---
title: "GB/T 22239-2019 classified protection baseline"
canonical_url: "https://www.sorena.io/artifacts/apac/china-cybersecurity-law/classified-protection-baseline"
source_url: "https://www.sorena.io/artifacts/apac/china-cybersecurity-law/classified-protection-baseline"
author: "Sorena AI"
description: "How to scope and document a GB/T 22239-2019 classified protection baseline without treating the recommended standard as a standalone law."
published_at: "2026-07-05"
updated_at: "2026-07-24"
keywords:
  - "China Cybersecurity Law"
  - "Data Security Law"
  - "Cybersecurity Review Measures"
  - "Mobile app filing"
  - "MLPS"
---
**[SORENA](https://www.sorena.io/)** - AI-Powered GRC Platform

[Home](https://www.sorena.io/) | [Solutions](https://www.sorena.io/solutions) | [Artifacts](https://www.sorena.io/artifacts) | [About Us](https://www.sorena.io/about-us) | [Contact](https://www.sorena.io/contact) | [Portal](https://app.sorena.io)

---

# GB/T 22239-2019 classified protection baseline

How to scope and document a GB/T 22239-2019 classified protection baseline without treating the recommended standard as a standalone law.

*Cybersecurity* *China*

## China Cybersecurity Law MLPS classified protection baseline evidence

How to scope a system and document a GB/T 22239-2019 classified protection baseline.

GB/T 22239-2019 is a current recommended national standard, implemented on 1 December 2019. The official standards record confirms its identity and status, but the captured source does not provide the full control text. Obtain the complete current standard and apply the governing classification rules before claiming control-level conformity.

GB/T 22239-2019 is the current recommended national standard titled Baseline for classified protection of cybersecurity. It supports China's Multi-Level Protection Scheme (MLPS). Use it after defining the system boundary and classification basis.

## Definitions

### Network security classified protection

**Term:** classified protection

Classified protection is China's graded system for protecting networks according to their security significance and the harm that compromise could cause. Article 23 of the current Cybersecurity Law requires every network operator to establish internal responsibility, protect against malware and intrusion, monitor network operation and security events, retain network logs for at least six months, and apply data classification, important-data backup, encryption, and other required measures under this system. The applicable level and detailed controls depend on the defined system and the governing classification and implementation rules.

**Why it matters here:** Define the network or information-system boundary and document the classification basis before selecting a GB/T 22239-2019 control set. Data classification under the Data Security Law, critical-information-infrastructure status, and cybersecurity review are related but separate decisions.

Sources:

- [PRC Cybersecurity Law, Articles 23, 33, and 78](https://www.cac.gov.cn/2025-12/29/c_1768735112911946.htm?ref=sorena.io)
- [PRC Data Security Law, Articles 21 and 27](https://www.cac.gov.cn/2021-06/11/c_1624994566919140.htm?ref=sorena.io)

### GB/T 22239-2019 - Baseline for classified protection of cybersecurity

**Term:** GB/T 22239-2019

GB/T 22239-2019 is a current recommended Chinese national standard for baseline classified-protection requirements. The official standards record gives the Chinese and English titles, identifies the standard as current, and records publication on 10 May 2019 and implementation on 1 December 2019. That record does not expose the full clauses.

**Why it matters here:** Use the complete applicable standard text for clause-level mapping. The standard's implementation date is not an annual deadline, and its recommended status does not remove the binding Article 23 duty or create the same control set for every system.

Sources:

- [Official national standards record for GB/T 22239-2019](https://openstd.samr.gov.cn/bzgk/gb/newGbInfo?hcno=BAFB47E8874764186BDB7865E8344DAF&ref=sorena.io)

### Multi-Level Protection Scheme

**Term:** MLPS

MLPS is a common English label for China's network security classified-protection system. The current Cybersecurity Law calls this the network security classified-protection system and places baseline duties on network operators. GB/T 22239-2019 is a recommended national baseline standard used within that wider legal and implementation framework; the acronym does not identify a separate certification or a single control set for every network.

**Why it matters here:** Use MLPS as shorthand only after identifying the specific network, its operator, the system boundary, the classification method and level, and the rules and standard edition used. Do not treat an MLPS level as proof of critical-information-infrastructure status or completion of a cybersecurity review.

Sources:

- [PRC Cybersecurity Law, Articles 23 and 78](https://www.cac.gov.cn/2025-12/29/c_1768735112911946.htm?ref=sorena.io)
- [Official national standards record for GB/T 22239-2019](https://openstd.samr.gov.cn/bzgk/gb/newGbInfo?hcno=BAFB47E8874764186BDB7865E8344DAF&ref=sorena.io)

### System boundary for classified-protection work

**Term:** system boundary

The system boundary is the documented scope of the network or information system being classified and assessed. It should identify the business functions, owners, users, applications, infrastructure, hosting, interfaces, dependencies, data, and external connections included in or excluded from the assessment.

