---
title: "MLPS classified protection evidence map"
canonical_url: "https://www.sorena.io/artifacts/apac/china-cybersecurity-law/mlps-classified-protection-evidence-map"
source_url: "https://www.sorena.io/artifacts/apac/china-cybersecurity-law/mlps-classified-protection-evidence-map"
author: "Sorena AI"
description: "Classify a China network under MLPS, complete level 2 or above filing, map controls, and retain assessment, remediation, and change evidence."
published_at: "2026-07-05"
updated_at: "2026-07-25"
keywords:
  - "China Cybersecurity Law"
  - "Data Security Law"
  - "Cybersecurity Review Measures"
  - "Mobile app filing"
  - "MLPS"
---
**[SORENA](https://www.sorena.io/)** - AI-Powered GRC Platform

[Home](https://www.sorena.io/) | [Solutions](https://www.sorena.io/solutions) | [Artifacts](https://www.sorena.io/artifacts) | [About Us](https://www.sorena.io/about-us) | [Contact](https://www.sorena.io/contact) | [Portal](https://app.sorena.io)

---

# MLPS classified protection evidence map

Classify a China network under MLPS, complete level 2 or above filing, map controls, and retain assessment, remediation, and change evidence.

*Cybersecurity* *China*

## China Cybersecurity Law MLPS classified protection evidence map

Build the evidence trail for network inventory, MLPS classification, filing, control implementation, assessment and remediation.

The amended Cybersecurity Law creates the classified-protection duty. GB/T 22240-2020 guides the five-level decision; level 2 and above networks are filed, and level 3 and above networks follow the annual assessment route in the cited MPS guidance.

Use this MLPS evidence map in sequence: define one protected object, determine its security protection level from the harm test, file a level 2 or above network, map the applicable legal and GB/T controls, assess level 3 or above networks on the required cycle, close findings, and reopen the record after material change.

## Definitions

### Multi-Level Protection Scheme

**Term:** MLPS

MLPS is the commonly used English label for China's cybersecurity classified-protection system. Under Article 23 of the amended Cybersecurity Law, network operators must protect networks according to their security protection level and implement specified management, technical, monitoring, logging, data-classification, backup and encryption measures.

**Why it matters here:** MLPS is a legal and operational lifecycle, not a one-time certificate. The operator must identify the protected network, determine its level, complete any required filing, implement level-appropriate controls, assess them, remedy findings and revisit the record after material change.

Sources:

- [Amended PRC Cybersecurity Law](https://www.cac.gov.cn/2025-12/29/c_1768735112911946.htm?ref=sorena.io)
- [MPS guidance on implementing classified protection and CII protection](https://www.dhlc.gov.cn/jtj/Web/_F0_0_63FGXV347805E5AE44ED49D184.htm?ref=sorena.io)

### GB/T 22239-2019 baseline requirements

**Term:** GB/T 22239-2019

GB/T 22239-2019 is the current recommended national standard titled Information security technology - Baseline for classified protection of cybersecurity. It sets general security requirements for level 1 through level 4 protected objects and additional requirements for cloud computing, mobile interconnection, Internet of Things, industrial control systems and big-data environments.

**Why it matters here:** Use the clauses that match the recorded security protection level and technology context. The standard supports the control map, but its publication page and a generic policy do not by themselves prove that a particular network is correctly classified or that its controls operate effectively.

Sources:

- [GB/T 22239-2019 national standard record](https://openstd.samr.gov.cn/bzgk/gb/newGbInfo?hcno=BAFB47E8874764186BDB7865E8344DAF&ref=sorena.io)

### Protected object

A protected object is the network or system boundary that receives one classified-protection level and is then used consistently for filing, control selection, assessment, and remediation. It may include a cloud, mobile, Internet of Things, industrial-control, or big-data environment, but the boundary must be based on the actual operator, functions, architecture, data, users, and dependencies.

**Why it matters here:** If the protected object is drawn too broadly or too narrowly, the selected level, filed diagrams, applicable clauses, and assessment scope may no longer describe the same system. Record boundary changes before reusing an earlier filing or assessment.

