CybersecurityChina

China Cybersecurity Law Comparison

Crosswalk for review triggers and data export assessment triggers so teams do not mix procurement/platform review with outbound data transfer review.

Cybersecurity review vs data export security assessment explains where two compliance regimes overlap, where they diverge, and how to keep decisions, owners, evidence, and timing separate.

Author
Sorena AI
Published
Jul 5, 2026
Updated
Jul 5, 2026
Sections
1

Structured answer sets in this page tree.

Primary sources
6

Cited legal and guidance references.

Publication metadata
Sorena AI
Published Jul 5, 2026
Updated Jul 5, 2026
Overview

Crosswalk for review triggers and data export assessment triggers so teams do not mix procurement/platform review with outbound data transfer review.

Comparison

Cybersecurity review vs Data export security assessment

This comparison helps separate Cybersecurity review decisions from Data export security assessment decisions without merging evidence, owners, or timing.

Review all sources
First framework
Cybersecurity review

Use for national-security review of certain CII procurement and platform/network product or service scenarios. Keep its evidence and legal conclusion separate.

Second framework
Data export security assessment

Use for CAC assessment for outbound important data or personal information transfers that meet assessment triggers. Keep its evidence and legal conclusion separate.

Comparison row 1

Scope boundary

Cybersecurity review

Cybersecurity review covers national-security review of certain CII procurement and platform/network product or service scenarios.

Data export security assessment

Data export security assessment covers CAC assessment for outbound important data or personal information transfers that meet assessment triggers.

Operational implication

Run separate scope decisions when the same launch can trigger both Cybersecurity review and Data export security assessment.

Comparison row 2

Covered actors

Cybersecurity review

Cybersecurity review work is usually owned by CII operator, network platform operator, procurement/security/legal owner.

Data export security assessment

Data export security assessment work is usually owned by data processor or personal information processor exporting data overseas.

Operational implication

Assign separate owners when the legal route, regulator, filing, assessment, permit, or evidence package is different.

Comparison row 3

Trigger event

Cybersecurity review

Cybersecurity review screening starts with procurement of network products/services or platform listing/activity that may affect national security.

Data export security assessment

Data export security assessment screening starts with important data export or personal-information export threshold requiring security assessment.

Operational implication

Record the triggering event and launch date for each route before reusing technical evidence.

Comparison row 4

Core obligations

Cybersecurity review

Cybersecurity review requires the team to translate its official articles or measures into concrete controls for national-security review of certain CII procurement and platform/network product or service scenarios.

Data export security assessment

Data export security assessment requires controls for CAC assessment for outbound important data or personal information transfers that meet assessment triggers.

Operational implication

Shared facts can support both routes, but the legal conclusion and required action must be written separately.

Comparison row 5

Evidence package

Cybersecurity review

A defensible Cybersecurity review file includes review filing materials, procurement facts, national-security risk analysis, and review correspondence.

Data export security assessment

A defensible Data export security assessment file includes self-assessment, application materials, overseas recipient legal terms, assessment result, validity, and re-application monitoring.

Operational implication

Reuse common documents only after each file identifies why the document satisfies that route.

Comparison row 6

Timing and refresh points

Cybersecurity review

Cybersecurity review timing should track effective dates, filing windows, review periods, renewals, or transition dates named in its sources.

Data export security assessment

Data export security assessment timing should track its own effective dates, implementation windows, reporting periods, renewals, or market-entry deadlines.

Operational implication

Calendar each route independently; a date in one regime does not extend or replace a date in the other.

Comparison row 7

Enforcement exposure

Cybersecurity review

Cybersecurity review exposure usually follows the actor, regulator, and failure mode tied to procurement of network products/services or platform listing/activity that may affect national security.

Data export security assessment

Data export security assessment exposure usually follows the actor, regulator, and failure mode tied to important data export or personal-information export threshold requiring security assessment.

Operational implication

Preserve the evidence trail before launch, filing, transfer, procurement, sale, or disposal because later remediation is weaker than a dated decision record.

Comparison row 8

Overlap and routing

Cybersecurity review

Cybersecurity review and Data export security assessment can use the same product, app, supplier, data-flow, or equipment facts, but Cybersecurity review owns the decision for national-security review of certain CII procurement and platform/network product or service scenarios.

Data export security assessment

Data export security assessment owns the decision for CAC assessment for outbound important data or personal information transfers that meet assessment triggers.

Operational implication

Create linked records rather than copying one conclusion across both regimes.

Comparison row 9

Practical decision rule

Cybersecurity review

Choose Cybersecurity review when the immediate blocker is procurement of network products/services or platform listing/activity that may affect national security.

Data export security assessment

Choose Data export security assessment when the immediate blocker is important data export or personal-information export threshold requiring security assessment.

Operational implication

Run both tracks when the same China or cross-market launch creates both Cybersecurity review and Data export security assessment triggers.

