---
title: "China Cybersecurity Law FAQ"
canonical_url: "https://www.sorena.io/artifacts/apac/china-cybersecurity-law/faq"
source_url: "https://www.sorena.io/artifacts/apac/china-cybersecurity-law/faq"
author: "Sorena AI"
description: "Practical answers on China network-operator scope, MLPS evidence, important data, cybersecurity review, app filing and governance, and smart-home standards under the law in force from 1 January 2026."
published_at: "2026-07-05"
updated_at: "2026-07-24"
keywords:
  - "China Cybersecurity Law"
  - "Data Security Law"
  - "Cybersecurity Review Measures"
  - "Mobile app filing"
  - "MLPS"
---
**[SORENA](https://www.sorena.io/)** - AI-Powered GRC Platform

[Home](https://www.sorena.io/) | [Solutions](https://www.sorena.io/solutions) | [Artifacts](https://www.sorena.io/artifacts) | [About Us](https://www.sorena.io/about-us) | [Contact](https://www.sorena.io/contact) | [Portal](https://app.sorena.io)

---

# China Cybersecurity Law FAQ

Practical answers on China network-operator scope, MLPS evidence, important data, cybersecurity review, app filing and governance, and smart-home standards under the law in force from 1 January 2026.

*FAQ* *China*

## China Cybersecurity Law FAQ

Use these answers to decide who is a network operator, what MLPS evidence should contain, when important-data and cybersecurity-review rules apply, and how app and smart-home requirements fit together.

The Cybersecurity Law was amended in 2025 and the amended law took effect on 1 January 2026. The Data Security Law, app rules, review measures, and technical standards are separate instruments.

Start with the China activity, system, network operator, data, product, and transaction. These FAQs separate the Cybersecurity Law's baseline duties from MLPS evidence, important-data rules, cybersecurity review, app filing and governance, and product standards.

## Definitions

### Network operator

The current Cybersecurity Law defines a network operator as the owner or administrator of a network or a network service provider. A network is a system of computers or other information terminals and related equipment that collects, stores, transmits, exchanges, or processes information under defined rules and procedures.

**Why it matters here:** Identify the legal entity that owns, administers, or provides the specific network service in China. That entity carries the Article 23 classified-protection baseline and Article 27 incident duties for the network; the label should not be assigned to a corporate group without a system-level analysis.

Sources:

- [PRC Cybersecurity Law, Articles 23, 27, and 78](https://www.cac.gov.cn/2025-12/29/c_1768735112911946.htm?ref=sorena.io)

### Critical information infrastructure

**Term:** CII

CII means important network facilities and information systems in sectors such as public communications and information services, energy, transport, water, finance, public services, e-government, and defence science and industry, plus other infrastructure whose destruction, loss of function, or data leakage could seriously harm national security, the national economy and people's livelihoods, or the public interest.

**Why it matters here:** The responsible sector protection department applies its recognition rules, identifies the infrastructure, and notifies the operator. A network operator, large company, high classified-protection level, or business in a named sector is not automatically a CII operator.

Sources:

- [Regulations on the Security Protection of Critical Information Infrastructure, Articles 2 and 8-11](https://www.cac.gov.cn/2021-08/17/c_1630785976988160.htm?ref=sorena.io)

### Multi-Level Protection Scheme

**Term:** MLPS

MLPS is a common English label for China's network security classified-protection system. Article 23 of the current Cybersecurity Law imposes baseline classified-protection duties on network operators. GB/T 22239-2019 is a recommended national baseline standard used within the wider system, not a standalone statute or a universal certification requirement.

**Why it matters here:** Define the network boundary, operator, classification method and level before selecting controls or describing an assessment result. MLPS classification does not decide CII, important-data, cybersecurity-review, privacy, or app-filing status.

Sources:

- [PRC Cybersecurity Law, Articles 23 and 78](https://www.cac.gov.cn/2025-12/29/c_1768735112911946.htm?ref=sorena.io)
- [Official national standards record for GB/T 22239-2019](https://openstd.samr.gov.cn/bzgk/gb/newGbInfo?hcno=BAFB47E8874764186BDB7865E8344DAF&ref=sorena.io)

### Important data

The Data Security Law requires important data to receive enhanced protection under national and relevant regional, departmental, industry, and sector catalogues. The classification turns on the applicable catalogue, authority identification, and the harm that alteration, destruction, leakage, illegal acquisition, or illegal use could cause; a data-volume threshold alone does not create the category.

