---
title: "China cybersecurity review workflow"
canonical_url: "https://www.sorena.io/artifacts/apac/china-cybersecurity-law/cybersecurity-review-workflow"
source_url: "https://www.sorena.io/artifacts/apac/china-cybersecurity-law/cybersecurity-review-workflow"
author: "Sorena AI"
description: "Determine whether CII procurement, platform data processing, or a qualifying foreign listing triggers China's Cybersecurity Review Measures."
published_at: "2026-07-05"
updated_at: "2026-07-25"
keywords:
  - "China Cybersecurity Law"
  - "Data Security Law"
  - "Cybersecurity Review Measures"
  - "Mobile app filing"
  - "MLPS"
---
**[SORENA](https://www.sorena.io/)** - AI-Powered GRC Platform

[Home](https://www.sorena.io/) | [Solutions](https://www.sorena.io/solutions) | [Artifacts](https://www.sorena.io/artifacts) | [About Us](https://www.sorena.io/about-us) | [Contact](https://www.sorena.io/contact) | [Portal](https://app.sorena.io)

---

# China cybersecurity review workflow

Determine whether CII procurement, platform data processing, or a qualifying foreign listing triggers China's Cybersecurity Review Measures.

*Cybersecurity* *China*

## China Cybersecurity Law cybersecurity review workflow

Identify the actor and trigger before preparing a filing. Not every network operator, vendor purchase, data export, or security assessment is a cybersecurity review.

The Measures cover CII operators procuring network products or services and network platform operators conducting data processing where national security is or may be affected. A network platform operator holding personal information of more than one million users must also file before seeking a listing abroad.

Use this workflow to decide whether a critical information infrastructure operator's procurement, a network platform operator's data-processing activity, or a listing abroad requires a filing under China's Cybersecurity Review Measures.

## Definitions

### Critical information infrastructure operator

An operator is treated as a critical information infrastructure operator when the responsible protection department identifies an important network facility or information system as critical information infrastructure under its sector rules and notifies the operator. Relevant sectors include public communications and information services, energy, transport, water, finance, public services, e-government, and defence science and industry, but sector presence alone does not settle the classification.

**Why it matters here:** This status changes the procurement branch of the workflow. The operator must pre-judge whether use of a network product or service may affect national security and file for cybersecurity review when it does.

Sources:

- [Regulations on the Security Protection of Critical Information Infrastructure](https://www.cac.gov.cn/2021-08/17/c_1630785976988160.htm?ref=sorena.io)
- [Cybersecurity Review Measures](https://www.cac.gov.cn/2022-01/04/c_1642894602182845.htm?ref=sorena.io)

### Cybersecurity Review Office

The Cybersecurity Review Office is located within the Cyberspace Administration of China and organises cybersecurity reviews under the national review mechanism. It receives filings, decides whether a filed matter requires review, coordinates initial and special review, requests supplemental material, and issues the written conclusion.

**Why it matters here:** A required filing is made to this office. Its 10-working-day screening period starts only after it receives filing materials that satisfy Article 8, and time used to provide supplemental materials is excluded from the review periods.

Sources:

- [Cybersecurity Review Measures](https://www.cac.gov.cn/2022-01/04/c_1642894602182845.htm?ref=sorena.io)

### Network platform operator

The Cybersecurity Review Measures use this actor label for the platform operator in the data-processing and foreign-listing branches, but the Measures do not provide a standalone definition or a size test for the role. The entity operating the platform, controlling the relevant processing, and proposing the listing must be identified from the actual corporate and operating facts.

**Why it matters here:** Do not treat every website, app, network operator, or data processor as a network platform operator without recording the platform and operating facts. Once the role applies, national-security-sensitive processing may be reviewed at any scale, and Article 7 adds a mandatory pre-listing filing when the operator holds personal information of more than one million users.

