---
title: "China Cybersecurity Review vs Data Export Assessment"
canonical_url: "https://www.sorena.io/artifacts/apac/china-cybersecurity-law/cybersecurity-review-vs-data-export-security-assessment"
source_url: "https://www.sorena.io/artifacts/apac/china-cybersecurity-law/cybersecurity-review-vs-data-export-security-assessment"
author: "Sorena AI"
description: "Separate China's cybersecurity-review triggers from CAC data-export assessment triggers, thresholds, filings, evidence, timing, and reapplication rules."
published_at: "2026-07-05"
updated_at: "2026-07-24"
keywords:
  - "China Cybersecurity Law"
  - "Data Security Law"
  - "Cybersecurity Review Measures"
  - "Mobile app filing"
  - "MLPS"
---
**[SORENA](https://www.sorena.io/)** - AI-Powered GRC Platform

[Home](https://www.sorena.io/) | [Solutions](https://www.sorena.io/solutions) | [Artifacts](https://www.sorena.io/artifacts) | [About Us](https://www.sorena.io/about-us) | [Contact](https://www.sorena.io/contact) | [Portal](https://app.sorena.io)

---

# China Cybersecurity Review vs Data Export Assessment

Separate China's cybersecurity-review triggers from CAC data-export assessment triggers, thresholds, filings, evidence, timing, and reapplication rules.

*Cybersecurity* *China*

## Cybersecurity review vs data export assessment

Cybersecurity review tests national-security risk in covered procurement, platform activity, and foreign-listing cases. Data export assessment tests covered transfers of important data or personal information abroad.

The same project can trigger both, but the event, threshold, filing materials, review clock, result, and reapplication rule differ.

Use cybersecurity review for covered CII procurement, network-platform activity that affects or may affect national security, and the express foreign-listing trigger for a network platform operator holding personal information on more than one million users. Use data export security assessment when a covered exporter sends important data abroad or crosses the current personal-information thresholds. A procurement or listing project that also transfers covered data can require both filings; one result does not approve the other activity.

## Definitions

### Cybersecurity review

Cybersecurity review is the national-security review organized by the Cybersecurity Review Office for covered CII procurement and network-platform data processing that affects or may affect national security. Article 7 also requires a network platform operator holding personal information of more than one million users to file before a listing in a foreign country.

**Why it matters here:** The review examines the covered procurement, processing activity, or listing and its national-security risks. It does not authorize a data export or replace the separate transfer threshold, exemption, self-assessment, and filing analysis.

Sources:

- [Cybersecurity Review Measures](https://www.cac.gov.cn/2022-01/04/c_1642894602182845.htm?ref=sorena.io)

### Data export security assessment

A data export security assessment is the CAC-administered assessment required before a covered data processor provides important data or threshold volumes of personal information abroad. The applicant first completes its own export-risk assessment and submits through the provincial cyberspace administration to the national cyberspace administration.

**Why it matters here:** This route evaluates the specific outbound transfer, overseas recipient, agreement, safeguards, and effects on national security, public interests, and individual rights. It is different from cybersecurity review, a personal-information standard contract, and personal-information protection certification.

Sources:

- [Measures for Security Assessment of Data Export](https://www.cac.gov.cn/2022-07/07/c_1658811536396503.htm?ref=sorena.io)
- [Provisions on Promoting and Regulating Cross-border Data Flow](https://www.cac.gov.cn/2024-03/22/c_1712776611775634.htm?ref=sorena.io)

### Critical information infrastructure

**Term:** CII

CII is an important network facility or information system whose destruction, loss of function, or data leakage could seriously harm national security, the national economy, people's livelihoods, or the public interest. The responsible protection department identifies it under sector rules and notifies the operator.

**Why it matters here:** A CII operator must use the data export security assessment route when exporting personal information or important data, subject to the stated 2024 exemptions. The same operator must also screen procurement of network products and services for cybersecurity review.

Sources:

- [Regulations on the Security Protection of Critical Information Infrastructure](https://www.cac.gov.cn/2021-08/17/c_1630785976988160.htm?ref=sorena.io)
- [Provisions on Promoting and Regulating Cross-border Data Flow](https://www.cac.gov.cn/2024-03/22/c_1712776611775634.htm?ref=sorena.io)

### Important data

Important data is data that may endanger national security, economic operation, social stability, public health, or public safety if tampered with, destroyed, leaked, illegally obtained, or illegally used. Under the 2024 cross-border provisions, a processor need not file an export assessment on the important-data ground unless a relevant department or region has notified it or publicly identified the data as important.

**Why it matters here:** Once important-data status is established, the personal-information volume thresholds do not create a safe harbour. Keep the authority notice, catalogue entry, or other official identification with the export decision.

Sources:

- [Measures for Security Assessment of Data Export](https://www.cac.gov.cn/2022-07/07/c_1658811536396503.htm?ref=sorena.io)
- [Provisions on Promoting and Regulating Cross-border Data Flow](https://www.cac.gov.cn/2024-03/22/c_1712776611775634.htm?ref=sorena.io)

### Sensitive personal information

Sensitive personal information is personal information that, if leaked or illegally used, could readily harm a person's dignity or personal or property safety. PIPL examples include biometric, religious-belief, specific-identity, medical-health, financial-account, and precise-location or movement information, plus all personal information of children under 14.

**Why it matters here:** For a non-CII processor, exporting sensitive personal information of at least 10,000 people since 1 January of the current year triggers security assessment, unless a 2024 exemption applies. Sensitive and non-sensitive counts use different thresholds.

Sources:

- [PRC Personal Information Protection Law](https://www.cac.gov.cn/2021-08/20/c_1631050028355286.htm?ref=sorena.io)
- [Provisions on Promoting and Regulating Cross-border Data Flow](https://www.cac.gov.cn/2024-03/22/c_1712776611775634.htm?ref=sorena.io)

### Personal information protection impact assessment

A personal information protection impact assessment is the PIPL assessment completed before specified high-impact processing, including sensitive-information processing, automated decision-making, entrusted processing or provision to another processor, public disclosure, and cross-border provision. It evaluates lawfulness, necessity, effects on individuals, and whether safeguards match the risk.

