---
title: "China Cybersecurity Law FAQ"
canonical_url: "https://www.sorena.io/artifacts/apac/china-cybersecurity-law/faq"
source_url: "https://www.sorena.io/artifacts/apac/china-cybersecurity-law/faq/items"
author: "Sorena AI"
description: "Practical answers on China network-operator scope, MLPS evidence, important data, cybersecurity review, app filing and governance, and smart-home standards under the law in force from 1 January 2026."
published_at: "2026-07-05"
updated_at: "2026-07-24"
keywords:
  - "China Cybersecurity Law"
  - "Data Security Law"
  - "Cybersecurity Review Measures"
  - "Mobile app filing"
  - "MLPS"
---
**[SORENA](https://www.sorena.io/)** - AI-Powered GRC Platform

[Home](https://www.sorena.io/) | [Solutions](https://www.sorena.io/solutions) | [Artifacts](https://www.sorena.io/artifacts) | [About Us](https://www.sorena.io/about-us) | [Contact](https://www.sorena.io/contact) | [Portal](https://app.sorena.io)

---

# China Cybersecurity Law FAQ

Practical answers on China network-operator scope, MLPS evidence, important data, cybersecurity review, app filing and governance, and smart-home standards under the law in force from 1 January 2026.

*FAQ* *China*

## China Cybersecurity Law FAQ

Use these answers to decide who is a network operator, what MLPS evidence should contain, when important-data and cybersecurity-review rules apply, and how app and smart-home requirements fit together.

The Cybersecurity Law was amended in 2025 and the amended law took effect on 1 January 2026. The Data Security Law, app rules, review measures, and technical standards are separate instruments.

Start with the China activity, system, network operator, data, product, and transaction. These FAQs separate the Cybersecurity Law's baseline duties from MLPS evidence, important-data rules, cybersecurity review, app filing and governance, and product standards.

## Definitions

### Network operator

The current Cybersecurity Law defines a network operator as the owner or administrator of a network or a network service provider. A network is a system of computers or other information terminals and related equipment that collects, stores, transmits, exchanges, or processes information under defined rules and procedures.

**Why it matters here:** Identify the legal entity that owns, administers, or provides the specific network service in China. That entity carries the Article 23 classified-protection baseline and Article 27 incident duties for the network; the label should not be assigned to a corporate group without a system-level analysis.

Sources:

- [PRC Cybersecurity Law, Articles 23, 27, and 78](https://www.cac.gov.cn/2025-12/29/c_1768735112911946.htm?ref=sorena.io)

### Critical information infrastructure

**Term:** CII

CII means important network facilities and information systems in sectors such as public communications and information services, energy, transport, water, finance, public services, e-government, and defence science and industry, plus other infrastructure whose destruction, loss of function, or data leakage could seriously harm national security, the national economy and people's livelihoods, or the public interest.

**Why it matters here:** The responsible sector protection department applies its recognition rules, identifies the infrastructure, and notifies the operator. A network operator, large company, high classified-protection level, or business in a named sector is not automatically a CII operator.

Sources:

- [Regulations on the Security Protection of Critical Information Infrastructure, Articles 2 and 8-11](https://www.cac.gov.cn/2021-08/17/c_1630785976988160.htm?ref=sorena.io)

### Multi-Level Protection Scheme

**Term:** MLPS

MLPS is a common English label for China's network security classified-protection system. Article 23 of the current Cybersecurity Law imposes baseline classified-protection duties on network operators. GB/T 22239-2019 is a recommended national baseline standard used within the wider system, not a standalone statute or a universal certification requirement.

**Why it matters here:** Define the network boundary, operator, classification method and level before selecting controls or describing an assessment result. MLPS classification does not decide CII, important-data, cybersecurity-review, privacy, or app-filing status.

Sources:

- [PRC Cybersecurity Law, Articles 23 and 78](https://www.cac.gov.cn/2025-12/29/c_1768735112911946.htm?ref=sorena.io)
- [Official national standards record for GB/T 22239-2019](https://openstd.samr.gov.cn/bzgk/gb/newGbInfo?hcno=BAFB47E8874764186BDB7865E8344DAF&ref=sorena.io)

### Important data

The Data Security Law requires important data to receive enhanced protection under national and relevant regional, departmental, industry, and sector catalogues. The classification turns on the applicable catalogue, authority identification, and the harm that alteration, destruction, leakage, illegal acquisition, or illegal use could cause; a data-volume threshold alone does not create the category.

