---
title: "Is every company a network operator under China Cybersecurity Law?"
canonical_url: "https://www.sorena.io/artifacts/apac/china-cybersecurity-law/faq/is-every-company-a-network-operator-under-china-cybersecurity-law"
source_url: "https://www.sorena.io/artifacts/apac/china-cybersecurity-law/faq/is-every-company-a-network-operator-under-china-cybersecurity-law"
author: "Sorena AI"
description: "No. Under China's Cybersecurity Law, a network operator is an owner or administrator of a network or a network service provider. Apply that definition to each China network or service, then test CII and other roles separately."
published_at: "2026-07-05"
updated_at: "2026-07-24"
keywords:
  - "China Cybersecurity Law"
  - "Data Security Law"
  - "Cybersecurity Review Measures"
  - "Mobile app filing"
  - "MLPS"
---
**[SORENA](https://www.sorena.io/)** - AI-Powered GRC Platform

[Home](https://www.sorena.io/) | [Solutions](https://www.sorena.io/solutions) | [Artifacts](https://www.sorena.io/artifacts) | [About Us](https://www.sorena.io/about-us) | [Contact](https://www.sorena.io/contact) | [Portal](https://app.sorena.io)

---

# Is every company a network operator under China Cybersecurity Law?

No. Under China's Cybersecurity Law, a network operator is an owner or administrator of a network or a network service provider. Apply that definition to each China network or service, then test CII and other roles separately.

*Question* *China*

## Is every company a network operator under China Cybersecurity Law? Direct answer

No. The Cybersecurity Law defines a network operator as a network owner or administrator, or a network service provider. Apply that definition to each China network or service.

A company can be a network operator for one activity and not another. Network-operator, app-provider, platform, data-processor, CII, and cybersecurity-review status require separate findings.

No. A company is a network operator when it owns or administers a network or provides network services within the Cybersecurity Law's scope. Apply that test to the specific China network, system, app, platform, or service and identify the entity that performs the relevant role.

## Definitions

### Network operator under the PRC Cybersecurity Law

**Term:** network operator

A network operator is an owner or administrator of a network, or a provider of network services. The label attaches to the entity's role for a particular network or service, not to every company merely because it uses computers, buys cloud services, or has a China subsidiary.

**Why it matters here:** Identify the network or service first, then record which entity owns it, administers it, or provides the network service. A company can qualify for one activity but not another, and more than one entity can have relevant responsibilities.

Sources:

- [PRC Cybersecurity Law, consolidated 2025 text](https://sdca.miit.gov.cn/zwgk/fgbz/art/2026/art_4815dd4ec11d454783b83a91502a3cc7.html?ref=sorena.io)

### Network under the PRC Cybersecurity Law

**Term:** network

A network is a system of computers or other information terminals and related equipment that collects, stores, transmits, exchanges, or processes information according to rules and procedures. The definition is broad, but a role analysis still needs a defined system boundary and responsible entity.

**Why it matters here:** An office system, app backend, connected-product platform, or other system can be a network if the statutory elements are present. Merely naming a product or corporate group does not identify who owns, administers, or provides the relevant service.

Sources:

- [PRC Cybersecurity Law, consolidated 2025 text](https://sdca.miit.gov.cn/zwgk/fgbz/art/2026/art_4815dd4ec11d454783b83a91502a3cc7.html?ref=sorena.io)

### Cybersecurity classified protection

**Term:** classified protection

Classified protection is the graded cybersecurity system under which a network operator identifies the protected network, determines its protection level, and applies management and technical safeguards appropriate to that level. GB/T 22239-2019 is a recommended national baseline standard used for control mapping; it is not itself a universal certificate.

**Why it matters here:** Every network-operator finding should lead to a classified-protection analysis. Filing, assessment, and inspection details depend on the protection level, sector, system facts, and current implementing rules.

Sources:

- [PRC Cybersecurity Law, consolidated 2025 text](https://sdca.miit.gov.cn/zwgk/fgbz/art/2026/art_4815dd4ec11d454783b83a91502a3cc7.html?ref=sorena.io)
- [GB/T 22239-2019 classified protection baseline](https://openstd.samr.gov.cn/bzgk/gb/newGbInfo?hcno=BAFB47E8874764186BDB7865E8344DAF&ref=sorena.io)

### Critical information infrastructure

**Term:** CII

Critical information infrastructure is infrastructure in important sectors and fields, or other infrastructure, whose destruction, loss of function, or data leakage could seriously harm national security, the national economy and people's livelihoods, or the public interest. The competent protection authority organizes identification under the applicable rules; ordinary network-operator status does not by itself establish CII status.

