---
title: "China cybersecurity deadlines and compliance calendar"
canonical_url: "https://www.sorena.io/artifacts/apac/china-cybersecurity-law/deadlines-and-compliance-calendar"
source_url: "https://www.sorena.io/artifacts/apac/china-cybersecurity-law/deadlines-and-compliance-calendar"
author: "Sorena AI"
description: "Separate China cybersecurity commencement dates from recurring duties, filing lead times, review periods, and event-driven response deadlines."
published_at: "2026-07-05"
updated_at: "2026-07-24"
keywords:
  - "China Cybersecurity Law"
  - "Data Security Law"
  - "Cybersecurity Review Measures"
  - "Mobile app filing"
  - "MLPS"
---
**[SORENA](https://www.sorena.io/)** - AI-Powered GRC Platform

[Home](https://www.sorena.io/) | [Solutions](https://www.sorena.io/solutions) | [Artifacts](https://www.sorena.io/artifacts) | [About Us](https://www.sorena.io/about-us) | [Contact](https://www.sorena.io/contact) | [Portal](https://app.sorena.io)

---

# China cybersecurity deadlines and compliance calendar

Separate China cybersecurity commencement dates from recurring duties, filing lead times, review periods, and event-driven response deadlines.

*Cybersecurity* *China*

## China Cybersecurity Law deadlines and compliance calendar

Calendar the event that creates the duty, not the anniversary of the law: launch, procurement, filing, material change, assessment, defect, or incident.

The Cybersecurity Law first took effect on 1 June 2017 and its amended text has applied since 1 January 2026. Other dates below mark separate laws, measures, standards, and filing phases.

Most China cybersecurity dates are commencement dates, not annual renewals. A critical information infrastructure operator must assess its network security and risks at least once each year. Other work starts when a specific actor, system, procurement, app, data set, defect, or incident meets the relevant trigger.

## Definitions

### Network operator

A network operator is the owner or manager of a network or a network service provider. Under the amended Cybersecurity Law, this actor carries the general classified-protection, security-event monitoring, incident-response, data-protection, and network-log duties for the network it operates.

**Why it matters here:** The six-month log-retention floor and continuing baseline duties attach to the network operator. They do not depend on CII status or create one annual renewal date.

Sources:

- [PRC Cybersecurity Law, consolidated after the 2025 amendment](https://www.cac.gov.cn/2025-12/29/c_1768735112911946.htm?ref=sorena.io)

### Critical information infrastructure operator

A critical information infrastructure operator is the operator notified after the responsible protection department identifies its important network facility or information system as critical information infrastructure under the sector identification rules. Operating in energy, finance, transport, public services, or another listed sector does not by itself complete that identification.

**Why it matters here:** This status adds the at-least-annual network-security and risk assessment, report submission to the responsible protection department, and procurement-review screening described on this calendar.

Sources:

- [Regulations on the Security Protection of Critical Information Infrastructure](https://www.cac.gov.cn/2021-08/17/c_1630785976988160.htm?ref=sorena.io)
- [PRC Cybersecurity Law, consolidated after the 2025 amendment](https://www.cac.gov.cn/2025-12/29/c_1768735112911946.htm?ref=sorena.io)

### Important data

Important data is data that may endanger national security, economic operation, social stability, public health, or public safety if it is tampered with, destroyed, leaked, illegally obtained, or illegally used. It is a regulated classification, not a synonym for confidential business data or all personal information.

**Why it matters here:** An important-data processor must run periodic risk assessments and submit reports as required, but the Data Security Law does not set one universal annual date. Sector catalogues, authority identification, and applicable rules determine the reporting cycle and recipient.

Sources:

- [PRC Data Security Law](https://www.cac.gov.cn/2021-06/11/c_1624994566919140.htm?ref=sorena.io)
- [Measures for Security Assessment of Data Export](https://www.cac.gov.cn/2022-07/07/c_1658811536396503.htm?ref=sorena.io)

### App organizer

The app organizer is the organization or individual responsible for the app internet information service and named in the MIIT filing. It submits truthful filing information through its network access provider or app distribution platform to the provincial communications administration where it is domiciled.

**Why it matters here:** The organizer must complete filing before a new covered app begins service, display and link the filing number, and file changes or cancellation with the original filing authority. A platform or access provider may submit the material, but does not replace the organizer's responsibility.

Sources:

- [MIIT notice on mobile app filing work](https://www.miit.gov.cn/zwgk/zcwj/wjfb/tz/art/2023/art_920db564162e4312916a01bed6540ad8.html?ref=sorena.io)

## Legal milestones: use the text that applied on the event date

The Cybersecurity Law took effect on 1 June 2017. The National People's Congress Standing Committee amended it in 2025, and the amended provisions have applied since 1 January 2026. For an incident or decision before that date, check the version then in force; for current planning, use the consolidated amended text.

