---
title: "What is MLPS classified protection evidence?"
canonical_url: "https://www.sorena.io/artifacts/apac/china-cybersecurity-law/faq/what-is-mlps-classified-protection-evidence"
source_url: "https://www.sorena.io/artifacts/apac/china-cybersecurity-law/faq/what-is-mlps-classified-protection-evidence"
author: "Sorena AI"
description: "MLPS evidence shows how a defined China network or system was graded and protected. Keep the scope, grading rationale, filing or assessment records where applicable, control mapping, test results, remediation, and reassessment history."
published_at: "2026-07-05"
updated_at: "2026-07-25"
keywords:
  - "China Cybersecurity Law"
  - "Data Security Law"
  - "Cybersecurity Review Measures"
  - "Mobile app filing"
  - "MLPS"
---
**[SORENA](https://www.sorena.io/)** - AI-Powered GRC Platform

[Home](https://www.sorena.io/) | [Solutions](https://www.sorena.io/solutions) | [Artifacts](https://www.sorena.io/artifacts) | [About Us](https://www.sorena.io/about-us) | [Contact](https://www.sorena.io/contact) | [Portal](https://app.sorena.io)

---

# What is MLPS classified protection evidence?

MLPS evidence shows how a defined China network or system was graded and protected. Keep the scope, grading rationale, filing or assessment records where applicable, control mapping, test results, remediation, and reassessment history.

*Question* *China*

## What is MLPS classified protection evidence? Direct answer

MLPS, or classified protection, evidence is the record showing how a defined China network or system was graded, protected, tested, remediated, and reassessed.

The Cybersecurity Law establishes the classified-protection duty. GB/T 22239-2019 supplies a recommended baseline for control mapping; it is not itself a law, approval, or universal certificate.

MLPS, or classified protection, evidence is the record showing how a defined China network or system was graded, protected, tested, remediated, and reassessed. It should let a reviewer reproduce the scope decision and trace each applicable requirement to evidence.

## Definitions

### Multi-Level Protection Scheme

**Term:** MLPS

MLPS is a common English label for China's cybersecurity classified-protection system. The network operator defines the protected object, determines a protection level based on the harm that a security incident could cause, applies the management and technical measures for that level, and completes any required filing, assessment, remediation, and supervision steps.

**Why it matters here:** MLPS evidence is not one certificate. It is the linked record of scope, grading, filing where required, implemented controls, testing, findings, remediation, and later reassessment for the same protected object and released configuration.

Sources:

- [PRC Cybersecurity Law, consolidated 2025 text](https://sdca.miit.gov.cn/zwgk/fgbz/art/2026/art_4815dd4ec11d454783b83a91502a3cc7.html?ref=sorena.io)
- [Information Security Classified Protection Management Measures](https://www.miit.gov.cn/jgsj/xxjsfzs/xxgk/art/2020/art_a981907528694176a61b5b52c2d19895.html?ref=sorena.io)

### Cybersecurity protection level

**Term:** protection level

The protection level is the grade assigned to the defined protected object from the interests that could be harmed and the severity of that harm. Under GB/T 22240-2020, harm to citizens', legal persons', or other organizations' lawful rights maps to level 1 for general harm and level 2 for serious or especially serious harm; harm to social order or the public interest maps to levels 2, 3, or 4; and harm to national security maps to levels 3, 4, or 5 as severity rises.

**Why it matters here:** The level changes the control baseline and can change filing, assessment, inspection, documentation, and reassessment requirements. Record the classification guide and edition used because the 2007 management measures phrase the five information-system levels differently. Do not select a level from system size or data volume alone.

Sources:

- [GB/T 22240-2020 classification guide](https://openstd.samr.gov.cn/bzgk/std/newGbInfo?hcno=63B89FFF7CC97EBBBED8A403396F0F00&refer=outter&ref=sorena.io)
- [Information Security Classified Protection Management Measures](https://www.miit.gov.cn/jgsj/xxjsfzs/xxgk/art/2020/art_a981907528694176a61b5b52c2d19895.html?ref=sorena.io)

### Classified protection baseline standard

**Term:** GB/T 22239-2019

GB/T 22239-2019 is the current recommended national standard titled Information security technology - Baseline for classified protection of cybersecurity. It organizes management and technical requirements for classified-protection control mapping and took effect on 1 December 2019.

