China Cybersecurity Law deadlines and compliance calendar
Calendar the event that creates the duty, not the anniversary of the law: launch, procurement, filing, material change, assessment, defect, or incident.
The Cybersecurity Law first took effect on 1 June 2017 and its amended text has applied since 1 January 2026. Other dates below mark separate laws, measures, standards, and filing phases.
Most China cybersecurity dates are commencement dates, not annual renewals. A must assess its network security and risks at least once each year. Other work starts when a specific actor, system, procurement, app, data set, defect, or incident meets the relevant trigger.
1
Section 1
Legal milestones: use the text that applied on the event date
The Cybersecurity Law took effect on 1 June 2017. The National People's Congress Standing Committee amended it in 2025, and the amended provisions have applied since 1 January 2026. For an incident or decision before that date, check the version then in force; for current planning, use the consolidated amended text.
The Data Security Law took effect on 1 September 2021, the current Cybersecurity Review Measures on 15 February 2022, and the current Mobile Internet Application Information Service Management Provisions on 1 August 2022. GB/T 22239-2019 took effect on 1 December 2019. These dates identify applicable instruments; their anniversaries do not create a general annual filing.
Record the event date, covered actor, system or app, affected data, and source version before assigning a deadline.
Do not treat a voluntary GB/T standard's implementation anniversary as a statutory renewal. Determine separately whether a law, contract, procurement term, or classified-protection decision makes a control or assessment relevant.
Reopen the analysis when the operator, architecture, data classification, supplier, listing plan, app information, or service changes.
A must assess its network security and possible risks itself or through a network security service provider at least once each year, then submit the assessment and improvement measures to the responsible protection department. This annual duty belongs to the CII operator; it is not a general annual assessment rule for every .
After a qualifying cybersecurity review filing is complete, the Cybersecurity Review Office has 10 working days to decide whether review is needed. If review starts, initial review is 30 working days and may be extended by 15 working days in a complex case. Relevant mechanism members and departments then have 15 working days to respond to the proposed conclusion. A special review generally takes 90 working days and may be extended in a complex case. Time spent supplying requested supplementary materials is excluded from these periods.
Under the general classified-protection management measures, an operator or user files an operating level 2 or higher information system within 30 days after determining its level; a new level 2 or higher system is filed within 30 days after entering operation. Level 3 systems undergo classified-protection assessment and self-inspection at least annually, level 4 systems at least every six months, and level 5 systems according to their special security needs. Sector regimes can use different objects, channels, or cycles, so record which route controls.
A successful data export security assessment is valid for three years from the result date. If the export will continue and no re-application trigger has occurred, the processor may apply through the provincial cyberspace authority for a three-year extension within 60 working days before expiry. Extension is subject to national cyberspace authority approval.
CII annual assessment: assign the operator, covered networks, assessment period, responsible protection department, submission evidence, remediation owner, and next due date.
Cybersecurity review: plan from complete submission, keep the written intake decision, and do not promise a completion date that ignores consultations, special review, or excluded supplementary-material time.
General MLPS route: keep the grading decision, filing date and receipt, assessment and self-inspection schedule, findings, remediation, retest, and any separate sector filing. Do not treat a filing receipt as proof that controls passed assessment.
Data export assessment: calendar the result date, three-year expiry, 60-working-day extension window, continued-export decision, and any change that requires a new application.
Network logs: the Cybersecurity Law requires network operators to retain relevant network logs for at least six months. Treat this as a rolling retention floor, not a once-a-year task.
App distribution platform filing: a platform must file with the provincial-level cyberspace authority within 30 days after commencing online operation.
A CII operator must screen procurement before using a network product or service that may affect national security. The Cybersecurity Review Measures also require a network platform operator holding personal information of more than one million users to apply for review before seeking a listing in a foreign country. The Measures use that specific foreign-listing trigger; do not broaden it to every overseas capital-market transaction.
Data Security Law deadlines depend on the event. A processor that discovers a data-security defect, vulnerability, or other risk must take remedial measures immediately. When a data-security incident occurs, it must take response measures immediately and, as required, promptly notify users and report to the competent authority. A processor of must conduct risk assessments periodically and submit reports, but the Law does not supply one universal annual date for every sector.
Before covered CII procurement: document the national-security risk pre-judgment, filing decision, submission materials, contractual security terms, and the review outcome before use.
Before a qualifying foreign-listing application: confirm operator status and the personal-information count, then retain the review filing and decision.
On discovery of a defect or vulnerability: open a response record immediately and document containment, remediation, user notice, and regulator reporting decisions.
On an important-data classification or material processing change: identify the competent authority and sector rules, then set the assessment period and report date they require.
On app launch: complete MIIT app filing before providing the internet information service. On a change or cancellation: file the corresponding procedure with the original filing authority.
MIIT app filing: historical transition and ongoing work
The MIIT notice used four implementation phases: preparation through August 2023, filing for existing apps from September 2023 through March 2024, supervision and inspection from April through June 2024, and normalized work from July 2024 onward. The first three periods have ended. They do not recur every year and should remain in a legal-history timeline, not appear as open deadlines.
In normalized work, a new app must be filed before service begins. The files through its network access provider or app distribution platform to the provincial communications administration where the organizer is domiciled. If submitted materials are complete and accurate, that authority is to complete filing within 20 working days and issue a filing number. The organizer must display the number prominently and link it to the filing system.
: keep the submitted registration form, commitments, identity and network-resource checks, filing number, display and link evidence, and any sector approval required for regulated information services.
Access provider or distribution platform: verify identity and network-resource information, submit through the national filing system, and do not provide access or distribution to an unfiled app.
Distribution platform or terminal manufacturer: keep checks showing that apps offered for distribution or pre-installation have completed filing.
Change control: compare each release against filed app information and start a change or cancellation filing when the recorded facts change.
Articles 5 and 7 establish the CII procurement pre-judgment and mandatory review for a network platform operator holding more than one million users' personal information before a foreign listing.
Sets the four implementation phases, actor responsibilities, pre-service filing for new apps, 20-working-day authority period for complete and accurate materials, filing-number display, and change or cancellation procedures.
Articles 29 and 30 establish immediate defect and incident action and periodic important-data risk assessment and reporting without a universal statutory annual date.