Sources:

- [Cybersecurity Review Measures](https://www.cac.gov.cn/2022-01/04/c_1642894602182845.htm?ref=sorena.io)

### Network product or service

For cybersecurity review, network products and services principally include core network equipment, important communications products, high-performance computers and servers, mass-storage equipment, large databases and application software, cybersecurity equipment, cloud-computing services, and other products or services that significantly affect CII, network, or data security.

**Why it matters here:** This category sets the procurement object for the CII branch. Ordinary purchasing labels do not settle scope; record what is being acquired, how it will connect to the identified CII, and whether its use may affect national security.

Sources:

- [Cybersecurity Review Measures](https://www.cac.gov.cn/2022-01/04/c_1642894602182845.htm?ref=sorena.io)

### Special cybersecurity review

**Term:** special review

Special review is the additional procedure used when members of the national cybersecurity-review mechanism or relevant departments do not agree with the initial proposed conclusion. The Review Office conducts a deeper assessment, consults the mechanism again, obtains approval through the stated central process, and then gives the applicant a written conclusion.

**Why it matters here:** The Measures generally allow 90 working days for special review and permit an extension in a complex case without fixing the additional period. Time used to provide requested supplemental material is also excluded, so entry into special review prevents a reliable single-date completion forecast.

Sources:

- [Cybersecurity Review Measures](https://www.cac.gov.cn/2022-01/04/c_1642894602182845.htm?ref=sorena.io)

## 1. Identify the actor and review trigger

Start with the named legal entity and the activity. A critical information infrastructure operator procuring a network product or service must pre-judge the national-security risk created by using it and file when the procurement affects or may affect national security. A network platform operator conducting data processing is within the Measures when that activity affects or may affect national security.

Apply the separate Article 7 rule to a proposed listing abroad: a network platform operator holding personal information of more than one million users must file with the Cybersecurity Review Office before the listing. Article 7 uses the Chinese phrase for listing in a foreign country; it should not be assumed to cover or exclude a particular offshore venue without checking current authority practice and the transaction facts. The one-million-user threshold is not a general safe harbour: it does not exempt a smaller operator or another transaction from the broader national-security trigger. Review-mechanism members may also refer a product, service, or data-processing activity for review under Article 16.

- CII procurement branch: identify the notified CII operator, the product or service, supplier, intended use, affected critical functions, and the operator's written national-security pre-judgment.
- Platform data-processing branch: identify the operator, processing activity, core data, important data and personal-information scale, systems, overseas dependencies, and the facts connecting the activity to national security.
- Listing-abroad branch: confirm the listing destination, the network platform operator, and whether it holds personal information of more than one million users before the listing application is made.
- No express self-filing trigger found: retain the analysis, monitor material changes, and recognise that Article 16 permits an authority-initiated review. Do not invent a quantitative national-security safe harbour.

### Is one million users a general cybersecurity-review threshold?

No. More than one million users' personal information is the express filing threshold for a network platform operator seeking a listing abroad under Article 7. CII procurement and platform data processing can still require review at any scale when the activity affects or may affect national security, and Article 16 permits an authority-initiated review.

Sources for this answer:

- [Cybersecurity Review Measures](https://www.cac.gov.cn/2022-01/04/c_1642894602182845.htm?ref=sorena.io) - Articles 2, 5, 7 and 16 establish the CII-procurement, platform data-processing, mandatory listing-abroad and authority-initiated review paths.
- [Regulations on the Security Protection of Critical Information Infrastructure](https://www.cac.gov.cn/2021-08/17/c_1630785976988160.htm?ref=sorena.io) - Articles 2 and 8-11 explain the CII concept, sector recognition rules, operator notification and reassessment after material changes.

## 2. Build and submit the filing

If a filing is required, submit the application, an analysis of actual or possible effects on national security, the relevant procurement document, agreement, proposed contract or listing application, and any other material the review requires. Keep the analysis tied to the specific systems, data, supplier dependencies, transaction and listing facts.

For a CII procurement, the procurement documents or agreement must require the supplier to cooperate with review. The documents must include commitments not to use the supply relationship to obtain user data illegally, control or manipulate user equipment illegally, or interrupt supply or necessary technical support without proper reason.