**Why it matters here:** An exporter of personal information must complete and retain this impact assessment even when a 2024 exemption removes the security-assessment, standard-contract, or certification route. PIPL requires the report and processing record to be kept for at least three years.

Sources:

- [PRC Personal Information Protection Law](https://www.cac.gov.cn/2021-08/20/c_1631050028355286.htm?ref=sorena.io)
- [Provisions on Promoting and Regulating Cross-border Data Flow](https://www.cac.gov.cn/2024-03/22/c_1712776611775634.htm?ref=sorena.io)

## Cybersecurity review vs Data export security assessment

Use the left track for covered national-security review and the right track for covered outbound data transfers. Run both when a procurement, platform, or listing project also exports data above the applicable trigger.

- **Cybersecurity review**: Use for covered CII procurement, network-platform activity affecting or possibly affecting national security, and the express foreign-listing trigger.
- **Data export security assessment**: Use for CAC assessment before covered exports of important data or personal information, applying the current 2024 thresholds and exemptions.

| Dimension | Cybersecurity review | Data export security assessment | Operational implication | Sources |
| --- | --- | --- | --- | --- |
| Scope boundary | Cybersecurity review covers CII procurement of network products or services that affects or may affect national security, specified network-platform activity, and the express qualifying foreign-listing trigger. | Data export security assessment covers a data processor's provision of data abroad when exporter status, important-data status, or cumulative personal-information volume meets a current assessment trigger. | The review route focuses on national-security risk in the covered activity; the export route focuses on a covered outbound data transfer. A single project can meet both tests. | [Cybersecurity Review Measures](https://www.cac.gov.cn/2022-01/04/c_1642894602182845.htm?ref=sorena.io) - Use for cybersecurity review scope, CII procurement filing, platform operator review triggers, review materials, special review, and 15 February 2022 effective date.<br>[Measures for Security Assessment of Data Export](https://www.cac.gov.cn/2022-07/07/c_1658811536396503.htm?ref=sorena.io) - Use with the 2024 cross-border provisions for data export assessment triggers, application evidence, authority review, validity, and re-application.<br>[Provisions on Promoting and Regulating Cross-border Data Flow](https://www.cac.gov.cn/2024-03/22/c_1712776611775634.htm?ref=sorena.io) - Use for the current assessment thresholds, important-data identification rule, exemptions, three-year validity period, and extension route.<br>[PRC Cybersecurity Law](https://www.cac.gov.cn/2016-11/07/c_1119867116.htm?ref=sorena.io) - Use for network operator security duties, network product/service security, CII provisions, personal-information security articles, penalties, and 1 June 2017 effective date. |
| Covered actors | The filing actor is the CII operator or network platform operator, supported by procurement, listing, security, data, and legal owners. The Cybersecurity Review Office organizes the review. | The data processor that exports the data submits the application through the provincial cyberspace administration to the national cyberspace administration and remains responsible for the transfer and recipient controls. | Name one accountable applicant for each route. A supplier or overseas recipient can provide evidence but does not replace the applicant's responsibility. | [Cybersecurity Review Measures](https://www.cac.gov.cn/2022-01/04/c_1642894602182845.htm?ref=sorena.io) - Use for cybersecurity review scope, CII procurement filing, platform operator review triggers, review materials, special review, and 15 February 2022 effective date.<br>[Measures for Security Assessment of Data Export](https://www.cac.gov.cn/2022-07/07/c_1658811536396503.htm?ref=sorena.io) - Use with the 2024 cross-border provisions for data export assessment triggers, application evidence, authority review, validity, and re-application.<br>[Provisions on Promoting and Regulating Cross-border Data Flow](https://www.cac.gov.cn/2024-03/22/c_1712776611775634.htm?ref=sorena.io) - Use for the current assessment thresholds, important-data identification rule, exemptions, three-year validity period, and extension route.<br>[PRC Cybersecurity Law](https://www.cac.gov.cn/2016-11/07/c_1119867116.htm?ref=sorena.io) - Use for network operator security duties, network product/service security, CII provisions, personal-information security articles, penalties, and 1 June 2017 effective date. |
| Trigger event | Screen before covered CII procurement or before a network platform operator holding personal information on more than one million users lists abroad. Also assess whether other covered platform activity affects or may affect national security. | A CII operator triggers assessment by exporting personal information or important data. A non-CII data processor triggers it by exporting important data or, since 1 January of the current year, personal information of at least one million individuals excluding sensitive personal information, or sensitive personal information of at least 10,000 individuals. | Document CII and platform status separately from data classification and annual individual counts. Recalculate export volumes as the calendar year progresses. | [Cybersecurity Review Measures](https://www.cac.gov.cn/2022-01/04/c_1642894602182845.htm?ref=sorena.io) - Use for cybersecurity review scope, CII procurement filing, platform operator review triggers, review materials, special review, and 15 February 2022 effective date.<br>[Measures for Security Assessment of Data Export](https://www.cac.gov.cn/2022-07/07/c_1658811536396503.htm?ref=sorena.io) - Use with the 2024 cross-border provisions for data export assessment triggers, application evidence, authority review, validity, and re-application.<br>[Provisions on Promoting and Regulating Cross-border Data Flow](https://www.cac.gov.cn/2024-03/22/c_1712776611775634.htm?ref=sorena.io) - Use for the current assessment thresholds, important-data identification rule, exemptions, three-year validity period, and extension route.<br>[PRC Cybersecurity Law](https://www.cac.gov.cn/2016-11/07/c_1119867116.htm?ref=sorena.io) - Use for network operator security duties, network product/service security, CII provisions, personal-information security articles, penalties, and 1 June 2017 effective date. |
| Core obligations | Submit the written declaration, analysis of effects or possible effects on national security, relevant procurement documents or intended listing materials, and other requested material. Covered CII procurement contracts must address supplier cooperation and specified supply, data, and control risks. | Complete the pre-filing self-assessment, personal information protection impact assessment when PIPL requires it, legal agreement or other binding document with the overseas recipient, application form, and other required material before the covered export. | A single architecture or contract may support both files, but each filing needs its own trigger analysis and required materials. | [Cybersecurity Review Measures](https://www.cac.gov.cn/2022-01/04/c_1642894602182845.htm?ref=sorena.io) - Use for cybersecurity review scope, CII procurement filing, platform operator review triggers, review materials, special review, and 15 February 2022 effective date.<br>[Measures for Security Assessment of Data Export](https://www.cac.gov.cn/2022-07/07/c_1658811536396503.htm?ref=sorena.io) - Use with the 2024 cross-border provisions for data export assessment triggers, application evidence, authority review, validity, and re-application.<br>[Provisions on Promoting and Regulating Cross-border Data Flow](https://www.cac.gov.cn/2024-03/22/c_1712776611775634.htm?ref=sorena.io) - Use for the current assessment thresholds, important-data identification rule, exemptions, three-year validity period, and extension route.<br>[PRC Cybersecurity Law](https://www.cac.gov.cn/2016-11/07/c_1119867116.htm?ref=sorena.io) - Use for network operator security duties, network product/service security, CII provisions, personal-information security articles, penalties, and 1 June 2017 effective date. |
