CybersecurityChina

China Cybersecurity Law deadlines and compliance calendar

Calendar the event that creates the duty, not the anniversary of the law: launch, procurement, filing, material change, assessment, defect, or incident.

The Cybersecurity Law first took effect on 1 June 2017 and its amended text has applied since 1 January 2026. Other dates below mark separate laws, measures, standards, and filing phases.

Author
Sorena AI
Published
Jul 5, 2026
Updated
Jul 24, 2026
Sections
4

Structured answer sets in this page tree.

Primary sources
9

Cited legal and guidance references.

Publication metadata
Sorena AI
Published Jul 5, 2026
Updated Jul 24, 2026
Overview

Most China cybersecurity dates are commencement dates, not annual renewals. A must assess its network security and risks at least once each year. Other work starts when a specific actor, system, procurement, app, data set, defect, or incident meets the relevant trigger.

Section 2

Fixed and procedure-based calendar entries

A must assess its network security and possible risks itself or through a network security service provider at least once each year, then submit the assessment and improvement measures to the responsible protection department. This annual duty belongs to the CII operator; it is not a general annual assessment rule for every .

After a qualifying cybersecurity review filing is complete, the Cybersecurity Review Office has 10 working days to decide whether review is needed. If review starts, initial review is 30 working days and may be extended by 15 working days in a complex case. Relevant mechanism members and departments then have 15 working days to respond to the proposed conclusion. A special review generally takes 90 working days and may be extended in a complex case. Time spent supplying requested supplementary materials is excluded from these periods.

Under the general classified-protection management measures, an operator or user files an operating level 2 or higher information system within 30 days after determining its level; a new level 2 or higher system is filed within 30 days after entering operation. Level 3 systems undergo classified-protection assessment and self-inspection at least annually, level 4 systems at least every six months, and level 5 systems according to their special security needs. Sector regimes can use different objects, channels, or cycles, so record which route controls.

A successful data export security assessment is valid for three years from the result date. If the export will continue and no re-application trigger has occurred, the processor may apply through the provincial cyberspace authority for a three-year extension within 60 working days before expiry. Extension is subject to national cyberspace authority approval.

  • CII annual assessment: assign the operator, covered networks, assessment period, responsible protection department, submission evidence, remediation owner, and next due date.
  • Cybersecurity review: plan from complete submission, keep the written intake decision, and do not promise a completion date that ignores consultations, special review, or excluded supplementary-material time.
  • General MLPS route: keep the grading decision, filing date and receipt, assessment and self-inspection schedule, findings, remediation, retest, and any separate sector filing. Do not treat a filing receipt as proof that controls passed assessment.
  • Data export assessment: calendar the result date, three-year expiry, 60-working-day extension window, continued-export decision, and any change that requires a new application.
  • Network logs: the Cybersecurity Law requires network operators to retain relevant network logs for at least six months. Treat this as a rolling retention floor, not a once-a-year task.
  • App distribution platform filing: a platform must file with the provincial-level cyberspace authority within 30 days after commencing online operation.
Section 3

Event-driven deadlines and branches

A CII operator must screen procurement before using a network product or service that may affect national security. The Cybersecurity Review Measures also require a network platform operator holding personal information of more than one million users to apply for review before seeking a listing in a foreign country. The Measures use that specific foreign-listing trigger; do not broaden it to every overseas capital-market transaction.

Data Security Law deadlines depend on the event. A processor that discovers a data-security defect, vulnerability, or other risk must take remedial measures immediately. When a data-security incident occurs, it must take response measures immediately and, as required, promptly notify users and report to the competent authority. A processor of must conduct risk assessments periodically and submit reports, but the Law does not supply one universal annual date for every sector.

  • Before covered CII procurement: document the national-security risk pre-judgment, filing decision, submission materials, contractual security terms, and the review outcome before use.
  • Before a qualifying foreign-listing application: confirm operator status and the personal-information count, then retain the review filing and decision.
  • On discovery of a defect or vulnerability: open a response record immediately and document containment, remediation, user notice, and regulator reporting decisions.
  • On an important-data classification or material processing change: identify the competent authority and sector rules, then set the assessment period and report date they require.
  • On app launch: complete MIIT app filing before providing the internet information service. On a change or cancellation: file the corresponding procedure with the original filing authority.
Section 4

MIIT app filing: historical transition and ongoing work

The MIIT notice used four implementation phases: preparation through August 2023, filing for existing apps from September 2023 through March 2024, supervision and inspection from April through June 2024, and normalized work from July 2024 onward. The first three periods have ended. They do not recur every year and should remain in a legal-history timeline, not appear as open deadlines.

In normalized work, a new app must be filed before service begins. The files through its network access provider or app distribution platform to the provincial communications administration where the organizer is domiciled. If submitted materials are complete and accurate, that authority is to complete filing within 20 working days and issue a filing number. The organizer must display the number prominently and link it to the filing system.