**Why it matters here:** A processor of important data must identify a data-security responsible person and management body, conduct periodic risk assessments, submit reports to the relevant competent department, respond to incidents, and analyse any export under the applicable route.

Sources:

- [PRC Data Security Law, Articles 21 and 27-31](https://www.cac.gov.cn/2021-06/11/c_1624994566919140.htm?ref=sorena.io)

### Cybersecurity review

Cybersecurity review is the national-security review under the Cybersecurity Review Measures. It covers CII operators procuring network products or services and network platform operators conducting data-processing activities when the activity affects or may affect national security. A network platform operator holding personal information of more than one million users must also file before seeking a foreign listing.

**Why it matters here:** Identify the actor and trigger before preparing a filing. Keep the procurement national-security screen, platform data-processing screen, and specific one-million-user foreign-listing filing separate from data-export security assessment.

Sources:

- [Cybersecurity Review Measures, Articles 2 and 5-10](https://www.cac.gov.cn/2022-01/04/c_1642894602182845.htm?ref=sorena.io)

### Ministry of Industry and Information Technology app filing

**Term:** MIIT app filing

MIIT app filing is the filing for an app sponsor providing an app-based internet information service in China. The sponsor submits through a network access provider or app distribution platform to the provincial communications administration for the sponsor's place of residence. A new covered app files before service begins, displays the filing number and query link, and files later changes or cancellation.

**Why it matters here:** This sponsor filing is separate from the provincial cyberspace filing and continuing governance duties that apply to an app distribution platform.

Sources:

- [MIIT notice on mobile app filing work](https://www.miit.gov.cn/zwgk/zcwj/wjfb/tz/art/2023/art_920db564162e4312916a01bed6540ad8.html?ref=sorena.io)

### Mobile app distribution platform

**Term:** app distribution platform

An app distribution platform is an internet information service provider that offers app publication, download, or dynamic-loading services. The 2022 app provisions include app stores, quick-app centres, internet mini-program platforms, and browser plug-in platforms.

**Why it matters here:** The platform files with its provincial cyberspace authority within 30 days after going online and maintains provider verification, listing and update review, monitoring, complaint, enforcement-record, suspension, takedown, and reporting controls. These duties are separate from an app sponsor's MIIT filing.

Sources:

- [Mobile Internet Application Information Service Management Provisions, Articles 2 and 17-22](https://www.cac.gov.cn/2022-06/14/c_1656821626455324.htm?ref=sorena.io)

### Core data

Core data is the Data Security Law's highest-protection category for data connected to national security, the lifelines of the national economy, important aspects of people's livelihoods, or major public interests. The law requires stricter management of core data than the general classified and graded protection system.

**Why it matters here:** Do not use core data as a synonym for important data, personal information, commercially sensitive data, or a large data set. Record the authority, catalogue, or other controlling basis for the classification and apply the stricter management required for the category.

Sources:

- [PRC Data Security Law, Article 21](https://www.cac.gov.cn/2021-06/11/c_1624994566919140.htm?ref=sorena.io)

### App sponsor for MIIT filing

**Term:** app sponsor

The app sponsor is the organisation or individual providing the app-based internet information service and named in the MIIT filing. It supplies truthful identity, network-resource, service, approval, and contact information, displays the filing number and query link, and files changes or cancellation.

**Why it matters here:** Confirm the filed legal entity instead of assuming that the developer, brand owner, app provider, access provider, or distribution platform is the sponsor. One entity may hold several roles, but each role needs its own record.

Sources:

- [MIIT notice on mobile app filing work](https://www.miit.gov.cn/zwgk/zcwj/wjfb/tz/art/2023/art_920db564162e4312916a01bed6540ad8.html?ref=sorena.io)

### Network platform operator under the Cybersecurity Review Measures

**Term:** network platform operator

The Cybersecurity Review Measures use network platform operator for the operator whose data-processing activity affects or may affect national security. The measures also require such an operator to file before a foreign listing when it holds personal information of more than one million users. The term is not defined as another name for every network operator, online service, or CII operator.

**Why it matters here:** Document the platform role, data-processing activity, user count, listing destination, and national-security analysis. The measures use the phrase foreign listing; check the current official interpretation for a specific destination or transaction rather than extending the trigger to every overseas corporate event.