| Evidence package | Retain the CII or platform decision, user-count evidence where relevant, product or service scope, supplier and ownership facts, national-security analysis, contracts or listing materials, filing, questions, result, and imposed conditions. | Retain the data inventory and classification, CII decision, annual counts, exemption analysis, self-assessment, impact assessment, recipient agreement, filing, result, transfer logs, material changes, expiry date, and extension or reapplication decision. | Version both files against the same system, transaction, supplier, recipient, and data set so later changes can be routed correctly. | [Cybersecurity Review Measures](https://www.cac.gov.cn/2022-01/04/c_1642894602182845.htm?ref=sorena.io) - Use for cybersecurity review scope, CII procurement filing, platform operator review triggers, review materials, special review, and 15 February 2022 effective date.<br>[Measures for Security Assessment of Data Export](https://www.cac.gov.cn/2022-07/07/c_1658811536396503.htm?ref=sorena.io) - Use with the 2024 cross-border provisions for data export assessment triggers, application evidence, authority review, validity, and re-application.<br>[Provisions on Promoting and Regulating Cross-border Data Flow](https://www.cac.gov.cn/2024-03/22/c_1712776611775634.htm?ref=sorena.io) - Use for the current assessment thresholds, important-data identification rule, exemptions, three-year validity period, and extension route.<br>[PRC Cybersecurity Law](https://www.cac.gov.cn/2016-11/07/c_1119867116.htm?ref=sorena.io) - Use for network operator security duties, network product/service security, CII provisions, personal-information security articles, penalties, and 1 June 2017 effective date. |
| Timing and refresh points | After receiving filing materials, the Review Office has 10 working days to decide whether review is required. An ordinary review is normally completed within 30 working days and may be extended by 15 working days; a special review is normally completed within 90 working days and may be extended. | CAC's 2024 provisions make an assessment result valid for three years from issuance. If no reapplication trigger occurs, the exporter may seek one extension of up to three years by applying within the 60 working days before expiry; CAC must approve the extension. | Do not promise a launch date from the nominal periods: supplementation and special review can change the schedule. Track export-result expiry and material changes separately. | [Cybersecurity Review Measures](https://www.cac.gov.cn/2022-01/04/c_1642894602182845.htm?ref=sorena.io) - Use for cybersecurity review scope, CII procurement filing, platform operator review triggers, review materials, special review, and 15 February 2022 effective date.<br>[Measures for Security Assessment of Data Export](https://www.cac.gov.cn/2022-07/07/c_1658811536396503.htm?ref=sorena.io) - Use with the 2024 cross-border provisions for data export assessment triggers, application evidence, authority review, validity, and re-application.<br>[Provisions on Promoting and Regulating Cross-border Data Flow](https://www.cac.gov.cn/2024-03/22/c_1712776611775634.htm?ref=sorena.io) - Use for the current assessment thresholds, important-data identification rule, exemptions, three-year validity period, and extension route.<br>[PRC Cybersecurity Law](https://www.cac.gov.cn/2016-11/07/c_1119867116.htm?ref=sorena.io) - Use for network operator security duties, network product/service security, CII provisions, personal-information security articles, penalties, and 1 June 2017 effective date. |
| Enforcement exposure | Failure consequences depend on the applicant, breached duty, and applicable Cybersecurity Law, Data Security Law, or other provision. The Cybersecurity Law's liability provisions were amended effective 1 January 2026. | CAC may require correction, suspend a transfer, or act under PIPL, the Data Security Law, the Cybersecurity Law, or other rules when assessment duties or approved transfer conditions are not met. | Do not proceed on an expired, materially outdated, or unrelated result. Preserve the decision record that supported each procurement, listing step, and transfer. | [Cybersecurity Review Measures](https://www.cac.gov.cn/2022-01/04/c_1642894602182845.htm?ref=sorena.io) - Use for cybersecurity review scope, CII procurement filing, platform operator review triggers, review materials, special review, and 15 February 2022 effective date.<br>[PRC Cybersecurity Law, consolidated after the 2025 amendment](https://www.cac.gov.cn/2025-12/29/c_1768735112911946.htm?ref=sorena.io) - Current official text for the liability provisions in force from 1 January 2026.<br>[Measures for Security Assessment of Data Export](https://www.cac.gov.cn/2022-07/07/c_1658811536396503.htm?ref=sorena.io) - Use with the 2024 cross-border provisions for data export assessment triggers, application evidence, authority review, validity, and re-application.<br>[Provisions on Promoting and Regulating Cross-border Data Flow](https://www.cac.gov.cn/2024-03/22/c_1712776611775634.htm?ref=sorena.io) - Use for the current assessment thresholds, important-data identification rule, exemptions, three-year validity period, and extension route.<br>[PRC Cybersecurity Law](https://www.cac.gov.cn/2016-11/07/c_1119867116.htm?ref=sorena.io) - Use for network operator security duties, network product/service security, CII provisions, personal-information security articles, penalties, and 1 June 2017 effective date. |
| Overlap and routing | Cybersecurity review can examine data concentration, control, supply interruption, product security, foreign influence, and listing-related risks within the national-security analysis. | Data export assessment examines the legality, legitimacy, necessity, scale, sensitivity, recipient safeguards, transfer agreement, and risk to national security, public interests, and individual rights in the outbound transfer. | Share the data map, architecture, supplier, and recipient evidence, but issue separate findings for the covered activity and the covered transfer. | [Cybersecurity Review Measures](https://www.cac.gov.cn/2022-01/04/c_1642894602182845.htm?ref=sorena.io) - Use for cybersecurity review scope, CII procurement filing, platform operator review triggers, review materials, special review, and 15 February 2022 effective date.<br>[Measures for Security Assessment of Data Export](https://www.cac.gov.cn/2022-07/07/c_1658811536396503.htm?ref=sorena.io) - Use with the 2024 cross-border provisions for data export assessment triggers, application evidence, authority review, validity, and re-application.<br>[Provisions on Promoting and Regulating Cross-border Data Flow](https://www.cac.gov.cn/2024-03/22/c_1712776611775634.htm?ref=sorena.io) - Use for the current assessment thresholds, important-data identification rule, exemptions, three-year validity period, and extension route.<br>[PRC Cybersecurity Law](https://www.cac.gov.cn/2016-11/07/c_1119867116.htm?ref=sorena.io) - Use for network operator security duties, network product/service security, CII provisions, personal-information security articles, penalties, and 1 June 2017 effective date. |
| Practical decision rule | Run cybersecurity review when covered procurement, platform activity, or a qualifying foreign listing is the trigger, even if no data is exported. | Run data export assessment when a covered outbound transfer meets an important-data, CII, or current personal-information threshold, even if no procurement or listing is involved. | Run both when the same supplier, platform, listing, or cloud arrangement creates both triggers. Record separately why any exemption applies. | [Cybersecurity Review Measures](https://www.cac.gov.cn/2022-01/04/c_1642894602182845.htm?ref=sorena.io) - Use for cybersecurity review scope, CII procurement filing, platform operator review triggers, review materials, special review, and 15 February 2022 effective date.<br>[Measures for Security Assessment of Data Export](https://www.cac.gov.cn/2022-07/07/c_1658811536396503.htm?ref=sorena.io) - Use with the 2024 cross-border provisions for data export assessment triggers, application evidence, authority review, validity, and re-application.<br>[Provisions on Promoting and Regulating Cross-border Data Flow](https://www.cac.gov.cn/2024-03/22/c_1712776611775634.htm?ref=sorena.io) - Use for the current assessment thresholds, important-data identification rule, exemptions, three-year validity period, and extension route.<br>[PRC Cybersecurity Law](https://www.cac.gov.cn/2016-11/07/c_1119867116.htm?ref=sorena.io) - Use for network operator security duties, network product/service security, CII provisions, personal-information security articles, penalties, and 1 June 2017 effective date. |

