposition deadline does not prove that every national rule or procedure is identical.

Sources:

- [EU NIS2 Directive](https://eur-lex.europa.eu/eli/dir/2022/2555/oj?ref=sorena.io)

### Medium-sized enterprise for NIS2 scope

**Term:** medium-sized

For the general NIS2 scope rule, medium-sized status comes from the EU SME Recommendation. An SME employs fewer than 250 people and has annual turnover not exceeding EUR 50 million or an annual balance-sheet total not exceeding EUR 43 million; within that category, a small enterprise employs fewer than 50 people and has turnover or a balance-sheet total not exceeding EUR 10 million. NIS2 generally captures medium-sized enterprises and entities that exceed those ceilings. NIS2 disapplies the Recommendation's Article 3(4) rule for certain publicly controlled enterprises, but the remaining partner, linked-enterprise, staff, turnover, balance-sheet, and two-accounting-period rules still apply.

**Why it matters here:** A medium-sized or larger entity in an Annex I or II sector is generally in scope, but size-independent categories, Member State designations, exclusions, and sector-specific EU-law rules can change the result. Do not use the entity's standalone headcount as the final test.

Sources:

- [EU NIS2 Directive](https://eur-lex.europa.eu/eli/dir/2022/2555/oj?ref=sorena.io)
- [Commission Recommendation 2003/361/EC](https://eur-lex.europa.eu/eli/reco/2003/361/oj?ref=sorena.io)

### NIS2 essential entities

**Term:** essential entities

Essential entities include Annex I entities that exceed the medium-sized-enterprise ceilings, qualified trust service providers, top-level-domain registries and DNS service providers regardless of size, medium-sized public electronic communications providers, specified central public administrations, critical entities, and other entities designated under Article 2. The exact national list and implementing law still matter.

**Why it matters here:** Essential status changes supervision and the Directive's required maximum-fine floor, but essential and important entities share the Article 20 management and Article 21 risk-management baseline.

Sources:

- [EU NIS2 Directive](https://eur-lex.europa.eu/eli/dir/2022/2555/oj?ref=sorena.io)

### NIS2 important entities

**Term:** important entities

Important entities are in-scope Annex I or II entities that do not qualify as essential under Article 3, including entities that a Member State identifies as important under the Directive's size-independent designation criteria.

**Why it matters here:** Important entities are generally subject to ex post supervision after evidence, indications, or information suggests noncompliance. They still owe the same core management, risk-management, and significant-incident duties described here.

Sources:

- [EU NIS2 Directive](https://eur-lex.europa.eu/eli/dir/2022/2555/oj?ref=sorena.io)

### NIS2 management bodies

**Term:** management bodies

Management bodies are the governing persons or body that national company and public-law rules make responsible for directing or supervising the covered entity. NIS2 requires them to approve the Article 21 cybersecurity measures, oversee implementation, and receive training; national law determines the exact office and liability rules.

**Why it matters here:** A central security team can prepare and operate controls, but it cannot replace the approval, oversight, and training evidence for the management body of each covered entity.

Sources:

- [EU NIS2 Directive](https://eur-lex.europa.eu/eli/dir/2022/2555/oj?ref=sorena.io)

### Significant incidents under NIS2

**Term:** significant incidents

An incident is significant under NIS2 when it has caused or can cause severe operational disruption or financial loss for the entity, or considerable material or non-material damage to other people or organizations. For the entities it covers, Implementing Regulation (EU) 2024/2690 adds more detailed thresholds.

**Why it matters here:** Only a significant incident starts the Directive's staged 24-hour, 72-hour, and one-month reporting sequence. Apply the relevant national procedure and any sector-specific EU threshold before starting or closing the clock.

Sources:

- [EU NIS2 Directive](https://eur-lex.europa.eu/eli/dir/2022/2555/oj?ref=sorena.io)
- [Commission Implementing Regulation (EU) 2024/2690](https://eur-lex.europa.eu/eli/reg_impl/2024/2690/oj?ref=sorena.io)

## China Cybersecurity Law vs EU NIS2 Directive

Compare a China network-operator regime with an EU entity-governance regime. Shared security controls can support both, but scope, management approval, incident reporting, and supervision require separate decisions.

- **China Cybersecurity Law**: Use for networks and network operators in China, with separate screening for graded protection, CII, cybersecurity review, app, personal-information, and data duties.
- **EU NIS2 Directive**: Use for covered entities under Member State NIS2 law, including management accountability, risk-management measures, supply-chain security, incident reporting, and supervision.