**Why it matters here:** The boundary determines which assets, risks, controls, evidence, and changes belong to the classified-protection record. A company-wide label without a defined system boundary does not show which network was classified or tested.

Sources:

- [PRC Cybersecurity Law, Articles 23 and 78](https://www.cac.gov.cn/2025-12/29/c_1768735112911946.htm?ref=sorena.io)
- [Official national standards record for GB/T 22239-2019](https://openstd.samr.gov.cn/bzgk/gb/newGbInfo?hcno=BAFB47E8874764186BDB7865E8344DAF&ref=sorena.io)

## Define the system before mapping controls

Define the information system or network boundary first. Cybersecurity Law Article 23 creates the binding network security classified protection duty and lists baseline obligations for network operators. The Data Security Law creates a separate data classification and graded-protection system for data-processing activities conducted through information networks. GB/T 22239-2019 supports the network control mapping. The governing classification rules determine the system's level and applicable control set; the recommended standard is not a standalone statute.

The official standards record identifies GB/T 22239-2019 as a current recommended national standard, published on 10 May 2019 and implemented on 1 December 2019. That record does not provide the complete requirement text, so obtain the applicable standard text and the governing classification and implementation rules before citing clauses, assigning a level, describing an authority-facing procedure, or asserting conformity.

- Scope owner: record the system boundary, business purpose, network operator, users, data types, applications, infrastructure, hosting, interfaces, dependencies, external connections, and exclusions.
- Classification owner: record the governing classification method, system facts, proposed or confirmed level, decision status, approver, date, and any authority-facing step required by the applicable rules; do not infer a level from a company name, sector, data category, or critical-information-infrastructure status alone.
- Control owner: obtain the applicable standard text before mapping level-specific controls or asserting an assessment result.
- Evidence owner: keep the legal duties, classification decision, standard mapping, implementation evidence, testing, findings, exceptions, remediation, retesting, and any authority-facing process as linked but distinct records.

Sources for this answer:

- [GB/T 22239 classified protection baseline requirements](https://openstd.samr.gov.cn/bzgk/gb/newGbInfo?hcno=BAFB47E8874764186BDB7865E8344DAF&ref=sorena.io) - Use as the MLPS/classified protection baseline standard reference for control evidence mapping and the 1 December 2019 implementation date.
- [PRC Cybersecurity Law, current text](https://www.cac.gov.cn/2025-12/29/c_1768735112911946.htm?ref=sorena.io) - Use Article 23 for the binding classified-protection baseline and Article 78 for the network and network-operator definitions.

## Map and test the classified-protection controls

Translate the applicable baseline into technical and management controls only after the system scope and level are resolved. For each clause, record applicability, the control owner, implementation evidence, test method and result, open finding, exception approval, remediation date, and retest. Keep Article 23's express duties visible even when a broader standard mapping is used: internal responsibility, malware and intrusion protection, monitoring, at least six months of network logs, and data classification, important-data backup, and encryption.

Reassess the classification and control mapping when system boundaries, hosting, business functions, users, data sensitivity, interconnections, suppliers, or threat exposure materially change. A change may affect the level, the applicable controls, or both; the standards record does not establish a universal renewal date.

- Approve the asset inventory, interfaces, dependencies, exclusions, and system boundary before classification.
- Record the classification method, facts, result, approver, date, and any required authority-facing step or specialist input.
- Map only the clauses and controls applicable to that system, classification level, and technical environment.
- Test implementation and preserve the method, sample, result, finding, accepted exception, remediation owner, due date, and retest result.
- Set review ownership and triggers for changes to function, boundary, hosting, data, interconnection, supplier, users, or threat exposure without inventing a universal renewal date.

Sources for this answer:

- [GB/T 22239 classified protection baseline requirements](https://openstd.samr.gov.cn/bzgk/gb/newGbInfo?hcno=BAFB47E8874764186BDB7865E8344DAF&ref=sorena.io) - Use as the MLPS/classified protection baseline standard reference for control evidence mapping and the 1 December 2019 implementation date.
- [PRC Cybersecurity Law, current text](https://www.cac.gov.cn/2025-12/29/c_1768735112911946.htm?ref=sorena.io) - Use Article 23 for the classified-protection duties that the mapping must evidence.

## Evidence to keep before launch or change approval

Keep the classification and control file tied to the defined system, its approved level, and the edition of every standard used.

A reviewer should be able to trace each applicable requirement from the classification decision to implementation, test results, gaps, remediation, and retesting.

