CybersecurityChina

China Cybersecurity Law cybersecurity review workflow

Identify the actor and trigger before preparing a filing. Not every network operator, vendor purchase, data export, or security assessment is a cybersecurity review.

The Measures cover CII operators procuring network products or services and network platform operators conducting data processing where national security is or may be affected. A network platform operator holding personal information of more than one million users must also file before seeking a listing abroad.

Author
Sorena AI
Published
Jul 5, 2026
Updated
Jul 25, 2026
Sections
4

Structured answer sets in this page tree.

Primary sources
3

Cited legal and guidance references.

Publication metadata
Sorena AI
Published Jul 5, 2026
Updated Jul 25, 2026
Overview

Use this workflow to decide whether a 's procurement, a 's data-processing activity, or a listing abroad requires a filing under China's Cybersecurity Review Measures.

Section 1

1. Identify the actor and review trigger

Start with the named legal entity and the activity. A procuring a must pre-judge the national-security risk created by using it and file when the procurement affects or may affect national security. A conducting data processing is within the Measures when that activity affects or may affect national security.

Apply the separate Article 7 rule to a proposed listing abroad: a holding personal information of more than one million users must file with the before the listing. Article 7 uses the Chinese phrase for listing in a foreign country; it should not be assumed to cover or exclude a particular offshore venue without checking current authority practice and the transaction facts. The one-million-user threshold is not a general safe harbour: it does not exempt a smaller operator or another transaction from the broader national-security trigger. Review-mechanism members may also refer a product, service, or data-processing activity for review under Article 16.

Is one million users a general cybersecurity-review threshold?

No. More than one million users' personal information is the express filing threshold for a seeking a listing abroad under Article 7. CII procurement and platform data processing can still require review at any scale when the activity affects or may affect national security, and Article 16 permits an authority-initiated review.

  • CII procurement branch: identify the notified CII operator, the product or service, supplier, intended use, affected critical functions, and the operator's written national-security pre-judgment.
  • Platform data-processing branch: identify the operator, processing activity, core data, important data and personal-information scale, systems, overseas dependencies, and the facts connecting the activity to national security.
  • Listing-abroad branch: confirm the listing destination, the , and whether it holds personal information of more than one million users before the listing application is made.
  • No express self-filing trigger found: retain the analysis, monitor material changes, and recognise that Article 16 permits an authority-initiated review. Do not invent a quantitative national-security safe harbour.
Section 2

2. Build and submit the filing

If a filing is required, submit the application, an analysis of actual or possible effects on national security, the relevant procurement document, agreement, proposed contract or listing application, and any other material the review requires. Keep the analysis tied to the specific systems, data, supplier dependencies, transaction and listing facts.

For a CII procurement, the procurement documents or agreement must require the supplier to cooperate with review. The documents must include commitments not to use the supply relationship to obtain user data illegally, control or manipulate user equipment illegally, or interrupt supply or necessary technical support without proper reason.

  • Confirm the actor, legal trigger and filing owner before drafting the application.
  • Map the national-security analysis to the Article 10 risk factors and the evidence supporting each conclusion.
  • Attach the correct transaction document and preserve the filed version, submission receipt and correspondence.
  • For CII procurement, retain supplier due diligence, the required cooperation commitments and evidence that the supplier continues to honour commitments made during review.
  • During review, implement any measures the authority requires to prevent or reduce risk.
Section 3

3. Assess the review factors and timing

Article 10 requires an assessment of specific national-security risks. A generic vendor score is insufficient. Address possible illegal control, interference or destruction of CII; harm from supply interruption; product or service security, openness and transparency; source diversity and supply-channel reliability; supplier compliance with Chinese law; and risks to core data, important data or large volumes of personal information.

For a listing, also assess the risk that CII, core data, important data or large volumes of personal information could be influenced, controlled or maliciously used by a foreign government, together with other network and information-security risks.

Do the stated review periods guarantee a final decision date?

No. Complex initial reviews may be extended by 15 working days, complex special reviews may be extended without a fixed additional period in the Measures, and time used to supply requested supplemental material is excluded. Plan against each procedural stage and the written notices, not a single guaranteed end date.

  • Completeness screening: the has 10 working days from receipt of Article 8-compliant materials to decide whether review is needed and notify the filer in writing.
  • Initial review: when review is opened, the office generally has 30 working days from its written notice to complete the initial review; a complex matter may add 15 working days.
  • Department consultation: mechanism members and relevant departments have 15 working days to reply to the initial conclusion proposal.
  • : if opinions differ, the matter enters special review, which generally takes 90 working days and may be extended in complex cases.
  • Excluded time: time used by the filer or supplier to provide requested supplemental material does not count toward the review periods. Treat the statutory periods as process stages, not guaranteed completion dates.
Section 4

4. Record the outcome and keep nearby regimes separate

Retain the trigger analysis, filed materials, supplemental submissions, supplier commitments, risk-reduction measures, written notices and final conclusion. Reopen the analysis when the operator, CII status, product or service, supplier, use case, data categories or volume, listing plan, affected systems, or national-security risk changes.

