CybersecurityChina

China Cybersecurity Law MLPS classified protection baseline evidence

How to scope a system and document a GB/T 22239-2019 classified protection baseline.

GB/T 22239-2019 is a current recommended national standard, implemented on 1 December 2019. The official standards record confirms its identity and status, but the captured source does not provide the full control text. Obtain the complete current standard and apply the governing classification rules before claiming control-level conformity.

Author
Sorena AI
Published
Jul 5, 2026
Updated
Jul 24, 2026
Sections
4

Structured answer sets in this page tree.

Primary sources
2

Cited legal and guidance references.

Publication metadata
Sorena AI
Published Jul 5, 2026
Updated Jul 24, 2026
Overview

is the current recommended national standard titled Baseline for of cybersecurity. It supports China's Multi-Level Protection Scheme (). Use it after defining the and classification basis.

Section 1

Define the system before mapping controls

Define the information system or network boundary first. Cybersecurity Law Article 23 creates the binding network security duty and lists baseline obligations for network operators. The Data Security Law creates a separate data classification and graded-protection system for data-processing activities conducted through information networks. supports the network control mapping. The governing classification rules determine the system's level and applicable control set; the recommended standard is not a standalone statute.

The official standards record identifies as a current recommended national standard, published on 10 May 2019 and implemented on 1 December 2019. That record does not provide the complete requirement text, so obtain the applicable standard text and the governing classification and implementation rules before citing clauses, assigning a level, describing an authority-facing procedure, or asserting conformity.

  • Scope owner: record the , business purpose, network operator, users, data types, applications, infrastructure, hosting, interfaces, dependencies, external connections, and exclusions.
  • Classification owner: record the governing classification method, system facts, proposed or confirmed level, decision status, approver, date, and any authority-facing step required by the applicable rules; do not infer a level from a company name, sector, data category, or critical-information-infrastructure status alone.
  • Control owner: obtain the applicable standard text before mapping level-specific controls or asserting an assessment result.
  • Evidence owner: keep the legal duties, classification decision, standard mapping, implementation evidence, testing, findings, exceptions, remediation, retesting, and any authority-facing process as linked but distinct records.
Section 2

Map and test the classified-protection controls

Translate the applicable baseline into technical and management controls only after the system scope and level are resolved. For each clause, record applicability, the control owner, implementation evidence, test method and result, open finding, exception approval, remediation date, and retest. Keep Article 23's express duties visible even when a broader standard mapping is used: internal responsibility, malware and intrusion protection, monitoring, at least six months of network logs, and data classification, important-data backup, and encryption.

Reassess the classification and control mapping when system boundaries, hosting, business functions, users, data sensitivity, interconnections, suppliers, or threat exposure materially change. A change may affect the level, the applicable controls, or both; the standards record does not establish a universal renewal date.

  • Approve the asset inventory, interfaces, dependencies, exclusions, and before classification.
  • Record the classification method, facts, result, approver, date, and any required authority-facing step or specialist input.
  • Map only the clauses and controls applicable to that system, classification level, and technical environment.
  • Test implementation and preserve the method, sample, result, finding, accepted exception, remediation owner, due date, and retest result.
  • Set review ownership and triggers for changes to function, boundary, hosting, data, interconnection, supplier, users, or threat exposure without inventing a universal renewal date.
Section 3

Evidence to keep before launch or change approval

Keep the classification and control file tied to the defined system, its approved level, and the edition of every standard used.

A reviewer should be able to trace each applicable requirement from the classification decision to implementation, test results, gaps, remediation, and retesting.

  • System inventory, boundary diagram, business purpose, owners, users, hosting, dependencies, and data types.
  • Classification rationale, decision, approver, date, and any authority or specialist input.
  • Clause-level applicability and control mapping for the complete current standard text.
  • Policies, configurations, architecture records, test results, findings, exceptions, remediation, and retest evidence.
  • Material-change triggers, periodic review owner, and links to separate incident, important-data, critical-information-infrastructure, or cybersecurity-review records where relevant.
Section 4

Boundary with nearby China regimes

does not answer every China cybersecurity question. Assess important-data duties, critical-information-infrastructure status, cybersecurity review, personal-information processing and export, and app or product rules under their own instruments.