Sources:

- [Cybersecurity Review Measures, Articles 2 and 7-10](https://www.cac.gov.cn/2022-01/04/c_1642894602182845.htm?ref=sorena.io)

## Browse sub-FAQ modules

### [Does an app need MIIT filing and CAC app governance review?](/artifacts/apac/china-cybersecurity-law/faq/does-an-app-need-miit-filing-and-cac-app-governance-review.md)

An app sponsor providing internet information services through an app in China must complete MIIT filing. CAC rules separately govern app providers and distribution platforms without creating one routine CAC approval for every app.

- 2 items

### [How do smart home security standards fit with China cybersecurity law?](/artifacts/apac/china-cybersecurity-law/faq/how-do-smart-home-security-standards-fit-with-china-cybersecurity-law.md)

GB/T 41387-2022 can organize smart-home security evidence, but it is a recommended standard, not a product approval. Check app, data, MLPS, telecom access, and radio requirements separately.

- 2 items

### [How does important data change China cybersecurity obligations?](/artifacts/apac/china-cybersecurity-law/faq/how-does-important-data-change-cybersecurity-obligations.md)

Once data is officially identified as important data, the processor needs named governance, periodic risk assessments and reports, incident controls, and a separate export decision. An internal sensitivity label alone does not establish the legal category.

- 2 items

### [Is every company a network operator under China Cybersecurity Law?](/artifacts/apac/china-cybersecurity-law/faq/is-every-company-a-network-operator-under-china-cybersecurity-law.md)

No. Under China's Cybersecurity Law, a network operator is an owner or administrator of a network or a network service provider. Apply that definition to each China network or service, then test CII and other roles separately.

- 2 items

### [What is MLPS classified protection evidence?](/artifacts/apac/china-cybersecurity-law/faq/what-is-mlps-classified-protection-evidence.md)

MLPS evidence shows how a defined China network or system was graded and protected. Keep the scope, grading rationale, filing or assessment records where applicable, control mapping, test results, remediation, and reassessment history.

- 2 items

### [When does China cybersecurity review apply?](/artifacts/apac/china-cybersecurity-law/faq/when-does-china-cybersecurity-review-apply.md)

China cybersecurity review applies to CII procurement or network-platform data processing that affects or may affect national security, plus a mandatory pre-filing trigger for certain foreign listings involving more than one million users' personal information.

- 2 items

Browse all indexed questions: [/artifacts/apac/china-cybersecurity-law/faq/items](/artifacts/apac/china-cybersecurity-law/faq/items.md)

## All FAQ items

*Page 1 of 1. Showing 12 of 12 items.*

### [Short answer](/artifacts/apac/china-cybersecurity-law/faq/does-an-app-need-miit-filing-and-cac-app-governance-review.md#short-answer)

*Module: [Does an app need MIIT filing and CAC app governance review?](/artifacts/apac/china-cybersecurity-law/faq/does-an-app-need-miit-filing-and-cac-app-governance-review.md)*

The 2023 MIIT notice says an app sponsor engaged in internet information services within China must complete app filing and may not provide those services without it. The filing work covers mobile apps, mini-programs, and quick apps. The sponsor files with its provincial communications administration through its network access service provider or app distribution platform; an app-store listing is not the filing. After receiving complete and accurate materials, the provincial communications administration completes the filing within 20 working days, issues a filing number, and publishes the filing information.

Sources for this answer:

- [MIIT notice on mobile app filing work](https://www.miit.gov.cn/zwgk/zcwj/wjfb/tz/art/2023/art_920db564162e4312916a01bed6540ad8.html?ref=sorena.io) - States that app sponsors providing internet information services in China must complete filing, identifies filing channels and app forms, and bars unfiled apps from providing those services.
- [Mobile Internet Application Information Service Management Provisions](https://www.cac.gov.cn/2022-06/14/c_1656821626455324.htm?ref=sorena.io) - Articles 5-17 and 19-22 set provider and distribution-platform duties, including the platform's provincial filing within 30 days after launch, provider verification, app review, data and privacy controls, complaints, and records.
- [Necessary Personal Information Scope for Common Types of Mobile Apps](https://www.cac.gov.cn/2021-03/22/c_1617990997054277.htm?ref=sorena.io) - Defines basic functions and necessary personal information by common app category and bars refusal of the basic function solely because a user declines non-necessary personal information.

