---
title: "Does an app need MIIT filing and CAC app governance review?"
canonical_url: "https://www.sorena.io/artifacts/apac/china-cybersecurity-law/faq/does-an-app-need-miit-filing-and-cac-app-governance-review"
source_url: "https://www.sorena.io/artifacts/apac/china-cybersecurity-law/faq/does-an-app-need-miit-filing-and-cac-app-governance-review"
author: "Sorena AI"
description: "An app sponsor providing internet information services through an app in China must complete MIIT filing. CAC rules separately govern app providers and distribution platforms without creating one routine CAC approval for every app."
published_at: "2026-07-05"
updated_at: "2026-07-24"
keywords:
  - "China Cybersecurity Law"
  - "Data Security Law"
  - "Cybersecurity Review Measures"
  - "Mobile app filing"
  - "MLPS"
---
**[SORENA](https://www.sorena.io/)** - AI-Powered GRC Platform

[Home](https://www.sorena.io/) | [Solutions](https://www.sorena.io/solutions) | [Artifacts](https://www.sorena.io/artifacts) | [About Us](https://www.sorena.io/about-us) | [Contact](https://www.sorena.io/contact) | [Portal](https://app.sorena.io)

---

# Does an app need MIIT filing and CAC app governance review?

An app sponsor providing internet information services through an app in China must complete MIIT filing. CAC rules separately govern app providers and distribution platforms without creating one routine CAC approval for every app.

*Question* *China*

## Does an app need MIIT filing and CAC app governance review? Direct answer

An app sponsor providing internet information services through an app in China must complete MIIT filing before providing the service. The CAC app rules separately govern the app provider and any distribution platform.

There is no routine CAC approval called an 'app governance review' for every app. A distribution platform, however, must file with its provincial cyberspace authority within 30 days after starting operations.

An app sponsor providing internet information services through an app in China must complete MIIT filing, and the app provider must separately comply with the CAC app-governance rules. These are separate tracks. The CAC rules impose operating duties, not one routine approval called an 'app governance review' for every app.

## Definitions

### Ministry of Industry and Information Technology mobile app filing

**Term:** MIIT filing

MIIT filing is the internet-information-service record required by the 2023 MIIT notice for an app sponsor providing app-based internet information services within China. The sponsor files with its provincial communications administration through a network access service provider or app distribution platform and receives a filing number for public display and verification.

**Why it matters here:** A new covered app must complete filing before providing the service. Filing records the app and sponsor; it does not replace a licence required for a regulated service or prove compliance with CAC, personal-information, content, or security rules.

Sources:

- [MIIT notice on mobile app filing work](https://www.miit.gov.cn/zwgk/zcwj/wjfb/tz/art/2023/art_920db564162e4312916a01bed6540ad8.html?ref=sorena.io)

### Cyberspace Administration of China app-governance rules

**Term:** CAC app-governance

The Cyberspace Administration of China (CAC) app-governance rules are the 2022 Mobile Internet Application Information Service Management Provisions. They impose duties on app providers and separate duties on app distribution platforms for content, security, data, personal information, minors, complaints, verification, review, and records.

**Why it matters here:** These rules apply separately from MIIT filing. They do not create one routine CAC approval for every app, although a regulated service or qualifying new function can require a licence or security assessment.

Sources:

- [Mobile Internet Application Information Service Management Provisions](https://www.cac.gov.cn/2022-06/14/c_1656821626455324.htm?ref=sorena.io)

### App sponsor for MIIT filing

**Term:** app sponsor

The app sponsor is the organization or individual identified as responsible for the app's internet information service in the MIIT filing. It submits truthful identity, app, domain, IP-resource, access, and service information through the prescribed channel.

**Why it matters here:** Name the sponsor for each app, mini-program, or quick app. A developer, brand owner, China affiliate, access provider, and distribution platform may be different entities, so do not copy one entity across every role without checking the facts.

Sources:

- [MIIT notice on mobile app filing work](https://www.miit.gov.cn/zwgk/zcwj/wjfb/tz/art/2023/art_920db564162e4312916a01bed6540ad8.html?ref=sorena.io)

### App provider under the CAC app rules

**Term:** app provider

An app provider is the owner or operator of a mobile internet application that provides information services through the app. This CAC role is based on who provides the service and can differ from the MIIT filing channel or the app store.

**Why it matters here:** The app provider carries the CAC duties for content, security, data processing, personal information, minors where relevant, complaints, vulnerabilities, and incidents. It may also need a sector licence or a security assessment for a qualifying new function.

