Cybersecurity review tests national-security risk in covered procurement, platform activity, and foreign-listing cases. Data export assessment tests covered transfers of important data or personal information abroad.
The same project can trigger both, but the event, threshold, filing materials, review clock, result, and reapplication rule differ.
Use for covered procurement, network-platform activity that affects or may affect national security, and the express foreign-listing trigger for a network platform operator holding personal information on more than one million users. Use when a covered exporter sends abroad or crosses the current personal-information thresholds. A procurement or listing project that also transfers covered data can require both filings; one result does not approve the other activity.
Comparison
Cybersecurity review vs Data export security assessment
Use the left track for covered national-security review and the right track for covered outbound data transfers. Run both when a procurement, platform, or listing project also exports data above the applicable trigger.
covers procurement of network products or services that affects or may affect national security, specified network-platform activity, and the express qualifying foreign-listing trigger.
covers a data processor's provision of data abroad when exporter status, important-data status, or cumulative personal-information volume meets a current assessment trigger.
The review route focuses on national-security risk in the covered activity; the export route focuses on a covered outbound data transfer. A single project can meet both tests.
The filing actor is the operator or network platform operator, supported by procurement, listing, security, data, and legal owners. The Office organizes the review.
The data processor that exports the data submits the application through the provincial cyberspace administration to the national cyberspace administration and remains responsible for the transfer and recipient controls.
Name one accountable applicant for each route. A supplier or overseas recipient can provide evidence but does not replace the applicant's responsibility.
Screen before covered procurement or before a network platform operator holding personal information on more than one million users lists abroad. Also assess whether other covered platform activity affects or may affect national security.
A operator triggers assessment by exporting personal information or . A non-CII data processor triggers it by exporting important data or, since 1 January of the current year, personal information of at least one million individuals excluding , or sensitive personal information of at least 10,000 individuals.
Document and platform status separately from data classification and annual individual counts. Recalculate export volumes as the calendar year progresses.
Submit the written declaration, analysis of effects or possible effects on national security, relevant procurement documents or intended listing materials, and other requested material. Covered procurement contracts must address supplier cooperation and specified supply, data, and control risks.
Complete the pre-filing self-assessment, when PIPL requires it, legal agreement or other binding document with the overseas recipient, application form, and other required material before the covered export.
Retain the or platform decision, user-count evidence where relevant, product or service scope, supplier and ownership facts, national-security analysis, contracts or listing materials, filing, questions, result, and imposed conditions.
Retain the data inventory and classification, decision, annual counts, exemption analysis, self-assessment, impact assessment, recipient agreement, filing, result, transfer logs, material changes, expiry date, and extension or reapplication decision.
After receiving filing materials, the Review Office has 10 working days to decide whether review is required. An ordinary review is normally completed within 30 working days and may be extended by 15 working days; a special review is normally completed within 90 working days and may be extended.
CAC's 2024 provisions make an assessment result valid for three years from issuance. If no reapplication trigger occurs, the exporter may seek one extension of up to three years by applying within the 60 working days before expiry; CAC must approve the extension.
Do not promise a launch date from the nominal periods: supplementation and special review can change the schedule. Track export-result expiry and material changes separately.
Failure consequences depend on the applicant, breached duty, and applicable Cybersecurity Law, Data Security Law, or other provision. The Cybersecurity Law's liability provisions were amended effective 1 January 2026.
CAC may require correction, suspend a transfer, or act under PIPL, the Data Security Law, the Cybersecurity Law, or other rules when assessment duties or approved transfer conditions are not met.
Do not proceed on an expired, materially outdated, or unrelated result. Preserve the decision record that supported each procurement, listing step, and transfer.
can examine data concentration, control, supply interruption, product security, foreign influence, and listing-related risks within the national-security analysis.
Data export assessment examines the legality, legitimacy, necessity, scale, sensitivity, recipient safeguards, transfer agreement, and risk to national security, public interests, and individual rights in the outbound transfer.
Run data export assessment when a covered outbound transfer meets an important-data, , or current personal-information threshold, even if no procurement or listing is involved.
covers procurement of network products or services that affects or may affect national security, specified network-platform activity, and the express qualifying foreign-listing trigger.
covers a data processor's provision of data abroad when exporter status, important-data status, or cumulative personal-information volume meets a current assessment trigger.
The review route focuses on national-security risk in the covered activity; the export route focuses on a covered outbound data transfer. A single project can meet both tests.
The filing actor is the operator or network platform operator, supported by procurement, listing, security, data, and legal owners. The Office organizes the review.
The data processor that exports the data submits the application through the provincial cyberspace administration to the national cyberspace administration and remains responsible for the transfer and recipient controls.
Name one accountable applicant for each route. A supplier or overseas recipient can provide evidence but does not replace the applicant's responsibility.
Screen before covered procurement or before a network platform operator holding personal information on more than one million users lists abroad. Also assess whether other covered platform activity affects or may affect national security.