**Why it matters here:** A processor of important data must identify a data-security responsible person and management body, conduct periodic risk assessments, submit reports to the relevant competent department, respond to incidents, and analyse any export under the applicable route.

Sources:

- [PRC Data Security Law, Articles 21 and 27-31](https://www.cac.gov.cn/2021-06/11/c_1624994566919140.htm?ref=sorena.io)

### Cybersecurity review

Cybersecurity review is the national-security review under the Cybersecurity Review Measures. It covers CII operators procuring network products or services and network platform operators conducting data-processing activities when the activity affects or may affect national security. A network platform operator holding personal information of more than one million users must also file before seeking a foreign listing.

**Why it matters here:** Identify the actor and trigger before preparing a filing. Keep the procurement national-security screen, platform data-processing screen, and specific one-million-user foreign-listing filing separate from data-export security assessment.

Sources:

- [Cybersecurity Review Measures, Articles 2 and 5-10](https://www.cac.gov.cn/2022-01/04/c_1642894602182845.htm?ref=sorena.io)

### Ministry of Industry and Information Technology app filing

**Term:** MIIT app filing

MIIT app filing is the filing for an app sponsor providing an app-based internet information service in China. The sponsor submits through a network access provider or app distribution platform to the provincial communications administration for the sponsor's place of residence. A new covered app files before service begins, displays the filing number and query link, and files later changes or cancellation.

**Why it matters here:** This sponsor filing is separate from the provincial cyberspace filing and continuing governance duties that apply to an app distribution platform.

Sources:

- [MIIT notice on mobile app filing work](https://www.miit.gov.cn/zwgk/zcwj/wjfb/tz/art/2023/art_920db564162e4312916a01bed6540ad8.html?ref=sorena.io)

### Mobile app distribution platform

**Term:** app distribution platform

An app distribution platform is an internet information service provider that offers app publication, download, or dynamic-loading services. The 2022 app provisions include app stores, quick-app centres, internet mini-program platforms, and browser plug-in platforms.

**Why it matters here:** The platform files with its provincial cyberspace authority within 30 days after going online and maintains provider verification, listing and update review, monitoring, complaint, enforcement-record, suspension, takedown, and reporting controls. These duties are separate from an app sponsor's MIIT filing.

Sources:

- [Mobile Internet Application Information Service Management Provisions, Articles 2 and 17-22](https://www.cac.gov.cn/2022-06/14/c_1656821626455324.htm?ref=sorena.io)

### Core data

Core data is the Data Security Law's highest-protection category for data connected to national security, the lifelines of the national economy, important aspects of people's livelihoods, or major public interests. The law requires stricter management of core data than the general classified and graded protection system.

**Why it matters here:** Do not use core data as a synonym for important data, personal information, commercially sensitive data, or a large data set. Record the authority, catalogue, or other controlling basis for the classification and apply the stricter management required for the category.

Sources:

- [PRC Data Security Law, Article 21](https://www.cac.gov.cn/2021-06/11/c_1624994566919140.htm?ref=sorena.io)

### App sponsor for MIIT filing

**Term:** app sponsor

The app sponsor is the organisation or individual providing the app-based internet information service and named in the MIIT filing. It supplies truthful identity, network-resource, service, approval, and contact information, displays the filing number and query link, and files changes or cancellation.

**Why it matters here:** Confirm the filed legal entity instead of assuming that the developer, brand owner, app provider, access provider, or distribution platform is the sponsor. One entity may hold several roles, but each role needs its own record.

Sources:

- [MIIT notice on mobile app filing work](https://www.miit.gov.cn/zwgk/zcwj/wjfb/tz/art/2023/art_920db564162e4312916a01bed6540ad8.html?ref=sorena.io)

### Network platform operator under the Cybersecurity Review Measures

**Term:** network platform operator

The Cybersecurity Review Measures use network platform operator for the operator whose data-processing activity affects or may affect national security. The measures also require such an operator to file before a foreign listing when it holds personal information of more than one million users. The term is not defined as another name for every network operator, online service, or CII operator.

