FAQChina

China Cybersecurity Law FAQ

Use these answers to decide who is a network operator, what MLPS evidence should contain, when important-data and cybersecurity-review rules apply, and how app and smart-home requirements fit together.

The Cybersecurity Law was amended in 2025 and the amended law took effect on 1 January 2026. The Data Security Law, app rules, review measures, and technical standards are separate instruments.

Author
Sorena AI
Published
Jul 5, 2026
Updated
Jul 24, 2026
FAQ modules
6

Structured answer sets in this page tree.

Primary sources
12

Cited legal and guidance references.

Publication metadata
Sorena AI
Published Jul 5, 2026
Updated Jul 24, 2026
Overview

Start with the China activity, system, , data, product, and transaction. These FAQs separate the Cybersecurity Law's baseline duties from evidence, important-data rules, , app filing and governance, and product standards.

Browse sub-FAQs

Choose the question set you need

These focused FAQ modules break this artifact into narrower answer sets so teams can move straight to the right source-backed guidance.

Browse all FAQ items12
Focused FAQ modules
6
Showing 6 of 6
FAQ module

Does an app need MIIT filing and CAC app governance review?

An app sponsor providing internet information services through an app in China must complete MIIT filing. CAC rules separately govern app providers and distribution platforms without creating one routine CAC approval for every app.

2 items
FAQ module

How do smart home security standards fit with China cybersecurity law?

GB/T 41387-2022 can organize smart-home security evidence, but it is a recommended standard, not a product approval. Check app, data, MLPS, telecom access, and radio requirements separately.

2 items
FAQ module

How does important data change China cybersecurity obligations?

Once data is officially identified as important data, the processor needs named governance, periodic risk assessments and reports, incident controls, and a separate export decision. An internal sensitivity label alone does not establish the legal category.

2 items
FAQ module

Is every company a network operator under China Cybersecurity Law?

No. Under China's Cybersecurity Law, a network operator is an owner or administrator of a network or a network service provider. Apply that definition to each China network or service, then test CII and other roles separately.

2 items
FAQ module

What is MLPS classified protection evidence?

MLPS evidence shows how a defined China network or system was graded and protected. Keep the scope, grading rationale, filing or assessment records where applicable, control mapping, test results, remediation, and reassessment history.

2 items
FAQ module

When does China cybersecurity review apply?

China cybersecurity review applies to CII procurement or network-platform data processing that affects or may affect national security, plus a mandatory pre-filing trigger for certain foreign listings involving more than one million users' personal information.

2 items
Question 1

Most China Cybersecurity Law questions start with scope

The Cybersecurity Law applies to building, operating, maintaining, and using networks in China. A is a network owner or administrator or a network service provider. Apply those definitions to each system and entity rather than labeling an entire corporate group.

Network operators have baseline classified-protection duties. Additional routes depend on separate facts: status and procurement, or , personal-information processing and export, operation of an app or distribution platform, radio functions, telecom network access, and sector rules.

The Cybersecurity Law was amended in 2025 and the amended law took effect on 1 January 2026. The amendment changed legal-liability provisions and added artificial-intelligence governance language. Use the amended law for current penalty or enforcement conclusions, while the linked full text supplies the core scope and duty provisions discussed in these FAQs.

  • Define the China network, system, app, platform, connected product, data flow, procurement, or listing transaction and the entity performing each role.
  • Map Article 23 controls, including responsible personnel, technical protection, monitoring, at least six months of network logs, data classification and backup, and the separate Article 27 incident plan.
  • Screen against current sector or regional catalogues, authority notices, and public identifications; keep personal information and as separate categories.
  • For procurement or network-platform processing, apply the Measures' national-security test and the distinct one-million-user foreign-listing trigger.
  • For apps, separate for the , app-provider duties under the 2022 provisions, a distribution platform's provincial cyberspace filing, and personal-information minimization.
  • For smart-home products, treat GB/T 41387-2022 as a recommended security standard and run telecom, radio, app, privacy, network-operation, and routes separately.
Question 2

How to use the FAQ answers

For each question, record the facts, actor, controlling source and version, conclusion, evidence owner, unresolved issue, approval or filing where applicable, and change triggers. A group-wide policy or product label cannot replace a system- or transaction-specific decision.