  • : keep the submitted registration form, commitments, identity and network-resource checks, filing number, display and link evidence, and any sector approval required for regulated information services.
  • Access provider or distribution platform: verify identity and network-resource information, submit through the national filing system, and do not provide access or distribution to an unfiled app.
  • Distribution platform or terminal manufacturer: keep checks showing that apps offered for distribution or pre-installation have completed filing.
  • Change control: compare each release against filed app information and start a change or cancellation filing when the recorded facts change.
Primary sources

References and citations

cac.gov.cn
Referenced sections
  • Articles 5 and 7 establish the CII procurement pre-judgment and mandatory review for a network platform operator holding more than one million users' personal information before a foreign listing.
miit.gov.cn
Referenced sections
  • Sets the four implementation phases, actor responsibilities, pre-service filing for new apps, 20-working-day authority period for complete and accurate materials, filing-number display, and change or cancellation procedures.
cac.gov.cn
Referenced sections
  • Articles 29 and 30 establish immediate defect and incident action and periodic important-data risk assessment and reporting without a universal statutory annual date.
Related guides

Explore more topics

China App Filing vs Personal Information Rules
Decide whether a China mobile app needs MIIT filing, personal-information controls, or both, with current triggers, duties, dates, and evidence.
China cybersecurity and data security requirements
China cybersecurity requirements by actor: network operators, data processors, CII operators, platforms, app providers, and distribution platforms.
China cybersecurity compliance checklist
A China cybersecurity checklist for scoping network duties, data security, CII procurement review, app rules, MIIT filing, and supporting standards.
China Cybersecurity Law FAQ
Practical answers on China network-operator scope, MLPS evidence, important data, cybersecurity review, app filing and governance, and smart-home standards under the law in force from 1 January 2026.
China Cybersecurity Law vs EU Cyber Resilience Act
Compare China's network-operator rules with the EU CRA's product duties, including scope, actors, evidence, reporting dates, and launch decisions.
China Cybersecurity Law vs EU NIS2 Directive
Compare China's network-operator duties with NIS2 entity duties, including scope, management accountability, incident reporting, evidence, and enforcement.
China cybersecurity penalties and fines
Compare current China Cybersecurity Law and Data Security Law fines by actor, breach, severity, and enforcement consequence.
China Cybersecurity Review vs Data Export Assessment
Separate China's cybersecurity-review triggers from CAC data-export assessment triggers, thresholds, filings, evidence, timing, and reapplication rules.
China cybersecurity review workflow
Determine whether CII procurement, platform data processing, or a qualifying foreign listing triggers China's Cybersecurity Review Measures.
China mobile app filing and app governance
Identify the China app sponsor, complete MIIT filing before service, and separate provider, platform, privacy, content, and security duties.
China Smart-Home Security vs Telecom and Radio Approval
Separate GB/T 41387-2022 smart-home security evidence from China telecom network-access and radio approval decisions for connected products.
CII and network operator role triage
How to separate ordinary network operator duties from CII, procurement, and review-risk questions under China cybersecurity sources.
Does an app need MIIT filing and CAC app governance review?
An app sponsor providing internet information services through an app in China must complete MIIT filing. CAC rules separately govern app providers and distribution platforms without creating one routine CAC approval for every app.
GB/T 22239-2019 classified protection baseline
How to scope and document a GB/T 22239-2019 classified protection baseline without treating the recommended standard as a standalone law.
GB/T 41387-2022 smart home security standard
How connected-device teams can scope and document GB/T 41387-2022 without treating it as an automatic certification or product-approval duty.
How do smart home security standards fit with China cybersecurity law?
GB/T 41387-2022 can organize smart-home security evidence, but it is a recommended standard, not a product approval. Check app, data, MLPS, telecom access, and radio requirements separately.
How does important data change China cybersecurity obligations?
Once data is officially identified as important data, the processor needs named governance, periodic risk assessments and reports, incident controls, and a separate export decision. An internal sensitivity label alone does not establish the legal category.
Is every company a network operator under China Cybersecurity Law?
No. Under China's Cybersecurity Law, a network operator is an owner or administrator of a network or a network service provider. Apply that definition to each China network or service, then test CII and other roles separately.
MLPS classified protection evidence map
Classify a China network under MLPS, complete level 2 or above filing, map controls, and retain assessment, remediation, and change evidence.
What is MLPS classified protection evidence?
MLPS evidence shows how a defined China network or system was graded and protected. Keep the scope, grading rationale, filing or assessment records where applicable, control mapping, test results, remediation, and reassessment history.
When does China cybersecurity review apply?
China cybersecurity review applies to CII procurement or network-platform data processing that affects or may affect national security, plus a mandatory pre-filing trigger for certain foreign listings involving more than one million users' personal information.