- Confirm the actor, legal trigger and filing owner before drafting the application.
- Map the national-security analysis to the Article 10 risk factors and the evidence supporting each conclusion.
- Attach the correct transaction document and preserve the filed version, submission receipt and correspondence.
- For CII procurement, retain supplier due diligence, the required cooperation commitments and evidence that the supplier continues to honour commitments made during review.
- During review, implement any measures the authority requires to prevent or reduce risk.

Sources for this answer:

- [Cybersecurity Review Measures](https://www.cac.gov.cn/2022-01/04/c_1642894602182845.htm?ref=sorena.io) - Articles 6, 8, 16 and 19 establish procurement-document commitments, filing materials, risk-reduction measures during review and follow-through on supplier commitments.

## 3. Assess the review factors and timing

Article 10 requires an assessment of specific national-security risks. A generic vendor score is insufficient. Address possible illegal control, interference or destruction of CII; harm from supply interruption; product or service security, openness and transparency; source diversity and supply-channel reliability; supplier compliance with Chinese law; and risks to core data, important data or large volumes of personal information.

For a listing, also assess the risk that CII, core data, important data or large volumes of personal information could be influenced, controlled or maliciously used by a foreign government, together with other network and information-security risks.

- Completeness screening: the Cybersecurity Review Office has 10 working days from receipt of Article 8-compliant materials to decide whether review is needed and notify the filer in writing.
- Initial review: when review is opened, the office generally has 30 working days from its written notice to complete the initial review; a complex matter may add 15 working days.
- Department consultation: mechanism members and relevant departments have 15 working days to reply to the initial conclusion proposal.
- Special review: if opinions differ, the matter enters special review, which generally takes 90 working days and may be extended in complex cases.
- Excluded time: time used by the filer or supplier to provide requested supplemental material does not count toward the review periods. Treat the statutory periods as process stages, not guaranteed completion dates.

### Do the stated review periods guarantee a final decision date?

No. Complex initial reviews may be extended by 15 working days, complex special reviews may be extended without a fixed additional period in the Measures, and time used to supply requested supplemental material is excluded. Plan against each procedural stage and the written notices, not a single guaranteed end date.

Sources for this answer:

- [Cybersecurity Review Measures](https://www.cac.gov.cn/2022-01/04/c_1642894602182845.htm?ref=sorena.io) - Articles 9-15 list the review factors and set the completeness, initial-review, consultation, special-review and supplemental-material timing rules.

## 4. Record the outcome and keep nearby regimes separate

Retain the trigger analysis, filed materials, supplemental submissions, supplier commitments, risk-reduction measures, written notices and final conclusion. Reopen the analysis when the operator, CII status, product or service, supplier, use case, data categories or volume, listing plan, affected systems, or national-security risk changes.

A cybersecurity review is separate from a personal-information or important-data export assessment, MLPS work, CII annual risk assessment, app filing, sector licensing and foreign-investment security review. The same facts may feed several analyses, but one approval or filing does not replace another.

- Do not treat every data export as a cybersecurity-review filing; apply the actor and national-security triggers first.
- Do not close CII supplier approval before recording the procurement pre-judgment and required contract commitments.
- Do not treat the Article 7 threshold as a safe harbour for other transactions or for authority-initiated review.
- Keep the written review conclusion and ongoing supplier commitments linked to the approved transaction.

Related resources:

- [CII and network operator role triage](/artifacts/apac/china-cybersecurity-law/critical-information-infrastructure-and-network-operators.md): Determine whether the system is ordinary network infrastructure or authority-identified CII before applying the procurement branch.
- [MLPS classified protection evidence map](/artifacts/apac/china-cybersecurity-law/mlps-classified-protection-evidence-map.md): Keep the separate classified-protection baseline, filing, assessment and remediation evidence for the affected network.