Shared technical evidence may support several records, but keep the system classification, data classification, filing, review, and product-approval conclusions separate.

  • Treating the standard's 1 December 2019 implementation date as an annual deadline.
  • Assigning a level before documenting the and classification rationale.
  • Claiming conformance from a policy list without clause mapping, implementation evidence, testing, and remediation.
  • Using a result as a substitute for separate important-data, critical-information-infrastructure, review, privacy, app, telecom, or radio decisions.
Primary sources

References and citations

cac.gov.cn
Referenced sections
  • Use Articles 23 and 33-40 to distinguish baseline classified protection from additional critical-information-infrastructure duties.
Related guides

Explore more topics

China App Filing vs Personal Information Rules
Decide whether a China mobile app needs MIIT filing, personal-information controls, or both, with current triggers, duties, dates, and evidence.
China cybersecurity and data security requirements
China cybersecurity requirements by actor: network operators, data processors, CII operators, platforms, app providers, and distribution platforms.
China cybersecurity compliance checklist
A China cybersecurity checklist for scoping network duties, data security, CII procurement review, app rules, MIIT filing, and supporting standards.
China cybersecurity deadlines and compliance calendar
Separate China cybersecurity commencement dates from recurring duties, filing lead times, review periods, and event-driven response deadlines.
China Cybersecurity Law FAQ
Practical answers on China network-operator scope, MLPS evidence, important data, cybersecurity review, app filing and governance, and smart-home standards under the law in force from 1 January 2026.
China Cybersecurity Law vs EU Cyber Resilience Act
Compare China's network-operator rules with the EU CRA's product duties, including scope, actors, evidence, reporting dates, and launch decisions.
China Cybersecurity Law vs EU NIS2 Directive
Compare China's network-operator duties with NIS2 entity duties, including scope, management accountability, incident reporting, evidence, and enforcement.
China cybersecurity penalties and fines
Compare current China Cybersecurity Law and Data Security Law fines by actor, breach, severity, and enforcement consequence.
China Cybersecurity Review vs Data Export Assessment
Separate China's cybersecurity-review triggers from CAC data-export assessment triggers, thresholds, filings, evidence, timing, and reapplication rules.
China cybersecurity review workflow
Determine whether CII procurement, platform data processing, or a qualifying foreign listing triggers China's Cybersecurity Review Measures.
China mobile app filing and app governance
Identify the China app sponsor, complete MIIT filing before service, and separate provider, platform, privacy, content, and security duties.
China Smart-Home Security vs Telecom and Radio Approval
Separate GB/T 41387-2022 smart-home security evidence from China telecom network-access and radio approval decisions for connected products.
CII and network operator role triage
How to separate ordinary network operator duties from CII, procurement, and review-risk questions under China cybersecurity sources.
Does an app need MIIT filing and CAC app governance review?
An app sponsor providing internet information services through an app in China must complete MIIT filing. CAC rules separately govern app providers and distribution platforms without creating one routine CAC approval for every app.
GB/T 41387-2022 smart home security standard
How connected-device teams can scope and document GB/T 41387-2022 without treating it as an automatic certification or product-approval duty.
How do smart home security standards fit with China cybersecurity law?
GB/T 41387-2022 can organize smart-home security evidence, but it is a recommended standard, not a product approval. Check app, data, MLPS, telecom access, and radio requirements separately.
How does important data change China cybersecurity obligations?
Once data is officially identified as important data, the processor needs named governance, periodic risk assessments and reports, incident controls, and a separate export decision. An internal sensitivity label alone does not establish the legal category.
Is every company a network operator under China Cybersecurity Law?
No. Under China's Cybersecurity Law, a network operator is an owner or administrator of a network or a network service provider. Apply that definition to each China network or service, then test CII and other roles separately.
MLPS classified protection evidence map
Classify a China network under MLPS, complete level 2 or above filing, map controls, and retain assessment, remediation, and change evidence.
What is MLPS classified protection evidence?
MLPS evidence shows how a defined China network or system was graded and protected. Keep the scope, grading rationale, filing or assessment records where applicable, control mapping, test results, remediation, and reassessment history.
When does China cybersecurity review apply?
China cybersecurity review applies to CII procurement or network-platform data processing that affects or may affect national security, plus a mandatory pre-filing trigger for certain foreign listings involving more than one million users' personal information.