- System inventory, boundary diagram, business purpose, owners, users, hosting, dependencies, and data types.
- Classification rationale, decision, approver, date, and any authority or specialist input.
- Clause-level applicability and control mapping for the complete current standard text.
- Policies, configurations, architecture records, test results, findings, exceptions, remediation, and retest evidence.
- Material-change triggers, periodic review owner, and links to separate incident, important-data, critical-information-infrastructure, or cybersecurity-review records where relevant.

Sources for this answer:

- [GB/T 22239 classified protection baseline requirements](https://openstd.samr.gov.cn/bzgk/gb/newGbInfo?hcno=BAFB47E8874764186BDB7865E8344DAF&ref=sorena.io) - Use as the MLPS/classified protection baseline standard reference for control evidence mapping and the 1 December 2019 implementation date.
- [PRC Cybersecurity Law, current text](https://www.cac.gov.cn/2025-12/29/c_1768735112911946.htm?ref=sorena.io) - Use Articles 23 and 78 to connect the evidence file to the defined network and responsible network operator.

## Boundary with nearby China regimes

Classified protection does not answer every China cybersecurity question. Assess important-data duties, critical-information-infrastructure status, cybersecurity review, personal-information processing and export, and app or product rules under their own instruments.

Shared technical evidence may support several records, but keep the system classification, data classification, filing, review, and product-approval conclusions separate.

- Treating the standard's 1 December 2019 implementation date as an annual deadline.
- Assigning a level before documenting the system boundary and classification rationale.
- Claiming conformance from a policy list without clause mapping, implementation evidence, testing, and remediation.
- Using a classified protection result as a substitute for separate important-data, critical-information-infrastructure, review, privacy, app, telecom, or radio decisions.

Sources for this answer:

- [GB/T 22239 classified protection baseline requirements](https://openstd.samr.gov.cn/bzgk/gb/newGbInfo?hcno=BAFB47E8874764186BDB7865E8344DAF&ref=sorena.io) - Use as the MLPS/classified protection baseline standard reference for control evidence mapping and the 1 December 2019 implementation date.
- [PRC Cybersecurity Law, current text](https://www.cac.gov.cn/2025-12/29/c_1768735112911946.htm?ref=sorena.io) - Use Articles 23 and 33-40 to distinguish baseline classified protection from additional critical-information-infrastructure duties.

*Apply the requirement*

*Placement: Before primary sources*

## Build the China network security evidence file

Track the system boundary, classification decision, Article 23 controls, GB/T 22239-2019 mapping, tests, findings, remediation, and material changes.

- [Map official sources to evidence](/solutions/research-copilot.md): Connect Article 23, the system classification, applicable GB/T clauses, control owners, test results, and later boundary changes.
- [Review the China route](/contact.md): Check the China Cybersecurity Law scope decision and unresolved launch questions with Sorena.

## Primary sources

- [GB/T 22239 classified protection baseline requirements](https://openstd.samr.gov.cn/bzgk/gb/newGbInfo?hcno=BAFB47E8874764186BDB7865E8344DAF&ref=sorena.io) - Use as the MLPS/classified protection baseline standard reference for control evidence mapping and the 1 December 2019 implementation date.
- [PRC Cybersecurity Law, current text](https://www.cac.gov.cn/2025-12/29/c_1768735112911946.htm?ref=sorena.io) - Use Articles 23, 33-40, and 78 for the classified-protection baseline, the separate critical-information-infrastructure layer, and network and operator definitions.