**Why it matters here:** Use the standard to map controls for the assigned level, but do not treat its GB/T status, an assessment report, or a filing receipt as a universal government approval of the system.

Sources:

- [GB/T 22239-2019 classified protection baseline](https://openstd.samr.gov.cn/bzgk/gb/newGbInfo?hcno=BAFB47E8874764186BDB7865E8344DAF&ref=sorena.io)

### Classified-protection filing

**Term:** filing

Under the general classified-protection management measures, an operator or user of a level 2 or higher information system files the grading information with the public-security authority after the level is determined. New level 2 or higher systems are filed within 30 days after entering operation; sector-specific systems can also have separate or additional filing regimes.

**Why it matters here:** A filing receipt records a submitted classification. It does not replace control implementation, testing, remediation, ongoing operation, or a separate sector filing such as the communications-network regime.

Sources:

- [Information Security Classified Protection Management Measures](https://www.miit.gov.cn/jgsj/xxjsfzs/xxgk/art/2020/art_a981907528694176a61b5b52c2d19895.html?ref=sorena.io)

### Network operator under the PRC Cybersecurity Law

**Term:** network operator

A network operator is an owner or administrator of a network, or a provider of network services. The operator is responsible for the classified-protection duties attached to the defined network.

**Why it matters here:** Identify the responsible operator for each protected object. A corporate group, cloud provider, customer, and outsourced administrator can have different roles, so contracts and system facts must support the recorded allocation.

Sources:

- [PRC Cybersecurity Law, consolidated 2025 text](https://sdca.miit.gov.cn/zwgk/fgbz/art/2026/art_4815dd4ec11d454783b83a91502a3cc7.html?ref=sorena.io)

## Short answer

Article 23 of the Cybersecurity Law's consolidated 2025 text requires each network operator to perform security-protection duties under the classified protection system. The evidence starts with the protected object, responsible operator, system boundary, and protection level, then records filing where required, controls, operating procedures, monitoring, backup, incident handling, testing, gaps, remediation, and reassessment tied to that decision.

GB/T 22239-2019, Information security technology - Baseline for classified protection of cybersecurity, is a current recommended national standard. It took effect on 1 December 2019 and supports clause-level control mapping. Its '/T' designation and implementation date do not turn it into a separate law or prove that a system has completed every applicable filing, assessment, or sector requirement.

GB/T 22240-2020 grades a protected object from the interest harmed and the severity of that harm. Level 1 covers general harm to the lawful rights and interests of citizens, legal persons, or other organizations without harm to national security, social order, or the public interest. Level 2 covers serious or especially serious harm to those rights and interests, or general harm to social order or the public interest, without harm to national security. Level 3 covers serious harm to social order or the public interest, or general harm to national security. Level 4 covers especially serious harm to social order or the public interest, or serious harm to national security. Level 5 covers especially serious harm to national security. The 2007 management measures use older information-system wording, so retain the classification guide, edition, rationale, and approval record rather than mixing the two descriptions. System size or data volume alone does not determine the level.

The general classified-protection management measures require filing for level 2 or higher information systems: an operating system files within 30 days after its level is determined, and a new system files within 30 days after entering operation. Level 3 systems undergo assessment and self-inspection at least annually, level 4 systems at least every six months, and level 5 systems according to special security needs. Sector regimes can use different protected objects, filing channels, or cycles, so first determine whether the general public-security route, a sector route, or both apply; MIIT's communications-network grading and filing is not the same procedure as public-security classified-protection filing.