Sources for this answer:

- [Cybersecurity Review Measures](https://www.cac.gov.cn/2022-01/04/c_1642894602182845.htm?ref=sorena.io) - Articles 19, 21 and 22 cover post-review supplier commitments, the products and services within scope, and the coexistence of other security-review regimes.
- [Amended PRC Cybersecurity Law](https://www.cac.gov.cn/2025-12/29/c_1768735112911946.htm?ref=sorena.io) - Current consolidated law, effective 1 January 2026, including CII procurement review and security-confidentiality agreement duties in Articles 37 and 38.

*Apply the requirement*

*Placement: Before primary sources*

## Build the China network security evidence file

Turn the cybersecurity-review decision into named owners, filed materials, supplier commitments, written notices and change triggers.

- [Map official sources to evidence](/solutions/research-copilot.md): Connect the official source, decision, owner, retained evidence and change history.
- [Review the China route](/contact.md): Check the China Cybersecurity Law scope decision and unresolved launch questions with Sorena.

## Primary sources

- [Cybersecurity Review Measures](https://www.cac.gov.cn/2022-01/04/c_1642894602182845.htm?ref=sorena.io) - Binding review rules effective 15 February 2022 for triggers, filings, review factors, procedure, timing and post-review commitments.
- [Amended PRC Cybersecurity Law](https://www.cac.gov.cn/2025-12/29/c_1768735112911946.htm?ref=sorena.io) - Current consolidated Cybersecurity Law, effective 1 January 2026, including the CII procurement review and supplier-agreement provisions.
- [Regulations on the Security Protection of Critical Information Infrastructure](https://www.cac.gov.cn/2021-08/17/c_1630785976988160.htm?ref=sorena.io) - Binding CII regulation for the CII definition, sector recognition process, operator notification and procurement duties.