The Data Security Law took effect on 1 September 2021, the current Cybersecurity Review Measures on 15 February 2022, and the current Mobile Internet Application Information Service Management Provisions on 1 August 2022. GB/T 22239-2019 took effect on 1 December 2019. These dates identify applicable instruments; their anniversaries do not create a general annual filing.

- Record the event date, covered actor, system or app, affected data, and source version before assigning a deadline.
- Do not treat a voluntary GB/T standard's implementation anniversary as a statutory renewal. Determine separately whether a law, contract, procurement term, or classified-protection decision makes a control or assessment relevant.
- Reopen the analysis when the operator, architecture, data classification, supplier, listing plan, app information, or service changes.

Sources for this answer:

- [PRC Cybersecurity Law, consolidated after the 2025 amendment](https://www.cac.gov.cn/2025-12/29/c_1768735112911946.htm?ref=sorena.io) - Current official text, including the original 1 June 2017 commencement, amended article numbering, network-operator duties, CII duties, and legal responsibility.
- [NPC Standing Committee decision amending the PRC Cybersecurity Law](https://www.cac.gov.cn/2025-10/29/c_1763461514768457.htm?ref=sorena.io) - Establishes that the 2025 amendment took effect on 1 January 2026.
- [PRC Data Security Law](https://www.cac.gov.cn/2021-06/11/c_1624994566919140.htm?ref=sorena.io) - Articles 27, 29, and 30 establish data-security controls, immediate defect and incident action, and periodic important-data risk assessments; Article 55 sets 1 September 2021 as the commencement date.

## Fixed and procedure-based calendar entries

A critical information infrastructure operator must assess its network security and possible risks itself or through a network security service provider at least once each year, then submit the assessment and improvement measures to the responsible protection department. This annual duty belongs to the CII operator; it is not a general annual assessment rule for every network operator.

After a qualifying cybersecurity review filing is complete, the Cybersecurity Review Office has 10 working days to decide whether review is needed. If review starts, initial review is 30 working days and may be extended by 15 working days in a complex case. Relevant mechanism members and departments then have 15 working days to respond to the proposed conclusion. A special review generally takes 90 working days and may be extended in a complex case. Time spent supplying requested supplementary materials is excluded from these periods.

Under the general classified-protection management measures, an operator or user files an operating level 2 or higher information system within 30 days after determining its level; a new level 2 or higher system is filed within 30 days after entering operation. Level 3 systems undergo classified-protection assessment and self-inspection at least annually, level 4 systems at least every six months, and level 5 systems according to their special security needs. Sector regimes can use different objects, channels, or cycles, so record which route controls.

A successful data export security assessment is valid for three years from the result date. If the export will continue and no re-application trigger has occurred, the processor may apply through the provincial cyberspace authority for a three-year extension within 60 working days before expiry. Extension is subject to national cyberspace authority approval.

- CII annual assessment: assign the operator, covered networks, assessment period, responsible protection department, submission evidence, remediation owner, and next due date.
- Cybersecurity review: plan from complete submission, keep the written intake decision, and do not promise a completion date that ignores consultations, special review, or excluded supplementary-material time.
- General MLPS route: keep the grading decision, filing date and receipt, assessment and self-inspection schedule, findings, remediation, retest, and any separate sector filing. Do not treat a filing receipt as proof that controls passed assessment.
- Data export assessment: calendar the result date, three-year expiry, 60-working-day extension window, continued-export decision, and any change that requires a new application.
- Network logs: the Cybersecurity Law requires network operators to retain relevant network logs for at least six months. Treat this as a rolling retention floor, not a once-a-year task.
- App distribution platform filing: a platform must file with the provincial-level cyberspace authority within 30 days after commencing online operation.

Sources for this answer:

- [PRC Cybersecurity Law, consolidated after the 2025 amendment](https://www.cac.gov.cn/2025-12/29/c_1768735112911946.htm?ref=sorena.io) - Articles 23 and 40 establish the six-month network-log retention floor and the CII operator's at-least-annual security and risk assessment.
- [Cybersecurity Review Measures](https://www.cac.gov.cn/2022-01/04/c_1642894602182845.htm?ref=sorena.io) - Articles 9 and 11-15 establish the 10-, 30-, 15-, and 90-working-day procedure periods, possible extensions, and exclusion of supplementary-material time.
- [Mobile Internet Application Information Service Management Provisions](https://www.cac.gov.cn/2022-06/14/c_1656821626455324.htm?ref=sorena.io) - Article 17 requires an app distribution platform to file within 30 days after commencing online operation.
- [Information Security Classified Protection Management Measures](https://www.miit.gov.cn/jgsj/xxjsfzs/xxgk/art/2020/art_a981907528694176a61b5b52c2d19895.html?ref=sorena.io) - Articles 14-18 establish the general level 2-and-above filing periods, level 3-5 assessment and self-inspection cycles, filing materials, authority review, and inspection periods.
- [Provisions on Promoting and Regulating Cross-border Data Flow](https://www.cac.gov.cn/2024-03/22/c_1712776611775634.htm?ref=sorena.io) - Article 9 sets the three-year assessment-result validity period, the 60-working-day extension application window, and a possible three-year extension.

## Event-driven deadlines and branches

A CII operator must screen procurement before using a network product or service that may affect national security. The Cybersecurity Review Measures also require a network platform operator holding personal information of more than one million users to apply for review before seeking a listing in a foreign country. The Measures use that specific foreign-listing trigger; do not broaden it to every overseas capital-market transaction.

Data Security Law deadlines depend on the event. A processor that discovers a data-security defect, vulnerability, or other risk must take remedial measures immediately. When a data-security incident occurs, it must take response measures immediately and, as required, promptly notify users and report to the competent authority. A processor of important data must conduct risk assessments periodically and submit reports, but the Law does not supply one universal annual date for every sector.

- Before covered CII procurement: document the national-security risk pre-judgment, filing decision, submission materials, contractual security terms, and the review outcome before use.
- Before a qualifying foreign-listing application: confirm operator status and the personal-information count, then retain the review filing and decision.
- On discovery of a defect or vulnerability: open a response record immediately and document containment, remediation, user notice, and regulator reporting decisions.
- On an important-data classification or material processing change: identify the competent authority and sector rules, then set the assessment period and report date they require.
- On app launch: complete MIIT app filing before providing the internet information service. On a change or cancellation: file the corresponding procedure with the original filing authority.

Sources for this answer:

- [PRC Cybersecurity Law, consolidated after the 2025 amendment](https://www.cac.gov.cn/2025-12/29/c_1768735112911946.htm?ref=sorena.io) - Articles 37 and 38 govern CII procurement review and security/confidentiality agreements.
- [Cybersecurity Review Measures](https://www.cac.gov.cn/2022-01/04/c_1642894602182845.htm?ref=sorena.io) - Articles 5 and 7 establish the CII procurement pre-judgment and mandatory review for a network platform operator holding more than one million users' personal information before a foreign listing.
- [PRC Data Security Law](https://www.cac.gov.cn/2021-06/11/c_1624994566919140.htm?ref=sorena.io) - Articles 29 and 30 establish immediate defect and incident action and periodic important-data risk assessment and reporting without a universal statutory annual date.
- [MIIT notice on mobile app filing work](https://www.miit.gov.cn/zwgk/zcwj/wjfb/tz/art/2023/art_920db564162e4312916a01bed6540ad8.html?ref=sorena.io) - Requires filing before a new app begins internet information services and change or cancellation procedures with the original filing authority.

## MIIT app filing: historical transition and ongoing work

The MIIT notice used four implementation phases: preparation through August 2023, filing for existing apps from September 2023 through March 2024, supervision and inspection from April through June 2024, and normalized work from July 2024 onward. The first three periods have ended. They do not recur every year and should remain in a legal-history timeline, not appear as open deadlines.

In normalized work, a new app must be filed before service begins. The app organizer files through its network access provider or app distribution platform to the provincial communications administration where the organizer is domiciled. If submitted materials are complete and accurate, that authority is to complete filing within 20 working days and issue a filing number. The organizer must display the number prominently and link it to the filing system.

- App organizer: keep the submitted registration form, commitments, identity and network-resource checks, filing number, display and link evidence, and any sector approval required for regulated information services.
- Access provider or distribution platform: verify identity and network-resource information, submit through the national filing system, and do not provide access or distribution to an unfiled app.
- Distribution platform or terminal manufacturer: keep checks showing that apps offered for distribution or pre-installation have completed filing.
- Change control: compare each release against filed app information and start a change or cancellation filing when the recorded facts change.

Sources for this answer:

- [MIIT notice on mobile app filing work](https://www.miit.gov.cn/zwgk/zcwj/wjfb/tz/art/2023/art_920db564162e4312916a01bed6540ad8.html?ref=sorena.io) - Sets the four implementation phases, actor responsibilities, pre-service filing for new apps, 20-working-day authority period for complete and accurate materials, filing-number display, and change or cancellation procedures.