### [What to keep as evidence](/artifacts/apac/china-cybersecurity-law/faq/does-an-app-need-miit-filing-and-cac-app-governance-review.md#what-to-keep-as-evidence)

*Module: [Does an app need MIIT filing and CAC app governance review?](/artifacts/apac/china-cybersecurity-law/faq/does-an-app-need-miit-filing-and-cac-app-governance-review.md)*

The evidence should identify each app form and each actor rather than relying on one screenshot from an app store.

- Scope record for each app, mini-program, or quick app: package or service identifier, sponsor and provider entities, services, users, domains and Internet Protocol (IP) address resources, access provider, and distribution channels.
- MIIT record: submitted information, access-provider or platform verification, filing number, required in-app display or link, public-query result, and change or cancellation records.
- Provider controls: required service permits, any applicable new-function security assessment, content review, account verification, vulnerability response, data security, personal information, minors, complaints, and incident reporting.
- Necessary-personal-information map: app category, basic function, each data field and permission, legal basis, whether it is necessary for the basic function, and behavior when consent is refused.
- For a distribution platform: provincial CAC filing, provider identity and permit verification, listing and update reviews, monitoring, complaints, warnings, suspensions, removals, retained records, and authority reports.

Sources for this answer:

- [MIIT notice on mobile app filing work](https://www.miit.gov.cn/zwgk/zcwj/wjfb/tz/art/2023/art_920db564162e4312916a01bed6540ad8.html?ref=sorena.io) - Supports the filing identifiers, submission path, display, public-query, change, cancellation, platform-checking, and supervision records.
- [Mobile Internet Application Information Service Management Provisions](https://www.cac.gov.cn/2022-06/14/c_1656821626455324.htm?ref=sorena.io) - Supports provider controls and the separate distribution-platform filing, verification, review, monitoring, complaint, action, and recordkeeping evidence.
- [Necessary Personal Information Scope for Common Types of Mobile Apps](https://www.cac.gov.cn/2021-03/22/c_1617990997054277.htm?ref=sorena.io) - Supports the category-by-category basic-function and necessary-personal-information map.

### [Short answer](/artifacts/apac/china-cybersecurity-law/faq/how-do-smart-home-security-standards-fit-with-china-cybersecurity-law.md#short-answer)

*Module: [How do smart home security standards fit with China cybersecurity law?](/artifacts/apac/china-cybersecurity-law/faq/how-do-smart-home-security-standards-fit-with-china-cybersecurity-law.md)*

GB/T 41387-2022, Information security technology - Smart home general security specification, is shown as current on the official standards page. It was published on 15 April 2022 and took effect on 1 November 2022. The '/T' designation identifies a recommended national standard; the implementation date is not an approval deadline or annual renewal date for every connected product.

Sources for this answer:

- [GB/T smart home general security specification](https://openstd.samr.gov.cn/bzgk/gb/newGbInfo?hcno=B1C14E854C0BA30D1C29FC376299761A&ref=sorena.io) - Confirms the standard number, recommended GB/T status, current status, title, publication date, 1 November 2022 implementation date, and standards authority.
- [PRC Cybersecurity Law](https://sdca.miit.gov.cn/zwgk/fgbz/art/2026/art_4815dd4ec11d454783b83a91502a3cc7.html?ref=sorena.io) - Articles 23, 24 and 27 support the separate network-operation, classified-protection, network-product security, and incident analysis in the consolidated 2025 text.
- [MIIT notice on 2400 MHz, 5100 MHz and 5800 MHz radio management](https://wap.miit.gov.cn/zwgk/zcwj/wjfb/tz/art/2021/art_e4ae71252eab42928daf0ea620976e4e.html?ref=sorena.io) - Sets model-approval, antenna, technical, band-use, and outdoor station-licensing requirements and identifies the cited power thresholds.

### [What to keep as evidence](/artifacts/apac/china-cybersecurity-law/faq/how-do-smart-home-security-standards-fit-with-china-cybersecurity-law.md#what-to-keep-as-evidence)

*Module: [How do smart home security standards fit with China cybersecurity law?](/artifacts/apac/china-cybersecurity-law/faq/how-do-smart-home-security-standards-fit-with-china-cybersecurity-law.md)*

The official metadata page confirms the standard's identity and status but does not supply enough text for clause-level claims. Obtain the applicable edition before building the control map.