Sources for Scope boundary - Cybersecurity review:

- [Cybersecurity Review Measures](https://www.cac.gov.cn/2022-01/04/c_1642894602182845.htm?ref=sorena.io) - Use for cybersecurity review scope, CII procurement filing, platform operator review triggers, review materials, special review, and 15 February 2022 effective date.

Sources for Scope boundary - Data export security assessment:

- [Measures for Security Assessment of Data Export](https://www.cac.gov.cn/2022-07/07/c_1658811536396503.htm?ref=sorena.io) - Use with the 2024 cross-border provisions for data export assessment triggers, application evidence, authority review, validity, and re-application.
- [Provisions on Promoting and Regulating Cross-border Data Flow](https://www.cac.gov.cn/2024-03/22/c_1712776611775634.htm?ref=sorena.io) - Use for the current assessment thresholds, important-data identification rule, exemptions, three-year validity period, and extension route.

Sources for Scope boundary - operational implication:

- [Cybersecurity Review Measures](https://www.cac.gov.cn/2022-01/04/c_1642894602182845.htm?ref=sorena.io) - Use for cybersecurity review scope, CII procurement filing, platform operator review triggers, review materials, special review, and 15 February 2022 effective date.
- [PRC Cybersecurity Law](https://www.cac.gov.cn/2016-11/07/c_1119867116.htm?ref=sorena.io) - Use for network operator security duties, network product/service security, CII provisions, personal-information security articles, penalties, and 1 June 2017 effective date.

Sources for Covered actors - Cybersecurity review:

- [Cybersecurity Review Measures](https://www.cac.gov.cn/2022-01/04/c_1642894602182845.htm?ref=sorena.io) - Use for cybersecurity review scope, CII procurement filing, platform operator review triggers, review materials, special review, and 15 February 2022 effective date.

Sources for Covered actors - Data export security assessment:

- [Measures for Security Assessment of Data Export](https://www.cac.gov.cn/2022-07/07/c_1658811536396503.htm?ref=sorena.io) - Use with the 2024 cross-border provisions for data export assessment triggers, application evidence, authority review, validity, and re-application.
- [Provisions on Promoting and Regulating Cross-border Data Flow](https://www.cac.gov.cn/2024-03/22/c_1712776611775634.htm?ref=sorena.io) - Use for the current assessment thresholds, important-data identification rule, exemptions, three-year validity period, and extension route.

Sources for Covered actors - operational implication:

- [Cybersecurity Review Measures](https://www.cac.gov.cn/2022-01/04/c_1642894602182845.htm?ref=sorena.io) - Use for cybersecurity review scope, CII procurement filing, platform operator review triggers, review materials, special review, and 15 February 2022 effective date.
- [PRC Cybersecurity Law](https://www.cac.gov.cn/2016-11/07/c_1119867116.htm?ref=sorena.io) - Use for network operator security duties, network product/service security, CII provisions, personal-information security articles, penalties, and 1 June 2017 effective date.