**Why it matters here:** A CII operator has additional duties and procurement, assessment, localization, and reporting consequences. Keep the CII conclusion separate from the baseline network-operator conclusion.

Sources:

- [PRC Cybersecurity Law, consolidated 2025 text](https://sdca.miit.gov.cn/zwgk/fgbz/art/2026/art_4815dd4ec11d454783b83a91502a3cc7.html?ref=sorena.io)

### Cybersecurity review under the Cybersecurity Review Measures

**Term:** cybersecurity review

Cybersecurity review is a national-security review under the Cybersecurity Review Measures. It can apply when CII procurement or a network platform operator's data-processing activity affects or may affect national security, and it has a separate mandatory filing trigger for a network platform operator holding personal information of more than one million users before a listing abroad.

**Why it matters here:** Network-operator status alone does not trigger this review. Test the actor, procurement or data-processing activity, listing facts, and national-security effects separately.

Sources:

- [Cybersecurity Review Measures](https://www.cac.gov.cn/2022-01/04/c_1642894602182845.htm?ref=sorena.io)

## Short answer

The Cybersecurity Law applies to the construction, operation, maintenance, and use of networks within China and to their cybersecurity supervision. It defines a network broadly as a system made up of computers or other information terminals and related equipment that collects, stores, transmits, exchanges, or processes information under rules and procedures. A network operator is the network's owner or administrator or a network service provider.

Start with facts, not the company's industry label. Identify the network or service, its China connection, the legal entity that owns it, who sets access and operating rules, who administers it, and who provides the network service. For example, an entity that operates a China office network, app backend, connected-product platform, or managed network service may meet the definition for that system. A company does not qualify merely because it buys software, uses a supplier's network, owns a product brand, or has a China affiliate. A parent company, China subsidiary, cloud provider, app provider, and outsourced administrator may each perform different roles; the contract helps identify responsibilities but does not replace the statutory facts.

Network-operator status brings classified protection and incident duties now found in Articles 23 and 27 of the law's consolidated 2025 text. They include internal rules and a named security lead, technical protections, monitoring, at least six months of network-log retention, data classification, backup and encryption, and a network-security incident plan. Additional duties depend on the service, data, users, sector, and whether another legal role applies.

Do not infer CII status or cybersecurity review from the baseline role. CII depends on the protected-sector and serious-harm tests and the competent protection authority's process. Cybersecurity review requires the separate triggers in the Cybersecurity Review Measures. An app provider is the owner or operator providing information services through a mobile app, while a distribution platform provides app publication, download, or dynamic-loading services. A personal-information processor determines the purpose and method of processing personal information; an important-data processor handles data identified under an applicable official catalogue, notice, or public identification. Each role needs a separate finding.

The Cybersecurity Law was amended in 2025 with effect from 1 January 2026. The statutory operator definition and baseline-duty analysis remain relevant, while current penalty or enforcement conclusions must use the amended law rather than the 2016 penalties alone.

Sources for this answer:

- [PRC Cybersecurity Law](https://sdca.miit.gov.cn/zwgk/fgbz/art/2026/art_4815dd4ec11d454783b83a91502a3cc7.html?ref=sorena.io) - Articles 2, 23, 27 and 78 provide the territorial scope, baseline and incident duties, the network and network-operator definitions, and the six-month minimum network-log retention in the consolidated 2025 text.
- [Mobile Internet Application Information Service Management Provisions](https://www.cac.gov.cn/2022-06/14/c_1656821626455324.htm?ref=sorena.io) - Shows that app provider and app distribution platform are separate operational roles with their own duties; those labels should not be collapsed into network-operator status.
- [NPC decision amending the PRC Cybersecurity Law](https://www.npc.gov.cn/npc/c2/c30834/202510/t20251028_449031.html?ref=sorena.io) - Confirms that the amended Cybersecurity Law took effect on 1 January 2026 and supersedes reliance on the original penalty provisions alone.

## What to keep as evidence

Keep one role record for each network or service. Update it when the architecture, entity responsibilities, hosting, users, data, or suppliers change.