Sources for this answer:

- [GB/T 22239 classified protection baseline requirements](https://openstd.samr.gov.cn/bzgk/gb/newGbInfo?hcno=BAFB47E8874764186BDB7865E8344DAF&ref=sorena.io) - Use as the MLPS/classified protection baseline standard reference for control evidence mapping and the 1 December 2019 implementation date.
- [GB/T 22240-2020 classification guide](https://openstd.samr.gov.cn/bzgk/std/newGbInfo?hcno=63B89FFF7CC97EBBBED8A403396F0F00&refer=outter&ref=sorena.io) - Supports the current affected-interest and harm-severity matrix, the five protection-level outcomes, and the 1 November 2020 implementation date.
- [PRC Cybersecurity Law](https://sdca.miit.gov.cn/zwgk/fgbz/art/2026/art_4815dd4ec11d454783b83a91502a3cc7.html?ref=sorena.io) - Articles 23 and 78 establish classified-protection duties for network operators and define the relevant network and operator terms in the consolidated 2025 text.
- [NPC decision amending the PRC Cybersecurity Law](https://www.npc.gov.cn/npc/c2/c30834/202510/t20251028_449031.html?ref=sorena.io) - Confirms that the amended Cybersecurity Law took effect on 1 January 2026; the amendment mainly changed legal-liability provisions and added artificial-intelligence governance language.
- [Information Security Classified Protection Management Measures](https://www.miit.gov.cn/jgsj/xxjsfzs/xxgk/art/2020/art_a981907528694176a61b5b52c2d19895.html?ref=sorena.io) - Articles 7-18 set the five-level harm framework, grading, control implementation, recurring assessment, level 2-and-above filing, level 3-and-above materials, and higher-level inspection rules.

## What to keep as evidence

A reviewer should be able to follow the record from system scope through classification, implementation, assessment, remediation, and reassessment.

- System boundary and inventory: owner, purpose, users, data, interfaces, infrastructure, hosting, dependencies, and suppliers.
- Grading record: protected object, responsible operator, affected interests, severity-of-harm analysis, proposed protection level, method, result, approver, date, and any required authority, sector, or specialist input.
- Applicability record: the law, current standard edition, sector rules, and each clause mapped to a technical or management control and evidence owner.
- Operating evidence: access control, malware protection, monitoring and logs, data classification and backup, incident plan and exercises, personnel controls, and supplier controls, to the extent applicable to the grade.
- Filing and assessment record where required: filing form and receipt, submitted topology and governance material, assessment scope, qualified assessor where required, findings, corrective actions, retest results, and closure evidence. Keep public-security and sector filings separate.
- Reassessment triggers for material changes to purpose, architecture, hosting, data, interfaces, suppliers, threats, or applicable rules; do not invent one renewal date for all systems.

Sources for this answer:

- [GB/T 22239 classified protection baseline requirements](https://openstd.samr.gov.cn/bzgk/gb/newGbInfo?hcno=BAFB47E8874764186BDB7865E8344DAF&ref=sorena.io) - Use as the MLPS/classified protection baseline standard reference for control evidence mapping and the 1 December 2019 implementation date.
- [PRC Cybersecurity Law](https://sdca.miit.gov.cn/zwgk/fgbz/art/2026/art_4815dd4ec11d454783b83a91502a3cc7.html?ref=sorena.io) - Articles 23 and 27 identify baseline classified-protection and incident duties, including internal rules, responsible personnel, technical protections, monitoring and logs, data classification, backup, encryption, and incident planning.
- [Information Security Classified Protection Management Measures](https://www.miit.gov.cn/jgsj/xxjsfzs/xxgk/art/2020/art_a981907528694176a61b5b52c2d19895.html?ref=sorena.io) - Supports the grading, filing, assessment, remediation, inspection, and supporting-document records, subject to current sector-specific rules.