- Architecture and data-flow record covering hardware, firmware, hub, app, cloud, accounts, interfaces, updates, data, and suppliers.
- Applicability record for GB/T 41387-2022: why it is used, who incorporated it, edition, clauses, exclusions, and whether the effect is legal, contractual, procurement-based, or voluntary.
- Clause-level control map with owner, design evidence, configuration, test method and result, exception, remediation, retest, and release decision.
- Separate MIIT app-filing, CAC app-governance, personal-information, network-operator, classified-protection, telecom network-access, radio type-approval, and station-licensing decisions.
- Change triggers for hardware, radio module, firmware, app permissions, cloud location, data use, interfaces, suppliers, standards editions, or incorporated requirements.

Sources for this answer:

- [GB/T smart home general security specification](https://openstd.samr.gov.cn/bzgk/gb/newGbInfo?hcno=B1C14E854C0BA30D1C29FC376299761A&ref=sorena.io) - Supports the standard identity, recommended status, current status, and edition date used in the applicability record.
- [PRC Cybersecurity Law](https://sdca.miit.gov.cn/zwgk/fgbz/art/2026/art_4815dd4ec11d454783b83a91502a3cc7.html?ref=sorena.io) - Supports the separate classified-protection and secure network-product analysis; it does not make the GB/T smart-home standard an approval.
- [MIIT notice on 2400 MHz, 5100 MHz and 5800 MHz radio management](https://wap.miit.gov.cn/zwgk/zcwj/wjfb/tz/art/2021/art_e4ae71252eab42928daf0ea620976e4e.html?ref=sorena.io) - Supports the radio type-approval exemptions and requirements and the station-licensing distinction for these common smart-home bands.

### [Short answer](/artifacts/apac/china-cybersecurity-law/faq/how-does-important-data-change-cybersecurity-obligations.md#short-answer)

*Module: [How does important data change China cybersecurity obligations?](/artifacts/apac/china-cybersecurity-law/faq/how-does-important-data-change-cybersecurity-obligations.md)*

The Data Security Law classifies data by its importance to economic and social development and by the harm that alteration, destruction, disclosure, illegal acquisition, or illegal use could cause to national security, the public interest, or lawful individual and organizational interests. Regions and departments must identify important-data catalogues for their sectors and protect listed data more closely. Core data is a separate, stricter category. A company's internal 'critical' or 'confidential' label can support screening, but it does not by itself establish either legal category.

Sources for this answer:

- [PRC Data Security Law](https://www.cac.gov.cn/2021-06/11/c_1624994566919140.htm?ref=sorena.io) - Articles 21 and 27-31 establish important-data catalogues, enhanced governance, monitoring, incident response, periodic risk assessment and reporting, and separate export rules.
- [Measures for Security Assessment of Data Export](https://www.cac.gov.cn/2022-07/07/c_1658811536396503.htm?ref=sorena.io) - Use for the security-assessment procedure, pre-filing self-assessment, application materials, assessment factors, and re-application triggers where the current 2024 Provisions require an assessment.
- [Provisions on Promoting and Regulating Cross-border Data Flow](https://www.cac.gov.cn/2024-03/22/c_1712776611775634.htm?ref=sorena.io) - Articles 2 and 7 state the official-identification rule and require CII operators exporting personal information or important data, and other processors exporting important data, to apply for a security assessment. Article 9 sets the assessment result's three-year validity and possible extension.

### [What to keep as evidence](/artifacts/apac/china-cybersecurity-law/faq/how-does-important-data-change-cybersecurity-obligations.md#what-to-keep-as-evidence)

*Module: [How does important data change China cybersecurity obligations?](/artifacts/apac/china-cybersecurity-law/faq/how-does-important-data-change-cybersecurity-obligations.md)*

Preserve the source and date behind the classification. A self-created label alone does not show that the legal category applies.

- Data inventory: source, type, quantity, purpose, processing operations, systems, storage location, recipients, retention, and business and system owners.
- Identification record: each applicable sector or regional catalogue, direct authority notice, or public identification, including version, date, matching data fields, and unresolved classification questions.
- Harm analysis tied to the statutory classification factors, without inventing a universal volume or sensitivity threshold.
- Governance evidence: named data-security responsible person and management body, decision rights, policies, training, access, monitoring, incident, supplier, and remediation records.
- Periodic risk-assessment report and submission evidence covering the important-data types and quantities, processing activities, risks, and response measures.
- For every transfer outside China, a documented CII-status and export-route decision, self-assessment where required, filing materials, outcome, validity period, and change triggers.