Sources:

- [GB/T 22240-2020 classification guide](https://openstd.samr.gov.cn/bzgk/std/newGbInfo?hcno=63B89FFF7CC97EBBBED8A403396F0F00&refer=outter&ref=sorena.io)
- [MPS guidance on implementing classified protection and CII protection](https://www.dhlc.gov.cn/jtj/Web/_F0_0_63FGXV347805E5AE44ED49D184.htm?ref=sorena.io)

### Security protection level

The security protection level is the level assigned to one protected object under the classified-protection method. GB/T 22240-2020 uses five levels based on the affected interest and severity of harm: level 1 concerns harm to citizens, legal persons, or other organisations without harm to national security, social order, or public interests; levels 2-4 cover progressively more serious harm to those interests or to national security; level 5 concerns especially serious harm to national security. The level is not a vendor maturity score.

**Why it matters here:** The assigned level determines the control baseline, filing path, and assessment expectations. The operator should retain the harm analysis, sector input, approvers, and authority interactions rather than choosing a level from system size or data sensitivity alone.

Sources:

- [GB/T 22240-2020 classification guide](https://openstd.samr.gov.cn/bzgk/std/newGbInfo?hcno=63B89FFF7CC97EBBBED8A403396F0F00&refer=outter&ref=sorena.io)

### Public-security organ

In this evidence map, the public-security organ is the competent public-security authority that receives classified-protection filings and, under the cited MPS implementation guidance, receives assessment reports for level 3 and above networks. It is distinct from the sector authority and the protection department that identifies CII.

**Why it matters here:** Retain the filing receipt, questions, corrections, and report-submission evidence from the correct authority. Acceptance of filing material does not certify the network or prove that controls operate effectively.

Sources:

- [MPS guidance on implementing classified protection and CII protection](https://www.dhlc.gov.cn/jtj/Web/_F0_0_63FGXV347805E5AE44ED49D184.htm?ref=sorena.io)

## 1. Establish the protected object and level

Begin with a complete inventory of networks and protected objects, including cloud, mobile, Internet of Things, industrial-control and big-data environments. Define each boundary, operator, business function, service population, data, dependencies and technology context. For a new network, determine the security protection level during planning and design rather than after launch.

GB/T 22240-2020 is the current recommended national classification guide, published on 28 April 2020 and implemented on 1 November 2020. It tests two factors: the interest harmed when the protected object is damaged and the severity of that harm. The affected interests are the lawful rights and interests of citizens, legal persons and other organisations; social order and public interests; and national security.

Level 1 covers harm to citizens, legal persons or other organisations without harm to national security, social order or public interests. Level 2 covers serious or especially serious harm to those private interests, or harm to social order or public interests, without harm to national security. Level 3 covers serious harm to social order or public interests, or harm to national security. Level 4 covers especially serious harm to social order or public interests, or serious harm to national security. Level 5 covers especially serious harm to national security. Keep the harm analysis and any sector guidance or authority review with the record; do not choose a level from system size, data sensitivity, or a vendor label alone.

- Protected-object record: system name and identifier, operator, owner, architecture, locations, interfaces, service users, business functions, data and external dependencies.
- Classification record: proposed level, classification guide edition, harm analysis, applicable sector guidance, approvers and date.
- Boundary evidence: architecture and data-flow diagrams that match the object submitted for filing and later assessment.
- Change triggers: major changes to function, service scope, users, architecture, hosting, data, interconnections or consequences of disruption.

Sources for this answer:

- [GB/T 22240-2020 classification guide](https://openstd.samr.gov.cn/bzgk/std/newGbInfo?hcno=63B89FFF7CC97EBBBED8A403396F0F00&refer=outter&ref=sorena.io) - Current national classification guide, published 28 April 2020 and effective 1 November 2020, for determining a protected object's security protection level.
- [MPS guidance on implementing classified protection and CII protection](https://www.dhlc.gov.cn/jtj/Web/_F0_0_63FGXV347805E5AE44ED49D184.htm?ref=sorena.io) - Official implementation guidance for network inventory, classification during new-network design and the filing, assessment and remediation lifecycle.