Sources:

- [Mobile Internet Application Information Service Management Provisions](https://www.cac.gov.cn/2022-06/14/c_1656821626455324.htm?ref=sorena.io)

### App distribution platform

**Term:** distribution platform

A distribution platform provides app publication, download, or dynamic-loading services through the internet. The definition includes app stores, quick-app centers, internet mini-program platforms, and browser plug-in platforms.

**Why it matters here:** The platform has its own CAC filing within 30 days after starting operations, plus provider-authentication, licence and assessment verification, app-review, monitoring, complaint, action, recordkeeping, and reporting duties. This platform filing is not the MIIT filing of each app sponsor.

Sources:

- [Mobile Internet Application Information Service Management Provisions](https://www.cac.gov.cn/2022-06/14/c_1656821626455324.htm?ref=sorena.io)

### Necessary personal information for an app's basic function

**Term:** necessary personal information

Necessary personal information is the minimum personal information needed to deliver an app category's basic function. The official rules list common app categories, their basic functions, and the information treated as necessary for those functions.

**Why it matters here:** An app may not refuse its basic function solely because a user declines personal information that is not necessary for that function. Classify the app's actual basic function before deciding which fields or permissions are required.

Sources:

- [Necessary Personal Information Scope for Common Types of Mobile Apps](https://www.cac.gov.cn/2021-03/22/c_1617990997054277.htm?ref=sorena.io)

### Security assessment for qualifying new app functions

**Term:** security assessment

Under the CAC app rules, an app provider launching a new technology, application, or function with public-opinion attributes or social-mobilization capacity must complete the security assessment required by the applicable state rules. This is a conditional assessment, not a routine CAC approval for every app.

**Why it matters here:** Document what the new function does and whether it has the stated attributes. A distribution platform must verify the assessment when reviewing an app that falls within this rule.

Sources:

- [Mobile Internet Application Information Service Management Provisions](https://www.cac.gov.cn/2022-06/14/c_1656821626455324.htm?ref=sorena.io)

## Short answer

The 2023 MIIT notice says an app sponsor engaged in internet information services within China must complete app filing and may not provide those services without it. The filing work covers mobile apps, mini-programs, and quick apps. The sponsor files with its provincial communications administration through its network access service provider or app distribution platform; an app-store listing is not the filing. After receiving complete and accurate materials, the provincial communications administration completes the filing within 20 working days, issues a filing number, and publishes the filing information.

The MIIT notice moved existing apps through a September 2023 to March 2024 filing phase and entered normalized work in July 2024. Those transition dates have passed. A new covered app now files before service begins, and the sponsor files changes or cancellation with the original filing authority when the recorded information changes.

CAC app-governance comes from the Mobile Internet Application Information Service Management Provisions, which took effect on 1 August 2022 and apply separately to app information services and distribution services provided within China. Covered information services include examples such as instant messaging, news, knowledge question-and-answer services, forums, livestreaming, e-commerce, online audiovisual services, and life services. An app provider must maintain content, data-security, personal-information, minors, complaint, vulnerability, and incident controls as applicable to its service. A regulated service such as internet news requires the relevant licence, while a new technology, application, or function with public-opinion attributes or social-mobilization capacity requires the applicable security assessment.

A distribution platform has distinct duties: it must file with its provincial cyberspace authority within 30 days after going online, authenticate app providers, verify relevant permits or assessments, review apps and updates, manage listed apps, and keep enforcement records. That platform filing is not a CAC filing imposed on every individual app provider.

MIIT filing does not prove CAC-rule or privacy compliance. The rule on necessary personal information also prevents an app from denying its basic function merely because a user refuses personal information that is not necessary for that function. Determine the app category and basic function before setting required fields or permissions.

Sources for this answer:

- [MIIT notice on mobile app filing work](https://www.miit.gov.cn/zwgk/zcwj/wjfb/tz/art/2023/art_920db564162e4312916a01bed6540ad8.html?ref=sorena.io) - States that app sponsors providing internet information services in China must complete filing, identifies filing channels and app forms, and bars unfiled apps from providing those services.
- [Mobile Internet Application Information Service Management Provisions](https://www.cac.gov.cn/2022-06/14/c_1656821626455324.htm?ref=sorena.io) - Articles 5-17 and 19-22 set provider and distribution-platform duties, including the platform's provincial filing within 30 days after launch, provider verification, app review, data and privacy controls, complaints, and records.
- [Necessary Personal Information Scope for Common Types of Mobile Apps](https://www.cac.gov.cn/2021-03/22/c_1617990997054277.htm?ref=sorena.io) - Defines basic functions and necessary personal information by common app category and bars refusal of the basic function solely because a user declines non-necessary personal information.

## What to keep as evidence

The evidence should identify each app form and each actor rather than relying on one screenshot from an app store.