*Apply the requirement*

*Placement: Before primary sources*

## Build the China network security evidence file

Track each China Cybersecurity Law deadline against the responsible team, required filing or report, and retained evidence.

- [Map official sources to evidence](/solutions/research-copilot.md): Research Copilot connects the official citation, decision, owner, retained evidence, and change history.
- [Review the China route](/contact.md): Check the China Cybersecurity Law scope decision and unresolved launch questions with Sorena.

## Primary sources

- [PRC Cybersecurity Law, consolidated after the 2025 amendment](https://www.cac.gov.cn/2025-12/29/c_1768735112911946.htm?ref=sorena.io) - Current official text for network operators, CII operators, log retention, annual CII assessment, procurement review, incident action, and legal responsibility.
- [NPC Standing Committee decision amending the PRC Cybersecurity Law](https://www.cac.gov.cn/2025-10/29/c_1763461514768457.htm?ref=sorena.io) - Official amendment decision effective 1 January 2026.
- [PRC Data Security Law](https://www.cac.gov.cn/2021-06/11/c_1624994566919140.htm?ref=sorena.io) - Official text for data-security controls, immediate defect and incident response, periodic important-data assessment and reporting, and commencement.
- [Cybersecurity Review Measures](https://www.cac.gov.cn/2022-01/04/c_1642894602182845.htm?ref=sorena.io) - Official review triggers, materials, procedure periods, excluded supplementary-material time, commitments, and legal-responsibility cross-reference.
- [Mobile Internet Application Information Service Management Provisions](https://www.cac.gov.cn/2022-06/14/c_1656821626455324.htm?ref=sorena.io) - Official app-provider and distribution-platform governance rules, including the platform filing period.
- [MIIT notice on mobile app filing work](https://www.miit.gov.cn/zwgk/zcwj/wjfb/tz/art/2023/art_920db564162e4312916a01bed6540ad8.html?ref=sorena.io) - Official app filing phases, responsibilities, submission route, authority processing period, filing-number display, and change or cancellation process.
- [GB/T 22239-2019 classified protection baseline requirements](https://openstd.samr.gov.cn/bzgk/gb/newGbInfo?hcno=BAFB47E8874764186BDB7865E8344DAF&ref=sorena.io) - Official standards record showing the 1 December 2019 implementation date for the classified-protection baseline.
- [Information Security Classified Protection Management Measures](https://www.miit.gov.cn/jgsj/xxjsfzs/xxgk/art/2020/art_a981907528694176a61b5b52c2d19895.html?ref=sorena.io) - Official source for the five levels, general filing periods, recurring level 3-5 assessment and self-inspection cycles, filing materials, and inspection rules.
- [Provisions on Promoting and Regulating Cross-border Data Flow](https://www.cac.gov.cn/2024-03/22/c_1712776611775634.htm?ref=sorena.io) - Official source for current export-assessment triggers, the three-year result period, and the extension route.