Sources for this answer:

- [PRC Data Security Law](https://www.cac.gov.cn/2021-06/11/c_1624994566919140.htm?ref=sorena.io) - Articles 21 and 27-31 support the classification, governance, assessment, reporting, incident, and export evidence listed here.
- [Measures for Security Assessment of Data Export](https://www.cac.gov.cn/2022-07/07/c_1658811536396503.htm?ref=sorena.io) - Supports the self-assessment, application materials, assessment factors, procedure, and change-trigger records where an export security assessment is required.
- [Provisions on Promoting and Regulating Cross-border Data Flow](https://www.cac.gov.cn/2024-03/22/c_1712776611775634.htm?ref=sorena.io) - Supports the current official-identification rule, important-data export trigger, three-year validity period, and extension route.

### [Short answer](/artifacts/apac/china-cybersecurity-law/faq/is-every-company-a-network-operator-under-china-cybersecurity-law.md#short-answer)

*Module: [Is every company a network operator under China Cybersecurity Law?](/artifacts/apac/china-cybersecurity-law/faq/is-every-company-a-network-operator-under-china-cybersecurity-law.md)*

The Cybersecurity Law applies to the construction, operation, maintenance, and use of networks within China and to their cybersecurity supervision. It defines a network broadly as a system made up of computers or other information terminals and related equipment that collects, stores, transmits, exchanges, or processes information under rules and procedures. A network operator is the network's owner or administrator or a network service provider.

Sources for this answer:

- [PRC Cybersecurity Law](https://sdca.miit.gov.cn/zwgk/fgbz/art/2026/art_4815dd4ec11d454783b83a91502a3cc7.html?ref=sorena.io) - Articles 2, 23, 27 and 78 provide the territorial scope, baseline and incident duties, the network and network-operator definitions, and the six-month minimum network-log retention in the consolidated 2025 text.
- [Mobile Internet Application Information Service Management Provisions](https://www.cac.gov.cn/2022-06/14/c_1656821626455324.htm?ref=sorena.io) - Shows that app provider and app distribution platform are separate operational roles with their own duties; those labels should not be collapsed into network-operator status.
- [NPC decision amending the PRC Cybersecurity Law](https://www.npc.gov.cn/npc/c2/c30834/202510/t20251028_449031.html?ref=sorena.io) - Confirms that the amended Cybersecurity Law took effect on 1 January 2026 and supersedes reliance on the original penalty provisions alone.

### [What to keep as evidence](/artifacts/apac/china-cybersecurity-law/faq/is-every-company-a-network-operator-under-china-cybersecurity-law.md#what-to-keep-as-evidence)

*Module: [Is every company a network operator under China Cybersecurity Law?](/artifacts/apac/china-cybersecurity-law/faq/is-every-company-a-network-operator-under-china-cybersecurity-law.md)*

Keep one role record for each network or service. Update it when the architecture, entity responsibilities, hosting, users, data, or suppliers change.

- Boundary and China nexus: purpose, architecture, equipment and terminals, users, data, interfaces, hosting, and service locations.
- Entity-role map: owner, administrator, network service provider, access-rule setter, maintainer, monitor, incident lead, and relevant contracts.
- Reasoned network-operator conclusion tied to Articles 2 and 78 of the consolidated 2025 text, including uncertainties and any local or sector input.
- Articles 23 and 27 control map and evidence, including responsible personnel, technical protections, monitoring, six-month minimum network logs, data classification, backup and encryption, and incident planning.
- Separate conclusions for CII, cybersecurity review, app provider, distribution platform, personal-information processing, important data, and data exports.
- Reassessment triggers for ownership, architecture, hosting, functions, users, data, suppliers, contracts, or applicable rules.

Sources for this answer:

- [PRC Cybersecurity Law](https://sdca.miit.gov.cn/zwgk/fgbz/art/2026/art_4815dd4ec11d454783b83a91502a3cc7.html?ref=sorena.io) - Supports the scope, role analysis, baseline-control map, and six-month minimum network-log record.
- [Mobile Internet Application Information Service Management Provisions](https://www.cac.gov.cn/2022-06/14/c_1656821626455324.htm?ref=sorena.io) - Supports the separate app-provider and distribution-platform role decisions.