**Why it matters here:** Document the platform role, data-processing activity, user count, listing destination, and national-security analysis. The measures use the phrase foreign listing; check the current official interpretation for a specific destination or transaction rather than extending the trigger to every overseas corporate event.

Sources:

- [Cybersecurity Review Measures, Articles 2 and 7-10](https://www.cac.gov.cn/2022-01/04/c_1642894602182845.htm?ref=sorena.io)

## Browse sub-FAQ modules

### [Does an app need MIIT filing and CAC app governance review?](/artifacts/apac/china-cybersecurity-law/faq/does-an-app-need-miit-filing-and-cac-app-governance-review.md)

An app sponsor providing internet information services through an app in China must complete MIIT filing. CAC rules separately govern app providers and distribution platforms without creating one routine CAC approval for every app.

- 2 items

### [How do smart home security standards fit with China cybersecurity law?](/artifacts/apac/china-cybersecurity-law/faq/how-do-smart-home-security-standards-fit-with-china-cybersecurity-law.md)

GB/T 41387-2022 can organize smart-home security evidence, but it is a recommended standard, not a product approval. Check app, data, MLPS, telecom access, and radio requirements separately.

- 2 items

### [How does important data change China cybersecurity obligations?](/artifacts/apac/china-cybersecurity-law/faq/how-does-important-data-change-cybersecurity-obligations.md)

Once data is officially identified as important data, the processor needs named governance, periodic risk assessments and reports, incident controls, and a separate export decision. An internal sensitivity label alone does not establish the legal category.

- 2 items

### [Is every company a network operator under China Cybersecurity Law?](/artifacts/apac/china-cybersecurity-law/faq/is-every-company-a-network-operator-under-china-cybersecurity-law.md)

No. Under China's Cybersecurity Law, a network operator is an owner or administrator of a network or a network service provider. Apply that definition to each China network or service, then test CII and other roles separately.

- 2 items

### [What is MLPS classified protection evidence?](/artifacts/apac/china-cybersecurity-law/faq/what-is-mlps-classified-protection-evidence.md)

MLPS evidence shows how a defined China network or system was graded and protected. Keep the scope, grading rationale, filing or assessment records where applicable, control mapping, test results, remediation, and reassessment history.

- 2 items

### [When does China cybersecurity review apply?](/artifacts/apac/china-cybersecurity-law/faq/when-does-china-cybersecurity-review-apply.md)

China cybersecurity review applies to CII procurement or network-platform data processing that affects or may affect national security, plus a mandatory pre-filing trigger for certain foreign listings involving more than one million users' personal information.

- 2 items

Browse all indexed questions: [/artifacts/apac/china-cybersecurity-law/faq/items](/artifacts/apac/china-cybersecurity-law/faq/items.md)

## Most China Cybersecurity Law questions start with scope

The Cybersecurity Law applies to building, operating, maintaining, and using networks in China. A network operator is a network owner or administrator or a network service provider. Apply those definitions to each system and entity rather than labeling an entire corporate group.

Network operators have baseline classified-protection duties. Additional routes depend on separate facts: CII status and procurement, important data or core data, personal-information processing and export, operation of an app or distribution platform, radio functions, telecom network access, and sector rules.

The Cybersecurity Law was amended in 2025 and the amended law took effect on 1 January 2026. The amendment changed legal-liability provisions and added artificial-intelligence governance language. Use the amended law for current penalty or enforcement conclusions, while the linked full text supplies the core scope and duty provisions discussed in these FAQs.

- Define the China network, system, app, platform, connected product, data flow, procurement, or listing transaction and the entity performing each role.
- Map Article 23 controls, including responsible personnel, technical protection, monitoring, at least six months of network logs, data classification and backup, and the separate Article 27 incident plan.
- Screen important data against current sector or regional catalogues, authority notices, and public identifications; keep personal information and core data as separate categories.
- For CII procurement or network-platform processing, apply the Cybersecurity Review Measures' national-security test and the distinct one-million-user foreign-listing trigger.
- For apps, separate MIIT app filing for the app sponsor, app-provider duties under the 2022 provisions, a distribution platform's provincial cyberspace filing, and personal-information minimization.
- For smart-home products, treat GB/T 41387-2022 as a recommended security standard and run telecom, radio, app, privacy, network-operation, and MLPS routes separately.