## Primary sources

- [GB/T 22239 classified protection baseline requirements](https://openstd.samr.gov.cn/bzgk/gb/newGbInfo?hcno=BAFB47E8874764186BDB7865E8344DAF&ref=sorena.io) - Use as the MLPS/classified protection baseline standard reference for control evidence mapping and the 1 December 2019 implementation date.
- [PRC Cybersecurity Law](https://sdca.miit.gov.cn/zwgk/fgbz/art/2026/art_4815dd4ec11d454783b83a91502a3cc7.html?ref=sorena.io) - Use the consolidated text for Articles 23, 27 and 78.
- [NPC decision amending the PRC Cybersecurity Law](https://www.npc.gov.cn/npc/c2/c30834/202510/t20251028_449031.html?ref=sorena.io) - Confirms adoption of the 2025 amendments and their 1 January 2026 effective date.
- [GB/T 22240-2020 classification guide](https://openstd.samr.gov.cn/bzgk/std/newGbInfo?hcno=63B89FFF7CC97EBBBED8A403396F0F00&refer=outter&ref=sorena.io) - Confirms the current recommended national classification guide and its 1 November 2020 implementation date.
- [Information Security Classified Protection Management Measures](https://www.miit.gov.cn/jgsj/xxjsfzs/xxgk/art/2020/art_a981907528694176a61b5b52c2d19895.html?ref=sorena.io) - Use for the five protection levels, general grading and filing steps, assessment frequencies, filing materials, and public-security supervision, while checking current sector-specific rules.

