| Scope boundary | Cybersecurity review covers national-security review of certain CII procurement and platform/network product or service scenarios. | Data export security assessment covers CAC assessment for outbound important data or personal information transfers that meet assessment triggers. | Run separate scope decisions when the same launch can trigger both Cybersecurity review and Data export security assessment. |
|---|
| Covered actors | Cybersecurity review work is usually owned by CII operator, network platform operator, procurement/security/legal owner. | Data export security assessment work is usually owned by data processor or personal information processor exporting data overseas. | Assign separate owners when the legal route, regulator, filing, assessment, permit, or evidence package is different. |
|---|
| Trigger event | Cybersecurity review screening starts with procurement of network products/services or platform listing/activity that may affect national security. | Data export security assessment screening starts with important data export or personal-information export threshold requiring security assessment. | Record the triggering event and launch date for each route before reusing technical evidence. |
|---|
| Core obligations | Cybersecurity review requires the team to translate its official articles or measures into concrete controls for national-security review of certain CII procurement and platform/network product or service scenarios. | Data export security assessment requires controls for CAC assessment for outbound important data or personal information transfers that meet assessment triggers. | Shared facts can support both routes, but the legal conclusion and required action must be written separately. |
|---|
| Evidence package | A defensible Cybersecurity review file includes review filing materials, procurement facts, national-security risk analysis, and review correspondence. | A defensible Data export security assessment file includes self-assessment, application materials, overseas recipient legal terms, assessment result, validity, and re-application monitoring. | Reuse common documents only after each file identifies why the document satisfies that route. |
|---|
| Timing and refresh points | Cybersecurity review timing should track effective dates, filing windows, review periods, renewals, or transition dates named in its sources. | Data export security assessment timing should track its own effective dates, implementation windows, reporting periods, renewals, or market-entry deadlines. | Calendar each route independently; a date in one regime does not extend or replace a date in the other. |
|---|
| Enforcement exposure | Cybersecurity review exposure usually follows the actor, regulator, and failure mode tied to procurement of network products/services or platform listing/activity that may affect national security. | Data export security assessment exposure usually follows the actor, regulator, and failure mode tied to important data export or personal-information export threshold requiring security assessment. | Preserve the evidence trail before launch, filing, transfer, procurement, sale, or disposal because later remediation is weaker than a dated decision record. |
|---|
| Overlap and routing | Cybersecurity review and Data export security assessment can use the same product, app, supplier, data-flow, or equipment facts, but Cybersecurity review owns the decision for national-security review of certain CII procurement and platform/network product or service scenarios. | Data export security assessment owns the decision for CAC assessment for outbound important data or personal information transfers that meet assessment triggers. | Create linked records rather than copying one conclusion across both regimes. |
|---|
| Practical decision rule | Choose Cybersecurity review when the immediate blocker is procurement of network products/services or platform listing/activity that may affect national security. | Choose Data export security assessment when the immediate blocker is important data export or personal-information export threshold requiring security assessment. | Run both tracks when the same China or cross-market launch creates both Cybersecurity review and Data export security assessment triggers. |
|---|