Keep related regimes distinct. Personal-information rights and export mechanisms belong in the privacy analysis. Telecom network access, radio approval, and mobile-terminal software rules need their own product analysis. Cross-link shared evidence without merging the legal conclusions.

  • Network-operator and other actor-role analysis for each system or service.
  • grading record and baseline security-control map.
  • Important-data screening, governance, assessment, and export decision.
  • Incident-response, vulnerability-remediation, backup, and log-retention evidence.
  • Cybersecurity-review intake decision and filing record where triggered.
  • , app-provider controls under the 2022 provisions, and distribution-platform filing and governance evidence.
  • Smart-home standard applicability and separate telecom, radio, privacy, app, and network-operation decisions.
Question 3

Frequently asked questions

Use the answer that matches the actor and activity. If the facts span several roles, keep a separate conclusion and evidence record for each instrument.

Which Cybersecurity Law text and article numbers apply now?

Use the Cybersecurity Law text amended on 28 October 2025 and effective from 1 January 2026. The amendment inserted new provisions and renumbered the operating rules. The current baseline classified-protection duties are in Article 23, network product and service duties in Article 24, network-operator incident duties in Article 27, duties in Articles 33-40, and network and network-operator definitions in Article 78. Older copies that cite Articles 21, 22, 25, 31-39, or 76 for those subjects use the pre-2026 numbering.

Is every a operator?

No. A is the owner or administrator of a network or a network service provider and carries the Article 23 and 27 baseline duties. Critical information infrastructure is a narrower category. The responsible sector protection department applies recognition rules to the specific facility or system, identifies it, and notifies the operator. Sector presence, company size, data volume, or a high level does not replace that notice.

What should an evidence file show?

An evidence file should identify the network, operator, system boundary, business functions, users, hosting, data, interfaces, dependencies, classification method and level, decision status, applicable standard edition and clauses, implemented controls, tests, findings, exceptions, remediation, and retest results. Under the general management measures, level 2 or higher systems have a 30-day filing rule, level 3 systems have at-least-annual assessment and self-inspection cycles, and level 4 systems have at-least-six-month cycles; level 5 follows special security needs. Sector routes can differ. GB/T 22239-2019 is a recommended national baseline standard, not a standalone law or universal certificate.

Does a large data set automatically become ?

No. is identified under the Data Security Law through the applicable national, regional, departmental, industry, or sector catalogue or an authority identification, with attention to the harm that misuse or compromise could cause. Data volume alone is not the classification test. If the data is important data, document the responsible person and management body, periodic risk assessment and report, incident process, and separate export-route decision.

When is a filing required?

A operator must first assess a procurement of network products or services before use and file when the procurement affects or may affect national security. The measures also cover a 's data-processing activity that affects or may affect national security. Separately, a network platform operator holding personal information of more than one million users must file before seeking a foreign listing. The measures use the phrase foreign listing, so check the current official interpretation for the specific destination and transaction. These triggers do not make every procurement, platform, overseas listing, or data export a filing.

Are and app-platform filing the same?

No. An providing an app-based internet information service in China completes through an access provider or distribution platform before a new covered app begins service. An separately files with its provincial cyberspace authority within 30 days after the platform goes online and maintains provider verification, listing and update review, monitoring, complaints, suspension, takedown, and reporting controls. One organisation may need both records if it holds both roles.

Does GB/T 41387-2022 require every smart-home product to be certified?

No. The official standards record identifies GB/T 41387-2022 as a current recommended national standard implemented on 1 November 2022. That record does not create automatic certification or product approval for every smart-home product. Obtain the complete applicable standard before making a clause-level claim, and assess telecom, radio, app, privacy, network-operation, and any voluntary China Cybersecurity Label route separately.