- Boundary and China nexus: purpose, architecture, equipment and terminals, users, data, interfaces, hosting, and service locations.
- Entity-role map: owner, administrator, network service provider, access-rule setter, maintainer, monitor, incident lead, and relevant contracts.
- Reasoned network-operator conclusion tied to Articles 2 and 78 of the consolidated 2025 text, including uncertainties and any local or sector input.
- Articles 23 and 27 control map and evidence, including responsible personnel, technical protections, monitoring, six-month minimum network logs, data classification, backup and encryption, and incident planning.
- Separate conclusions for CII, cybersecurity review, app provider, distribution platform, personal-information processing, important data, and data exports.
- Reassessment triggers for ownership, architecture, hosting, functions, users, data, suppliers, contracts, or applicable rules.

Sources for this answer:

- [PRC Cybersecurity Law](https://sdca.miit.gov.cn/zwgk/fgbz/art/2026/art_4815dd4ec11d454783b83a91502a3cc7.html?ref=sorena.io) - Supports the scope, role analysis, baseline-control map, and six-month minimum network-log record.
- [Mobile Internet Application Information Service Management Provisions](https://www.cac.gov.cn/2022-06/14/c_1656821626455324.htm?ref=sorena.io) - Supports the separate app-provider and distribution-platform role decisions.

## Primary sources

- [PRC Cybersecurity Law](https://sdca.miit.gov.cn/zwgk/fgbz/art/2026/art_4815dd4ec11d454783b83a91502a3cc7.html?ref=sorena.io) - Use Articles 2, 23, 27 and 78 for territorial scope, the network and operator definitions, baseline and incident duties, and log retention in the consolidated 2025 text.
- [Mobile Internet Application Information Service Management Provisions](https://www.cac.gov.cn/2022-06/14/c_1656821626455324.htm?ref=sorena.io) - Use for the distinct app-provider and distribution-platform roles and duties.
- [NPC decision amending the PRC Cybersecurity Law](https://www.npc.gov.cn/npc/c2/c30834/202510/t20251028_449031.html?ref=sorena.io) - Confirms the amended law's 1 January 2026 effective date.