Sources for Trigger event - Cybersecurity review:

- [Cybersecurity Review Measures](https://www.cac.gov.cn/2022-01/04/c_1642894602182845.htm?ref=sorena.io) - Use for cybersecurity review scope, CII procurement filing, platform operator review triggers, review materials, special review, and 15 February 2022 effective date.

Sources for Trigger event - Data export security assessment:

- [Measures for Security Assessment of Data Export](https://www.cac.gov.cn/2022-07/07/c_1658811536396503.htm?ref=sorena.io) - Use with the 2024 cross-border provisions for data export assessment triggers, application evidence, authority review, validity, and re-application.
- [Provisions on Promoting and Regulating Cross-border Data Flow](https://www.cac.gov.cn/2024-03/22/c_1712776611775634.htm?ref=sorena.io) - Use for the current assessment thresholds, important-data identification rule, exemptions, three-year validity period, and extension route.

Sources for Trigger event - operational implication:

- [Cybersecurity Review Measures](https://www.cac.gov.cn/2022-01/04/c_1642894602182845.htm?ref=sorena.io) - Use for cybersecurity review scope, CII procurement filing, platform operator review triggers, review materials, special review, and 15 February 2022 effective date.
- [PRC Cybersecurity Law](https://www.cac.gov.cn/2016-11/07/c_1119867116.htm?ref=sorena.io) - Use for network operator security duties, network product/service security, CII provisions, personal-information security articles, penalties, and 1 June 2017 effective date.

Sources for Core obligations - Cybersecurity review:

- [Cybersecurity Review Measures](https://www.cac.gov.cn/2022-01/04/c_1642894602182845.htm?ref=sorena.io) - Use for cybersecurity review scope, CII procurement filing, platform operator review triggers, review materials, special review, and 15 February 2022 effective date.

Sources for Core obligations - Data export security assessment:

- [Measures for Security Assessment of Data Export](https://www.cac.gov.cn/2022-07/07/c_1658811536396503.htm?ref=sorena.io) - Use with the 2024 cross-border provisions for data export assessment triggers, application evidence, authority review, validity, and re-application.
- [Provisions on Promoting and Regulating Cross-border Data Flow](https://www.cac.gov.cn/2024-03/22/c_1712776611775634.htm?ref=sorena.io) - Use for the current assessment thresholds, important-data identification rule, exemptions, three-year validity period, and extension route.

Sources for Core obligations - operational implication:

- [Cybersecurity Review Measures](https://www.cac.gov.cn/2022-01/04/c_1642894602182845.htm?ref=sorena.io) - Use for cybersecurity review scope, CII procurement filing, platform operator review triggers, review materials, special review, and 15 February 2022 effective date.
- [PRC Cybersecurity Law](https://www.cac.gov.cn/2016-11/07/c_1119867116.htm?ref=sorena.io) - Use for network operator security duties, network product/service security, CII provisions, personal-information security articles, penalties, and 1 June 2017 effective date.

Sources for Evidence package - Cybersecurity review:

- [Cybersecurity Review Measures](https://www.cac.gov.cn/2022-01/04/c_1642894602182845.htm?ref=sorena.io) - Use for cybersecurity review scope, CII procurement filing, platform operator review triggers, review materials, special review, and 15 February 2022 effective date.

Sources for Evidence package - Data export security assessment:

- [Measures for Security Assessment of Data Export](https://www.cac.gov.cn/2022-07/07/c_1658811536396503.htm?ref=sorena.io) - Use with the 2024 cross-border provisions for data export assessment triggers, application evidence, authority review, validity, and re-application.
- [Provisions on Promoting and Regulating Cross-border Data Flow](https://www.cac.gov.cn/2024-03/22/c_1712776611775634.htm?ref=sorena.io) - Use for the current assessment thresholds, important-data identification rule, exemptions, three-year validity period, and extension route.

Sources for Evidence package - operational implication:

- [Cybersecurity Review Measures](https://www.cac.gov.cn/2022-01/04/c_1642894602182845.htm?ref=sorena.io) - Use for cybersecurity review scope, CII procurement filing, platform operator review triggers, review materials, special review, and 15 February 2022 effective date.
- [PRC Cybersecurity Law](https://www.cac.gov.cn/2016-11/07/c_1119867116.htm?ref=sorena.io) - Use for network operator security duties, network product/service security, CII provisions, personal-information security articles, penalties, and 1 June 2017 effective date.

Sources for Timing and refresh points - Cybersecurity review:

- [Cybersecurity Review Measures](https://www.cac.gov.cn/2022-01/04/c_1642894602182845.htm?ref=sorena.io) - Use for cybersecurity review scope, CII procurement filing, platform operator review triggers, review materials, special review, and 15 February 2022 effective date.

Sources for Timing and refresh points - Data export security assessment:

- [Measures for Security Assessment of Data Export](https://www.cac.gov.cn/2022-07/07/c_1658811536396503.htm?ref=sorena.io) - Use with the 2024 cross-border provisions for data export assessment triggers, application evidence, authority review, validity, and re-application.
- [Provisions on Promoting and Regulating Cross-border Data Flow](https://www.cac.gov.cn/2024-03/22/c_1712776611775634.htm?ref=sorena.io) - Use for the current assessment thresholds, important-data identification rule, exemptions, three-year validity period, and extension route.

Sources for Timing and refresh points - operational implication:

- [Cybersecurity Review Measures](https://www.cac.gov.cn/2022-01/04/c_1642894602182845.htm?ref=sorena.io) - Use for cybersecurity review scope, CII procurement filing, platform operator review triggers, review materials, special review, and 15 February 2022 effective date.
- [PRC Cybersecurity Law](https://www.cac.gov.cn/2016-11/07/c_1119867116.htm?ref=sorena.io) - Use for network operator security duties, network product/service security, CII provisions, personal-information security articles, penalties, and 1 June 2017 effective date.