Sources for this answer
PRC Cybersecurity Law, current text
Current article numbering, network-operator baseline, product duties, incident duties, CII rules, and definitions.
Regulations on the Security Protection of Critical Information Infrastructure
CII definition, sector recognition rules, operator notification, and material-change reassessment.
PRC Data Security Law
Important-data catalogues, responsible person and management body, periodic assessment, reporting, incident, and export context.
Cybersecurity Review Measures
CII procurement and network-platform national-security triggers, one-million-user foreign-listing filing, and filing materials.
Mobile Internet Application Information Service Management Provisions
App-provider and distribution-platform scope, platform filing, verification, review, monitoring, complaints, and enforcement records.
MIIT notice on mobile app filing work
App-sponsor filing route, pre-service filing, display, changes, cancellation, and intermediary checks.
Official national standards record for GB/T 22239-2019
Current recommended classified-protection baseline standard and 1 December 2019 implementation date.
Official national standards record for GB/T 41387-2022
Current recommended smart-home security standard and 1 November 2022 implementation date.
Information Security Classified Protection Management Measures
Articles 14-18 support the general level 2-and-above filing period, level 3-5 assessment and self-inspection cycles, filing materials, and inspection rules summarized in the MLPS answer.
Primary sources

References and citations

cac.gov.cn
Referenced sections
  • CII procurement and network-platform national-security triggers, one-million-user foreign-listing filing, and filing materials.
cac.gov.cn
Referenced sections
  • Current article numbering, network-operator baseline, product duties, incident duties, CII rules, and definitions.
cac.gov.cn
Referenced sections
  • Important-data catalogues, responsible person and management body, periodic assessment, reporting, incident, and export context.
Related guides

Explore more topics

China App Filing vs Personal Information Rules
Decide whether a China mobile app needs MIIT filing, personal-information controls, or both, with current triggers, duties, dates, and evidence.
China cybersecurity and data security requirements
China cybersecurity requirements by actor: network operators, data processors, CII operators, platforms, app providers, and distribution platforms.
China cybersecurity compliance checklist
A China cybersecurity checklist for scoping network duties, data security, CII procurement review, app rules, MIIT filing, and supporting standards.
China cybersecurity deadlines and compliance calendar
Separate China cybersecurity commencement dates from recurring duties, filing lead times, review periods, and event-driven response deadlines.
China Cybersecurity Law vs EU Cyber Resilience Act
Compare China's network-operator rules with the EU CRA's product duties, including scope, actors, evidence, reporting dates, and launch decisions.
China Cybersecurity Law vs EU NIS2 Directive
Compare China's network-operator duties with NIS2 entity duties, including scope, management accountability, incident reporting, evidence, and enforcement.
China cybersecurity penalties and fines
Compare current China Cybersecurity Law and Data Security Law fines by actor, breach, severity, and enforcement consequence.
China Cybersecurity Review vs Data Export Assessment
Separate China's cybersecurity-review triggers from CAC data-export assessment triggers, thresholds, filings, evidence, timing, and reapplication rules.
China cybersecurity review workflow
Determine whether CII procurement, platform data processing, or a qualifying foreign listing triggers China's Cybersecurity Review Measures.
China mobile app filing and app governance
Identify the China app sponsor, complete MIIT filing before service, and separate provider, platform, privacy, content, and security duties.
China Smart-Home Security vs Telecom and Radio Approval
Separate GB/T 41387-2022 smart-home security evidence from China telecom network-access and radio approval decisions for connected products.
CII and network operator role triage
How to separate ordinary network operator duties from CII, procurement, and review-risk questions under China cybersecurity sources.
GB/T 22239-2019 classified protection baseline
How to scope and document a GB/T 22239-2019 classified protection baseline without treating the recommended standard as a standalone law.
GB/T 41387-2022 smart home security standard
How connected-device teams can scope and document GB/T 41387-2022 without treating it as an automatic certification or product-approval duty.
MLPS classified protection evidence map
Classify a China network under MLPS, complete level 2 or above filing, map controls, and retain assessment, remediation, and change evidence.