Short answer
Article 2 covers two situations when national security is or may be affected: a critical information infrastructure, or CII, operator procures network products or services; or a conducts data-processing activities. For CII procurement, Article 5 requires the operator to predict the national-security risk and apply when the product or service affects or may affect national security. For platform processing, keep a reasoned national-security analysis even though the Measures do not supply a numeric filing threshold.
Article 7 adds a mandatory trigger: a holding of more than one million users must apply before a to the Office, the CAC office that organizes the review. The threshold belongs to that trigger. It is not a safe harbour for CII procurement, other platform processing, or a review initiated by the authorities under Article 16.
The Measures say network products and services mainly include core network equipment, important communications products, high-performance computers and servers, high-capacity storage equipment, large databases and application software, network-security equipment, cloud-computing services, and other products or services with an important effect on CII, network security, or data security. This is an inclusive list, not a finding that every purchase in those categories requires review; the CII-operator and national-security tests still control.
The risk assessment is broader than a conventional technical-security test. Article 10 includes illegal control, interference, or destruction of CII; supply interruption and supplier reliability; product security, openness, transparency, and source diversity; the supplier's compliance with Chinese law; theft, disclosure, destruction, illegal use, or illegal export of , , or large amounts of ; and foreign-government influence or control associated with a listing.
If filing is required, the applicant submits an application, a national-security impact analysis, relevant procurement agreements or proposed listing documents, and other requested materials. The office has 10 working days after receiving compliant materials to decide whether a review is needed. The initial review period is generally 30 working days and may be extended by 15; a special review generally takes 90 working days and may be extended. Time spent supplying supplemental materials is excluded.
A written no-filing decision should identify the actor, transaction, product or service, supplier, system and data effects, listing facts, and national-security analysis. Reassess when those facts change. A general network-operator label or a user count below one million is not enough to close the analysis.
Articles 2, 5, 7-16 and 21 establish the covered actors and triggers, national-security factors, filing materials, review stages and timing, authority-initiated review, and covered network products and services.