Short answer
The Cybersecurity Law applies to the construction, operation, maintenance, and use of networks within China and to their cybersecurity supervision. It defines a broadly as a system made up of computers or other information terminals and related equipment that collects, stores, transmits, exchanges, or processes information under rules and procedures. A is the network's owner or administrator or a network service provider.
Start with facts, not the company's industry label. Identify the or service, its China connection, the legal entity that owns it, who sets access and operating rules, who administers it, and who provides the network service. For example, an entity that operates a China office network, app backend, connected-product platform, or managed network service may meet the definition for that system. A company does not qualify merely because it buys software, uses a supplier's network, owns a product brand, or has a China affiliate. A parent company, China subsidiary, cloud provider, app provider, and outsourced administrator may each perform different roles; the contract helps identify responsibilities but does not replace the statutory facts.
-operator status brings and incident duties now found in Articles 23 and 27 of the law's consolidated 2025 text. They include internal rules and a named security lead, technical protections, monitoring, at least six months of network-log retention, data classification, backup and encryption, and a network-security incident plan. Additional duties depend on the service, data, users, sector, and whether another legal role applies.
Do not infer status or from the baseline role. CII depends on the protected-sector and serious-harm tests and the competent protection authority's process. Cybersecurity review requires the separate triggers in the Cybersecurity Review Measures. An app provider is the owner or operator providing information services through a mobile app, while a distribution platform provides app publication, download, or dynamic-loading services. A personal-information processor determines the purpose and method of processing personal information; an important-data processor handles data identified under an applicable official catalogue, notice, or public identification. Each role needs a separate finding.
The Cybersecurity Law was amended in 2025 with effect from 1 January 2026. The statutory operator definition and baseline-duty analysis remain relevant, while current penalty or enforcement conclusions must use the amended law rather than the 2016 penalties alone.
Articles 2, 23, 27 and 78 provide the territorial scope, baseline and incident duties, the network and network-operator definitions, and the six-month minimum network-log retention in the consolidated 2025 text.
Shows that app provider and app distribution platform are separate operational roles with their own duties; those labels should not be collapsed into network-operator status.
Confirms that the amended Cybersecurity Law took effect on 1 January 2026 and supersedes reliance on the original penalty provisions alone.