---
title: "CII and network operator role triage"
canonical_url: "https://www.sorena.io/artifacts/apac/china-cybersecurity-law/critical-information-infrastructure-and-network-operators"
source_url: "https://www.sorena.io/artifacts/apac/china-cybersecurity-law/critical-information-infrastructure-and-network-operators"
author: "Sorena AI"
description: "How to separate ordinary network operator duties from CII, procurement, and review-risk questions under China cybersecurity sources."
published_at: "2026-07-05"
updated_at: "2026-07-25"
keywords:
  - "China Cybersecurity Law"
  - "Data Security Law"
  - "Cybersecurity Review Measures"
  - "Mobile app filing"
  - "MLPS"
---
**[SORENA](https://www.sorena.io/)** - AI-Powered GRC Platform

[Home](https://www.sorena.io/) | [Solutions](https://www.sorena.io/solutions) | [Artifacts](https://www.sorena.io/artifacts) | [About Us](https://www.sorena.io/about-us) | [Contact](https://www.sorena.io/contact) | [Portal](https://app.sorena.io)

---

# CII and network operator role triage

How to separate ordinary network operator duties from CII, procurement, and review-risk questions under China cybersecurity sources.

*Cybersecurity* *China*

## China Cybersecurity Law CII and network operator role triage

Separate baseline network operator duties from the enhanced duties that follow after a system is identified as critical information infrastructure.

The Cybersecurity Law applies to building, operating, maintaining and using networks in China. CII is narrower: the responsible protection department applies sector recognition rules and notifies the operator.

Identify the operator of each network in China and apply the baseline duties to that network. Add critical information infrastructure duties only when the responsible protection department has identified the specific infrastructure and notified its operator.

## Definitions

### Network operator

A network operator is the owner or administrator of a network or a network service provider. The Cybersecurity Law defines a network broadly as a system made up of computers or other information terminals and related equipment that collects, stores, transmits, exchanges or processes information under rules and procedures.

**Why it matters here:** Identify the entity that owns, administers or provides the concrete network service in China. That entity carries the baseline Article 23 security duties even when the network has not been identified as critical information infrastructure.

Sources:

- [Amended PRC Cybersecurity Law](https://www.cac.gov.cn/2025-12/29/c_1768735112911946.htm?ref=sorena.io)

### Critical information infrastructure

Critical information infrastructure consists of important network facilities and information systems in public communications and information services, energy, transport, water, finance, public services, e-government, defence science and industry, and other areas where destruction, loss of function or a data leak could seriously harm national security, the national economy and people's livelihoods, or the public interest.

**Why it matters here:** The responsible sector protection department develops recognition rules, identifies the specific infrastructure and notifies its operator. A company does not become a CII operator merely because it is large, handles sensitive data or works in a named sector.

Sources:

- [Regulations on the Security Protection of Critical Information Infrastructure](https://www.cac.gov.cn/2021-08/17/c_1630785976988160.htm?ref=sorena.io)
- [Amended PRC Cybersecurity Law](https://www.cac.gov.cn/2025-12/29/c_1768735112911946.htm?ref=sorena.io)

### Critical information infrastructure protection department

**Term:** protection department

For an important industry or field covered by the CII regulation, the competent or supervisory department responsible for that sector is the protection department. It develops sector recognition rules, identifies specific critical information infrastructure, notifies the operator, receives reports of material changes and major events, and supervises protection work.

**Why it matters here:** Identify the department for the relevant sector and keep its recognition rule, notice, correspondence, reporting instructions, and reassessment decision. A company assessment can flag a possible CII case, but it does not replace the department's identification and notice.

Sources:

- [Regulations on the Security Protection of Critical Information Infrastructure, Articles 8-11](https://www.cac.gov.cn/2021-08/17/c_1630785976988160.htm?ref=sorena.io)

### Network platform operator under the Cybersecurity Review Measures

**Term:** network platform operator

The Cybersecurity Review Measures use network platform operator for the operator whose data-processing activity affects or may affect national security. The measures also require such an operator to file before a foreign listing when it holds personal information of more than one million users. The term is not defined as another name for every network operator or CII operator.

**Why it matters here:** Analyse the platform role, data-processing activity, national-security effects, personal-information user count, and listing destination separately from network-operator and CII status.