## Related Topic Guides

- [China App Filing vs Personal Information Rules](/artifacts/apac/china-cybersecurity-law/mobile-app-filing-vs-app-personal-information-rules.md): Decide whether a China mobile app needs MIIT filing, personal-information controls, or both, with current triggers, duties, dates, and evidence.
- [China cybersecurity and data security requirements](/artifacts/apac/china-cybersecurity-law/requirements.md): China cybersecurity requirements by actor: network operators, data processors, CII operators, platforms, app providers, and distribution platforms.
- [China cybersecurity compliance checklist](/artifacts/apac/china-cybersecurity-law/checklist.md): A China cybersecurity checklist for scoping network duties, data security, CII procurement review, app rules, MIIT filing, and supporting standards.
- [China Cybersecurity Law FAQ](/artifacts/apac/china-cybersecurity-law/faq.md): Practical answers on China network-operator scope, MLPS evidence, important data, cybersecurity review, app filing and governance, and smart-home standards under the law in force from 1 January 2026.
- [China Cybersecurity Law vs EU Cyber Resilience Act](/artifacts/apac/china-cybersecurity-law/china-cybersecurity-law-vs-eu-cyber-resilience-act.md): Compare China's network-operator rules with the EU CRA's product duties, including scope, actors, evidence, reporting dates, and launch decisions.
- [China Cybersecurity Law vs EU NIS2 Directive](/artifacts/apac/china-cybersecurity-law/china-cybersecurity-law-vs-nis2.md): Compare China's network-operator duties with NIS2 entity duties, including scope, management accountability, incident reporting, evidence, and enforcement.
- [China cybersecurity penalties and fines](/artifacts/apac/china-cybersecurity-law/penalties-and-fines.md): Compare current China Cybersecurity Law and Data Security Law fines by actor, breach, severity, and enforcement consequence.
- [China Cybersecurity Review vs Data Export Assessment](/artifacts/apac/china-cybersecurity-law/cybersecurity-review-vs-data-export-security-assessment.md): Separate China's cybersecurity-review triggers from CAC data-export assessment triggers, thresholds, filings, evidence, timing, and reapplication rules.
- [China cybersecurity review workflow](/artifacts/apac/china-cybersecurity-law/cybersecurity-review-workflow.md): Determine whether CII procurement, platform data processing, or a qualifying foreign listing triggers China's Cybersecurity Review Measures.
- [China mobile app filing and app governance](/artifacts/apac/china-cybersecurity-law/mobile-app-filing-and-app-governance.md): Identify the China app sponsor, complete MIIT filing before service, and separate provider, platform, privacy, content, and security duties.
- [China Smart-Home Security vs Telecom and Radio Approval](/artifacts/apac/china-cybersecurity-law/smart-home-security-vs-telecom-wireless-launch.md): Separate GB/T 41387-2022 smart-home security evidence from China telecom network-access and radio approval decisions for connected products.
- [CII and network operator role triage](/artifacts/apac/china-cybersecurity-law/critical-information-infrastructure-and-network-operators.md): How to separate ordinary network operator duties from CII, procurement, and review-risk questions under China cybersecurity sources.
- [Does an app need MIIT filing and CAC app governance review?](/artifacts/apac/china-cybersecurity-law/faq/does-an-app-need-miit-filing-and-cac-app-governance-review.md): An app sponsor providing internet information services through an app in China must complete MIIT filing. CAC rules separately govern app providers and distribution platforms without creating one routine CAC approval for every app.
- [GB/T 22239-2019 classified protection baseline](/artifacts/apac/china-cybersecurity-law/classified-protection-baseline.md): How to scope and document a GB/T 22239-2019 classified protection baseline without treating the recommended standard as a standalone law.
- [GB/T 41387-2022 smart home security standard](/artifacts/apac/china-cybersecurity-law/smart-home-security-standard.md): How connected-device teams can scope and document GB/T 41387-2022 without treating it as an automatic certification or product-approval duty.
- [How do smart home security standards fit with China cybersecurity law?](/artifacts/apac/china-cybersecurity-law/faq/how-do-smart-home-security-standards-fit-with-china-cybersecurity-law.md): GB/T 41387-2022 can organize smart-home security evidence, but it is a recommended standard, not a product approval. Check app, data, MLPS, telecom access, and radio requirements separately.
- [How does important data change China cybersecurity obligations?](/artifacts/apac/china-cybersecurity-law/faq/how-does-important-data-change-cybersecurity-obligations.md): Once data is officially identified as important data, the processor needs named governance, periodic risk assessments and reports, incident controls, and a separate export decision. An internal sensitivity label alone does not establish the legal category.
- [Is every company a network operator under China Cybersecurity Law?](/artifacts/apac/china-cybersecurity-law/faq/is-every-company-a-network-operator-under-china-cybersecurity-law.md): No. Under China's Cybersecurity Law, a network operator is an owner or administrator of a network or a network service provider. Apply that definition to each China network or service, then test CII and other roles separately.
- [MLPS classified protection evidence map](/artifacts/apac/china-cybersecurity-law/mlps-classified-protection-evidence-map.md): Classify a China network under MLPS, complete level 2 or above filing, map controls, and retain assessment, remediation, and change evidence.
- [What is MLPS classified protection evidence?](/artifacts/apac/china-cybersecurity-law/faq/what-is-mlps-classified-protection-evidence.md): MLPS evidence shows how a defined China network or system was graded and protected. Keep the scope, grading rationale, filing or assessment records where applicable, control mapping, test results, remediation, and reassessment history.
- [When does China cybersecurity review apply?](/artifacts/apac/china-cybersecurity-law/faq/when-does-china-cybersecurity-review-apply.md): China cybersecurity review applies to CII procurement or network-platform data processing that affects or may affect national security, plus a mandatory pre-filing trigger for certain foreign listings involving more than one million users' personal information.


---

[Privacy Policy](https://www.sorena.io/privacy.md) | [Terms of Use](https://www.sorena.io/terms-of-use.md) | [DMCA](https://www.sorena.io/dmca.md) | [About Us](https://www.sorena.io/about-us.md)

(c) 2026 Sorena AB (559573-7338). All rights reserved.

Source: https://www.sorena.io/artifacts/apac/china-cybersecurity-law/deadlines-and-compliance-calendar.md