A cybersecurity review is separate from a personal-information or important-data export assessment, MLPS work, CII annual risk assessment, app filing, sector licensing and foreign-investment security review. The same facts may feed several analyses, but one approval or filing does not replace another.

  • Do not treat every data export as a cybersecurity-review filing; apply the actor and national-security triggers first.
  • Do not close CII supplier approval before recording the procurement pre-judgment and required contract commitments.
  • Do not treat the Article 7 threshold as a safe harbour for other transactions or for authority-initiated review.
  • Keep the written review conclusion and ongoing supplier commitments linked to the approved transaction.
Apply the requirement

Build the China network security evidence file

Turn the cybersecurity-review decision into named owners, filed materials, supplier commitments, written notices and change triggers.

Primary sources

References and citations

cac.gov.cn
Referenced sections
  • Current consolidated law, effective 1 January 2026, including CII procurement review and security-confidentiality agreement duties in Articles 37 and 38.
cac.gov.cn
Referenced sections
  • Articles 19, 21 and 22 cover post-review supplier commitments, the products and services within scope, and the coexistence of other security-review regimes.
Related guides

Explore more topics

China App Filing vs Personal Information Rules
Decide whether a China mobile app needs MIIT filing, personal-information controls, or both, with current triggers, duties, dates, and evidence.
China cybersecurity and data security requirements
China cybersecurity requirements by actor: network operators, data processors, CII operators, platforms, app providers, and distribution platforms.
China cybersecurity compliance checklist
A China cybersecurity checklist for scoping network duties, data security, CII procurement review, app rules, MIIT filing, and supporting standards.
China cybersecurity deadlines and compliance calendar
Separate China cybersecurity commencement dates from recurring duties, filing lead times, review periods, and event-driven response deadlines.
China Cybersecurity Law FAQ
Practical answers on China network-operator scope, MLPS evidence, important data, cybersecurity review, app filing and governance, and smart-home standards under the law in force from 1 January 2026.
China Cybersecurity Law vs EU Cyber Resilience Act
Compare China's network-operator rules with the EU CRA's product duties, including scope, actors, evidence, reporting dates, and launch decisions.
China Cybersecurity Law vs EU NIS2 Directive
Compare China's network-operator duties with NIS2 entity duties, including scope, management accountability, incident reporting, evidence, and enforcement.
China cybersecurity penalties and fines
Compare current China Cybersecurity Law and Data Security Law fines by actor, breach, severity, and enforcement consequence.
China Cybersecurity Review vs Data Export Assessment
Separate China's cybersecurity-review triggers from CAC data-export assessment triggers, thresholds, filings, evidence, timing, and reapplication rules.
China mobile app filing and app governance
Identify the China app sponsor, complete MIIT filing before service, and separate provider, platform, privacy, content, and security duties.
China Smart-Home Security vs Telecom and Radio Approval
Separate GB/T 41387-2022 smart-home security evidence from China telecom network-access and radio approval decisions for connected products.
CII and network operator role triage
How to separate ordinary network operator duties from CII, procurement, and review-risk questions under China cybersecurity sources.
Does an app need MIIT filing and CAC app governance review?
An app sponsor providing internet information services through an app in China must complete MIIT filing. CAC rules separately govern app providers and distribution platforms without creating one routine CAC approval for every app.
GB/T 22239-2019 classified protection baseline
How to scope and document a GB/T 22239-2019 classified protection baseline without treating the recommended standard as a standalone law.
GB/T 41387-2022 smart home security standard
How connected-device teams can scope and document GB/T 41387-2022 without treating it as an automatic certification or product-approval duty.
How do smart home security standards fit with China cybersecurity law?
GB/T 41387-2022 can organize smart-home security evidence, but it is a recommended standard, not a product approval. Check app, data, MLPS, telecom access, and radio requirements separately.
How does important data change China cybersecurity obligations?
Once data is officially identified as important data, the processor needs named governance, periodic risk assessments and reports, incident controls, and a separate export decision. An internal sensitivity label alone does not establish the legal category.
Is every company a network operator under China Cybersecurity Law?
No. Under China's Cybersecurity Law, a network operator is an owner or administrator of a network or a network service provider. Apply that definition to each China network or service, then test CII and other roles separately.
MLPS classified protection evidence map
Classify a China network under MLPS, complete level 2 or above filing, map controls, and retain assessment, remediation, and change evidence.
What is MLPS classified protection evidence?
MLPS evidence shows how a defined China network or system was graded and protected. Keep the scope, grading rationale, filing or assessment records where applicable, control mapping, test results, remediation, and reassessment history.
When does China cybersecurity review apply?
China cybersecurity review applies to CII procurement or network-platform data processing that affects or may affect national security, plus a mandatory pre-filing trigger for certain foreign listings involving more than one million users' personal information.