Sources:

- [Cybersecurity Review Measures, Articles 2 and 7-10](https://www.cac.gov.cn/2022-01/04/c_1642894602182845.htm?ref=sorena.io)

### Dedicated CII security-management body

**Term:** dedicated security-management body

A CII operator must establish a dedicated security-management body. Under the CII regulation, it develops protection plans, drives monitoring, testing and risk assessment, maintains incident plans and exercises, identifies key positions, organises training, protects personal information and data, manages security for design, construction, operation and maintenance services, and makes required reports.

**Why it matters here:** The operator must fund and staff the body, screen its head and key-position personnel, and include its personnel in cybersecurity and informatization decisions. A general policy without the body, authority, resources and operating records does not evidence these duties.

Sources:

- [Regulations on the Security Protection of Critical Information Infrastructure, Articles 14-16](https://www.cac.gov.cn/2021-08/17/c_1630785976988160.htm?ref=sorena.io)

### Multi-Level Protection Scheme

**Term:** MLPS

MLPS is a common English label for China's network security classified-protection system. Article 23 of the current Cybersecurity Law places baseline classified-protection duties on network operators. GB/T 22239-2019 is a recommended national baseline standard used within that wider system.

**Why it matters here:** MLPS classification and CII recognition are separate decisions. A classified-protection level does not replace identification and notice by the CII protection department, and CII notice does not replace the operator's classified-protection work.

Sources:

- [PRC Cybersecurity Law, Articles 23 and 78](https://www.cac.gov.cn/2025-12/29/c_1768735112911946.htm?ref=sorena.io)
- [Official national standards record for GB/T 22239-2019](https://openstd.samr.gov.cn/bzgk/gb/newGbInfo?hcno=BAFB47E8874764186BDB7865E8344DAF&ref=sorena.io)

### CII operator's main responsible person

**Term:** main responsible person

The CII regulation assigns overall responsibility for CII security protection to the operator's main responsible person. That person leads CII protection and the handling of major network-security incidents and organises work on major cybersecurity issues.

**Why it matters here:** Name the accountable person for the notified operator and retain the governance decisions, resources, incident leadership, and major-issue records that show the role is operating. This role does not replace the dedicated security-management body.

Sources:

- [Regulations on the Security Protection of Critical Information Infrastructure, Article 13](https://www.cac.gov.cn/2021-08/17/c_1630785976988160.htm?ref=sorena.io)

## 1. Identify the network and its operator

Scope the concrete network or network service in China instead of assigning one label to an entire corporate group. A network operator may be the network owner, administrator or network service provider. Record the legal entity that makes operational decisions, the system boundary, users, functions, infrastructure, data, suppliers and connection to China.

Apply the Cybersecurity Law's baseline duties to each in-scope network. Critical information infrastructure is a narrower category with added organisational, assessment, incident, procurement and data duties. The separate term 'network platform operator' in the Cybersecurity Review Measures should not be used as a synonym for either role.

- List the network facilities, information systems, cloud or hosting components, interfaces, users, business functions and data within the boundary.
- Name the owner, administrator and service providers; state which entity controls access, configuration, security operations and incident response.
- Map Article 23 duties to that operator: internal security rules and responsibility, protection against malware and attacks, network-status and incident monitoring, at least six months of network logs, and data classification, important-data backup and encryption.
- Reassess the operator analysis after changes to ownership, administration, hosting, architecture, service delivery or operational control.

### Does every network operator operate CII?

No. A network operator owns or administers a network or provides network services and must meet the baseline security duties. CII is a narrower class of important network facilities and information systems identified under sector rules by the responsible protection department. CII duties are added to, not substituted for, the baseline.

Sources for this answer:

- [Amended PRC Cybersecurity Law](https://www.cac.gov.cn/2025-12/29/c_1768735112911946.htm?ref=sorena.io) - Article 2 sets territorial scope, Article 23 establishes baseline classified-protection duties, and the definitions identify networks and network operators. The amended text took effect on 1 January 2026.

## 2. Determine whether the system has been identified as CII

The CII regulation names sectors and a consequence test, but the responsible protection department performs the recognition. Its rules must consider the facility's importance to the sector's key core business, the harm that destruction, loss of function or data leakage could cause, and effects on other industries or fields. The department identifies the specific infrastructure and notifies its operator; sector membership, company size, data volume, customer importance, or a classified-protection level does not replace that notice.