Sources for this answer:

- [PRC Cybersecurity Law, current text](https://www.cac.gov.cn/2025-12/29/c_1768735112911946.htm?ref=sorena.io) - Articles 2, 23, 27, and 78 support territorial scope, network and operator definitions, baseline classified-protection duties, incident planning, and six-month minimum log retention.
- [PRC Data Security Law](https://www.cac.gov.cn/2021-06/11/c_1624994566919140.htm?ref=sorena.io) - Articles 21 and 27-31 support important-data identification, governance, risk assessment, reporting, incidents, and export routing.
- [Cybersecurity Review Measures](https://www.cac.gov.cn/2022-01/04/c_1642894602182845.htm?ref=sorena.io) - Supports the CII procurement and network-platform national-security triggers, the one-million-user foreign-listing trigger, filing materials, and review process.
- [NPC report on adoption of the PRC Cybersecurity Law amendment](https://www.npc.gov.cn/npc/c2/c30834/202510/t20251028_449076.html?ref=sorena.io) - Confirms that the amended Cybersecurity Law took effect on 1 January 2026.

## How to use the FAQ answers

For each question, record the facts, actor, controlling source and version, conclusion, evidence owner, unresolved issue, approval or filing where applicable, and change triggers. A group-wide policy or product label cannot replace a system- or transaction-specific decision.

Keep related regimes distinct. Personal-information rights and export mechanisms belong in the privacy analysis. Telecom network access, radio approval, and mobile-terminal software rules need their own product analysis. Cross-link shared evidence without merging the legal conclusions.

- Network-operator and other actor-role analysis for each system or service.
- MLPS grading record and baseline security-control map.
- Important-data screening, governance, assessment, and export decision.
- Incident-response, vulnerability-remediation, backup, and log-retention evidence.
- Cybersecurity-review intake decision and filing record where triggered.
- MIIT app filing, app-provider controls under the 2022 provisions, and distribution-platform filing and governance evidence.
- Smart-home standard applicability and separate telecom, radio, privacy, app, and network-operation decisions.

Sources for this answer:

- [PRC Cybersecurity Law, current text](https://www.cac.gov.cn/2025-12/29/c_1768735112911946.htm?ref=sorena.io) - Supports system-specific operator analysis, Article 23 controls, Article 27 incident planning, and log-retention evidence.
- [PRC Data Security Law](https://www.cac.gov.cn/2021-06/11/c_1624994566919140.htm?ref=sorena.io) - Supports important-data identification, governance, assessment, incident, and export records.

## Frequently asked questions

Use the answer that matches the actor and activity. If the facts span several roles, keep a separate conclusion and evidence record for each instrument.

### Which Cybersecurity Law text and article numbers apply now?

Use the Cybersecurity Law text amended on 28 October 2025 and effective from 1 January 2026. The amendment inserted new provisions and renumbered the operating rules. The current baseline classified-protection duties are in Article 23, network product and service duties in Article 24, network-operator incident duties in Article 27, CII duties in Articles 33-40, and network and network-operator definitions in Article 78. Older copies that cite Articles 21, 22, 25, 31-39, or 76 for those subjects use the pre-2026 numbering.

### Is every network operator a CII operator?

No. A network operator is the owner or administrator of a network or a network service provider and carries the Article 23 and 27 baseline duties. Critical information infrastructure is a narrower category. The responsible sector protection department applies recognition rules to the specific facility or system, identifies it, and notifies the operator. Sector presence, company size, data volume, or a high MLPS level does not replace that notice.