Sources for Enforcement exposure - Cybersecurity review:

- [Cybersecurity Review Measures](https://www.cac.gov.cn/2022-01/04/c_1642894602182845.htm?ref=sorena.io) - Use for cybersecurity review scope, CII procurement filing, platform operator review triggers, review materials, special review, and 15 February 2022 effective date.
- [PRC Cybersecurity Law, consolidated after the 2025 amendment](https://www.cac.gov.cn/2025-12/29/c_1768735112911946.htm?ref=sorena.io) - Current official text for the liability provisions in force from 1 January 2026.

Sources for Enforcement exposure - Data export security assessment:

- [Measures for Security Assessment of Data Export](https://www.cac.gov.cn/2022-07/07/c_1658811536396503.htm?ref=sorena.io) - Use with the 2024 cross-border provisions for data export assessment triggers, application evidence, authority review, validity, and re-application.
- [Provisions on Promoting and Regulating Cross-border Data Flow](https://www.cac.gov.cn/2024-03/22/c_1712776611775634.htm?ref=sorena.io) - Use for the current assessment thresholds, important-data identification rule, exemptions, three-year validity period, and extension route.

Sources for Enforcement exposure - operational implication:

- [Cybersecurity Review Measures](https://www.cac.gov.cn/2022-01/04/c_1642894602182845.htm?ref=sorena.io) - Use for cybersecurity review scope, CII procurement filing, platform operator review triggers, review materials, special review, and 15 February 2022 effective date.
- [PRC Cybersecurity Law](https://www.cac.gov.cn/2016-11/07/c_1119867116.htm?ref=sorena.io) - Use for network operator security duties, network product/service security, CII provisions, personal-information security articles, penalties, and 1 June 2017 effective date.

Sources for Overlap and routing - Cybersecurity review:

- [Cybersecurity Review Measures](https://www.cac.gov.cn/2022-01/04/c_1642894602182845.htm?ref=sorena.io) - Use for cybersecurity review scope, CII procurement filing, platform operator review triggers, review materials, special review, and 15 February 2022 effective date.

Sources for Overlap and routing - Data export security assessment:

- [Measures for Security Assessment of Data Export](https://www.cac.gov.cn/2022-07/07/c_1658811536396503.htm?ref=sorena.io) - Use with the 2024 cross-border provisions for data export assessment triggers, application evidence, authority review, validity, and re-application.
- [Provisions on Promoting and Regulating Cross-border Data Flow](https://www.cac.gov.cn/2024-03/22/c_1712776611775634.htm?ref=sorena.io) - Use for the current assessment thresholds, important-data identification rule, exemptions, three-year validity period, and extension route.

Sources for Overlap and routing - operational implication:

- [Cybersecurity Review Measures](https://www.cac.gov.cn/2022-01/04/c_1642894602182845.htm?ref=sorena.io) - Use for cybersecurity review scope, CII procurement filing, platform operator review triggers, review materials, special review, and 15 February 2022 effective date.
- [PRC Cybersecurity Law](https://www.cac.gov.cn/2016-11/07/c_1119867116.htm?ref=sorena.io) - Use for network operator security duties, network product/service security, CII provisions, personal-information security articles, penalties, and 1 June 2017 effective date.

Sources for Practical decision rule - Cybersecurity review:

- [Cybersecurity Review Measures](https://www.cac.gov.cn/2022-01/04/c_1642894602182845.htm?ref=sorena.io) - Use for cybersecurity review scope, CII procurement filing, platform operator review triggers, review materials, special review, and 15 February 2022 effective date.

Sources for Practical decision rule - Data export security assessment:

- [Measures for Security Assessment of Data Export](https://www.cac.gov.cn/2022-07/07/c_1658811536396503.htm?ref=sorena.io) - Use with the 2024 cross-border provisions for data export assessment triggers, application evidence, authority review, validity, and re-application.
- [Provisions on Promoting and Regulating Cross-border Data Flow](https://www.cac.gov.cn/2024-03/22/c_1712776611775634.htm?ref=sorena.io) - Use for the current assessment thresholds, important-data identification rule, exemptions, three-year validity period, and extension route.

Sources for Practical decision rule - operational implication:

- [Cybersecurity Review Measures](https://www.cac.gov.cn/2022-01/04/c_1642894602182845.htm?ref=sorena.io) - Use for cybersecurity review scope, CII procurement filing, platform operator review triggers, review materials, special review, and 15 February 2022 effective date.
- [PRC Cybersecurity Law](https://www.cac.gov.cn/2016-11/07/c_1119867116.htm?ref=sorena.io) - Use for network operator security duties, network product/service security, CII provisions, personal-information security articles, penalties, and 1 June 2017 effective date.

### When to run one track or both

- Use cybersecurity review for covered CII procurement, covered platform activity affecting or possibly affecting national security, or the qualifying foreign-listing trigger.
- Use data export assessment for CII exports of personal information or important data and non-CII exports that meet the important-data or current personal-information thresholds, after testing the 2024 exemptions.
- Run both when both triggers exist; preserve separate filings, review results, conditions, expiry or change monitoring, and authority correspondence.

Sources for the practical decision rule:

- [Cybersecurity Review Measures](https://www.cac.gov.cn/2022-01/04/c_1642894602182845.htm?ref=sorena.io) - Use for cybersecurity review scope, CII procurement filing, platform operator review triggers, review materials, special review, and 15 February 2022 effective date.
- [PRC Cybersecurity Law](https://www.cac.gov.cn/2016-11/07/c_1119867116.htm?ref=sorena.io) - Use for network operator security duties, network product/service security, CII provisions, personal-information security articles, penalties, and 1 June 2017 effective date.
- [Measures for Security Assessment of Data Export](https://www.cac.gov.cn/2022-07/07/c_1658811536396503.htm?ref=sorena.io) - Use for the self-assessment, filing materials, authority review process, result conditions, and reapplication triggers.
- [Provisions on Promoting and Regulating Cross-border Data Flow](https://www.cac.gov.cn/2024-03/22/c_1712776611775634.htm?ref=sorena.io) - Use for current thresholds, exemptions, three-year validity, extension, and precedence over inconsistent earlier provisions.
- [2025 Decision amending the PRC Cybersecurity Law](https://www.npc.gov.cn/npc/c1773/c1848/c21114/wlaqfxz/wlaqfxz002/202511/t20251103_449242.html?ref=sorena.io) - Binding amendment effective on 1 January 2026; use for current liability provisions.

