FAQ item index

Search every question across sub-FAQs

Find the exact question, open the source answer card, and copy a direct link to the anchored sub-FAQ response.

Indexed coverage
12of12items
Across 6 modules • Updated Jul 24, 2026
Author
Sorena AI
Published
Jul 5, 2026
Updated
Jul 24, 2026
Does an app need MIIT filing and CAC app governance review?

Short answer

The 2023 MIIT notice says an app sponsor engaged in internet information services within China must complete app filing and may not provide those services without it. The filing work covers mobile apps, mini-programs, and quick apps. The sponsor files with its provincial communications administration through its network access service provider or app distribution platform; an app-store listing is not the filing. After receiving complete and accurate materials, the provincial communications administration completes the filing within 20 working days, issues a filing number, and publishes the filing information.

The MIIT notice moved existing apps through a September 2023 to March 2024 filing phase and entered normalized work in July 2024. Those transition dates have passed. A new covered app now files before service begins, and the sponsor files changes or cancellation with the original filing authority when the recorded information changes.

CAC app-governance comes from the Mobile Internet Application Information Service Management Provisions, which took effect on 1 August 2022 and apply separately to app information services and distribution services provided within China. Covered information services include examples such as instant messaging, news, knowledge question-and-answer services, forums, livestreaming, e-commerce, online audiovisual services, and life services. An app provider must maintain content, data-security, personal-information, minors, complaint, vulnerability, and incident controls as applicable to its service. A regulated service such as internet news requires the relevant licence, while a new technology, application, or function with public-opinion attributes or social-mobilization capacity requires the applicable security assessment.

A distribution platform has distinct duties: it must file with its provincial cyberspace authority within 30 days after going online, authenticate app providers, verify relevant permits or assessments, review apps and updates, manage listed apps, and keep enforcement records. That platform filing is not a CAC filing imposed on every individual app provider.

MIIT filing does not prove CAC-rule or privacy compliance. The rule on necessary personal information also prevents an app from denying its basic function merely because a user refuses personal information that is not necessary for that function. Determine the app category and basic function before setting required fields or permissions.

Citations
MIIT notice on mobile app filing work

States that app sponsors providing internet information services in China must complete filing, identifies filing channels and app forms, and bars unfiled apps from providing those services.

Does an app need MIIT filing and CAC app governance review?

What to keep as evidence

The evidence should identify each app form and each actor rather than relying on one screenshot from an app store.

  • Scope record for each app, mini-program, or quick app: package or service identifier, sponsor and provider entities, services, users, domains and Internet Protocol (IP) address resources, access provider, and distribution channels.
  • MIIT record: submitted information, access-provider or platform verification, filing number, required in-app display or link, public-query result, and change or cancellation records.
  • Provider controls: required service permits, any applicable new-function security assessment, content review, account verification, vulnerability response, data security, personal information, minors, complaints, and incident reporting.
  • Necessary-personal-information map: app category, basic function, each data field and permission, legal basis, whether it is necessary for the basic function, and behavior when consent is refused.
  • For a distribution platform: provincial CAC filing, provider identity and permit verification, listing and update reviews, monitoring, complaints, warnings, suspensions, removals, retained records, and authority reports.
Citations
How do smart home security standards fit with China cybersecurity law?

Short answer

GB/T 41387-2022, Information security technology - Smart home general security specification, is shown as current on the official standards page. It was published on 15 April 2022 and took effect on 1 November 2022. The '/T' designation identifies a recommended national standard; the implementation date is not an approval deadline or annual renewal date for every connected product.

Use the standard only after defining the product boundary: device hardware and firmware, local hub, mobile app, cloud services, accounts, data flows, interfaces, update path, and third-party components. Record which clauses apply, the design or test evidence for each clause, exceptions, remediation, and retest results. If a contract, procurement rule, certification scheme, or sector rule incorporates the standard, document that separate source and its legal or contractual effect.