## Topic Guides

- [China App Filing vs Personal Information Rules](/artifacts/apac/china-cybersecurity-law/mobile-app-filing-vs-app-personal-information-rules.md): Decide whether a China mobile app needs MIIT filing, personal-information controls, or both, with current triggers, duties, dates, and evidence.
- [China cybersecurity and data security requirements](/artifacts/apac/china-cybersecurity-law/requirements.md): China cybersecurity requirements by actor: network operators, data processors, CII operators, platforms, app providers, and distribution platforms.
- [China cybersecurity compliance checklist](/artifacts/apac/china-cybersecurity-law/checklist.md): A China cybersecurity checklist for scoping network duties, data security, CII procurement review, app rules, MIIT filing, and supporting standards.
- [China cybersecurity deadlines and compliance calendar](/artifacts/apac/china-cybersecurity-law/deadlines-and-compliance-calendar.md): Separate China cybersecurity commencement dates from recurring duties, filing lead times, review periods, and event-driven response deadlines.
- [China Cybersecurity Law FAQ](/artifacts/apac/china-cybersecurity-law/faq.md): Practical answers on China network-operator scope, MLPS evidence, important data, cybersecurity review, app filing and governance, and smart-home standards under the law in force from 1 January 2026.
- [China Cybersecurity Law vs EU Cyber Resilience Act](/artifacts/apac/china-cybersecurity-law/china-cybersecurity-law-vs-eu-cyber-resilience-act.md): Compare China's network-operator rules with the EU CRA's product duties, including scope, actors, evidence, reporting dates, and launch decisions.
- [China Cybersecurity Law vs EU NIS2 Directive](/artifacts/apac/china-cybersecurity-law/china-cybersecurity-law-vs-nis2.md): Compare China's network-operator duties with NIS2 entity duties, including scope, management accountability, incident reporting, evidence, and enforcement.
- [China cybersecurity penalties and fines](/artifacts/apac/china-cybersecurity-law/penalties-and-fines.md): Compare current China Cybersecurity Law and Data Security Law fines by actor, breach, severity, and enforcement consequence.
- [China Cybersecurity Review vs Data Export Assessment](/artifacts/apac/china-cybersecurity-law/cybersecurity-review-vs-data-export-security-assessment.md): Separate China's cybersecurity-review triggers from CAC data-export assessment triggers, thresholds, filings, evidence, timing, and reapplication rules.
- [China cybersecurity review workflow](/artifacts/apac/china-cybersecurity-law/cybersecurity-review-workflow.md): Determine whether CII procurement, platform data processing, or a qualifying foreign listing triggers China's Cybersecurity Review Measures.
- [China mobile app filing and app governance](/artifacts/apac/china-cybersecurity-law/mobile-app-filing-and-app-governance.md): Identify the China app sponsor, complete MIIT filing before service, and separate provider, platform, privacy, content, and security duties.
- [China Smart-Home Security vs Telecom and Radio Approval](/artifacts/apac/china-cybersecurity-law/smart-home-security-vs-telecom-wireless-launch.md): Separate GB/T 41387-2022 smart-home security evidence from China telecom network-access and radio approval decisions for connected products.
- [CII and network operator role triage](/artifacts/apac/china-cybersecurity-law/critical-information-infrastructure-and-network-operators.md): How to separate ordinary network operator duties from CII, procurement, and review-risk questions under China cybersecurity sources.
- [Does an app need MIIT filing and CAC app governance review?](/artifacts/apac/china-cybersecurity-law/faq/does-an-app-need-miit-filing-and-cac-app-governance-review.md): An app sponsor providing internet information services through an app in China must complete MIIT filing. CAC rules separately govern app providers and distribution platforms without creating one routine CAC approval for every app.
- [GB/T 22239-2019 classified protection baseline](/artifacts/apac/china-cybersecurity-law/classified-protection-baseline.md): How to scope and document a GB/T 22239-2019 classified protection baseline without treating the recommended standard as a standalone law.
- [GB/T 41387-2022 smart home security standard](/artifacts/apac/china-cybersecurity-law/smart-home-security-standard.md): How connected-device teams can scope and document GB/T 41387-2022 without treating it as an automatic certification or product-approval duty.
- [How do smart home security standards fit with China cybersecurity law?](/artifacts/apac/china-cybersecurity-law/faq/how-do-smart-home-security-standards-fit-with-china-cybersecurity-law.md): GB/T 41387-2022 can organize smart-home security evidence, but it is a recommended standard, not a product approval. Check app, data, MLPS, telecom access, and radio requirements separately.
- [How does important data change China cybersecurity obligations?](/artifacts/apac/china-cybersecurity-law/faq/how-does-important-data-change-cybersecurity-obligations.md): Once data is officially identified as important data, the processor needs named governance, periodic risk assessments and reports, incident controls, and a separate export decision. An internal sensitivity label alone does not establish the legal category.
- [Is every company a network operator under China Cybersecurity Law?](/artifacts/apac/china-cybersecurity-law/faq/is-every-company-a-network-operator-under-china-cybersecurity-law.md): No. Under China's Cybersecurity Law, a network operator is an owner or administrator of a network or a network service provider. Apply that definition to each China network or service, then test CII and other roles separately.
- [MLPS classified protection evidence map](/artifacts/apac/china-cybersecurity-law/mlps-classified-protection-evidence-map.md): Classify a China network under MLPS, complete level 2 or above filing, map controls, and retain assessment, remediation, and change evidence.
- [When does China cybersecurity review apply?](/artifacts/apac/china-cybersecurity-law/faq/when-does-china-cybersecurity-review-apply.md): China cybersecurity review applies to CII procurement or network-platform data processing that affects or may affect national security, plus a mandatory pre-filing trigger for certain foreign listings involving more than one million users' personal information.

*Operationalize the requirement*

*Placement: Before primary sources*

## Build the China network security evidence file

Sorena AI helps turn the answer to "What is MLPS classified protection evidence?" into assigned controls and retained evidence.

- [Map official sources to evidence](/solutions/research-copilot.md): Research Copilot connects the official citation, decision, owner, retained evidence, and change history.
- [Review the China route](/contact.md): Check the China Cybersecurity Law scope decision and unresolved launch questions with Sorena.


---

[Privacy Policy](https://www.sorena.io/privacy.md) | [Terms of Use](https://www.sorena.io/terms-of-use.md) | [DMCA](https://www.sorena.io/dmca.md) | [About Us](https://www.sorena.io/about-us.md)

(c) 2026 Sorena AB (559573-7338). All rights reserved.

Source: https://www.sorena.io/artifacts/apac/china-cybersecurity-law/faq/what-is-mlps-classified-protection-evidence.md
