---
title: "When does China cybersecurity review apply?"
canonical_url: "https://www.sorena.io/artifacts/apac/china-cybersecurity-law/faq/when-does-china-cybersecurity-review-apply"
source_url: "https://www.sorena.io/artifacts/apac/china-cybersecurity-law/faq/when-does-china-cybersecurity-review-apply"
author: "Sorena AI"
description: "China cybersecurity review applies to CII procurement or network-platform data processing that affects or may affect national security, plus a mandatory pre-filing trigger for certain foreign listings involving more than one million users' personal information."
published_at: "2026-07-05"
updated_at: "2026-07-24"
keywords:
  - "China Cybersecurity Law"
  - "Data Security Law"
  - "Cybersecurity Review Measures"
  - "Mobile app filing"
  - "MLPS"
---
**[SORENA](https://www.sorena.io/)** - AI-Powered GRC Platform

[Home](https://www.sorena.io/) | [Solutions](https://www.sorena.io/solutions) | [Artifacts](https://www.sorena.io/artifacts) | [About Us](https://www.sorena.io/about-us) | [Contact](https://www.sorena.io/contact) | [Portal](https://app.sorena.io)

---

# When does China cybersecurity review apply?

China cybersecurity review applies to CII procurement or network-platform data processing that affects or may affect national security, plus a mandatory pre-filing trigger for certain foreign listings involving more than one million users' personal information.

*Question* *China*

## When does China cybersecurity review apply? Direct answer

Screen for review when a CII operator procures network products or services, or a network platform operator processes data, in a way that affects or may affect national security.

A network platform operator holding personal information of more than one million users must also apply before a foreign listing. That threshold is not a general safe harbour.

China's Cybersecurity Review Measures cover CII procurement and network-platform data processing that affects or may affect national security. They also require a network platform operator holding personal information of more than one million users to apply before a foreign listing.

## Definitions

### Cybersecurity review under the 2022 Measures

**Term:** cybersecurity review

Cybersecurity review is the national-security review administered under the Cybersecurity Review Measures, effective 15 February 2022. It examines specified CII procurement, network-platform data processing, and listing situations rather than serving as a general cybersecurity audit.

**Why it matters here:** First establish the actor and activity, then assess whether national security is or may be affected or whether the separate listing threshold applies. A security test, privacy assessment, or ordinary network-operator classification does not replace this trigger analysis.

Sources:

- [Cybersecurity Review Measures](https://www.cac.gov.cn/2022-01/04/c_1642894602182845.htm?ref=sorena.io)

### Critical information infrastructure operator

**Term:** CII operator

A CII operator operates critical information infrastructure identified under the applicable protected-sector and serious-harm framework. Ordinary network operation or procurement does not by itself establish CII status.

**Why it matters here:** For a CII operator, procurement of network products or services must be screened for national-security effects. If the procurement affects or may affect national security, the operator applies for cybersecurity review.

Sources:

- [PRC Cybersecurity Law, consolidated 2025 text](https://sdca.miit.gov.cn/zwgk/fgbz/art/2026/art_4815dd4ec11d454783b83a91502a3cc7.html?ref=sorena.io)
- [Cybersecurity Review Measures](https://www.cac.gov.cn/2022-01/04/c_1642894602182845.htm?ref=sorena.io)

### Network platform operator

A network platform operator is the actor named in the Cybersecurity Review Measures for the data-processing and listing triggers. The Measures do not supply a self-contained definition that makes every website, app, or network operator a network platform operator.

**Why it matters here:** Record the platform functions, users, data-processing role, contracts, and any authority or sector guidance supporting the classification. Do not use the label merely to avoid or create a filing.

Sources:

- [Cybersecurity Review Measures](https://www.cac.gov.cn/2022-01/04/c_1642894602182845.htm?ref=sorena.io)

### Listing abroad trigger

**Term:** listing abroad

The Measures require a network platform operator holding personal information of more than one million users to apply before a listing abroad. The filing materials include the proposed initial public offering or other listing application documents.

**Why it matters here:** Count users whose personal information is held, document the counting method, and identify the proposed listing venue and transaction. Do not turn the one-million-user threshold into a safe harbour for other review triggers or authority-initiated review.