### [Short answer](/artifacts/apac/china-cybersecurity-law/faq/what-is-mlps-classified-protection-evidence.md#short-answer)

*Module: [What is MLPS classified protection evidence?](/artifacts/apac/china-cybersecurity-law/faq/what-is-mlps-classified-protection-evidence.md)*

Article 23 of the Cybersecurity Law's consolidated 2025 text requires each network operator to perform security-protection duties under the classified protection system. The evidence starts with the protected object, responsible operator, system boundary, and protection level, then records filing where required, controls, operating procedures, monitoring, backup, incident handling, testing, gaps, remediation, and reassessment tied to that decision.

Sources for this answer:

- [GB/T 22239 classified protection baseline requirements](https://openstd.samr.gov.cn/bzgk/gb/newGbInfo?hcno=BAFB47E8874764186BDB7865E8344DAF&ref=sorena.io) - Use as the MLPS/classified protection baseline standard reference for control evidence mapping and the 1 December 2019 implementation date.
- [GB/T 22240-2020 classification guide](https://openstd.samr.gov.cn/bzgk/std/newGbInfo?hcno=63B89FFF7CC97EBBBED8A403396F0F00&refer=outter&ref=sorena.io) - Supports the current affected-interest and harm-severity matrix, the five protection-level outcomes, and the 1 November 2020 implementation date.
- [PRC Cybersecurity Law](https://sdca.miit.gov.cn/zwgk/fgbz/art/2026/art_4815dd4ec11d454783b83a91502a3cc7.html?ref=sorena.io) - Articles 23 and 78 establish classified-protection duties for network operators and define the relevant network and operator terms in the consolidated 2025 text.
- [NPC decision amending the PRC Cybersecurity Law](https://www.npc.gov.cn/npc/c2/c30834/202510/t20251028_449031.html?ref=sorena.io) - Confirms that the amended Cybersecurity Law took effect on 1 January 2026; the amendment mainly changed legal-liability provisions and added artificial-intelligence governance language.
- [Information Security Classified Protection Management Measures](https://www.miit.gov.cn/jgsj/xxjsfzs/xxgk/art/2020/art_a981907528694176a61b5b52c2d19895.html?ref=sorena.io) - Articles 7-18 set the five-level harm framework, grading, control implementation, recurring assessment, level 2-and-above filing, level 3-and-above materials, and higher-level inspection rules.

### [What to keep as evidence](/artifacts/apac/china-cybersecurity-law/faq/what-is-mlps-classified-protection-evidence.md#what-to-keep-as-evidence)

*Module: [What is MLPS classified protection evidence?](/artifacts/apac/china-cybersecurity-law/faq/what-is-mlps-classified-protection-evidence.md)*

A reviewer should be able to follow the record from system scope through classification, implementation, assessment, remediation, and reassessment.

- System boundary and inventory: owner, purpose, users, data, interfaces, infrastructure, hosting, dependencies, and suppliers.
- Grading record: protected object, responsible operator, affected interests, severity-of-harm analysis, proposed protection level, method, result, approver, date, and any required authority, sector, or specialist input.
- Applicability record: the law, current standard edition, sector rules, and each clause mapped to a technical or management control and evidence owner.
- Operating evidence: access control, malware protection, monitoring and logs, data classification and backup, incident plan and exercises, personnel controls, and supplier controls, to the extent applicable to the grade.
- Filing and assessment record where required: filing form and receipt, submitted topology and governance material, assessment scope, qualified assessor where required, findings, corrective actions, retest results, and closure evidence. Keep public-security and sector filings separate.
- Reassessment triggers for material changes to purpose, architecture, hosting, data, interfaces, suppliers, threats, or applicable rules; do not invent one renewal date for all systems.