## How to use this comparison

Screen cybersecurity review from the procurement, platform-processing, and foreign-listing facts. A CII operator must apply before procuring a network product or service that affects or may affect national security. A network platform operator holding personal information on more than one million users must apply before listing abroad. The Review Office can also initiate review where covered activity affects or may affect national security.

Screen data export assessment from the exporter, data classification, destination, and cumulative volume since 1 January of the current year. A CII operator exporting personal information or important data must apply unless a 2024 exemption applies. A non-CII data processor must apply when exporting officially identified important data, at least one million individuals' non-sensitive personal information, or at least 10,000 individuals' sensitive personal information, again subject to the exemptions.

Apply the 22 March 2024 cross-border-data provisions with the 2022 assessment measures. A processor need not treat data as important for export filing unless a relevant department or region has notified it or publicly identified it as important. The 2024 provisions also exempt specified data without personal information or important data, pure transit of overseas-collected personal information without added China personal information or important data, certain necessary contract, human-resources, and emergency transfers, transfers of non-sensitive personal information involving fewer than 100,000 people by non-CII processors, and transfers outside an approved free-trade-zone negative list.

The 2024 provisions replace the earlier personal-information thresholds and extend an assessment result's validity to three years. If no reapplication trigger has occurred, the exporter may apply within the 60 working days before expiry for one extension of up to three years; the extension requires CAC approval.

- Procurement or listing owner: document the CII or platform status, covered event, national-security analysis, contracts or listing documents, filing, and review conditions.
- Data export owner: document data classification, exporter status, destination and recipient, annual individual counts, exemptions, personal information protection impact assessment, contract, filing, result, and reapplication monitoring.
- Program owner: link shared systems, suppliers, data inventories, and recipients without merging the two legal conclusions.

Sources for this answer:

- [Cybersecurity Review Measures](https://www.cac.gov.cn/2022-01/04/c_1642894602182845.htm?ref=sorena.io) - Use for cybersecurity review scope, CII procurement filing, platform operator review triggers, review materials, special review, and 15 February 2022 effective date.
- [PRC Cybersecurity Law, consolidated after the 2025 amendment](https://www.cac.gov.cn/2025-12/29/c_1768735112911946.htm?ref=sorena.io) - Current official text for network scope, CII procurement review, data-location cross-references, and liability after 1 January 2026.
- [2025 Decision amending the PRC Cybersecurity Law](https://www.npc.gov.cn/npc/c1773/c1848/c21114/wlaqfxz/wlaqfxz002/202511/t20251103_449242.html?ref=sorena.io) - Binding amendment effective on 1 January 2026; use for current article numbering and revised liability provisions.
- [Measures for Security Assessment of Data Export](https://www.cac.gov.cn/2022-07/07/c_1658811536396503.htm?ref=sorena.io) - Use for data export security assessment triggers, self-assessment, application materials, review timing, re-review, validity, and re-application triggers.
- [Provisions on Promoting and Regulating Cross-border Data Flow](https://www.cac.gov.cn/2024-03/22/c_1712776611775634.htm?ref=sorena.io) - Use for current data export exemptions, thresholds, three-year validity, extension process, and precedence over inconsistent earlier rules.

*Next step*

*Placement: Before primary sources*

## Route the activity and transfer separately

Link shared project facts to separate cybersecurity-review and data-export decisions, filings, results, and change monitoring.

- [Map official sources to evidence](/solutions/research-copilot.md): Link each review and export decision to its official source, owner, evidence, and change history.
- [Review the China route](/contact.md): Review unresolved national-security and data-export trigger questions.

## Primary sources

- [Cybersecurity Review Measures](https://www.cac.gov.cn/2022-01/04/c_1642894602182845.htm?ref=sorena.io) - Use for cybersecurity review scope, CII procurement filing, platform operator review triggers, review materials, special review, and 15 February 2022 effective date.
- [PRC Cybersecurity Law, consolidated after the 2025 amendment](https://www.cac.gov.cn/2025-12/29/c_1768735112911946.htm?ref=sorena.io) - Current official text for the liability provisions in force from 1 January 2026.
- [Measures for Security Assessment of Data Export](https://www.cac.gov.cn/2022-07/07/c_1658811536396503.htm?ref=sorena.io) - Use for the self-assessment, filing materials, authority review process, result conditions, and reapplication triggers.
- [Provisions on Promoting and Regulating Cross-border Data Flow](https://www.cac.gov.cn/2024-03/22/c_1712776611775634.htm?ref=sorena.io) - Use for current thresholds, exemptions, three-year validity, extension, and precedence over inconsistent earlier provisions.
- [PRC Personal Information Protection Law](https://www.cac.gov.cn/2021-08/20/c_1631050028355286.htm?ref=sorena.io) - Use for PIPL scope, processing bases, notice and consent, individual rights, processor duties, PIPIA, cross-border transfer duties, penalties, and effective date.
- [PRC Data Security Law](https://www.cac.gov.cn/2021-06/11/c_1624994566919140.htm?ref=sorena.io) - Use for data classification and graded protection, important-data risk assessment, security management, incident response, outbound important-data context, penalties, and 1 September 2021 effective date.
- [2025 Decision amending the PRC Cybersecurity Law](https://www.npc.gov.cn/npc/c1773/c1848/c21114/wlaqfxz/wlaqfxz002/202511/t20251103_449242.html?ref=sorena.io) - Binding amendment effective on 1 January 2026; use for current liability provisions.
- [PRC Cybersecurity Law](https://www.cac.gov.cn/2016-11/07/c_1119867116.htm?ref=sorena.io) - Use for network operator security duties, network product/service security, CII provisions, personal-information security articles, penalties, and 1 June 2017 effective date.