Sources:

- [Cybersecurity Review Measures](https://www.cac.gov.cn/2022-01/04/c_1642894602182845.htm?ref=sorena.io)

### Important data

Important data is a legal category identified through China's classified and graded data-protection system and applicable sector or regional catalogues, notices, or public identifications. It is distinct from personal information and from the stricter category of core data.

**Why it matters here:** The review's national-security assessment expressly considers risks that core data, important data, or large amounts of personal information could be stolen, leaked, destroyed, illegally used, or illegally exported.

Sources:

- [PRC Data Security Law](https://www.cac.gov.cn/2021-06/11/c_1624994566919140.htm?ref=sorena.io)
- [Cybersecurity Review Measures](https://www.cac.gov.cn/2022-01/04/c_1642894602182845.htm?ref=sorena.io)

### National core data

**Term:** core data

Core data is data related to national security, the lifelines of the national economy, important aspects of people's livelihoods, or major public interests. The Data Security Law subjects it to a stricter management system than important data.

**Why it matters here:** Cybersecurity review expressly considers the risk that core data could be stolen, leaked, destroyed, illegally used, or illegally exported. Keep core-data and important-data classifications separate in the filing analysis.

Sources:

- [PRC Data Security Law](https://www.cac.gov.cn/2021-06/11/c_1624994566919140.htm?ref=sorena.io)
- [Cybersecurity Review Measures](https://www.cac.gov.cn/2022-01/04/c_1642894602182845.htm?ref=sorena.io)

### Personal information

Personal information is information, recorded electronically or otherwise, that relates to an identified or identifiable natural person, excluding anonymized information. The Article 7 threshold counts users whose personal information the network platform operator holds.

**Why it matters here:** Document what information is held, whose information it is, and how users are counted. The threshold is more than one million users, not one million records or data fields.

Sources:

- [PRC Personal Information Protection Law](https://www.cac.gov.cn/2021-08/20/c_1631050028355286.htm?ref=sorena.io)
- [Cybersecurity Review Measures](https://www.cac.gov.cn/2022-01/04/c_1642894602182845.htm?ref=sorena.io)

## Short answer

Article 2 covers two situations when national security is or may be affected: a critical information infrastructure, or CII, operator procures network products or services; or a network platform operator conducts data-processing activities. For CII procurement, Article 5 requires the operator to predict the national-security risk and apply when the product or service affects or may affect national security. For platform processing, keep a reasoned national-security analysis even though the Measures do not supply a numeric filing threshold.

Article 7 adds a mandatory trigger: a network platform operator holding personal information of more than one million users must apply before a listing abroad to the Cybersecurity Review Office, the CAC office that organizes the review. The threshold belongs to that trigger. It is not a safe harbour for CII procurement, other platform processing, or a review initiated by the authorities under Article 16.

The Measures say network products and services mainly include core network equipment, important communications products, high-performance computers and servers, high-capacity storage equipment, large databases and application software, network-security equipment, cloud-computing services, and other products or services with an important effect on CII, network security, or data security. This is an inclusive list, not a finding that every purchase in those categories requires review; the CII-operator and national-security tests still control.

The risk assessment is broader than a conventional technical-security test. Article 10 includes illegal control, interference, or destruction of CII; supply interruption and supplier reliability; product security, openness, transparency, and source diversity; the supplier's compliance with Chinese law; theft, disclosure, destruction, illegal use, or illegal export of core data, important data, or large amounts of personal information; and foreign-government influence or control associated with a listing.

If filing is required, the applicant submits an application, a national-security impact analysis, relevant procurement agreements or proposed listing documents, and other requested materials. The office has 10 working days after receiving compliant materials to decide whether a review is needed. The initial review period is generally 30 working days and may be extended by 15; a special review generally takes 90 working days and may be extended. Time spent supplying supplemental materials is excluded.

A written no-filing decision should identify the actor, transaction, product or service, supplier, system and data effects, listing facts, and national-security analysis. Reassess when those facts change. A general network-operator label or a user count below one million is not enough to close the analysis.

Sources for this answer:

- [Cybersecurity Review Measures](https://www.cac.gov.cn/2022-01/04/c_1642894602182845.htm?ref=sorena.io) - Articles 2, 5, 7-16 and 21 establish the covered actors and triggers, national-security factors, filing materials, review stages and timing, authority-initiated review, and covered network products and services.