| Dimension | China Cybersecurity Law | EU NIS2 Directive | Operational implication | Sources |
| --- | --- | --- | --- | --- |
| Scope boundary | The Cybersecurity Law applies to the construction, operation, maintenance, and use of networks in China. Baseline network-operator duties and enhanced CII duties are separate layers. | NIS2 applies through Member State law to entities in the sectors and categories set by the Directive. The general size-cap rule captures medium-sized and larger Annex I or II entities, subject to size-independent inclusions, exclusions, and national additions. | Assess the China network and each EU legal entity separately. A corporate group, product, or system is not itself the complete unit of analysis for both regimes. | [PRC Cybersecurity Law](https://www.cac.gov.cn/2016-11/07/c_1119867116.htm?ref=sorena.io) - Use for network operator security duties, network product/service security, CII provisions, personal-information security articles, penalties, and 1 June 2017 effective date.<br>[EU NIS2 Directive](https://eur-lex.europa.eu/eli/dir/2022/2555/oj?ref=sorena.io) - Use for EU NIS2 entity scope, cybersecurity risk-management, incident reporting, governance, and enforcement comparison points.<br>[PRC Data Security Law](https://www.cac.gov.cn/2021-06/11/c_1624994566919140.htm?ref=sorena.io) - Use for data classification and graded protection, important-data risk assessment, security management, incident response, outbound important-data context, penalties, and 1 September 2021 effective date. |
| Covered actors | The network operator owns baseline duties. A CII operator has enhanced obligations only when the network and operator meet the applicable identification framework; CII status does not follow from company size alone. | The covered legal entity owns NIS2 compliance. Its management body must approve and oversee the Article 21 measures and receive training; operational security and supplier owners support that accountability. | Name the China network operator, the NIS2 legal entity, and the accountable management body. Do not assign the whole program only to a central security team. | [PRC Cybersecurity Law](https://www.cac.gov.cn/2016-11/07/c_1119867116.htm?ref=sorena.io) - Use for network operator security duties, network product/service security, CII provisions, personal-information security articles, penalties, and 1 June 2017 effective date.<br>[EU NIS2 Directive](https://eur-lex.europa.eu/eli/dir/2022/2555/oj?ref=sorena.io) - Use for EU NIS2 entity scope, cybersecurity risk-management, incident reporting, governance, and enforcement comparison points.<br>[PRC Data Security Law](https://www.cac.gov.cn/2021-06/11/c_1624994566919140.htm?ref=sorena.io) - Use for data classification and graded protection, important-data risk assessment, security management, incident response, outbound important-data context, penalties, and 1 September 2021 effective date. |
| Trigger event | Screen when an entity builds, operates, maintains, or uses a network in China, then identify the operator and any enhanced CII, review, app, personal-information, important-data, or export duty. | Screen each entity against its sector, services, size, establishment, jurisdiction, national registration rules, and Member State transposition. Certain public communications, trust, top-level-domain, DNS, and other listed entities can be covered regardless of size. | Repeat the scope review after acquisitions, legal-entity changes, new sectors or services, new Member State establishments, and material China network changes. | [PRC Cybersecurity Law](https://www.cac.gov.cn/2016-11/07/c_1119867116.htm?ref=sorena.io) - Use for network operator security duties, network product/service security, CII provisions, personal-information security articles, penalties, and 1 June 2017 effective date.<br>[EU NIS2 Directive](https://eur-lex.europa.eu/eli/dir/2022/2555/oj?ref=sorena.io) - Use for EU NIS2 entity scope, cybersecurity risk-management, incident reporting, governance, and enforcement comparison points.<br>[PRC Data Security Law](https://www.cac.gov.cn/2021-06/11/c_1624994566919140.htm?ref=sorena.io) - Use for data classification and graded protection, important-data risk assessment, security management, incident response, outbound important-data context, penalties, and 1 September 2021 effective date. |
| Core obligations | Network operators must follow the graded cybersecurity-protection framework and take technical and organizational measures for secure operation, incident response, and protection of network data. Further duties depend on CII and data status. | Article 21 requires proportionate technical, operational, and organizational measures covering risk analysis, incident handling, continuity and crisis management, supply-chain security, secure acquisition and development, vulnerability handling, effectiveness assessment, cyber hygiene and training, cryptography, access control, asset and HR security, and multi-factor or continuous authentication where appropriate. | A common control library can support both tracks, but each mapping must identify the regulated operator or entity, the system boundary, and the applicable legal text. | [PRC Cybersecurity Law](https://www.cac.gov.cn/2016-11/07/c_1119867116.htm?ref=sorena.io) - Use for network operator security duties, network product/service security, CII provisions, personal-information security articles, penalties, and 1 June 2017 effective date.<br>[EU NIS2 Directive](https://eur-lex.europa.eu/eli/dir/2022/2555/oj?ref=sorena.io) - Use for EU NIS2 entity scope, cybersecurity risk-management, incident reporting, governance, and enforcement comparison points.<br>[PRC Data Security Law](https://www.cac.gov.cn/2021-06/11/c_1624994566919140.htm?ref=sorena.io) - Use for data classification and graded protection, important-data risk assessment, security management, incident response, outbound important-data context, penalties, and 1 September 2021 effective date. |
| Evidence package | Retain the network boundary, operator and CII decisions, graded-protection classification and implementation, policies, supplier controls, monitoring, logs, incident plans, exercises, incidents, and remediation. | Retain the entity-scope rationale, essential or important classification, national registration, management approvals and training, Article 21 control mapping, supplier evidence, tests, incidents, staged reports, and authority correspondence. | Link shared technical evidence to separate legal records. A group policy without entity approval, system ownership, and implementation evidence is incomplete. | [PRC Cybersecurity Law](https://www.cac.gov.cn/2016-11/07/c_1119867116.htm?ref=sorena.io) - Use for network operator security duties, network product/service security, CII provisions, personal-information security articles, penalties, and 1 June 2017 effective date.<br>[EU NIS2 Directive](https://eur-lex.europa.eu/eli/dir/2022/2555/oj?ref=sorena.io) - Use for EU NIS2 entity scope, cybersecurity risk-management, incident reporting, governance, and enforcement comparison points.<br>[PRC Data Security Law](https://www.cac.gov.cn/2021-06/11/c_1624994566919140.htm?ref=sorena.io) - Use for data classification and graded protection, important-data risk assessment, security management, incident response, outbound important-data context, penalties, and 1 September 2021 effective date. |