Practical decision rule

When to run one track or both

  • Use Cybersecurity review when the facts match procurement of network products/services or platform listing/activity that may affect national security.
  • Use Data export security assessment when the facts match important data export or personal-information export threshold requiring security assessment.
  • Run both when the same launch creates both triggers, but keep separate approvals and official citations.
Section 1

How to use this comparison

Cybersecurity review vs data export security assessment compares the practical trigger, owner, timing, and evidence record for each regime so visitors can avoid collapsing two different compliance decisions into one checklist.

Start with the trigger and accountable owner, then build the evidence package for each route. A filing, assessment, permit, or policy under one regime is not proof that the other regime is complete.

  • Use the left column for the China-specific legal route and evidence package.
  • Use the right column for the compared regime or adjacent China route.
  • Keep shared facts linked, but preserve separate legal conclusions, owners, and official citations.
Operationalize the requirement

Build the China network security evidence file

Sorena AI helps turn the Cybersecurity review vs Data export security assessment decision into owners, controls, and reviewer-ready records.

Primary sources

References and citations

cac.gov.cn
Referenced sections
  • Use for cybersecurity review scope, CII procurement filing, platform operator review triggers, review materials, special review, and 15 February 2022 effective date.
cac.gov.cn
Referenced sections
  • Use for network operator security duties, network product/service security, CII provisions, personal-information security articles, penalties, and 1 June 2017 effective date.
cac.gov.cn
Referenced sections
  • Use for data classification and graded protection, important-data risk assessment, security management, incident response, outbound important-data context, penalties, and 1 September 2021 effective date.
cac.gov.cn
Referenced sections
  • Use for PIPL scope, processing bases, notice and consent, individual rights, processor duties, PIPIA, cross-border transfer duties, penalties, and effective date.
Related guides

Explore more topics

China cybersecurity and data security requirements
Network operator, data security, cybersecurity review, app governance, MLPS, and smart-home security requirements under China sources.
China cybersecurity compliance checklist
Checklist for network operators, app providers, connected-device teams, review screening, app filing, MLPS evidence, and smart-home security related review.
China cybersecurity deadlines and compliance calendar
Official cybersecurity, data security, review, app governance, filing, and standards dates.
China Cybersecurity Law FAQ
Answers to practical China Cybersecurity Law questions for scope, official source triggers, evidence records, and related China scope decisions.
China Cybersecurity Law vs EU Cyber Resilience Act
Comparison showing China operator/security duties versus EU product cybersecurity duties under the CRA.
China Cybersecurity Law vs EU NIS2
Comparison of China network/data security duties with EU NIS2 entity cybersecurity duties.
China cybersecurity penalties and enforcement exposure
China cybersecurity, data security, review, and app-governance enforcement exposure.
China cybersecurity review workflow
Intake workflow for procurement, platform, CII, and national-security risk review triggers.
China mobile app filing and app governance
How MIIT app filing and CAC app information service duties affect app providers and distribution workflows.
CII and network operator role triage
How to separate ordinary network operator duties from CII, procurement, and review-risk questions under China cybersecurity sources.
Does an app need MIIT filing and CAC app governance review?
Treat app filing and app information service governance as related but separate checks. MIIT filing evidence should not replace CAC app-provider governance, privacy minimization, or cybersecurity duties.
How do smart home security standards fit with China cybersecurity law?
The smart home security standard can support connected appliance security evidence, but it does not replace app privacy, network access, radio, or cybersecurity review analysis. Use it as one control map tied to the cited standard.
How does important data change China cybersecurity obligations?
Important data changes the risk analysis because the Data Security Law establishes data classification and graded protection. The practical record is an important-data screening note, plus export or security-assessment routing where applicable.
Is every company a network operator under China Cybersecurity Law?
Do not start with a generic company label. Start with the network, system, app, platform, data processing, and China operation facts, then map them to network operator, app provider, data processor, CII, or review triggers in the cited sources.
MLPS classified protection baseline evidence
How to use the classified protection baseline standard as evidence mapping without treating the standard itself as a standalone law.
MLPS classified protection evidence map
Evidence map for classified protection baseline controls, source status, owners, and security records.
Mobile app filing vs app personal information rules
Practical overlap guide for MIIT app filing, app information service governance, and app minimum personal-information duties.
Smart home security standard evidence
How connected-device teams can use the smart home security specification and cross-link telecom, privacy, and cybersecurity evidence.
Smart home security vs telecom and wireless launch
Cross-link page for smart connected appliance teams separating cybersecurity standard evidence from radio and network access evidence.
What is MLPS classified protection evidence?
MLPS evidence is a control and classification evidence set, not a standalone substitute for the Cybersecurity Law. Keep system scope, classification rationale, baseline requirement mapping, remediation, and review records.
When does China cybersecurity review apply?
Cybersecurity review analysis is needed when procurement, platform operation, CII, or national security risk facts match the Cybersecurity Review Measures. Keep an intake note with product/service, buyer/operator role, data/system impact, and official source trigger.