## What to keep as evidence

Keep enough information to reproduce the trigger analysis and, if applicable, the filing and authority procedure.

- Actor record: why the entity is or is not a CII operator or network platform operator for this activity, including any authority identification or sector input.
- Transaction record: procurement, product or service, supplier and subcontractors, affected CII functions, dependencies, continuity measures, data-processing activity, or proposed foreign listing.
- Data record: core data, important data, personal information, user count and counting method, storage and transfers, access, recipients, and risks of theft, disclosure, destruction, illegal use, or illegal export.
- Article 10 national-security assessment covering control or disruption, continuity, security and transparency, supply diversity and reliability, supplier legal compliance, data risks, and listing-related foreign influence or control.
- Where filed: application, impact analysis, procurement agreement or listing documents, supplier cooperation clauses, supplemental requests and responses, preventive measures during review, written outcome, and post-review commitments.
- Timeline record separating the 10-working-day screening decision, ordinary review, possible 15-working-day extension, special review, excluded supplemental-material time, and actual notices.
- Reassessment triggers for CII or platform status, product or service, supplier, architecture, dependency, data type or volume, processing, export, or listing changes.

Sources for this answer:

- [Cybersecurity Review Measures](https://www.cac.gov.cn/2022-01/04/c_1642894602182845.htm?ref=sorena.io) - Supports each actor, trigger, risk-factor, filing, procedure, timing, outcome, commitment, and reassessment record listed here.

## Primary sources

- [Cybersecurity Review Measures](https://www.cac.gov.cn/2022-01/04/c_1642894602182845.htm?ref=sorena.io) - Use Articles 2, 5, 7-16 and 21 for the triggers, risk factors, filing materials, procedure, timing, authority-initiated review, and covered products and services; effective 15 February 2022.