| Timing and refresh points | The Cybersecurity Law first took effect on 1 June 2017, and the 2025 amendment took effect on 1 January 2026. Security duties continue during network operation; neither date is an annual filing deadline. | Member States were required to transpose NIS2 by 17 October 2024. For a significant incident, the Directive sets an early warning within 24 hours of awareness, an incident notification within 72 hours, and a final report no later than one month after the incident notification. An ongoing incident instead requires a progress report at that point and a final report within one month after the incident is handled. | Use the current national law and authority channel for the NIS2 clock. Maintain a separate China incident matrix because thresholds, recipients, and timing can differ. | [PRC Cybersecurity Law, consolidated after the 2025 amendment](https://www.cac.gov.cn/2025-12/29/c_1768735112911946.htm?ref=sorena.io) - Current official text for the original 1 June 2017 commencement and the amended provisions effective from 1 January 2026.<br>[EU NIS2 Directive](https://eur-lex.europa.eu/eli/dir/2022/2555/oj?ref=sorena.io) - Use for EU NIS2 entity scope, cybersecurity risk-management, incident reporting, governance, and enforcement comparison points.<br>[PRC Cybersecurity Law](https://www.cac.gov.cn/2016-11/07/c_1119867116.htm?ref=sorena.io) - Use for network operator security duties, network product/service security, CII provisions, personal-information security articles, penalties, and 1 June 2017 effective date.<br>[PRC Data Security Law](https://www.cac.gov.cn/2021-06/11/c_1624994566919140.htm?ref=sorena.io) - Use for data classification and graded protection, important-data risk assessment, security management, incident response, outbound important-data context, penalties, and 1 September 2021 effective date. |
| Enforcement exposure | China consequences depend on the current amended provision, actor, conduct, severity, and linked laws. The 2025 amendment revised several liability provisions, so the 2016 penalty numbering is no longer current. | Essential entities are generally subject to proactive supervision, while important entities are generally supervised after evidence of non-compliance. NIS2 requires national maximum fines of at least EUR 10 million or 2% of worldwide annual turnover for essential entities and EUR 7 million or 1.4% for important entities, whichever is higher. | Confirm the national enforcement text before stating exposure. Preserve management, scope, control, reporting, and remediation records for each entity. | [PRC Cybersecurity Law, consolidated after the 2025 amendment](https://www.cac.gov.cn/2025-12/29/c_1768735112911946.htm?ref=sorena.io) - Current official text for actor-specific duties, revised liability provisions, penalty tiers, and other enforcement consequences.<br>[EU NIS2 Directive](https://eur-lex.europa.eu/eli/dir/2022/2555/oj?ref=sorena.io) - Use for EU NIS2 entity scope, cybersecurity risk-management, incident reporting, governance, and enforcement comparison points.<br>[PRC Cybersecurity Law](https://www.cac.gov.cn/2016-11/07/c_1119867116.htm?ref=sorena.io) - Use for network operator security duties, network product/service security, CII provisions, personal-information security articles, penalties, and 1 June 2017 effective date.<br>[PRC Data Security Law](https://www.cac.gov.cn/2021-06/11/c_1624994566919140.htm?ref=sorena.io) - Use for data classification and graded protection, important-data risk assessment, security management, incident response, outbound important-data context, penalties, and 1 September 2021 effective date. |
| Overlap and routing | Both tracks can use the same asset inventory, risk register, supplier reviews, vulnerability records, continuity plans, logs, and incident chronology. | The NIS2 file must still show entity scope, management approval, Article 21 mapping, significant-incident analysis, national reporting, and supervision status. | Link the evidence but write two conclusions. A China network classification does not establish NIS2 scope, and NIS2 registration does not establish China compliance. | [PRC Cybersecurity Law](https://www.cac.gov.cn/2016-11/07/c_1119867116.htm?ref=sorena.io) - Use for network operator security duties, network product/service security, CII provisions, personal-information security articles, penalties, and 1 June 2017 effective date.<br>[EU NIS2 Directive](https://eur-lex.europa.eu/eli/dir/2022/2555/oj?ref=sorena.io) - Use for EU NIS2 entity scope, cybersecurity risk-management, incident reporting, governance, and enforcement comparison points.<br>[PRC Data Security Law](https://www.cac.gov.cn/2021-06/11/c_1624994566919140.htm?ref=sorena.io) - Use for data classification and graded protection, important-data risk assessment, security management, incident response, outbound important-data context, penalties, and 1 September 2021 effective date. |
| Practical decision rule | Run the China track when the organization operates or uses a network in China, then determine baseline, graded-protection, CII, review, and data obligations. | Run the NIS2 track for each entity that provides a listed service or activity in the EU and meets a Directive or national scope rule. | Run both when an EU covered entity depends on systems or operations in China. Keep entity scope, network scope, approvals, and incident reporting separate. | [PRC Cybersecurity Law](https://www.cac.gov.cn/2016-11/07/c_1119867116.htm?ref=sorena.io) - Use for network operator security duties, network product/service security, CII provisions, personal-information security articles, penalties, and 1 June 2017 effective date.<br>[EU NIS2 Directive](https://eur-lex.europa.eu/eli/dir/2022/2555/oj?ref=sorena.io) - Use for EU NIS2 entity scope, cybersecurity risk-management, incident reporting, governance, and enforcement comparison points.<br>[PRC Data Security Law](https://www.cac.gov.cn/2021-06/11/c_1624994566919140.htm?ref=sorena.io) - Use for data classification and graded protection, important-data risk assessment, security management, incident response, outbound important-data context, penalties, and 1 September 2021 effective date. |