Then run the independent legal routes. A network operator for a China network may have classified protection and incident duties under Articles 23 and 27 of the consolidated 2025 Cybersecurity Law. A companion app may need MIIT app filing and must meet CAC app-governance and personal-information rules. Radio transmitters may need radio type approval unless an exemption applies. Under the cited band rules, certain outdoor access points, center stations, and point-to-point stations in the 2400 MHz or 5800 MHz bands need a station licence when they exceed the applicable power threshold. Covered telecom equipment connected to a public telecommunications network may require telecom network access under the current equipment catalogue.

For example, a smart camera sold with a China-facing companion app and cloud account needs separate decisions for the device boundary under GB/T 41387-2022, the app sponsor and app provider, the cloud or backend network operator, personal-information processing, and the radio configuration. A local-only sensor with no app, cloud service, or public-network connection can follow a different route, but its transmitter and any incorporated contractual standard still need their own checks. These are examples; the final result depends on the released functions, architecture, responsible entities, and current catalogues.

Citations
PRC Cybersecurity Law

Articles 23, 24 and 27 support the separate network-operation, classified-protection, network-product security, and incident analysis in the consolidated 2025 text.

How do smart home security standards fit with China cybersecurity law?

What to keep as evidence

The official metadata page confirms the standard's identity and status but does not supply enough text for clause-level claims. Obtain the applicable edition before building the control map.

  • Architecture and data-flow record covering hardware, firmware, hub, app, cloud, accounts, interfaces, updates, data, and suppliers.
  • Applicability record for GB/T 41387-2022: why it is used, who incorporated it, edition, clauses, exclusions, and whether the effect is legal, contractual, procurement-based, or voluntary.
  • Clause-level control map with owner, design evidence, configuration, test method and result, exception, remediation, retest, and release decision.
  • Separate MIIT app-filing, CAC app-governance, personal-information, network-operator, classified-protection, telecom network-access, radio type-approval, and station-licensing decisions.
  • Change triggers for hardware, radio module, firmware, app permissions, cloud location, data use, interfaces, suppliers, standards editions, or incorporated requirements.
Citations
PRC Cybersecurity Law

Supports the separate classified-protection and secure network-product analysis; it does not make the GB/T smart-home standard an approval.

How does important data change China cybersecurity obligations?

Short answer

The Data Security Law classifies data by its importance to economic and social development and by the harm that alteration, destruction, disclosure, illegal acquisition, or illegal use could cause to national security, the public interest, or lawful individual and organizational interests. Regions and departments must identify important-data catalogues for their sectors and protect listed data more closely. Core data is a separate, stricter category. A company's internal 'critical' or 'confidential' label can support screening, but it does not by itself establish either legal category.

For export screening, the 2024 Provisions say a processor does not need to declare data as important data unless a relevant department or region has notified the processor or publicly identified the data as important. This rule addresses the export filing decision; it does not remove the duty to monitor applicable catalogues and official notices.

An important-data processor must identify a data-security responsible person and management body: a named accountable lead and an organizational function responsible for implementing the data-security duties. The processor must periodically assess its data-processing activities and submit a report covering the types and quantities of important data, processing activities, risks, and response measures. The Data Security Law does not state one universal interval for every sector, so the processor must check applicable departmental and regional rules. General duties to monitor risk, remedy vulnerabilities, handle incidents, notify users where required, and report to the competent authority also apply.

A transfer outside China needs its own route. Under the 2024 Provisions, a CII operator exporting personal information or important data, and a non-CII processor exporting important data, must apply for a data export security assessment through the provincial cyberspace authority, subject to the stated special provisions. Personal-information volume exemptions do not exempt important-data exports.

A successful assessment result is valid for three years from the result date. If the export will continue and no re-application trigger has occurred, the processor may apply for a three-year extension within 60 working days before expiry; the national cyberspace authority decides whether to approve it. Keep the validity period, extension decision, and any change requiring a new application separate from the periodic domestic important-data risk assessment.

