Short answer
Article 23 of the Cybersecurity Law's consolidated 2025 text requires each to perform security-protection duties under the classified protection system. The evidence starts with the protected object, responsible operator, system boundary, and , then records where required, controls, operating procedures, monitoring, backup, incident handling, testing, gaps, remediation, and reassessment tied to that decision.
, Information security technology - Baseline for classified protection of cybersecurity, is a current recommended national standard. It took effect on 1 December 2019 and supports clause-level control mapping. Its '/T' designation and implementation date do not turn it into a separate law or prove that a system has completed every applicable , assessment, or sector requirement.
GB/T 22240-2020 grades a protected object from the interest harmed and the severity of that harm. Level 1 covers general harm to the lawful rights and interests of citizens, legal persons, or other organizations without harm to national security, social order, or the public interest. Level 2 covers serious or especially serious harm to those rights and interests, or general harm to social order or the public interest, without harm to national security. Level 3 covers serious harm to social order or the public interest, or general harm to national security. Level 4 covers especially serious harm to social order or the public interest, or serious harm to national security. Level 5 covers especially serious harm to national security. The 2007 management measures use older information-system wording, so retain the classification guide, edition, rationale, and approval record rather than mixing the two descriptions. System size or data volume alone does not determine the level.
The general classified-protection management measures require for level 2 or higher information systems: an operating system files within 30 days after its level is determined, and a new system files within 30 days after entering operation. Level 3 systems undergo assessment and self-inspection at least annually, level 4 systems at least every six months, and level 5 systems according to special security needs. Sector regimes can use different protected objects, filing channels, or cycles, so first determine whether the general public-security route, a sector route, or both apply; MIIT's communications-network grading and filing is not the same procedure as public-security classified-protection filing.
Use as the MLPS/classified protection baseline standard reference for control evidence mapping and the 1 December 2019 implementation date.
Supports the current affected-interest and harm-severity matrix, the five protection-level outcomes, and the 1 November 2020 implementation date.
Articles 23 and 78 establish classified-protection duties for network operators and define the relevant network and operator terms in the consolidated 2025 text.
Confirms that the amended Cybersecurity Law took effect on 1 January 2026; the amendment mainly changed legal-liability provisions and added artificial-intelligence governance language.
Articles 7-18 set the five-level harm framework, grading, control implementation, recurring assessment, level 2-and-above filing, level 3-and-above materials, and higher-level inspection rules.