China Cybersecurity Law CII and network operator role triage
Separate baseline network operator duties from the enhanced duties that follow after a system is identified as critical information infrastructure.
The Cybersecurity Law applies to building, operating, maintaining and using networks in China. CII is narrower: the responsible protection department applies sector recognition rules and notifies the operator.
Identify the operator of each network in China and apply the baseline duties to that network. Add duties only when the responsible has identified the specific infrastructure and notified its operator.
1
Section 1
1. Identify the network and its operator
Scope the concrete network or network service in China instead of assigning one label to an entire corporate group. A may be the network owner, administrator or network service provider. Record the legal entity that makes operational decisions, the system boundary, users, functions, infrastructure, data, suppliers and connection to China.
Apply the Cybersecurity Law's baseline duties to each in-scope network. is a narrower category with added organisational, assessment, incident, procurement and data duties. The separate term '' in the Cybersecurity Review Measures should not be used as a synonym for either role.
Does every operate CII?
No. A owns or administers a network or provides network services and must meet the baseline security duties. CII is a narrower class of important network facilities and information systems identified under sector rules by the responsible . CII duties are added to, not substituted for, the baseline.
List the network facilities, information systems, cloud or hosting components, interfaces, users, business functions and data within the boundary.
Name the owner, administrator and service providers; state which entity controls access, configuration, security operations and incident response.
Map Article 23 duties to that operator: internal security rules and responsibility, protection against malware and attacks, network-status and incident monitoring, at least six months of network logs, and data classification, important-data backup and encryption.
Reassess the operator analysis after changes to ownership, administration, hosting, architecture, service delivery or operational control.
2. Determine whether the system has been identified as CII
The CII regulation names sectors and a consequence test, but the responsible performs the recognition. Its rules must consider the facility's importance to the sector's key core business, the harm that destruction, loss of function or data leakage could cause, and effects on other industries or fields. The department identifies the specific infrastructure and notifies its operator; sector membership, company size, data volume, customer importance, or a classified-protection level does not replace that notice.
Treat a possible CII classification as an escalation point and do not self-certify the system. Preserve the authority notice and match it to the named facilities, systems, operator, and version or boundary facts. If identified CII changes materially in a way that could affect the result, the operator must report the change; the has three months after receiving the report to complete the new determination and notify the operator.
Does operating in a named sector automatically make a system CII?
No. Sector presence is relevant, but the responsible applies its recognition rules to the specific network facility or information system and notifies the operator. Importance to key core business, the harm from disruption or data leakage, and effects on other sectors are part of that determination.
Check whether the system supports a key core business in public communications and information services, energy, transport, water, finance, public services, e-government, defence science and industry, or another relevant field.
Document the consequences of destruction, loss of function or data leakage for national security, the national economy and people's livelihoods, the public interest and connected sectors.
Identify the responsible sector and retain its recognition rule, correspondence and formal notification where available.
Do not infer CII status only from company size, data volume, critical customers, a high level or presence in a named sector.
A notified CII operator keeps the baseline Article 23 controls and adds the CII controls in the amended Cybersecurity Law and the CII regulation. The operator's has overall responsibility. The operator must establish a , support it with people and funding, involve it in cybersecurity and informatization decisions, and conduct background screening for its head and key-position personnel.
The dedicated body must cover protection planning, monitoring, testing, risk assessment, incident plans and exercises, key roles, training, personal-information and data protection, service-provider security and required reporting. The operator must assess CII security and risk at least once each year, remedy findings and report as the requires.
Governance evidence: authority notification, named accountable executive, dedicated-body charter, staffing and budget, background-screening records, training and decision-participation records.
Operational evidence: CII protection plan, monitoring and testing outputs, risk register, incident plan and exercises, major-event reports, remediation records, continuity and disaster-recovery evidence.
Annual evidence: at least one CII network-security test and risk assessment each year, findings, completed remediation and any report required by the .
Procurement evidence: security and confidentiality agreement, supplier monitoring, national-security pre-judgment and cybersecurity-review filing and conclusion when the purchase may affect national security.
Data evidence: personal-information and data-protection controls, important-data inventory, and the separate route analysis for personal information or important data collected or generated through CII operations in China and provided abroad.
classification, CII recognition, cybersecurity review, important-data classification, personal-information protection and data-export routes answer different questions. A high MLPS level does not itself prove CII status, and a CII notice does not replace classified-protection, app, privacy or export work.
Use one system inventory and change record across the analyses, but keep each legal conclusion, authority interaction, filing, approval and recurring duty separately traceable.
Reopen the network-operator analysis when operational control changes.
Report a material CII change when it may affect the recognition result.
Reassess procurement when the supplier, product, service, use or affected critical function changes.
Keep annual CII testing separate from assessment evidence and other sector-specific inspections.
The regulation places enhanced CII protection on top of classified protection and requires renewed recognition after a potentially material infrastructure change.