## Topic Guides

- [China App Filing vs Personal Information Rules](/artifacts/apac/china-cybersecurity-law/mobile-app-filing-vs-app-personal-information-rules.md): Decide whether a China mobile app needs MIIT filing, personal-information controls, or both, with current triggers, duties, dates, and evidence.
- [China cybersecurity and data security requirements](/artifacts/apac/china-cybersecurity-law/requirements.md): China cybersecurity requirements by actor: network operators, data processors, CII operators, platforms, app providers, and distribution platforms.
- [China cybersecurity compliance checklist](/artifacts/apac/china-cybersecurity-law/checklist.md): A China cybersecurity checklist for scoping network duties, data security, CII procurement review, app rules, MIIT filing, and supporting standards.
- [China cybersecurity deadlines and compliance calendar](/artifacts/apac/china-cybersecurity-law/deadlines-and-compliance-calendar.md): Separate China cybersecurity commencement dates from recurring duties, filing lead times, review periods, and event-driven response deadlines.
- [China Cybersecurity Law FAQ](/artifacts/apac/china-cybersecurity-law/faq.md): Practical answers on China network-operator scope, MLPS evidence, important data, cybersecurity review, app filing and governance, and smart-home standards under the law in force from 1 January 2026.
- [China Cybersecurity Law vs EU Cyber Resilience Act](/artifacts/apac/china-cybersecurity-law/china-cybersecurity-law-vs-eu-cyber-resilience-act.md): Compare China's network-operator rules with the EU CRA's product duties, including scope, actors, evidence, reporting dates, and launch decisions.
- [China Cybersecurity Law vs EU NIS2 Directive](/artifacts/apac/china-cybersecurity-law/china-cybersecurity-law-vs-nis2.md): Compare China's network-operator duties with NIS2 entity duties, including scope, management accountability, incident reporting, evidence, and enforcement.
- [China cybersecurity penalties and fines](/artifacts/apac/china-cybersecurity-law/penalties-and-fines.md): Compare current China Cybersecurity Law and Data Security Law fines by actor, breach, severity, and enforcement consequence.
- [China Cybersecurity Review vs Data Export Assessment](/artifacts/apac/china-cybersecurity-law/cybersecurity-review-vs-data-export-security-assessment.md): Separate China's cybersecurity-review triggers from CAC data-export assessment triggers, thresholds, filings, evidence, timing, and reapplication rules.
- [China cybersecurity review workflow](/artifacts/apac/china-cybersecurity-law/cybersecurity-review-workflow.md): Determine whether CII procurement, platform data processing, or a qualifying foreign listing triggers China's Cybersecurity Review Measures.
- [China mobile app filing and app governance](/artifacts/apac/china-cybersecurity-law/mobile-app-filing-and-app-governance.md): Identify the China app sponsor, complete MIIT filing before service, and separate provider, platform, privacy, content, and security duties.
- [China Smart-Home Security vs Telecom and Radio Approval](/artifacts/apac/china-cybersecurity-law/smart-home-security-vs-telecom-wireless-launch.md): Separate GB/T 41387-2022 smart-home security evidence from China telecom network-access and radio approval decisions for connected products.
- [CII and network operator role triage](/artifacts/apac/china-cybersecurity-law/critical-information-infrastructure-and-network-operators.md): How to separate ordinary network operator duties from CII, procurement, and review-risk questions under China cybersecurity sources.
- [Does an app need MIIT filing and CAC app governance review?](/artifacts/apac/china-cybersecurity-law/faq/does-an-app-need-miit-filing-and-cac-app-governance-review.md): An app sponsor providing internet information services through an app in China must complete MIIT filing. CAC rules separately govern app providers and distribution platforms without creating one routine CAC approval for every app.
- [GB/T 22239-2019 classified protection baseline](/artifacts/apac/china-cybersecurity-law/classified-protection-baseline.md): How to scope and document a GB/T 22239-2019 classified protection baseline without treating the recommended standard as a standalone law.
- [GB/T 41387-2022 smart home security standard](/artifacts/apac/china-cybersecurity-law/smart-home-security-standard.md): How connected-device teams can scope and document GB/T 41387-2022 without treating it as an automatic certification or product-approval duty.
- [How do smart home security standards fit with China cybersecurity law?](/artifacts/apac/china-cybersecurity-law/faq/how-do-smart-home-security-standards-fit-with-china-cybersecurity-law.md): GB/T 41387-2022 can organize smart-home security evidence, but it is a recommended standard, not a product approval. Check app, data, MLPS, telecom access, and radio requirements separately.
- [How does important data change China cybersecurity obligations?](/artifacts/apac/china-cybersecurity-law/faq/how-does-important-data-change-cybersecurity-obligations.md): Once data is officially identified as important data, the processor needs named governance, periodic risk assessments and reports, incident controls, and a separate export decision. An internal sensitivity label alone does not establish the legal category.
- [MLPS classified protection evidence map](/artifacts/apac/china-cybersecurity-law/mlps-classified-protection-evidence-map.md): Classify a China network under MLPS, complete level 2 or above filing, map controls, and retain assessment, remediation, and change evidence.
- [What is MLPS classified protection evidence?](/artifacts/apac/china-cybersecurity-law/faq/what-is-mlps-classified-protection-evidence.md): MLPS evidence shows how a defined China network or system was graded and protected. Keep the scope, grading rationale, filing or assessment records where applicable, control mapping, test results, remediation, and reassessment history.
- [When does China cybersecurity review apply?](/artifacts/apac/china-cybersecurity-law/faq/when-does-china-cybersecurity-review-apply.md): China cybersecurity review applies to CII procurement or network-platform data processing that affects or may affect national security, plus a mandatory pre-filing trigger for certain foreign listings involving more than one million users' personal information.

*Operationalize the requirement*

*Placement: Before primary sources*

## Build the China network security evidence file

Sorena AI helps turn the answer to "Is every company a network operator under China Cybersecurity Law?" into assigned controls and retained evidence.

- [Map official sources to evidence](/solutions/research-copilot.md): Research Copilot connects the official citation, decision, owner, retained evidence, and change history.
- [Review the China route](/contact.md): Check the China Cybersecurity Law scope decision and unresolved launch questions with Sorena.


---

[Privacy Policy](https://www.sorena.io/privacy.md) | [Terms of Use](https://www.sorena.io/terms-of-use.md) | [DMCA](https://www.sorena.io/dmca.md) | [About Us](https://www.sorena.io/about-us.md)

(c) 2026 Sorena AB (559573-7338). All rights reserved.

Source: https://www.sorena.io/artifacts/apac/china-cybersecurity-law/faq/is-every-company-a-network-operator-under-china-cybersecurity-law.md