Sources for Scope boundary - China Cybersecurity Law:

- [PRC Cybersecurity Law](https://www.cac.gov.cn/2016-11/07/c_1119867116.htm?ref=sorena.io) - Use for network operator security duties, network product/service security, CII provisions, personal-information security articles, penalties, and 1 June 2017 effective date.

Sources for Scope boundary - EU NIS2 Directive:

- [EU NIS2 Directive](https://eur-lex.europa.eu/eli/dir/2022/2555/oj?ref=sorena.io) - Use for EU NIS2 entity scope, cybersecurity risk-management, incident reporting, governance, and enforcement comparison points.

Sources for Scope boundary - operational implication:

- [PRC Cybersecurity Law](https://www.cac.gov.cn/2016-11/07/c_1119867116.htm?ref=sorena.io) - Use for network operator security duties, network product/service security, CII provisions, personal-information security articles, penalties, and 1 June 2017 effective date.
- [PRC Data Security Law](https://www.cac.gov.cn/2021-06/11/c_1624994566919140.htm?ref=sorena.io) - Use for data classification and graded protection, important-data risk assessment, security management, incident response, outbound important-data context, penalties, and 1 September 2021 effective date.

Sources for Covered actors - China Cybersecurity Law:

- [PRC Cybersecurity Law](https://www.cac.gov.cn/2016-11/07/c_1119867116.htm?ref=sorena.io) - Use for network operator security duties, network product/service security, CII provisions, personal-information security articles, penalties, and 1 June 2017 effective date.

Sources for Covered actors - EU NIS2 Directive:

- [EU NIS2 Directive](https://eur-lex.europa.eu/eli/dir/2022/2555/oj?ref=sorena.io) - Use for EU NIS2 entity scope, cybersecurity risk-management, incident reporting, governance, and enforcement comparison points.

Sources for Covered actors - operational implication:

- [PRC Cybersecurity Law](https://www.cac.gov.cn/2016-11/07/c_1119867116.htm?ref=sorena.io) - Use for network operator security duties, network product/service security, CII provisions, personal-information security articles, penalties, and 1 June 2017 effective date.
- [PRC Data Security Law](https://www.cac.gov.cn/2021-06/11/c_1624994566919140.htm?ref=sorena.io) - Use for data classification and graded protection, important-data risk assessment, security management, incident response, outbound important-data context, penalties, and 1 September 2021 effective date.

Sources for Trigger event - China Cybersecurity Law:

- [PRC Cybersecurity Law](https://www.cac.gov.cn/2016-11/07/c_1119867116.htm?ref=sorena.io) - Use for network operator security duties, network product/service security, CII provisions, personal-information security articles, penalties, and 1 June 2017 effective date.

Sources for Trigger event - EU NIS2 Directive:

- [EU NIS2 Directive](https://eur-lex.europa.eu/eli/dir/2022/2555/oj?ref=sorena.io) - Use for EU NIS2 entity scope, cybersecurity risk-management, incident reporting, governance, and enforcement comparison points.

Sources for Trigger event - operational implication:

- [PRC Cybersecurity Law](https://www.cac.gov.cn/2016-11/07/c_1119867116.htm?ref=sorena.io) - Use for network operator security duties, network product/service security, CII provisions, personal-information security articles, penalties, and 1 June 2017 effective date.
- [PRC Data Security Law](https://www.cac.gov.cn/2021-06/11/c_1624994566919140.htm?ref=sorena.io) - Use for data classification and graded protection, important-data risk assessment, security management, incident response, outbound important-data context, penalties, and 1 September 2021 effective date.