### What should an MLPS evidence file show?

An MLPS evidence file should identify the network, operator, system boundary, business functions, users, hosting, data, interfaces, dependencies, classification method and level, decision status, applicable standard edition and clauses, implemented controls, tests, findings, exceptions, remediation, and retest results. Under the general management measures, level 2 or higher systems have a 30-day filing rule, level 3 systems have at-least-annual assessment and self-inspection cycles, and level 4 systems have at-least-six-month cycles; level 5 follows special security needs. Sector routes can differ. GB/T 22239-2019 is a recommended national baseline standard, not a standalone law or universal certificate.

### Does a large data set automatically become important data?

No. Important data is identified under the Data Security Law through the applicable national, regional, departmental, industry, or sector catalogue or an authority identification, with attention to the harm that misuse or compromise could cause. Data volume alone is not the classification test. If the data is important data, document the responsible person and management body, periodic risk assessment and report, incident process, and separate export-route decision.

### When is a cybersecurity review filing required?

A CII operator must first assess a procurement of network products or services before use and file when the procurement affects or may affect national security. The measures also cover a network platform operator's data-processing activity that affects or may affect national security. Separately, a network platform operator holding personal information of more than one million users must file before seeking a foreign listing. The measures use the phrase foreign listing, so check the current official interpretation for the specific destination and transaction. These triggers do not make every procurement, platform, overseas listing, or data export a cybersecurity review filing.

### Are MIIT app filing and app-platform filing the same?

No. An app sponsor providing an app-based internet information service in China completes MIIT app filing through an access provider or distribution platform before a new covered app begins service. An app distribution platform separately files with its provincial cyberspace authority within 30 days after the platform goes online and maintains provider verification, listing and update review, monitoring, complaints, suspension, takedown, and reporting controls. One organisation may need both records if it holds both roles.

### Does GB/T 41387-2022 require every smart-home product to be certified?

No. The official standards record identifies GB/T 41387-2022 as a current recommended national standard implemented on 1 November 2022. That record does not create automatic certification or product approval for every smart-home product. Obtain the complete applicable standard before making a clause-level claim, and assess telecom, radio, app, privacy, network-operation, and any voluntary China Cybersecurity Label route separately.

Sources for this answer:

- [PRC Cybersecurity Law, current text](https://www.cac.gov.cn/2025-12/29/c_1768735112911946.htm?ref=sorena.io) - Current article numbering, network-operator baseline, product duties, incident duties, CII rules, and definitions.
- [Regulations on the Security Protection of Critical Information Infrastructure](https://www.cac.gov.cn/2021-08/17/c_1630785976988160.htm?ref=sorena.io) - CII definition, sector recognition rules, operator notification, and material-change reassessment.
- [PRC Data Security Law](https://www.cac.gov.cn/2021-06/11/c_1624994566919140.htm?ref=sorena.io) - Important-data catalogues, responsible person and management body, periodic assessment, reporting, incident, and export context.
- [Cybersecurity Review Measures](https://www.cac.gov.cn/2022-01/04/c_1642894602182845.htm?ref=sorena.io) - CII procurement and network-platform national-security triggers, one-million-user foreign-listing filing, and filing materials.
- [Mobile Internet Application Information Service Management Provisions](https://www.cac.gov.cn/2022-06/14/c_1656821626455324.htm?ref=sorena.io) - App-provider and distribution-platform scope, platform filing, verification, review, monitoring, complaints, and enforcement records.
- [MIIT notice on mobile app filing work](https://www.miit.gov.cn/zwgk/zcwj/wjfb/tz/art/2023/art_920db564162e4312916a01bed6540ad8.html?ref=sorena.io) - App-sponsor filing route, pre-service filing, display, changes, cancellation, and intermediary checks.
- [Official national standards record for GB/T 22239-2019](https://openstd.samr.gov.cn/bzgk/gb/newGbInfo?hcno=BAFB47E8874764186BDB7865E8344DAF&ref=sorena.io) - Current recommended classified-protection baseline standard and 1 December 2019 implementation date.
- [Official national standards record for GB/T 41387-2022](https://openstd.samr.gov.cn/bzgk/gb/newGbInfo?hcno=B1C14E854C0BA30D1C29FC376299761A&ref=sorena.io) - Current recommended smart-home security standard and 1 November 2022 implementation date.
- [Information Security Classified Protection Management Measures](https://www.miit.gov.cn/jgsj/xxjsfzs/xxgk/art/2020/art_a981907528694176a61b5b52c2d19895.html?ref=sorena.io) - Articles 14-18 support the general level 2-and-above filing period, level 3-5 assessment and self-inspection cycles, filing materials, and inspection rules summarized in the MLPS answer.