## Topic Guides

- [China App Filing vs Personal Information Rules](/artifacts/apac/china-cybersecurity-law/mobile-app-filing-vs-app-personal-information-rules.md): Decide whether a China mobile app needs MIIT filing, personal-information controls, or both, with current triggers, duties, dates, and evidence.
- [China cybersecurity and data security requirements](/artifacts/apac/china-cybersecurity-law/requirements.md): China cybersecurity requirements by actor: network operators, data processors, CII operators, platforms, app providers, and distribution platforms.
- [China cybersecurity compliance checklist](/artifacts/apac/china-cybersecurity-law/checklist.md): A China cybersecurity checklist for scoping network duties, data security, CII procurement review, app rules, MIIT filing, and supporting standards.
- [China cybersecurity deadlines and compliance calendar](/artifacts/apac/china-cybersecurity-law/deadlines-and-compliance-calendar.md): Separate China cybersecurity commencement dates from recurring duties, filing lead times, review periods, and event-driven response deadlines.
- [China Cybersecurity Law FAQ](/artifacts/apac/china-cybersecurity-law/faq.md): Practical answers on China network-operator scope, MLPS evidence, important data, cybersecurity review, app filing and governance, and smart-home standards under the law in force from 1 January 2026.
- [China Cybersecurity Law vs EU Cyber Resilience Act](/artifacts/apac/china-cybersecurity-law/china-cybersecurity-law-vs-eu-cyber-resilience-act.md): Compare China's network-operator rules with the EU CRA's product duties, including scope, actors, evidence, reporting dates, and launch decisions.
- [China Cybersecurity Law vs EU NIS2 Directive](/artifacts/apac/china-cybersecurity-law/china-cybersecurity-law-vs-nis2.md): Compare China's network-operator duties with NIS2 entity duties, including scope, management accountability, incident reporting, evidence, and enforcement.
- [China cybersecurity penalties and fines](/artifacts/apac/china-cybersecurity-law/penalties-and-fines.md): Compare current China Cybersecurity Law and Data Security Law fines by actor, breach, severity, and enforcement consequence.
- [China Cybersecurity Review vs Data Export Assessment](/artifacts/apac/china-cybersecurity-law/cybersecurity-review-vs-data-export-security-assessment.md): Separate China's cybersecurity-review triggers from CAC data-export assessment triggers, thresholds, filings, evidence, timing, and reapplication rules.
- [China cybersecurity review workflow](/artifacts/apac/china-cybersecurity-law/cybersecurity-review-workflow.md): Determine whether CII procurement, platform data processing, or a qualifying foreign listing triggers China's Cybersecurity Review Measures.
- [China mobile app filing and app governance](/artifacts/apac/china-cybersecurity-law/mobile-app-filing-and-app-governance.md): Identify the China app sponsor, complete MIIT filing before service, and separate provider, platform, privacy, content, and security duties.
- [China Smart-Home Security vs Telecom and Radio Approval](/artifacts/apac/china-cybersecurity-law/smart-home-security-vs-telecom-wireless-launch.md): Separate GB/T 41387-2022 smart-home security evidence from China telecom network-access and radio approval decisions for connected products.
- [CII and network operator role triage](/artifacts/apac/china-cybersecurity-law/critical-information-infrastructure-and-network-operators.md): How to separate ordinary network operator duties from CII, procurement, and review-risk questions under China cybersecurity sources.
- [Does an app need MIIT filing and CAC app governance review?](/artifacts/apac/china-cybersecurity-law/faq/does-an-app-need-miit-filing-and-cac-app-governance-review.md): An app sponsor providing internet information services through an app in China must complete MIIT filing. CAC rules separately govern app providers and distribution platforms without creating one routine CAC approval for every app.
- [GB/T 22239-2019 classified protection baseline](/artifacts/apac/china-cybersecurity-law/classified-protection-baseline.md): How to scope and document a GB/T 22239-2019 classified protection baseline without treating the recommended standard as a standalone law.
- [GB/T 41387-2022 smart home security standard](/artifacts/apac/china-cybersecurity-law/smart-home-security-standard.md): How connected-device teams can scope and document GB/T 41387-2022 without treating it as an automatic certification or product-approval duty.
- [How do smart home security standards fit with China cybersecurity law?](/artifacts/apac/china-cybersecurity-law/faq/how-do-smart-home-security-standards-fit-with-china-cybersecurity-law.md): GB/T 41387-2022 can organize smart-home security evidence, but it is a recommended standard, not a product approval. Check app, data, MLPS, telecom access, and radio requirements separately.
- [How does important data change China cybersecurity obligations?](/artifacts/apac/china-cybersecurity-law/faq/how-does-important-data-change-cybersecurity-obligations.md): Once data is officially identified as important data, the processor needs named governance, periodic risk assessments and reports, incident controls, and a separate export decision. An internal sensitivity label alone does not establish the legal category.
- [Is every company a network operator under China Cybersecurity Law?](/artifacts/apac/china-cybersecurity-law/faq/is-every-company-a-network-operator-under-china-cybersecurity-law.md): No. Under China's Cybersecurity Law, a network operator is an owner or administrator of a network or a network service provider. Apply that definition to each China network or service, then test CII and other roles separately.
- [MLPS classified protection evidence map](/artifacts/apac/china-cybersecurity-law/mlps-classified-protection-evidence-map.md): Classify a China network under MLPS, complete level 2 or above filing, map controls, and retain assessment, remediation, and change evidence.
- [What is MLPS classified protection evidence?](/artifacts/apac/china-cybersecurity-law/faq/what-is-mlps-classified-protection-evidence.md): MLPS evidence shows how a defined China network or system was graded and protected. Keep the scope, grading rationale, filing or assessment records where applicable, control mapping, test results, remediation, and reassessment history.

*Operationalize the requirement*

*Placement: Before primary sources*

## Build the China network security evidence file

Sorena AI helps turn the answer to "When does China cybersecurity review apply?" into assigned controls and retained evidence.

- [Map official sources to evidence](/solutions/research-copilot.md): Research Copilot connects the official citation, decision, owner, retained evidence, and change history.
- [Review the China route](/contact.md): Check the China Cybersecurity Law scope decision and unresolved launch questions with Sorena.


---

[Privacy Policy](https://www.sorena.io/privacy.md) | [Terms of Use](https://www.sorena.io/terms-of-use.md) | [DMCA](https://www.sorena.io/dmca.md) | [About Us](https://www.sorena.io/about-us.md)

(c) 2026 Sorena AB (559573-7338). All rights reserved.

Source: https://www.sorena.io/artifacts/apac/china-cybersecurity-law/faq/when-does-china-cybersecurity-review-apply.md