Sources for Core obligations - China Cybersecurity Law:

- [PRC Cybersecurity Law](https://www.cac.gov.cn/2016-11/07/c_1119867116.htm?ref=sorena.io) - Use for network operator security duties, network product/service security, CII provisions, personal-information security articles, penalties, and 1 June 2017 effective date.

Sources for Core obligations - EU NIS2 Directive:

- [EU NIS2 Directive](https://eur-lex.europa.eu/eli/dir/2022/2555/oj?ref=sorena.io) - Use for EU NIS2 entity scope, cybersecurity risk-management, incident reporting, governance, and enforcement comparison points.

Sources for Core obligations - operational implication:

- [PRC Cybersecurity Law](https://www.cac.gov.cn/2016-11/07/c_1119867116.htm?ref=sorena.io) - Use for network operator security duties, network product/service security, CII provisions, personal-information security articles, penalties, and 1 June 2017 effective date.
- [PRC Data Security Law](https://www.cac.gov.cn/2021-06/11/c_1624994566919140.htm?ref=sorena.io) - Use for data classification and graded protection, important-data risk assessment, security management, incident response, outbound important-data context, penalties, and 1 September 2021 effective date.

Sources for Evidence package - China Cybersecurity Law:

- [PRC Cybersecurity Law](https://www.cac.gov.cn/2016-11/07/c_1119867116.htm?ref=sorena.io) - Use for network operator security duties, network product/service security, CII provisions, personal-information security articles, penalties, and 1 June 2017 effective date.

Sources for Evidence package - EU NIS2 Directive:

- [EU NIS2 Directive](https://eur-lex.europa.eu/eli/dir/2022/2555/oj?ref=sorena.io) - Use for EU NIS2 entity scope, cybersecurity risk-management, incident reporting, governance, and enforcement comparison points.

Sources for Evidence package - operational implication:

- [PRC Cybersecurity Law](https://www.cac.gov.cn/2016-11/07/c_1119867116.htm?ref=sorena.io) - Use for network operator security duties, network product/service security, CII provisions, personal-information security articles, penalties, and 1 June 2017 effective date.
- [PRC Data Security Law](https://www.cac.gov.cn/2021-06/11/c_1624994566919140.htm?ref=sorena.io) - Use for data classification and graded protection, important-data risk assessment, security management, incident response, outbound important-data context, penalties, and 1 September 2021 effective date.

Sources for Timing and refresh points - China Cybersecurity Law:

- [PRC Cybersecurity Law, consolidated after the 2025 amendment](https://www.cac.gov.cn/2025-12/29/c_1768735112911946.htm?ref=sorena.io) - Current official text for the original 1 June 2017 commencement and the amended provisions effective from 1 January 2026.

Sources for Timing and refresh points - EU NIS2 Directive:

- [EU NIS2 Directive](https://eur-lex.europa.eu/eli/dir/2022/2555/oj?ref=sorena.io) - Use for EU NIS2 entity scope, cybersecurity risk-management, incident reporting, governance, and enforcement comparison points.

Sources for Timing and refresh points - operational implication:

- [PRC Cybersecurity Law](https://www.cac.gov.cn/2016-11/07/c_1119867116.htm?ref=sorena.io) - Use for network operator security duties, network product/service security, CII provisions, personal-information security articles, penalties, and 1 June 2017 effective date.
- [PRC Data Security Law](https://www.cac.gov.cn/2021-06/11/c_1624994566919140.htm?ref=sorena.io) - Use for data classification and graded protection, important-data risk assessment, security management, incident response, outbound important-data context, penalties, and 1 September 2021 effective date.

Sources for Enforcement exposure - China Cybersecurity Law:

- [PRC Cybersecurity Law, consolidated after the 2025 amendment](https://www.cac.gov.cn/2025-12/29/c_1768735112911946.htm?ref=sorena.io) - Current official text for actor-specific duties, revised liability provisions, penalty tiers, and other enforcement consequences.

Sources for Enforcement exposure - EU NIS2 Directive:

- [EU NIS2 Directive](https://eur-lex.europa.eu/eli/dir/2022/2555/oj?ref=sorena.io) - Use for EU NIS2 entity scope, cybersecurity risk-management, incident reporting, governance, and enforcement comparison points.

Sources for Enforcement exposure - operational implication:

- [PRC Cybersecurity Law](https://www.cac.gov.cn/2016-11/07/c_1119867116.htm?ref=sorena.io) - Use for network operator security duties, network product/service security, CII provisions, personal-information security articles, penalties, and 1 June 2017 effective date.
- [PRC Data Security Law](https://www.cac.gov.cn/2021-06/11/c_1624994566919140.htm?ref=sorena.io) - Use for data classification and graded protection, important-data risk assessment, security management, incident response, outbound important-data context, penalties, and 1 September 2021 effective date.

Sources for Overlap and routing - China Cybersecurity Law:

- [PRC Cybersecurity Law](https://www.cac.gov.cn/2016-11/07/c_1119867116.htm?ref=sorena.io) - Use for network operator security duties, network product/service security, CII provisions, personal-information security articles, penalties, and 1 June 2017 effective date.

