CybersecurityChina

Cybersecurity review vs data export assessment

Cybersecurity review tests national-security risk in covered procurement, platform activity, and foreign-listing cases. Data export assessment tests covered transfers of important data or personal information abroad.

The same project can trigger both, but the event, threshold, filing materials, review clock, result, and reapplication rule differ.

Author
Sorena AI
Published
Jul 5, 2026
Updated
Jul 24, 2026
Sections
1

Structured answer sets in this page tree.

Primary sources
8

Cited legal and guidance references.

Publication metadata
Sorena AI
Published Jul 5, 2026
Updated Jul 24, 2026
Overview

Use for covered procurement, network-platform activity that affects or may affect national security, and the express foreign-listing trigger for a network platform operator holding personal information on more than one million users. Use when a covered exporter sends abroad or crosses the current personal-information thresholds. A procurement or listing project that also transfers covered data can require both filings; one result does not approve the other activity.

Comparison

Cybersecurity review vs Data export security assessment

Use the left track for covered national-security review and the right track for covered outbound data transfers. Run both when a procurement, platform, or listing project also exports data above the applicable trigger.

Review all sources
First framework
Cybersecurity review

Use for covered procurement, network-platform activity affecting or possibly affecting national security, and the express foreign-listing trigger.

Second framework
Data export security assessment

Use for CAC assessment before covered exports of or personal information, applying the current 2024 thresholds and exemptions.

Comparison row 1

Scope boundary

Cybersecurity review

covers procurement of network products or services that affects or may affect national security, specified network-platform activity, and the express qualifying foreign-listing trigger.

Data export security assessment

covers a data processor's provision of data abroad when exporter status, important-data status, or cumulative personal-information volume meets a current assessment trigger.

Operational implication

The review route focuses on national-security risk in the covered activity; the export route focuses on a covered outbound data transfer. A single project can meet both tests.

Comparison row 2

Covered actors

Cybersecurity review

The filing actor is the operator or network platform operator, supported by procurement, listing, security, data, and legal owners. The Office organizes the review.

Data export security assessment

The data processor that exports the data submits the application through the provincial cyberspace administration to the national cyberspace administration and remains responsible for the transfer and recipient controls.

Operational implication

Name one accountable applicant for each route. A supplier or overseas recipient can provide evidence but does not replace the applicant's responsibility.

Comparison row 3

Trigger event

Cybersecurity review

Screen before covered procurement or before a network platform operator holding personal information on more than one million users lists abroad. Also assess whether other covered platform activity affects or may affect national security.

Data export security assessment

A operator triggers assessment by exporting personal information or . A non-CII data processor triggers it by exporting important data or, since 1 January of the current year, personal information of at least one million individuals excluding , or sensitive personal information of at least 10,000 individuals.

Operational implication

Document and platform status separately from data classification and annual individual counts. Recalculate export volumes as the calendar year progresses.

Comparison row 4

Core obligations

Cybersecurity review

Submit the written declaration, analysis of effects or possible effects on national security, relevant procurement documents or intended listing materials, and other requested material. Covered procurement contracts must address supplier cooperation and specified supply, data, and control risks.

Data export security assessment

Complete the pre-filing self-assessment, when PIPL requires it, legal agreement or other binding document with the overseas recipient, application form, and other required material before the covered export.

Operational implication

A single architecture or contract may support both files, but each filing needs its own trigger analysis and required materials.

Comparison row 5

Evidence package

Cybersecurity review

Retain the or platform decision, user-count evidence where relevant, product or service scope, supplier and ownership facts, national-security analysis, contracts or listing materials, filing, questions, result, and imposed conditions.

Data export security assessment

Retain the data inventory and classification, decision, annual counts, exemption analysis, self-assessment, impact assessment, recipient agreement, filing, result, transfer logs, material changes, expiry date, and extension or reapplication decision.

Operational implication

Version both files against the same system, transaction, supplier, recipient, and data set so later changes can be routed correctly.

Comparison row 6

Timing and refresh points

Cybersecurity review

After receiving filing materials, the Review Office has 10 working days to decide whether review is required. An ordinary review is normally completed within 30 working days and may be extended by 15 working days; a special review is normally completed within 90 working days and may be extended.