Treat a possible CII classification as an escalation point and do not self-certify the system. Preserve the authority notice and match it to the named facilities, systems, operator, and version or boundary facts. If identified CII changes materially in a way that could affect the result, the operator must report the change; the protection department has three months after receiving the report to complete the new determination and notify the operator.

- Check whether the system supports a key core business in public communications and information services, energy, transport, water, finance, public services, e-government, defence science and industry, or another relevant field.
- Document the consequences of destruction, loss of function or data leakage for national security, the national economy and people's livelihoods, the public interest and connected sectors.
- Identify the responsible sector protection department and retain its recognition rule, correspondence and formal notification where available.
- Do not infer CII status only from company size, data volume, critical customers, a high MLPS level or presence in a named sector.

### Does operating in a named sector automatically make a system CII?

No. Sector presence is relevant, but the responsible protection department applies its recognition rules to the specific network facility or information system and notifies the operator. Importance to key core business, the harm from disruption or data leakage, and effects on other sectors are part of that determination.

Sources for this answer:

- [Regulations on the Security Protection of Critical Information Infrastructure](https://www.cac.gov.cn/2021-08/17/c_1630785976988160.htm?ref=sorena.io) - Articles 2 and 8-11 establish the CII definition, responsible protection departments, recognition factors, operator notification and three-month reassessment process after a material change.

## 3. Add the enhanced CII duties

A notified CII operator keeps the baseline Article 23 controls and adds the CII controls in the amended Cybersecurity Law and the CII regulation. The operator's main responsible person has overall responsibility. The operator must establish a dedicated security-management body, support it with people and funding, involve it in cybersecurity and informatization decisions, and conduct background screening for its head and key-position personnel.

The dedicated body must cover protection planning, monitoring, testing, risk assessment, incident plans and exercises, key roles, training, personal-information and data protection, service-provider security and required reporting. The operator must assess CII security and risk at least once each year, remedy findings and report as the protection department requires.

- Governance evidence: authority notification, named accountable executive, dedicated-body charter, staffing and budget, background-screening records, training and decision-participation records.
- Operational evidence: CII protection plan, monitoring and testing outputs, risk register, incident plan and exercises, major-event reports, remediation records, continuity and disaster-recovery evidence.
- Annual evidence: at least one CII network-security test and risk assessment each year, findings, completed remediation and any report required by the protection department.
- Procurement evidence: security and confidentiality agreement, supplier monitoring, national-security pre-judgment and cybersecurity-review filing and conclusion when the purchase may affect national security.
- Data evidence: personal-information and data-protection controls, important-data inventory, and the separate route analysis for personal information or important data collected or generated through CII operations in China and provided abroad.

Sources for this answer:

- [Regulations on the Security Protection of Critical Information Infrastructure](https://www.cac.gov.cn/2021-08/17/c_1630785976988160.htm?ref=sorena.io) - Articles 12-21 establish CII governance, the dedicated body's duties, annual testing and risk assessment, incident reporting, procurement and change obligations.
- [Amended PRC Cybersecurity Law](https://www.cac.gov.cn/2025-12/29/c_1768735112911946.htm?ref=sorena.io) - Articles 35-40 establish CII continuity, enhanced security, procurement review, supplier agreements, in-China storage and outbound assessment, and annual testing duties.

## 4. Keep the role decision connected but distinct

MLPS classification, CII recognition, cybersecurity review, important-data classification, personal-information protection and data-export routes answer different questions. A high MLPS level does not itself prove CII status, and a CII notice does not replace classified-protection, app, privacy or export work.

Use one system inventory and change record across the analyses, but keep each legal conclusion, authority interaction, filing, approval and recurring duty separately traceable.

- Reopen the network-operator analysis when operational control changes.
- Report a material CII change when it may affect the recognition result.
- Reassess procurement when the supplier, product, service, use or affected critical function changes.
- Keep annual CII testing separate from MLPS assessment evidence and other sector-specific inspections.