- Scope record for each app, mini-program, or quick app: package or service identifier, sponsor and provider entities, services, users, domains and Internet Protocol (IP) address resources, access provider, and distribution channels.
- MIIT record: submitted information, access-provider or platform verification, filing number, required in-app display or link, public-query result, and change or cancellation records.
- Provider controls: required service permits, any applicable new-function security assessment, content review, account verification, vulnerability response, data security, personal information, minors, complaints, and incident reporting.
- Necessary-personal-information map: app category, basic function, each data field and permission, legal basis, whether it is necessary for the basic function, and behavior when consent is refused.
- For a distribution platform: provincial CAC filing, provider identity and permit verification, listing and update reviews, monitoring, complaints, warnings, suspensions, removals, retained records, and authority reports.

Sources for this answer:

- [MIIT notice on mobile app filing work](https://www.miit.gov.cn/zwgk/zcwj/wjfb/tz/art/2023/art_920db564162e4312916a01bed6540ad8.html?ref=sorena.io) - Supports the filing identifiers, submission path, display, public-query, change, cancellation, platform-checking, and supervision records.
- [Mobile Internet Application Information Service Management Provisions](https://www.cac.gov.cn/2022-06/14/c_1656821626455324.htm?ref=sorena.io) - Supports provider controls and the separate distribution-platform filing, verification, review, monitoring, complaint, action, and recordkeeping evidence.
- [Necessary Personal Information Scope for Common Types of Mobile Apps](https://www.cac.gov.cn/2021-03/22/c_1617990997054277.htm?ref=sorena.io) - Supports the category-by-category basic-function and necessary-personal-information map.

## Primary sources

- [MIIT notice on mobile app filing work](https://www.miit.gov.cn/zwgk/zcwj/wjfb/tz/art/2023/art_920db564162e4312916a01bed6540ad8.html?ref=sorena.io) - Use for MIIT mobile app filing phases, registration, supervision, normalization, and operational filing evidence.
- [Mobile Internet Application Information Service Management Provisions](https://www.cac.gov.cn/2022-06/14/c_1656821626455324.htm?ref=sorena.io) - Use for app provider and app distribution platform governance, content/security/data duties, platform filing and verification, and 1 August 2022 effective date.
- [Necessary Personal Information Scope for Common Types of Mobile Apps](https://www.cac.gov.cn/2021-03/22/c_1617990997054277.htm?ref=sorena.io) - Use for app category, basic-function, minimum necessary personal information, no-refusal rule, and 1 May 2021 effective date.