Sources for Overlap and routing - EU NIS2 Directive:

- [EU NIS2 Directive](https://eur-lex.europa.eu/eli/dir/2022/2555/oj?ref=sorena.io) - Use for EU NIS2 entity scope, cybersecurity risk-management, incident reporting, governance, and enforcement comparison points.

Sources for Overlap and routing - operational implication:

- [PRC Cybersecurity Law](https://www.cac.gov.cn/2016-11/07/c_1119867116.htm?ref=sorena.io) - Use for network operator security duties, network product/service security, CII provisions, personal-information security articles, penalties, and 1 June 2017 effective date.
- [PRC Data Security Law](https://www.cac.gov.cn/2021-06/11/c_1624994566919140.htm?ref=sorena.io) - Use for data classification and graded protection, important-data risk assessment, security management, incident response, outbound important-data context, penalties, and 1 September 2021 effective date.

Sources for Practical decision rule - China Cybersecurity Law:

- [PRC Cybersecurity Law](https://www.cac.gov.cn/2016-11/07/c_1119867116.htm?ref=sorena.io) - Use for network operator security duties, network product/service security, CII provisions, personal-information security articles, penalties, and 1 June 2017 effective date.

Sources for Practical decision rule - EU NIS2 Directive:

- [EU NIS2 Directive](https://eur-lex.europa.eu/eli/dir/2022/2555/oj?ref=sorena.io) - Use for EU NIS2 entity scope, cybersecurity risk-management, incident reporting, governance, and enforcement comparison points.

Sources for Practical decision rule - operational implication:

- [PRC Cybersecurity Law](https://www.cac.gov.cn/2016-11/07/c_1119867116.htm?ref=sorena.io) - Use for network operator security duties, network product/service security, CII provisions, personal-information security articles, penalties, and 1 June 2017 effective date.
- [PRC Data Security Law](https://www.cac.gov.cn/2021-06/11/c_1624994566919140.htm?ref=sorena.io) - Use for data classification and graded protection, important-data risk assessment, security management, incident response, outbound important-data context, penalties, and 1 September 2021 effective date.

### When to run one track or both

- Use the China track for the China network and operator; separately screen graded protection, CII, cybersecurity review, app, personal-information, important-data, and export rules.
- Use the NIS2 track entity by entity, applying the relevant Member State law, sector, size, jurisdiction, essential or important classification, management, risk-management, and reporting requirements.
- Run both when the same systems support both operations, but retain separate scope rationales, authority routes, management approvals, and incident clocks.

Sources for the practical decision rule:

- [PRC Cybersecurity Law](https://www.cac.gov.cn/2016-11/07/c_1119867116.htm?ref=sorena.io) - Use for network operator security duties, network product/service security, CII provisions, personal-information security articles, penalties, and 1 June 2017 effective date.
- [PRC Data Security Law](https://www.cac.gov.cn/2021-06/11/c_1624994566919140.htm?ref=sorena.io) - Use for data classification and graded protection, important-data risk assessment, security management, incident response, outbound important-data context, penalties, and 1 September 2021 effective date.
- [2025 Decision amending the PRC Cybersecurity Law](https://www.npc.gov.cn/npc/c1773/c1848/c21114/wlaqfxz/wlaqfxz002/202511/t20251103_449242.html?ref=sorena.io) - Binding amendment effective on 1 January 2026; use for current article numbering and revised liability provisions.
- [EU NIS2 Directive](https://eur-lex.europa.eu/eli/dir/2022/2555/oj?ref=sorena.io) - Binding source for entity scope, management accountability, Article 21 measures, incident reporting, supervision, enforcement, and transposition.

## How to use this comparison

For China, identify the network, its operator, the applicable graded-protection duties, and any separate CII, cybersecurity-review, app, personal-information, important-data, or data-export trigger. The 2025 amendment to the Cybersecurity Law took effect on 1 January 2026 and revised liability provisions and article numbering.

For NIS2, assess each legal entity against Annex I and Annex II sectors, the EU size rules, size-independent categories, Member State additions, establishment and jurisdiction rules, and the relevant national transposition law. Under the general size test, an SME has fewer than 250 employees and no more than EUR 50 million in annual turnover or EUR 43 million on its annual balance sheet; a small enterprise has fewer than 50 employees and no more than EUR 10 million in turnover or on its balance sheet. NIS2 generally captures medium-sized enterprises and entities above the SME ceilings, but partner and linked enterprises can change the staff and financial totals, and specified categories apply regardless of size. Essential entities and important entities have different supervision and maximum-fine requirements, but both follow the Article 21 risk-management baseline.

If NIS2 applies, management bodies must approve and oversee the cybersecurity measures and receive training. Significant incidents follow a staged process: early warning within 24 hours of awareness, incident notification within 72 hours, and a final report no later than one month after that notification. If the incident is still ongoing when the final report is due, the entity submits a progress report and then a final report within one month after handling the incident. The relevant national procedure controls the filing channel.

- Keep one system and supplier inventory, but identify the China network operator and the NIS2 entity separately.
- Map shared risk, incident, continuity, vulnerability, cryptography, access-control, and supply-chain evidence to each regime's legal requirement.
- Maintain separate authority contacts, incident thresholds, clocks, reporting forms, management approvals, and enforcement records.