*Apply the requirement*

*Placement: Before primary sources*

## Build the China network security evidence file

Keep the network role, classified-protection, important-data, review, app-filing, and product-standard conclusions in separate records.

- [Map official sources to evidence](/solutions/research-copilot.md): Connect each FAQ conclusion to the current article number, regulated actor, trigger, evidence, filing result, and change event.
- [Review the China route](/contact.md): Check the China Cybersecurity Law scope decision and unresolved launch questions with Sorena.

## Primary sources

- [PRC Cybersecurity Law, current text](https://www.cac.gov.cn/2025-12/29/c_1768735112911946.htm?ref=sorena.io) - Use Articles 2, 23, 27, 33-40, and 78 for scope, definitions, baseline duties, incident duties, CII rules, and log retention.
- [PRC Data Security Law](https://www.cac.gov.cn/2021-06/11/c_1624994566919140.htm?ref=sorena.io) - Use Articles 21 and 27-31 for important-data classification, governance, assessment, reporting, incidents, and export routing.
- [Cybersecurity Review Measures](https://www.cac.gov.cn/2022-01/04/c_1642894602182845.htm?ref=sorena.io) - Use for CII procurement and platform-processing triggers, the one-million-user foreign-listing trigger, risk factors, filing materials, and review procedure.
- [Mobile Internet Application Information Service Management Provisions](https://www.cac.gov.cn/2022-06/14/c_1656821626455324.htm?ref=sorena.io) - Use for separate app-provider and distribution-platform duties, including the platform's provincial cyberspace filing within 30 days after launch.
- [MIIT notice on mobile app filing work](https://www.miit.gov.cn/zwgk/zcwj/wjfb/tz/art/2023/art_920db564162e4312916a01bed6540ad8.html?ref=sorena.io) - Use for the sponsor filing obligation, submission channels, filing display, changes, cancellation, platform checks, and supervision.
- [GB/T 22239 classified protection baseline requirements](https://openstd.samr.gov.cn/bzgk/gb/newGbInfo?hcno=BAFB47E8874764186BDB7865E8344DAF&ref=sorena.io) - Confirms that GB/T 22239-2019 is a current recommended national baseline standard implemented on 1 December 2019.
- [GB/T smart home general security specification](https://openstd.samr.gov.cn/bzgk/gb/newGbInfo?hcno=B1C14E854C0BA30D1C29FC376299761A&ref=sorena.io) - Confirms that GB/T 41387-2022 is a current recommended national smart-home security standard implemented on 1 November 2022.
- [NPC report on adoption of the PRC Cybersecurity Law amendment](https://www.npc.gov.cn/npc/c2/c30834/202510/t20251028_449076.html?ref=sorena.io) - Confirms adoption of the 2025 amendments and their 1 January 2026 effective date.
- [Regulations on the Security Protection of Critical Information Infrastructure](https://www.cac.gov.cn/2021-08/17/c_1630785976988160.htm?ref=sorena.io) - Use for CII recognition factors, protection-department identification and notice, operator duties, annual testing, procurement, incidents, and material-change reassessment.
- [Information Security Classified Protection Management Measures](https://www.miit.gov.cn/jgsj/xxjsfzs/xxgk/art/2020/art_a981907528694176a61b5b52c2d19895.html?ref=sorena.io) - Use for the general five-level harm framework, filing periods, assessment and self-inspection cycles, filing materials, and public-security supervision.


---

[Privacy Policy](https://www.sorena.io/privacy.md) | [Terms of Use](https://www.sorena.io/terms-of-use.md) | [DMCA](https://www.sorena.io/dmca.md) | [About Us](https://www.sorena.io/about-us.md)

(c) 2026 Sorena AB (559573-7338). All rights reserved.

Source: https://www.sorena.io/artifacts/apac/china-cybersecurity-law/faq.md