Related resources:

- [Cybersecurity review workflow](/artifacts/apac/china-cybersecurity-law/cybersecurity-review-workflow.md): Apply the procurement-review trigger and prepare the filing when a CII purchase may affect national security.
- [MLPS classified protection evidence map](/artifacts/apac/china-cybersecurity-law/mlps-classified-protection-evidence-map.md): Build the baseline classified-protection record that applies before any enhanced CII controls.

Sources for this answer:

- [Regulations on the Security Protection of Critical Information Infrastructure](https://www.cac.gov.cn/2021-08/17/c_1630785976988160.htm?ref=sorena.io) - The regulation places enhanced CII protection on top of classified protection and requires renewed recognition after a potentially material infrastructure change.
- [Cybersecurity Review Measures](https://www.cac.gov.cn/2022-01/04/c_1642894602182845.htm?ref=sorena.io) - Articles 5-6 establish the separate CII procurement pre-judgment, filing and supplier-commitment steps.

*Apply the requirement*

*Placement: Before primary sources*

## Build the China network security evidence file

Turn the network-operator and CII role decision into named owners, controls, authority records and reassessment triggers.

- [Map official sources to evidence](/solutions/research-copilot.md): Connect the network-operator analysis, CII recognition notice, annual assessment, procurement screen, reports and material changes.
- [Review the China route](/contact.md): Check the China Cybersecurity Law scope decision and unresolved launch questions with Sorena.

## Primary sources

- [Amended PRC Cybersecurity Law](https://www.cac.gov.cn/2025-12/29/c_1768735112911946.htm?ref=sorena.io) - Current consolidated Cybersecurity Law, effective 1 January 2026, for network-operator definitions, Article 23 baseline duties and Articles 33-40 CII duties.
- [Regulations on the Security Protection of Critical Information Infrastructure](https://www.cac.gov.cn/2021-08/17/c_1630785976988160.htm?ref=sorena.io) - Binding CII regulation effective 1 September 2021 for recognition, notification, operator governance, annual assessment, incident, procurement and change duties.
- [Cybersecurity Review Measures](https://www.cac.gov.cn/2022-01/04/c_1642894602182845.htm?ref=sorena.io) - Binding rules for screening and filing CII procurement that affects or may affect national security.