A operator triggers assessment by exporting personal information or . A non-CII data processor triggers it by exporting important data or, since 1 January of the current year, personal information of at least one million individuals excluding , or sensitive personal information of at least 10,000 individuals.
Document and platform status separately from data classification and annual individual counts. Recalculate export volumes as the calendar year progresses.
Submit the written declaration, analysis of effects or possible effects on national security, relevant procurement documents or intended listing materials, and other requested material. Covered procurement contracts must address supplier cooperation and specified supply, data, and control risks.
Complete the pre-filing self-assessment, when PIPL requires it, legal agreement or other binding document with the overseas recipient, application form, and other required material before the covered export.
Retain the or platform decision, user-count evidence where relevant, product or service scope, supplier and ownership facts, national-security analysis, contracts or listing materials, filing, questions, result, and imposed conditions.
Retain the data inventory and classification, decision, annual counts, exemption analysis, self-assessment, impact assessment, recipient agreement, filing, result, transfer logs, material changes, expiry date, and extension or reapplication decision.
After receiving filing materials, the Review Office has 10 working days to decide whether review is required. An ordinary review is normally completed within 30 working days and may be extended by 15 working days; a special review is normally completed within 90 working days and may be extended.
CAC's 2024 provisions make an assessment result valid for three years from issuance. If no reapplication trigger occurs, the exporter may seek one extension of up to three years by applying within the 60 working days before expiry; CAC must approve the extension.
Do not promise a launch date from the nominal periods: supplementation and special review can change the schedule. Track export-result expiry and material changes separately.
Failure consequences depend on the applicant, breached duty, and applicable Cybersecurity Law, Data Security Law, or other provision. The Cybersecurity Law's liability provisions were amended effective 1 January 2026.
CAC may require correction, suspend a transfer, or act under PIPL, the Data Security Law, the Cybersecurity Law, or other rules when assessment duties or approved transfer conditions are not met.
Do not proceed on an expired, materially outdated, or unrelated result. Preserve the decision record that supported each procurement, listing step, and transfer.
can examine data concentration, control, supply interruption, product security, foreign influence, and listing-related risks within the national-security analysis.
Data export assessment examines the legality, legitimacy, necessity, scale, sensitivity, recipient safeguards, transfer agreement, and risk to national security, public interests, and individual rights in the outbound transfer.
Run data export assessment when a covered outbound transfer meets an important-data, , or current personal-information threshold, even if no procurement or listing is involved.
Use for covered procurement, covered platform activity affecting or possibly affecting national security, or the qualifying foreign-listing trigger.
Use data export assessment for exports of personal information or and non-CII exports that meet the important-data or current personal-information thresholds, after testing the 2024 exemptions.
Run both when both triggers exist; preserve separate filings, review results, conditions, expiry or change monitoring, and authority correspondence.
Screen from the procurement, platform-processing, and foreign-listing facts. A operator must apply before procuring a network product or service that affects or may affect national security. A network platform operator holding personal information on more than one million users must apply before listing abroad. The Review Office can also initiate review where covered activity affects or may affect national security.
Screen data export assessment from the exporter, data classification, destination, and cumulative volume since 1 January of the current year. A operator exporting personal information or must apply unless a 2024 exemption applies. A non-CII data processor must apply when exporting officially identified important data, at least one million individuals' non-, or at least 10,000 individuals' sensitive personal information, again subject to the exemptions.
Apply the 22 March 2024 cross-border-data provisions with the 2022 assessment measures. A processor need not treat data as important for export filing unless a relevant department or region has notified it or publicly identified it as important. The 2024 provisions also exempt specified data without personal information or , pure transit of overseas-collected personal information without added China personal information or important data, certain necessary contract, human-resources, and emergency transfers, transfers of non- involving fewer than 100,000 people by non- processors, and transfers outside an approved free-trade-zone negative list.
The 2024 provisions replace the earlier personal-information thresholds and extend an assessment result's validity to three years. If no reapplication trigger has occurred, the exporter may apply within the 60 working days before expiry for one extension of up to three years; the extension requires CAC approval.
Procurement or listing owner: document the or platform status, covered event, national-security analysis, contracts or listing documents, filing, and review conditions.
Data export owner: document data classification, exporter status, destination and recipient, annual individual counts, exemptions, , contract, filing, result, and reapplication monitoring.
Program owner: link shared systems, suppliers, data inventories, and recipients without merging the two legal conclusions.
Use for cybersecurity review scope, CII procurement filing, platform operator review triggers, review materials, special review, and 15 February 2022 effective date.
Use for data classification and graded protection, important-data risk assessment, security management, incident response, outbound important-data context, penalties, and 1 September 2021 effective date.
Use for PIPL scope, processing bases, notice and consent, individual rights, processor duties, PIPIA, cross-border transfer duties, penalties, and effective date.