Citations
PRC Data Security Law

Articles 21 and 27-31 establish important-data catalogues, enhanced governance, monitoring, incident response, periodic risk assessment and reporting, and separate export rules.

Measures for Security Assessment of Data Export

Use for the security-assessment procedure, pre-filing self-assessment, application materials, assessment factors, and re-application triggers where the current 2024 Provisions require an assessment.

Provisions on Promoting and Regulating Cross-border Data Flow

Articles 2 and 7 state the official-identification rule and require CII operators exporting personal information or important data, and other processors exporting important data, to apply for a security assessment. Article 9 sets the assessment result's three-year validity and possible extension.

How does important data change China cybersecurity obligations?

What to keep as evidence

Preserve the source and date behind the classification. A self-created label alone does not show that the legal category applies.

  • Data inventory: source, type, quantity, purpose, processing operations, systems, storage location, recipients, retention, and business and system owners.
  • Identification record: each applicable sector or regional catalogue, direct authority notice, or public identification, including version, date, matching data fields, and unresolved classification questions.
  • Harm analysis tied to the statutory classification factors, without inventing a universal volume or sensitivity threshold.
  • Governance evidence: named data-security responsible person and management body, decision rights, policies, training, access, monitoring, incident, supplier, and remediation records.
  • Periodic risk-assessment report and submission evidence covering the important-data types and quantities, processing activities, risks, and response measures.
  • For every transfer outside China, a documented CII-status and export-route decision, self-assessment where required, filing materials, outcome, validity period, and change triggers.
Citations
PRC Data Security Law

Articles 21 and 27-31 support the classification, governance, assessment, reporting, incident, and export evidence listed here.

Is every company a network operator under China Cybersecurity Law?

Short answer

The Cybersecurity Law applies to the construction, operation, maintenance, and use of networks within China and to their cybersecurity supervision. It defines a network broadly as a system made up of computers or other information terminals and related equipment that collects, stores, transmits, exchanges, or processes information under rules and procedures. A network operator is the network's owner or administrator or a network service provider.

Start with facts, not the company's industry label. Identify the network or service, its China connection, the legal entity that owns it, who sets access and operating rules, who administers it, and who provides the network service. For example, an entity that operates a China office network, app backend, connected-product platform, or managed network service may meet the definition for that system. A company does not qualify merely because it buys software, uses a supplier's network, owns a product brand, or has a China affiliate. A parent company, China subsidiary, cloud provider, app provider, and outsourced administrator may each perform different roles; the contract helps identify responsibilities but does not replace the statutory facts.

Network-operator status brings classified protection and incident duties now found in Articles 23 and 27 of the law's consolidated 2025 text. They include internal rules and a named security lead, technical protections, monitoring, at least six months of network-log retention, data classification, backup and encryption, and a network-security incident plan. Additional duties depend on the service, data, users, sector, and whether another legal role applies.

Do not infer CII status or cybersecurity review from the baseline role. CII depends on the protected-sector and serious-harm tests and the competent protection authority's process. Cybersecurity review requires the separate triggers in the Cybersecurity Review Measures. An app provider is the owner or operator providing information services through a mobile app, while a distribution platform provides app publication, download, or dynamic-loading services. A personal-information processor determines the purpose and method of processing personal information; an important-data processor handles data identified under an applicable official catalogue, notice, or public identification. Each role needs a separate finding.

The Cybersecurity Law was amended in 2025 with effect from 1 January 2026. The statutory operator definition and baseline-duty analysis remain relevant, while current penalty or enforcement conclusions must use the amended law rather than the 2016 penalties alone.

Citations
PRC Cybersecurity Law

Articles 2, 23, 27 and 78 provide the territorial scope, baseline and incident duties, the network and network-operator definitions, and the six-month minimum network-log retention in the consolidated 2025 text.

Is every company a network operator under China Cybersecurity Law?