## Topic Guides

- [China App Filing vs Personal Information Rules](/artifacts/apac/china-cybersecurity-law/mobile-app-filing-vs-app-personal-information-rules.md): Decide whether a China mobile app needs MIIT filing, personal-information controls, or both, with current triggers, duties, dates, and evidence.
- [China cybersecurity and data security requirements](/artifacts/apac/china-cybersecurity-law/requirements.md): China cybersecurity requirements by actor: network operators, data processors, CII operators, platforms, app providers, and distribution platforms.
- [China cybersecurity compliance checklist](/artifacts/apac/china-cybersecurity-law/checklist.md): A China cybersecurity checklist for scoping network duties, data security, CII procurement review, app rules, MIIT filing, and supporting standards.
- [China cybersecurity deadlines and compliance calendar](/artifacts/apac/china-cybersecurity-law/deadlines-and-compliance-calendar.md): Separate China cybersecurity commencement dates from recurring duties, filing lead times, review periods, and event-driven response deadlines.
- [China Cybersecurity Law FAQ](/artifacts/apac/china-cybersecurity-law/faq.md): Practical answers on China network-operator scope, MLPS evidence, important data, cybersecurity review, app filing and governance, and smart-home standards under the law in force from 1 January 2026.
- [China Cybersecurity Law vs EU Cyber Resilience Act](/artifacts/apac/china-cybersecurity-law/china-cybersecurity-law-vs-eu-cyber-resilience-act.md): Compare China's network-operator rules with the EU CRA's product duties, including scope, actors, evidence, reporting dates, and launch decisions.
- [China Cybersecurity Law vs EU NIS2 Directive](/artifacts/apac/china-cybersecurity-law/china-cybersecurity-law-vs-nis2.md): Compare China's network-operator duties with NIS2 entity duties, including scope, management accountability, incident reporting, evidence, and enforcement.
- [China cybersecurity penalties and fines](/artifacts/apac/china-cybersecurity-law/penalties-and-fines.md): Compare current China Cybersecurity Law and Data Security Law fines by actor, breach, severity, and enforcement consequence.
- [China Cybersecurity Review vs Data Export Assessment](/artifacts/apac/china-cybersecurity-law/cybersecurity-review-vs-data-export-security-assessment.md): Separate China's cybersecurity-review triggers from CAC data-export assessment triggers, thresholds, filings, evidence, timing, and reapplication rules.
- [China cybersecurity review workflow](/artifacts/apac/china-cybersecurity-law/cybersecurity-review-workflow.md): Determine whether CII procurement, platform data processing, or a qualifying foreign listing triggers China's Cybersecurity Review Measures.
- [China mobile app filing and app governance](/artifacts/apac/china-cybersecurity-law/mobile-app-filing-and-app-governance.md): Identify the China app sponsor, complete MIIT filing before service, and separate provider, platform, privacy, content, and security duties.
- [China Smart-Home Security vs Telecom and Radio Approval](/artifacts/apac/china-cybersecurity-law/smart-home-security-vs-telecom-wireless-launch.md): Separate GB/T 41387-2022 smart-home security evidence from China telecom network-access and radio approval decisions for connected products.
- [CII and network operator role triage](/artifacts/apac/china-cybersecurity-law/critical-information-infrastructure-and-network-operators.md): How to separate ordinary network operator duties from CII, procurement, and review-risk questions under China cybersecurity sources.
- [GB/T 22239-2019 classified protection baseline](/artifacts/apac/china-cybersecurity-law/classified-protection-baseline.md): How to scope and document a GB/T 22239-2019 classified protection baseline without treating the recommended standard as a standalone law.
- [GB/T 41387-2022 smart home security standard](/artifacts/apac/china-cybersecurity-law/smart-home-security-standard.md): How connected-device teams can scope and document GB/T 41387-2022 without treating it as an automatic certification or product-approval duty.
- [How do smart home security standards fit with China cybersecurity law?](/artifacts/apac/china-cybersecurity-law/faq/how-do-smart-home-security-standards-fit-with-china-cybersecurity-law.md): GB/T 41387-2022 can organize smart-home security evidence, but it is a recommended standard, not a product approval. Check app, data, MLPS, telecom access, and radio requirements separately.
- [How does important data change China cybersecurity obligations?](/artifacts/apac/china-cybersecurity-law/faq/how-does-important-data-change-cybersecurity-obligations.md): Once data is officially identified as important data, the processor needs named governance, periodic risk assessments and reports, incident controls, and a separate export decision. An internal sensitivity label alone does not establish the legal category.
- [Is every company a network operator under China Cybersecurity Law?](/artifacts/apac/china-cybersecurity-law/faq/is-every-company-a-network-operator-under-china-cybersecurity-law.md): No. Under China's Cybersecurity Law, a network operator is an owner or administrator of a network or a network service provider. Apply that definition to each China network or service, then test CII and other roles separately.
- [MLPS classified protection evidence map](/artifacts/apac/china-cybersecurity-law/mlps-classified-protection-evidence-map.md): Classify a China network under MLPS, complete level 2 or above filing, map controls, and retain assessment, remediation, and change evidence.
- [What is MLPS classified protection evidence?](/artifacts/apac/china-cybersecurity-law/faq/what-is-mlps-classified-protection-evidence.md): MLPS evidence shows how a defined China network or system was graded and protected. Keep the scope, grading rationale, filing or assessment records where applicable, control mapping, test results, remediation, and reassessment history.
- [When does China cybersecurity review apply?](/artifacts/apac/china-cybersecurity-law/faq/when-does-china-cybersecurity-review-apply.md): China cybersecurity review applies to CII procurement or network-platform data processing that affects or may affect national security, plus a mandatory pre-filing trigger for certain foreign listings involving more than one million users' personal information.

*Operationalize the requirement*

*Placement: Before primary sources*

## Build the China network security evidence file

Sorena AI helps turn the answer to "Does an app need MIIT filing and CAC app governance review?" into assigned controls and retained evidence.

- [Map official sources to evidence](/solutions/research-copilot.md): Research Copilot connects the official citation, decision, owner, retained evidence, and change history.
- [Review the China route](/contact.md): Check the China Cybersecurity Law scope decision and unresolved launch questions with Sorena.


---

[Privacy Policy](https://www.sorena.io/privacy.md) | [Terms of Use](https://www.sorena.io/terms-of-use.md) | [DMCA](https://www.sorena.io/dmca.md) | [About Us](https://www.sorena.io/about-us.md)

(c) 2026 Sorena AB (559573-7338). All rights reserved.

Source: https://www.sorena.io/artifacts/apac/china-cybersecurity-law/faq/does-an-app-need-miit-filing-and-cac-app-governance-review.md