## Related Topic Guides

- [China App Filing vs Personal Information Rules](/artifacts/apac/china-cybersecurity-law/mobile-app-filing-vs-app-personal-information-rules.md): Decide whether a China mobile app needs MIIT filing, personal-information controls, or both, with current triggers, duties, dates, and evidence.
- [China cybersecurity and data security requirements](/artifacts/apac/china-cybersecurity-law/requirements.md): China cybersecurity requirements by actor: network operators, data processors, CII operators, platforms, app providers, and distribution platforms.
- [China cybersecurity compliance checklist](/artifacts/apac/china-cybersecurity-law/checklist.md): A China cybersecurity checklist for scoping network duties, data security, CII procurement review, app rules, MIIT filing, and supporting standards.
- [China cybersecurity deadlines and compliance calendar](/artifacts/apac/china-cybersecurity-law/deadlines-and-compliance-calendar.md): Separate China cybersecurity commencement dates from recurring duties, filing lead times, review periods, and event-driven response deadlines.
- [China Cybersecurity Law FAQ](/artifacts/apac/china-cybersecurity-law/faq.md): Practical answers on China network-operator scope, MLPS evidence, important data, cybersecurity review, app filing and governance, and smart-home standards under the law in force from 1 January 2026.
- [China Cybersecurity Law vs EU Cyber Resilience Act](/artifacts/apac/china-cybersecurity-law/china-cybersecurity-law-vs-eu-cyber-resilience-act.md): Compare China's network-operator rules with the EU CRA's product duties, including scope, actors, evidence, reporting dates, and launch decisions.
- [China Cybersecurity Law vs EU NIS2 Directive](/artifacts/apac/china-cybersecurity-law/china-cybersecurity-law-vs-nis2.md): Compare China's network-operator duties with NIS2 entity duties, including scope, management accountability, incident reporting, evidence, and enforcement.
- [China cybersecurity penalties and fines](/artifacts/apac/china-cybersecurity-law/penalties-and-fines.md): Compare current China Cybersecurity Law and Data Security Law fines by actor, breach, severity, and enforcement consequence.
- [China Cybersecurity Review vs Data Export Assessment](/artifacts/apac/china-cybersecurity-law/cybersecurity-review-vs-data-export-security-assessment.md): Separate China's cybersecurity-review triggers from CAC data-export assessment triggers, thresholds, filings, evidence, timing, and reapplication rules.
- [China mobile app filing and app governance](/artifacts/apac/china-cybersecurity-law/mobile-app-filing-and-app-governance.md): Identify the China app sponsor, complete MIIT filing before service, and separate provider, platform, privacy, content, and security duties.
- [China Smart-Home Security vs Telecom and Radio Approval](/artifacts/apac/china-cybersecurity-law/smart-home-security-vs-telecom-wireless-launch.md): Separate GB/T 41387-2022 smart-home security evidence from China telecom network-access and radio approval decisions for connected products.
- [CII and network operator role triage](/artifacts/apac/china-cybersecurity-law/critical-information-infrastructure-and-network-operators.md): How to separate ordinary network operator duties from CII, procurement, and review-risk questions under China cybersecurity sources.
- [Does an app need MIIT filing and CAC app governance review?](/artifacts/apac/china-cybersecurity-law/faq/does-an-app-need-miit-filing-and-cac-app-governance-review.md): An app sponsor providing internet information services through an app in China must complete MIIT filing. CAC rules separately govern app providers and distribution platforms without creating one routine CAC approval for every app.
- [GB/T 22239-2019 classified protection baseline](/artifacts/apac/china-cybersecurity-law/classified-protection-baseline.md): How to scope and document a GB/T 22239-2019 classified protection baseline without treating the recommended standard as a standalone law.
- [GB/T 41387-2022 smart home security standard](/artifacts/apac/china-cybersecurity-law/smart-home-security-standard.md): How connected-device teams can scope and document GB/T 41387-2022 without treating it as an automatic certification or product-approval duty.
- [How do smart home security standards fit with China cybersecurity law?](/artifacts/apac/china-cybersecurity-law/faq/how-do-smart-home-security-standards-fit-with-china-cybersecurity-law.md): GB/T 41387-2022 can organize smart-home security evidence, but it is a recommended standard, not a product approval. Check app, data, MLPS, telecom access, and radio requirements separately.
- [How does important data change China cybersecurity obligations?](/artifacts/apac/china-cybersecurity-law/faq/how-does-important-data-change-cybersecurity-obligations.md): Once data is officially identified as important data, the processor needs named governance, periodic risk assessments and reports, incident controls, and a separate export decision. An internal sensitivity label alone does not establish the legal category.
- [Is every company a network operator under China Cybersecurity Law?](/artifacts/apac/china-cybersecurity-law/faq/is-every-company-a-network-operator-under-china-cybersecurity-law.md): No. Under China's Cybersecurity Law, a network operator is an owner or administrator of a network or a network service provider. Apply that definition to each China network or service, then test CII and other roles separately.
- [MLPS classified protection evidence map](/artifacts/apac/china-cybersecurity-law/mlps-classified-protection-evidence-map.md): Classify a China network under MLPS, complete level 2 or above filing, map controls, and retain assessment, remediation, and change evidence.
- [What is MLPS classified protection evidence?](/artifacts/apac/china-cybersecurity-law/faq/what-is-mlps-classified-protection-evidence.md): MLPS evidence shows how a defined China network or system was graded and protected. Keep the scope, grading rationale, filing or assessment records where applicable, control mapping, test results, remediation, and reassessment history.
- [When does China cybersecurity review apply?](/artifacts/apac/china-cybersecurity-law/faq/when-does-china-cybersecurity-review-apply.md): China cybersecurity review applies to CII procurement or network-platform data processing that affects or may affect national security, plus a mandatory pre-filing trigger for certain foreign listings involving more than one million users' personal information.


---

[Privacy Policy](https://www.sorena.io/privacy.md) | [Terms of Use](https://www.sorena.io/terms-of-use.md) | [DMCA](https://www.sorena.io/dmca.md) | [About Us](https://www.sorena.io/about-us.md)

(c) 2026 Sorena AB (559573-7338). All rights reserved.

Source: https://www.sorena.io/artifacts/apac/china-cybersecurity-law/cybersecurity-review-workflow.md