## Related Topic Guides

- [China App Filing vs Personal Information Rules](/artifacts/apac/china-cybersecurity-law/mobile-app-filing-vs-app-personal-information-rules.md): Decide whether a China mobile app needs MIIT filing, personal-information controls, or both, with current triggers, duties, dates, and evidence.
- [China cybersecurity and data security requirements](/artifacts/apac/china-cybersecurity-law/requirements.md): China cybersecurity requirements by actor: network operators, data processors, CII operators, platforms, app providers, and distribution platforms.
- [China cybersecurity compliance checklist](/artifacts/apac/china-cybersecurity-law/checklist.md): A China cybersecurity checklist for scoping network duties, data security, CII procurement review, app rules, MIIT filing, and supporting standards.
- [China cybersecurity deadlines and compliance calendar](/artifacts/apac/china-cybersecurity-law/deadlines-and-compliance-calendar.md): Separate China cybersecurity commencement dates from recurring duties, filing lead times, review periods, and event-driven response deadlines.
- [China Cybersecurity Law FAQ](/artifacts/apac/china-cybersecurity-law/faq.md): Practical answers on China network-operator scope, MLPS evidence, important data, cybersecurity review, app filing and governance, and smart-home standards under the law in force from 1 January 2026.
- [China Cybersecurity Law vs EU Cyber Resilience Act](/artifacts/apac/china-cybersecurity-law/china-cybersecurity-law-vs-eu-cyber-resilience-act.md): Compare China's network-operator rules with the EU CRA's product duties, including scope, actors, evidence, reporting dates, and launch decisions.
- [China Cybersecurity Law vs EU NIS2 Directive](/artifacts/apac/china-cybersecurity-law/china-cybersecurity-law-vs-nis2.md): Compare China's network-operator duties with NIS2 entity duties, including scope, management accountability, incident reporting, evidence, and enforcement.
- [China cybersecurity penalties and fines](/artifacts/apac/china-cybersecurity-law/penalties-and-fines.md): Compare current China Cybersecurity Law and Data Security Law fines by actor, breach, severity, and enforcement consequence.
- [China Cybersecurity Review vs Data Export Assessment](/artifacts/apac/china-cybersecurity-law/cybersecurity-review-vs-data-export-security-assessment.md): Separate China's cybersecurity-review triggers from CAC data-export assessment triggers, thresholds, filings, evidence, timing, and reapplication rules.
- [China cybersecurity review workflow](/artifacts/apac/china-cybersecurity-law/cybersecurity-review-workflow.md): Determine whether CII procurement, platform data processing, or a qualifying foreign listing triggers China's Cybersecurity Review Measures.
- [China mobile app filing and app governance](/artifacts/apac/china-cybersecurity-law/mobile-app-filing-and-app-governance.md): Identify the China app sponsor, complete MIIT filing before service, and separate provider, platform, privacy, content, and security duties.
- [China Smart-Home Security vs Telecom and Radio Approval](/artifacts/apac/china-cybersecurity-law/smart-home-security-vs-telecom-wireless-launch.md): Separate GB/T 41387-2022 smart-home security evidence from China telecom network-access and radio approval decisions for connected products.
- [CII and network operator role triage](/artifacts/apac/china-cybersecurity-law/critical-information-infrastructure-and-network-operators.md): How to separate ordinary network operator duties from CII, procurement, and review-risk questions under China cybersecurity sources.
- [Does an app need MIIT filing and CAC app governance review?](/artifacts/apac/china-cybersecurity-law/faq/does-an-app-need-miit-filing-and-cac-app-governance-review.md): An app sponsor providing internet information services through an app in China must complete MIIT filing. CAC rules separately govern app providers and distribution platforms without creating one routine CAC approval for every app.
- [GB/T 41387-2022 smart home security standard](/artifacts/apac/china-cybersecurity-law/smart-home-security-standard.md): How connected-device teams can scope and document GB/T 41387-2022 without treating it as an automatic certification or product-approval duty.
- [How do smart home security standards fit with China cybersecurity law?](/artifacts/apac/china-cybersecurity-law/faq/how-do-smart-home-security-standards-fit-with-china-cybersecurity-law.md): GB/T 41387-2022 can organize smart-home security evidence, but it is a recommended standard, not a product approval. Check app, data, MLPS, telecom access, and radio requirements separately.
- [How does important data change China cybersecurity obligations?](/artifacts/apac/china-cybersecurity-law/faq/how-does-important-data-change-cybersecurity-obligations.md): Once data is officially identified as important data, the processor needs named governance, periodic risk assessments and reports, incident controls, and a separate export decision. An internal sensitivity label alone does not establish the legal category.
- [Is every company a network operator under China Cybersecurity Law?](/artifacts/apac/china-cybersecurity-law/faq/is-every-company-a-network-operator-under-china-cybersecurity-law.md): No. Under China's Cybersecurity Law, a network operator is an owner or administrator of a network or a network service provider. Apply that definition to each China network or service, then test CII and other roles separately.
- [MLPS classified protection evidence map](/artifacts/apac/china-cybersecurity-law/mlps-classified-protection-evidence-map.md): Classify a China network under MLPS, complete level 2 or above filing, map controls, and retain assessment, remediation, and change evidence.
- [What is MLPS classified protection evidence?](/artifacts/apac/china-cybersecurity-law/faq/what-is-mlps-classified-protection-evidence.md): MLPS evidence shows how a defined China network or system was graded and protected. Keep the scope, grading rationale, filing or assessment records where applicable, control mapping, test results, remediation, and reassessment history.
- [When does China cybersecurity review apply?](/artifacts/apac/china-cybersecurity-law/faq/when-does-china-cybersecurity-review-apply.md): China cybersecurity review applies to CII procurement or network-platform data processing that affects or may affect national security, plus a mandatory pre-filing trigger for certain foreign listings involving more than one million users' personal information.


---

[Privacy Policy](https://www.sorena.io/privacy.md) | [Terms of Use](https://www.sorena.io/terms-of-use.md) | [DMCA](https://www.sorena.io/dmca.md) | [About Us](https://www.sorena.io/about-us.md)

(c) 2026 Sorena AB (559573-7338). All rights reserved.

Source: https://www.sorena.io/artifacts/apac/china-cybersecurity-law/classified-protection-baseline.md