What to keep as evidence

Keep one role record for each network or service. Update it when the architecture, entity responsibilities, hosting, users, data, or suppliers change.

  • Boundary and China nexus: purpose, architecture, equipment and terminals, users, data, interfaces, hosting, and service locations.
  • Entity-role map: owner, administrator, network service provider, access-rule setter, maintainer, monitor, incident lead, and relevant contracts.
  • Reasoned network-operator conclusion tied to Articles 2 and 78 of the consolidated 2025 text, including uncertainties and any local or sector input.
  • Articles 23 and 27 control map and evidence, including responsible personnel, technical protections, monitoring, six-month minimum network logs, data classification, backup and encryption, and incident planning.
  • Separate conclusions for CII, cybersecurity review, app provider, distribution platform, personal-information processing, important data, and data exports.
  • Reassessment triggers for ownership, architecture, hosting, functions, users, data, suppliers, contracts, or applicable rules.
Citations
PRC Cybersecurity Law

Supports the scope, role analysis, baseline-control map, and six-month minimum network-log record.

What is MLPS classified protection evidence?

Short answer

Article 23 of the Cybersecurity Law's consolidated 2025 text requires each network operator to perform security-protection duties under the classified protection system. The evidence starts with the protected object, responsible operator, system boundary, and protection level, then records filing where required, controls, operating procedures, monitoring, backup, incident handling, testing, gaps, remediation, and reassessment tied to that decision.

GB/T 22239-2019, Information security technology - Baseline for classified protection of cybersecurity, is a current recommended national standard. It took effect on 1 December 2019 and supports clause-level control mapping. Its '/T' designation and implementation date do not turn it into a separate law or prove that a system has completed every applicable filing, assessment, or sector requirement.

GB/T 22240-2020 grades a protected object from the interest harmed and the severity of that harm. Level 1 covers general harm to the lawful rights and interests of citizens, legal persons, or other organizations without harm to national security, social order, or the public interest. Level 2 covers serious or especially serious harm to those rights and interests, or general harm to social order or the public interest, without harm to national security. Level 3 covers serious harm to social order or the public interest, or general harm to national security. Level 4 covers especially serious harm to social order or the public interest, or serious harm to national security. Level 5 covers especially serious harm to national security. The 2007 management measures use older information-system wording, so retain the classification guide, edition, rationale, and approval record rather than mixing the two descriptions. System size or data volume alone does not determine the level.

The general classified-protection management measures require filing for level 2 or higher information systems: an operating system files within 30 days after its level is determined, and a new system files within 30 days after entering operation. Level 3 systems undergo assessment and self-inspection at least annually, level 4 systems at least every six months, and level 5 systems according to special security needs. Sector regimes can use different protected objects, filing channels, or cycles, so first determine whether the general public-security route, a sector route, or both apply; MIIT's communications-network grading and filing is not the same procedure as public-security classified-protection filing.

Citations
PRC Cybersecurity Law

Articles 23 and 78 establish classified-protection duties for network operators and define the relevant network and operator terms in the consolidated 2025 text.

What is MLPS classified protection evidence?

What to keep as evidence

A reviewer should be able to follow the record from system scope through classification, implementation, assessment, remediation, and reassessment.

  • System boundary and inventory: owner, purpose, users, data, interfaces, infrastructure, hosting, dependencies, and suppliers.
  • Grading record: protected object, responsible operator, affected interests, severity-of-harm analysis, proposed protection level, method, result, approver, date, and any required authority, sector, or specialist input.
  • Applicability record: the law, current standard edition, sector rules, and each clause mapped to a technical or management control and evidence owner.
  • Operating evidence: access control, malware protection, monitoring and logs, data classification and backup, incident plan and exercises, personnel controls, and supplier controls, to the extent applicable to the grade.
  • Filing and assessment record where required: filing form and receipt, submitted topology and governance material, assessment scope, qualified assessor where required, findings, corrective actions, retest results, and closure evidence. Keep public-security and sector filings separate.
  • Reassessment triggers for material changes to purpose, architecture, hosting, data, interfaces, suppliers, threats, or applicable rules; do not invent one renewal date for all systems.
Citations
PRC Cybersecurity Law

Articles 23 and 27 identify baseline classified-protection and incident duties, including internal rules, responsible personnel, technical protections, monitoring and logs, data classification, backup, encryption, and incident planning.