Data export security assessment

CAC's 2024 provisions make an assessment result valid for three years from issuance. If no reapplication trigger occurs, the exporter may seek one extension of up to three years by applying within the 60 working days before expiry; CAC must approve the extension.

Operational implication

Do not promise a launch date from the nominal periods: supplementation and special review can change the schedule. Track export-result expiry and material changes separately.

Comparison row 7

Enforcement exposure

Cybersecurity review

Failure consequences depend on the applicant, breached duty, and applicable Cybersecurity Law, Data Security Law, or other provision. The Cybersecurity Law's liability provisions were amended effective 1 January 2026.

Data export security assessment

CAC may require correction, suspend a transfer, or act under PIPL, the Data Security Law, the Cybersecurity Law, or other rules when assessment duties or approved transfer conditions are not met.

Operational implication

Do not proceed on an expired, materially outdated, or unrelated result. Preserve the decision record that supported each procurement, listing step, and transfer.

Comparison row 8

Overlap and routing

Cybersecurity review

can examine data concentration, control, supply interruption, product security, foreign influence, and listing-related risks within the national-security analysis.

Data export security assessment

Data export assessment examines the legality, legitimacy, necessity, scale, sensitivity, recipient safeguards, transfer agreement, and risk to national security, public interests, and individual rights in the outbound transfer.

Operational implication

Share the data map, architecture, supplier, and recipient evidence, but issue separate findings for the covered activity and the covered transfer.

Comparison row 9

Practical decision rule

Cybersecurity review

Run when covered procurement, platform activity, or a qualifying foreign listing is the trigger, even if no data is exported.

Data export security assessment

Run data export assessment when a covered outbound transfer meets an important-data, , or current personal-information threshold, even if no procurement or listing is involved.

Operational implication

Run both when the same supplier, platform, listing, or cloud arrangement creates both triggers. Record separately why any exemption applies.

Practical decision rule

When to run one track or both

  • Use for covered procurement, covered platform activity affecting or possibly affecting national security, or the qualifying foreign-listing trigger.
  • Use data export assessment for exports of personal information or and non-CII exports that meet the important-data or current personal-information thresholds, after testing the 2024 exemptions.
  • Run both when both triggers exist; preserve separate filings, review results, conditions, expiry or change monitoring, and authority correspondence.
Section 1

How to use this comparison

Screen from the procurement, platform-processing, and foreign-listing facts. A operator must apply before procuring a network product or service that affects or may affect national security. A network platform operator holding personal information on more than one million users must apply before listing abroad. The Review Office can also initiate review where covered activity affects or may affect national security.

Screen data export assessment from the exporter, data classification, destination, and cumulative volume since 1 January of the current year. A operator exporting personal information or must apply unless a 2024 exemption applies. A non-CII data processor must apply when exporting officially identified important data, at least one million individuals' non-, or at least 10,000 individuals' sensitive personal information, again subject to the exemptions.

Apply the 22 March 2024 cross-border-data provisions with the 2022 assessment measures. A processor need not treat data as important for export filing unless a relevant department or region has notified it or publicly identified it as important. The 2024 provisions also exempt specified data without personal information or , pure transit of overseas-collected personal information without added China personal information or important data, certain necessary contract, human-resources, and emergency transfers, transfers of non- involving fewer than 100,000 people by non- processors, and transfers outside an approved free-trade-zone negative list.

The 2024 provisions replace the earlier personal-information thresholds and extend an assessment result's validity to three years. If no reapplication trigger has occurred, the exporter may apply within the 60 working days before expiry for one extension of up to three years; the extension requires CAC approval.