Sources for this answer:

- [GB/T 22239 classified protection baseline requirements](https://openstd.samr.gov.cn/bzgk/gb/newGbInfo?hcno=BAFB47E8874764186BDB7865E8344DAF&ref=sorena.io) - Use as the MLPS/classified protection baseline standard reference for control evidence mapping and the 1 December 2019 implementation date.
- [PRC Cybersecurity Law](https://sdca.miit.gov.cn/zwgk/fgbz/art/2026/art_4815dd4ec11d454783b83a91502a3cc7.html?ref=sorena.io) - Articles 23 and 27 identify baseline classified-protection and incident duties, including internal rules, responsible personnel, technical protections, monitoring and logs, data classification, backup, encryption, and incident planning.
- [Information Security Classified Protection Management Measures](https://www.miit.gov.cn/jgsj/xxjsfzs/xxgk/art/2020/art_a981907528694176a61b5b52c2d19895.html?ref=sorena.io) - Supports the grading, filing, assessment, remediation, inspection, and supporting-document records, subject to current sector-specific rules.

### [Short answer](/artifacts/apac/china-cybersecurity-law/faq/when-does-china-cybersecurity-review-apply.md#short-answer)

*Module: [When does China cybersecurity review apply?](/artifacts/apac/china-cybersecurity-law/faq/when-does-china-cybersecurity-review-apply.md)*

Article 2 covers two situations when national security is or may be affected: a critical information infrastructure, or CII, operator procures network products or services; or a network platform operator conducts data-processing activities. For CII procurement, Article 5 requires the operator to predict the national-security risk and apply when the product or service affects or may affect national security. For platform processing, keep a reasoned national-security analysis even though the Measures do not supply a numeric filing threshold.

Sources for this answer:

- [Cybersecurity Review Measures](https://www.cac.gov.cn/2022-01/04/c_1642894602182845.htm?ref=sorena.io) - Articles 2, 5, 7-16 and 21 establish the covered actors and triggers, national-security factors, filing materials, review stages and timing, authority-initiated review, and covered network products and services.

### [What to keep as evidence](/artifacts/apac/china-cybersecurity-law/faq/when-does-china-cybersecurity-review-apply.md#what-to-keep-as-evidence)

*Module: [When does China cybersecurity review apply?](/artifacts/apac/china-cybersecurity-law/faq/when-does-china-cybersecurity-review-apply.md)*

Keep enough information to reproduce the trigger analysis and, if applicable, the filing and authority procedure.

- Actor record: why the entity is or is not a CII operator or network platform operator for this activity, including any authority identification or sector input.
- Transaction record: procurement, product or service, supplier and subcontractors, affected CII functions, dependencies, continuity measures, data-processing activity, or proposed foreign listing.
- Data record: core data, important data, personal information, user count and counting method, storage and transfers, access, recipients, and risks of theft, disclosure, destruction, illegal use, or illegal export.
- Article 10 national-security assessment covering control or disruption, continuity, security and transparency, supply diversity and reliability, supplier legal compliance, data risks, and listing-related foreign influence or control.
- Where filed: application, impact analysis, procurement agreement or listing documents, supplier cooperation clauses, supplemental requests and responses, preventive measures during review, written outcome, and post-review commitments.
- Timeline record separating the 10-working-day screening decision, ordinary review, possible 15-working-day extension, special review, excluded supplemental-material time, and actual notices.
- Reassessment triggers for CII or platform status, product or service, supplier, architecture, dependency, data type or volume, processing, export, or listing changes.

Sources for this answer:

- [Cybersecurity Review Measures](https://www.cac.gov.cn/2022-01/04/c_1642894602182845.htm?ref=sorena.io) - Supports each actor, trigger, risk-factor, filing, procedure, timing, outcome, commitment, and reassessment record listed here.

*Apply the requirement*

*Placement: Before primary sources*

## Build the China network security evidence file

Keep the network role, classified-protection, important-data, review, app-filing, and product-standard conclusions in separate records.

- [Map official sources to evidence](/solutions/research-copilot.md): Connect each FAQ conclusion to the current article number, regulated actor, trigger, evidence, filing result, and change event.
- [Review the China route](/contact.md): Check the China Cybersecurity Law scope decision and unresolved launch questions with Sorena.


---

[Privacy Policy](https://www.sorena.io/privacy.md) | [Terms of Use](https://www.sorena.io/terms-of-use.md) | [DMCA](https://www.sorena.io/dmca.md) | [About Us](https://www.sorena.io/about-us.md)

(c) 2026 Sorena AB (559573-7338). All rights reserved.

Source: https://www.sorena.io/artifacts/apac/china-cybersecurity-law/faq/items.md