## Related Topic Guides

- [China App Filing vs Personal Information Rules](/artifacts/apac/china-cybersecurity-law/mobile-app-filing-vs-app-personal-information-rules.md): Decide whether a China mobile app needs MIIT filing, personal-information controls, or both, with current triggers, duties, dates, and evidence.
- [China cybersecurity and data security requirements](/artifacts/apac/china-cybersecurity-law/requirements.md): China cybersecurity requirements by actor: network operators, data processors, CII operators, platforms, app providers, and distribution platforms.
- [China cybersecurity compliance checklist](/artifacts/apac/china-cybersecurity-law/checklist.md): A China cybersecurity checklist for scoping network duties, data security, CII procurement review, app rules, MIIT filing, and supporting standards.
- [China cybersecurity deadlines and compliance calendar](/artifacts/apac/china-cybersecurity-law/deadlines-and-compliance-calendar.md): Separate China cybersecurity commencement dates from recurring duties, filing lead times, review periods, and event-driven response deadlines.
- [China Cybersecurity Law FAQ](/artifacts/apac/china-cybersecurity-law/faq.md): Practical answers on China network-operator scope, MLPS evidence, important data, cybersecurity review, app filing and governance, and smart-home standards under the law in force from 1 January 2026.
- [China Cybersecurity Law vs EU Cyber Resilience Act](/artifacts/apac/china-cybersecurity-law/china-cybersecurity-law-vs-eu-cyber-resilience-act.md): Compare China's network-operator rules with the EU CRA's product duties, including scope, actors, evidence, reporting dates, and launch decisions.
- [China Cybersecurity Law vs EU NIS2 Directive](/artifacts/apac/china-cybersecurity-law/china-cybersecurity-law-vs-nis2.md): Compare China's network-operator duties with NIS2 entity duties, including scope, management accountability, incident reporting, evidence, and enforcement.
- [China cybersecurity penalties and fines](/artifacts/apac/china-cybersecurity-law/penalties-and-fines.md): Compare current China Cybersecurity Law and Data Security Law fines by actor, breach, severity, and enforcement consequence.
- [China Cybersecurity Review vs Data Export Assessment](/artifacts/apac/china-cybersecurity-law/cybersecurity-review-vs-data-export-security-assessment.md): Separate China's cybersecurity-review triggers from CAC data-export assessment triggers, thresholds, filings, evidence, timing, and reapplication rules.
- [China cybersecurity review workflow](/artifacts/apac/china-cybersecurity-law/cybersecurity-review-workflow.md): Determine whether CII procurement, platform data processing, or a qualifying foreign listing triggers China's Cybersecurity Review Measures.
- [China mobile app filing and app governance](/artifacts/apac/china-cybersecurity-law/mobile-app-filing-and-app-governance.md): Identify the China app sponsor, complete MIIT filing before service, and separate provider, platform, privacy, content, and security duties.
- [China Smart-Home Security vs Telecom and Radio Approval](/artifacts/apac/china-cybersecurity-law/smart-home-security-vs-telecom-wireless-launch.md): Separate GB/T 41387-2022 smart-home security evidence from China telecom network-access and radio approval decisions for connected products.
- [Does an app need MIIT filing and CAC app governance review?](/artifacts/apac/china-cybersecurity-law/faq/does-an-app-need-miit-filing-and-cac-app-governance-review.md): An app sponsor providing internet information services through an app in China must complete MIIT filing. CAC rules separately govern app providers and distribution platforms without creating one routine CAC approval for every app.
- [GB/T 22239-2019 classified protection baseline](/artifacts/apac/china-cybersecurity-law/classified-protection-baseline.md): How to scope and document a GB/T 22239-2019 classified protection baseline without treating the recommended standard as a standalone law.
- [GB/T 41387-2022 smart home security standard](/artifacts/apac/china-cybersecurity-law/smart-home-security-standard.md): How connected-device teams can scope and document GB/T 41387-2022 without treating it as an automatic certification or product-approval duty.
- [How do smart home security standards fit with China cybersecurity law?](/artifacts/apac/china-cybersecurity-law/faq/how-do-smart-home-security-standards-fit-with-china-cybersecurity-law.md): GB/T 41387-2022 can organize smart-home security evidence, but it is a recommended standard, not a product approval. Check app, data, MLPS, telecom access, and radio requirements separately.
- [How does important data change China cybersecurity obligations?](/artifacts/apac/china-cybersecurity-law/faq/how-does-important-data-change-cybersecurity-obligations.md): Once data is officially identified as important data, the processor needs named governance, periodic risk assessments and reports, incident controls, and a separate export decision. An internal sensitivity label alone does not establish the legal category.
- [Is every company a network operator under China Cybersecurity Law?](/artifacts/apac/china-cybersecurity-law/faq/is-every-company-a-network-operator-under-china-cybersecurity-law.md): No. Under China's Cybersecurity Law, a network operator is an owner or administrator of a network or a network service provider. Apply that definition to each China network or service, then test CII and other roles separately.
- [MLPS classified protection evidence map](/artifacts/apac/china-cybersecurity-law/mlps-classified-protection-evidence-map.md): Classify a China network under MLPS, complete level 2 or above filing, map controls, and retain assessment, remediation, and change evidence.
- [What is MLPS classified protection evidence?](/artifacts/apac/china-cybersecurity-law/faq/what-is-mlps-classified-protection-evidence.md): MLPS evidence shows how a defined China network or system was graded and protected. Keep the scope, grading rationale, filing or assessment records where applicable, control mapping, test results, remediation, and reassessment history.
- [When does China cybersecurity review apply?](/artifacts/apac/china-cybersecurity-law/faq/when-does-china-cybersecurity-review-apply.md): China cybersecurity review applies to CII procurement or network-platform data processing that affects or may affect national security, plus a mandatory pre-filing trigger for certain foreign listings involving more than one million users' personal information.


---

[Privacy Policy](https://www.sorena.io/privacy.md) | [Terms of Use](https://www.sorena.io/terms-of-use.md) | [DMCA](https://www.sorena.io/dmca.md) | [About Us](https://www.sorena.io/about-us.md)

(c) 2026 Sorena AB (559573-7338). All rights reserved.

Source: https://www.sorena.io/artifacts/apac/china-cybersecurity-law/critical-information-infrastructure-and-network-operators.md