  • Procurement or listing owner: document the or platform status, covered event, national-security analysis, contracts or listing documents, filing, and review conditions.
  • Data export owner: document data classification, exporter status, destination and recipient, annual individual counts, exemptions, , contract, filing, result, and reapplication monitoring.
  • Program owner: link shared systems, suppliers, data inventories, and recipients without merging the two legal conclusions.
Primary sources

References and citations

cac.gov.cn
Referenced sections
  • Use for cybersecurity review scope, CII procurement filing, platform operator review triggers, review materials, special review, and 15 February 2022 effective date.
cac.gov.cn
Referenced sections
  • Use for network operator security duties, network product/service security, CII provisions, personal-information security articles, penalties, and 1 June 2017 effective date.
cac.gov.cn
Referenced sections
  • Use for data classification and graded protection, important-data risk assessment, security management, incident response, outbound important-data context, penalties, and 1 September 2021 effective date.
cac.gov.cn
Referenced sections
  • Use for PIPL scope, processing bases, notice and consent, individual rights, processor duties, PIPIA, cross-border transfer duties, penalties, and effective date.
Related guides

Explore more topics

China App Filing vs Personal Information Rules
Decide whether a China mobile app needs MIIT filing, personal-information controls, or both, with current triggers, duties, dates, and evidence.
China cybersecurity and data security requirements
China cybersecurity requirements by actor: network operators, data processors, CII operators, platforms, app providers, and distribution platforms.
China cybersecurity compliance checklist
A China cybersecurity checklist for scoping network duties, data security, CII procurement review, app rules, MIIT filing, and supporting standards.
China cybersecurity deadlines and compliance calendar
Separate China cybersecurity commencement dates from recurring duties, filing lead times, review periods, and event-driven response deadlines.
China Cybersecurity Law FAQ
Practical answers on China network-operator scope, MLPS evidence, important data, cybersecurity review, app filing and governance, and smart-home standards under the law in force from 1 January 2026.
China Cybersecurity Law vs EU Cyber Resilience Act
Compare China's network-operator rules with the EU CRA's product duties, including scope, actors, evidence, reporting dates, and launch decisions.
China Cybersecurity Law vs EU NIS2 Directive
Compare China's network-operator duties with NIS2 entity duties, including scope, management accountability, incident reporting, evidence, and enforcement.
China cybersecurity penalties and fines
Compare current China Cybersecurity Law and Data Security Law fines by actor, breach, severity, and enforcement consequence.
China cybersecurity review workflow
Determine whether CII procurement, platform data processing, or a qualifying foreign listing triggers China's Cybersecurity Review Measures.
China mobile app filing and app governance
Identify the China app sponsor, complete MIIT filing before service, and separate provider, platform, privacy, content, and security duties.
China Smart-Home Security vs Telecom and Radio Approval
Separate GB/T 41387-2022 smart-home security evidence from China telecom network-access and radio approval decisions for connected products.
CII and network operator role triage
How to separate ordinary network operator duties from CII, procurement, and review-risk questions under China cybersecurity sources.
Does an app need MIIT filing and CAC app governance review?
An app sponsor providing internet information services through an app in China must complete MIIT filing. CAC rules separately govern app providers and distribution platforms without creating one routine CAC approval for every app.
GB/T 22239-2019 classified protection baseline
How to scope and document a GB/T 22239-2019 classified protection baseline without treating the recommended standard as a standalone law.
GB/T 41387-2022 smart home security standard
How connected-device teams can scope and document GB/T 41387-2022 without treating it as an automatic certification or product-approval duty.
How do smart home security standards fit with China cybersecurity law?
GB/T 41387-2022 can organize smart-home security evidence, but it is a recommended standard, not a product approval. Check app, data, MLPS, telecom access, and radio requirements separately.
How does important data change China cybersecurity obligations?
Once data is officially identified as important data, the processor needs named governance, periodic risk assessments and reports, incident controls, and a separate export decision. An internal sensitivity label alone does not establish the legal category.
Is every company a network operator under China Cybersecurity Law?
No. Under China's Cybersecurity Law, a network operator is an owner or administrator of a network or a network service provider. Apply that definition to each China network or service, then test CII and other roles separately.
MLPS classified protection evidence map
Classify a China network under MLPS, complete level 2 or above filing, map controls, and retain assessment, remediation, and change evidence.
What is MLPS classified protection evidence?
MLPS evidence shows how a defined China network or system was graded and protected. Keep the scope, grading rationale, filing or assessment records where applicable, control mapping, test results, remediation, and reassessment history.
When does China cybersecurity review apply?
China cybersecurity review applies to CII procurement or network-platform data processing that affects or may affect national security, plus a mandatory pre-filing trigger for certain foreign listings involving more than one million users' personal information.