## Related Topic Guides

- [China App Filing vs Personal Information Rules](/artifacts/apac/china-cybersecurity-law/mobile-app-filing-vs-app-personal-information-rules.md): Decide whether a China mobile app needs MIIT filing, personal-information controls, or both, with current triggers, duties, dates, and evidence.
- [China cybersecurity and data security requirements](/artifacts/apac/china-cybersecurity-law/requirements.md): China cybersecurity requirements by actor: network operators, data processors, CII operators, platforms, app providers, and distribution platforms.
- [China cybersecurity compliance checklist](/artifacts/apac/china-cybersecurity-law/checklist.md): A China cybersecurity checklist for scoping network duties, data security, CII procurement review, app rules, MIIT filing, and supporting standards.
- [China cybersecurity deadlines and compliance calendar](/artifacts/apac/china-cybersecurity-law/deadlines-and-compliance-calendar.md): Separate China cybersecurity commencement dates from recurring duties, filing lead times, review periods, and event-driven response deadlines.
- [China Cybersecurity Law FAQ](/artifacts/apac/china-cybersecurity-law/faq.md): Practical answers on China network-operator scope, MLPS evidence, important data, cybersecurity review, app filing and governance, and smart-home standards under the law in force from 1 January 2026.
- [China Cybersecurity Law vs EU Cyber Resilience Act](/artifacts/apac/china-cybersecurity-law/china-cybersecurity-law-vs-eu-cyber-resilience-act.md): Compare China's network-operator rules with the EU CRA's product duties, including scope, actors, evidence, reporting dates, and launch decisions.
- [China Cybersecurity Law vs EU NIS2 Directive](/artifacts/apac/china-cybersecurity-law/china-cybersecurity-law-vs-nis2.md): Compare China's network-operator duties with NIS2 entity duties, including scope, management accountability, incident reporting, evidence, and enforcement.
- [China cybersecurity penalties and fines](/artifacts/apac/china-cybersecurity-law/penalties-and-fines.md): Compare current China Cybersecurity Law and Data Security Law fines by actor, breach, severity, and enforcement consequence.
- [China cybersecurity review workflow](/artifacts/apac/china-cybersecurity-law/cybersecurity-review-workflow.md): Determine whether CII procurement, platform data processing, or a qualifying foreign listing triggers China's Cybersecurity Review Measures.
- [China mobile app filing and app governance](/artifacts/apac/china-cybersecurity-law/mobile-app-filing-and-app-governance.md): Identify the China app sponsor, complete MIIT filing before service, and separate provider, platform, privacy, content, and security duties.
- [China Smart-Home Security vs Telecom and Radio Approval](/artifacts/apac/china-cybersecurity-law/smart-home-security-vs-telecom-wireless-launch.md): Separate GB/T 41387-2022 smart-home security evidence from China telecom network-access and radio approval decisions for connected products.
- [CII and network operator role triage](/artifacts/apac/china-cybersecurity-law/critical-information-infrastructure-and-network-operators.md): How to separate ordinary network operator duties from CII, procurement, and review-risk questions under China cybersecurity sources.
- [Does an app need MIIT filing and CAC app governance review?](/artifacts/apac/china-cybersecurity-law/faq/does-an-app-need-miit-filing-and-cac-app-governance-review.md): An app sponsor providing internet information services through an app in China must complete MIIT filing. CAC rules separately govern app providers and distribution platforms without creating one routine CAC approval for every app.
- [GB/T 22239-2019 classified protection baseline](/artifacts/apac/china-cybersecurity-law/classified-protection-baseline.md): How to scope and document a GB/T 22239-2019 classified protection baseline without treating the recommended standard as a standalone law.
- [GB/T 41387-2022 smart home security standard](/artifacts/apac/china-cybersecurity-law/smart-home-security-standard.md): How connected-device teams can scope and document GB/T 41387-2022 without treating it as an automatic certification or product-approval duty.
- [How do smart home security standards fit with China cybersecurity law?](/artifacts/apac/china-cybersecurity-law/faq/how-do-smart-home-security-standards-fit-with-china-cybersecurity-law.md): GB/T 41387-2022 can organize smart-home security evidence, but it is a recommended standard, not a product approval. Check app, data, MLPS, telecom access, and radio requirements separately.
- [How does important data change China cybersecurity obligations?](/artifacts/apac/china-cybersecurity-law/faq/how-does-important-data-change-cybersecurity-obligations.md): Once data is officially identified as important data, the processor needs named governance, periodic risk assessments and reports, incident controls, and a separate export decision. An internal sensitivity label alone does not establish the legal category.
- [Is every company a network operator under China Cybersecurity Law?](/artifacts/apac/china-cybersecurity-law/faq/is-every-company-a-network-operator-under-china-cybersecurity-law.md): No. Under China's Cybersecurity Law, a network operator is an owner or administrator of a network or a network service provider. Apply that definition to each China network or service, then test CII and other roles separately.
- [MLPS classified protection evidence map](/artifacts/apac/china-cybersecurity-law/mlps-classified-protection-evidence-map.md): Classify a China network under MLPS, complete level 2 or above filing, map controls, and retain assessment, remediation, and change evidence.
- [What is MLPS classified protection evidence?](/artifacts/apac/china-cybersecurity-law/faq/what-is-mlps-classified-protection-evidence.md): MLPS evidence shows how a defined China network or system was graded and protected. Keep the scope, grading rationale, filing or assessment records where applicable, control mapping, test results, remediation, and reassessment history.
- [When does China cybersecurity review apply?](/artifacts/apac/china-cybersecurity-law/faq/when-does-china-cybersecurity-review-apply.md): China cybersecurity review applies to CII procurement or network-platform data processing that affects or may affect national security, plus a mandatory pre-filing trigger for certain foreign listings involving more than one million users' personal information.


---

[Privacy Policy](https://www.sorena.io/privacy.md) | [Terms of Use](https://www.sorena.io/terms-of-use.md) | [DMCA](https://www.sorena.io/dmca.md) | [About Us](https://www.sorena.io/about-us.md)

(c) 2026 Sorena AB (559573-7338). All rights reserved.

Source: https://www.sorena.io/artifacts/apac/china-cybersecurity-law/cybersecurity-review-vs-data-export-security-assessment.md