Sources for this answer:

- [PRC Cybersecurity Law, consolidated after the 2025 amendment](https://www.cac.gov.cn/2025-12/29/c_1768735112911946.htm?ref=sorena.io) - Current official text for network scope, operator duties, CII provisions, product and service security, and liability after 1 January 2026.
- [PRC Data Security Law](https://www.cac.gov.cn/2021-06/11/c_1624994566919140.htm?ref=sorena.io) - Use for data classification and graded protection, important-data risk assessment, security management, incident response, outbound important-data context, penalties, and 1 September 2021 effective date.
- [2025 Decision amending the PRC Cybersecurity Law](https://www.npc.gov.cn/npc/c1773/c1848/c21114/wlaqfxz/wlaqfxz002/202511/t20251103_449242.html?ref=sorena.io) - Binding amendment adopted on 28 October 2025 and effective on 1 January 2026; use for current article renumbering and revised liability provisions.
- [EU NIS2 Directive](https://eur-lex.europa.eu/eli/dir/2022/2555/oj?ref=sorena.io) - Binding Directive (EU) 2022/2555; use for entity scope, management duties, Article 21 measures, incident reporting, jurisdiction, supervision, and national transposition.
- [Commission Recommendation 2003/361/EC](https://eur-lex.europa.eu/eli/reco/2003/361/oj?ref=sorena.io) - Official source for the employee, turnover, balance-sheet, partner-enterprise, linked-enterprise, and accounting-period rules used in the general NIS2 size test.

*Next step*

*Placement: Before primary sources*

## Map the network and entity obligations

Connect shared controls to the China network operator and each NIS2 entity, with separate approvals and reporting routes.

- [Map official sources to evidence](/solutions/research-copilot.md): Link each China and NIS2 decision to its official source, owner, evidence, and change history.
- [Review the China route](/contact.md): Review unresolved China network and NIS2 entity-scope questions.

## Primary sources

- [PRC Cybersecurity Law, consolidated after the 2025 amendment](https://www.cac.gov.cn/2025-12/29/c_1768735112911946.htm?ref=sorena.io) - Current official text for actor-specific duties, revised liability provisions, penalty tiers, and other enforcement consequences.
- [PRC Data Security Law](https://www.cac.gov.cn/2021-06/11/c_1624994566919140.htm?ref=sorena.io) - Use for data classification and graded protection, important-data risk assessment, security management, incident response, outbound important-data context, penalties, and 1 September 2021 effective date.
- [Cybersecurity Review Measures](https://www.cac.gov.cn/2022-01/04/c_1642894602182845.htm?ref=sorena.io) - Use for cybersecurity review scope, CII procurement filing, platform operator review triggers, review materials, special review, and 15 February 2022 effective date.
- [EU NIS2 Directive](https://eur-lex.europa.eu/eli/dir/2022/2555/oj?ref=sorena.io) - Binding source for entity scope, management accountability, Article 21 measures, incident reporting, supervision, enforcement, and transposition.
- [Commission Recommendation 2003/361/EC](https://eur-lex.europa.eu/eli/reco/2003/361/oj?ref=sorena.io) - Official source for the SME employee and financial ceilings and the affiliation rules used in the general NIS2 scope test.
- [2025 Decision amending the PRC Cybersecurity Law](https://www.npc.gov.cn/npc/c1773/c1848/c21114/wlaqfxz/wlaqfxz002/202511/t20251103_449242.html?ref=sorena.io) - Binding amendment effective on 1 January 2026; use for current article numbering and revised liability provisions.
- [PRC Cybersecurity Law](https://www.cac.gov.cn/2016-11/07/c_1119867116.htm?ref=sorena.io) - Use for network operator security duties, network product/service security, CII provisions, personal-information security articles, penalties, and 1 June 2017 effective date.