When does China cybersecurity review apply?

Short answer

Article 2 covers two situations when national security is or may be affected: a critical information infrastructure, or CII, operator procures network products or services; or a network platform operator conducts data-processing activities. For CII procurement, Article 5 requires the operator to predict the national-security risk and apply when the product or service affects or may affect national security. For platform processing, keep a reasoned national-security analysis even though the Measures do not supply a numeric filing threshold.

Article 7 adds a mandatory trigger: a network platform operator holding personal information of more than one million users must apply before a listing abroad to the Cybersecurity Review Office, the CAC office that organizes the review. The threshold belongs to that trigger. It is not a safe harbour for CII procurement, other platform processing, or a review initiated by the authorities under Article 16.

The Measures say network products and services mainly include core network equipment, important communications products, high-performance computers and servers, high-capacity storage equipment, large databases and application software, network-security equipment, cloud-computing services, and other products or services with an important effect on CII, network security, or data security. This is an inclusive list, not a finding that every purchase in those categories requires review; the CII-operator and national-security tests still control.

The risk assessment is broader than a conventional technical-security test. Article 10 includes illegal control, interference, or destruction of CII; supply interruption and supplier reliability; product security, openness, transparency, and source diversity; the supplier's compliance with Chinese law; theft, disclosure, destruction, illegal use, or illegal export of core data, important data, or large amounts of personal information; and foreign-government influence or control associated with a listing.

If filing is required, the applicant submits an application, a national-security impact analysis, relevant procurement agreements or proposed listing documents, and other requested materials. The office has 10 working days after receiving compliant materials to decide whether a review is needed. The initial review period is generally 30 working days and may be extended by 15; a special review generally takes 90 working days and may be extended. Time spent supplying supplemental materials is excluded.

A written no-filing decision should identify the actor, transaction, product or service, supplier, system and data effects, listing facts, and national-security analysis. Reassess when those facts change. A general network-operator label or a user count below one million is not enough to close the analysis.

Citations
Cybersecurity Review Measures

Articles 2, 5, 7-16 and 21 establish the covered actors and triggers, national-security factors, filing materials, review stages and timing, authority-initiated review, and covered network products and services.

When does China cybersecurity review apply?

What to keep as evidence

Keep enough information to reproduce the trigger analysis and, if applicable, the filing and authority procedure.

  • Actor record: why the entity is or is not a CII operator or network platform operator for this activity, including any authority identification or sector input.
  • Transaction record: procurement, product or service, supplier and subcontractors, affected CII functions, dependencies, continuity measures, data-processing activity, or proposed foreign listing.
  • Data record: core data, important data, personal information, user count and counting method, storage and transfers, access, recipients, and risks of theft, disclosure, destruction, illegal use, or illegal export.
  • Article 10 national-security assessment covering control or disruption, continuity, security and transparency, supply diversity and reliability, supplier legal compliance, data risks, and listing-related foreign influence or control.
  • Where filed: application, impact analysis, procurement agreement or listing documents, supplier cooperation clauses, supplemental requests and responses, preventive measures during review, written outcome, and post-review commitments.
  • Timeline record separating the 10-working-day screening decision, ordinary review, possible 15-working-day extension, special review, excluded supplemental-material time, and actual notices.
  • Reassessment triggers for CII or platform status, product or service, supplier, architecture, dependency, data type or volume, processing, export, or listing changes.
Citations
Cybersecurity Review Measures

Supports each actor, trigger, risk-factor, filing, procedure, timing, outcome, commitment, and reassessment record listed here.

Page 1 of 1
Previous1Next