## Related Topic Guides

- [China App Filing vs Personal Information Rules](/artifacts/apac/china-cybersecurity-law/mobile-app-filing-vs-app-personal-information-rules.md): Decide whether a China mobile app needs MIIT filing, personal-information controls, or both, with current triggers, duties, dates, and evidence.
- [China cybersecurity and data security requirements](/artifacts/apac/china-cybersecurity-law/requirements.md): China cybersecurity requirements by actor: network operators, data processors, CII operators, platforms, app providers, and distribution platforms.
- [China cybersecurity compliance checklist](/artifacts/apac/china-cybersecurity-law/checklist.md): A China cybersecurity checklist for scoping network duties, data security, CII procurement review, app rules, MIIT filing, and supporting standards.
- [China cybersecurity deadlines and compliance calendar](/artifacts/apac/china-cybersecurity-law/deadlines-and-compliance-calendar.md): Separate China cybersecurity commencement dates from recurring duties, filing lead times, review periods, and event-driven response deadlines.
- [China Cybersecurity Law FAQ](/artifacts/apac/china-cybersecurity-law/faq.md): Practical answers on China network-operator scope, MLPS evidence, important data, cybersecurity review, app filing and governance, and smart-home standards under the law in force from 1 January 2026.
- [China Cybersecurity Law vs EU Cyber Resilience Act](/artifacts/apac/china-cybersecurity-law/china-cybersecurity-law-vs-eu-cyber-resilience-act.md): Compare China's network-operator rules with the EU CRA's product duties, including scope, actors, evidence, reporting dates, and launch decisions.
- [China cybersecurity penalties and fines](/artifacts/apac/china-cybersecurity-law/penalties-and-fines.md): Compare current China Cybersecurity Law and Data Security Law fines by actor, breach, severity, and enforcement consequence.
- [China Cybersecurity Review vs Data Export Assessment](/artifacts/apac/china-cybersecurity-law/cybersecurity-review-vs-data-export-security-assessment.md): Separate China's cybersecurity-review triggers from CAC data-export assessment triggers, thresholds, filings, evidence, timing, and reapplication rules.
- [China cybersecurity review workflow](/artifacts/apac/china-cybersecurity-law/cybersecurity-review-workflow.md): Determine whether CII procurement, platform data processing, or a qualifying foreign listing triggers China's Cybersecurity Review Measures.
- [China mobile app filing and app governance](/artifacts/apac/china-cybersecurity-law/mobile-app-filing-and-app-governance.md): Identify the China app sponsor, complete MIIT filing before service, and separate provider, platform, privacy, content, and security duties.
- [China Smart-Home Security vs Telecom and Radio Approval](/artifacts/apac/china-cybersecurity-law/smart-home-security-vs-telecom-wireless-launch.md): Separate GB/T 41387-2022 smart-home security evidence from China telecom network-access and radio approval decisions for connected products.
- [CII and network operator role triage](/artifacts/apac/china-cybersecurity-law/critical-information-infrastructure-and-network-operators.md): How to separate ordinary network operator duties from CII, procurement, and review-risk questions under China cybersecurity sources.
- [Does an app need MIIT filing and CAC app governance review?](/artifacts/apac/china-cybersecurity-law/faq/does-an-app-need-miit-filing-and-cac-app-governance-review.md): An app sponsor providing internet information services through an app in China must complete MIIT filing. CAC rules separately govern app providers and distribution platforms without creating one routine CAC approval for every app.
- [GB/T 22239-2019 classified protection baseline](/artifacts/apac/china-cybersecurity-law/classified-protection-baseline.md): How to scope and document a GB/T 22239-2019 classified protection baseline without treating the recommended standard as a standalone law.
- [GB/T 41387-2022 smart home security standard](/artifacts/apac/china-cybersecurity-law/smart-home-security-standard.md): How connected-device teams can scope and document GB/T 41387-2022 without treating it as an automatic certification or product-approval duty.
- [How do smart home security standards fit with China cybersecurity law?](/artifacts/apac/china-cybersecurity-law/faq/how-do-smart-home-security-standards-fit-with-china-cybersecurity-law.md): GB/T 41387-2022 can organize smart-home security evidence, but it is a recommended standard, not a product approval. Check app, data, MLPS, telecom access, and radio requirements separately.
- [How does important data change China cybersecurity obligations?](/artifacts/apac/china-cybersecurity-law/faq/how-does-important-data-change-cybersecurity-obligations.md): Once data is officially identified as important data, the processor needs named governance, periodic risk assessments and reports, incident controls, and a separate export decision. An internal sensitivity label alone does not establish the legal category.
- [Is every company a network operator under China Cybersecurity Law?](/artifacts/apac/china-cybersecurity-law/faq/is-every-company-a-network-operator-under-china-cybersecurity-law.md): No. Under China's Cybersecurity Law, a network operator is an owner or administrator of a network or a network service provider. Apply that definition to each China network or service, then test CII and other roles separately.
- [MLPS classified protection evidence map](/artifacts/apac/china-cybersecurity-law/mlps-classified-protection-evidence-map.md): Classify a China network under MLPS, complete level 2 or above filing, map controls, and retain assessment, remediation, and change evidence.
- [What is MLPS classified protection evidence?](/artifacts/apac/china-cybersecurity-law/faq/what-is-mlps-classified-protection-evidence.md): MLPS evidence shows how a defined China network or system was graded and protected. Keep the scope, grading rationale, filing or assessment records where applicable, control mapping, test results, remediation, and reassessment history.
- [When does China cybersecurity review apply?](/artifacts/apac/china-cybersecurity-law/faq/when-does-china-cybersecurity-review-apply.md): China cybersecurity review applies to CII procurement or network-platform data processing that affects or may affect national security, plus a mandatory pre-filing trigger for certain foreign listings involving more than one million users' personal information.


---

[Privacy Policy](https://www.sorena.io/privacy.md) | [Terms of Use](https://www.sorena.io/terms-of-use.md) | [DMCA](https://www.sorena.io/dmca.md) | [About Us](https://www.sorena.io/about-us.md)

(c) 2026 Sorena AB (559573-7338). All rights reserved.

Source: https://www.sorena.io/artifacts/apac/china-cybersecurity-law/china-cybersecurity-law-vs-nis2.md