## 2. Complete filing and map the applicable controls

Networks at level 2 or above are filed with the public-security organ. Under the 2007 classified-protection management measures, an operating level 2 or above information system is filed within 30 days after its level is determined, and a new one within 30 days after it enters operation. Apply any current sector procedure and filing channel to the protected object. Level 1 remains subject to the Cybersecurity Law's Article 23 baseline even though the cited filing route starts at level 2.

Keep the submitted classification and filing materials, filing receipt or certificate, authority questions and responses, and the final accepted system boundary. A filing record shows that the materials were accepted; it does not prove that every control operates effectively.

Build the control map from Article 23 and the standards that apply to the recorded level and technology context. GB/T 22239-2019 separates technical requirements for the secure communications network, secure area boundary, secure computing environment and security management centre from management requirements for policies, organisation, personnel, construction and operations.

- Filing evidence: filed forms, classification rationale, supporting diagrams, authority receipt or certificate, corrections and final accepted details.
- Clause map: standard clause, applicability decision, control owner, implementation description, evidence location, gap, remediation owner and due date.
- Technical evidence: configurations, access and privilege records, network and boundary protections, malware and intrusion controls, monitoring, backups, encryption and security-management-centre outputs.
- Management evidence: approved policies, accountable security roles, personnel screening and training, supplier controls, secure development and change records, operations procedures and incident plans.
- Article 23 evidence: monitoring and records of network status and security events, including network logs retained for at least six months.

Sources for this answer:

- [GB/T 22239 classified protection baseline requirements](https://openstd.samr.gov.cn/bzgk/gb/newGbInfo?hcno=BAFB47E8874764186BDB7865E8344DAF&ref=sorena.io) - Current GB/T 22239-2019 record for the level 1-4 general requirements and cloud, mobile, IoT, industrial-control and big-data extensions; effective 1 December 2019.
- [Amended PRC Cybersecurity Law](https://www.cac.gov.cn/2025-12/29/c_1768735112911946.htm?ref=sorena.io) - Article 23 establishes the current baseline classified-protection duties, including security responsibility, technical protection, monitoring, at least six months of network logs, data classification, important-data backup and encryption.
- [MPS guidance on implementing classified protection and CII protection](https://www.dhlc.gov.cn/jtj/Web/_F0_0_63FGXV347805E5AE44ED49D184.htm?ref=sorena.io) - Official implementation guidance stating that level 2 and above networks are filed with the public-security organ and that operators should build and remediate controls against the applicable national standards.
- [Information Security Classified Protection Management Measures](https://www.miit.gov.cn/jgsj/xxjsfzs/xxgk/art/2020/art_a981907528694176a61b5b52c2d19895.html?ref=sorena.io) - Article 15 sets the 30-day filing rules for operating and newly operated level 2 or above information systems; Article 16 identifies the filing materials for level 3 or above systems.

## 3. Assess, remediate and retain operating evidence

Assess the controls against the same object, level, standard clauses and technology extensions used in the control map. The MPS implementation guidance directs level 3 and above operators to use a qualified assessment institution once each year and submit the assessment report to the public-security organ that accepted the filing and to the industry authority. It also directs a new level 3 or above network to pass assessment before operation.

Track every finding to a responsible owner, corrective action, completion date and retest result. Preserve evidence from normal operation as well as the assessment package. A policy, filing certificate or assessment report cannot substitute for current configurations, logs, access reviews, incident exercises, backups and completed remediation.

- Assessment package: scope confirmation, assessor qualifications, plan, evidence requests, test records, findings, report, submission evidence and management response.
- Remediation package: finding identifier, risk, affected clause and asset, corrective action, owner, due date, implementation evidence and retest or closure decision.
- Recurring evidence: access and privilege reviews, monitoring alerts, network logs, vulnerability and patch records, backup and recovery tests, supplier reviews, security training and incident exercises.
- Exception evidence: approved reason, affected requirement, compensating measure, risk owner, expiry date and reassessment trigger.
- Change evidence: impact analysis showing whether the object boundary, level, filing, control map or assessment must be updated.

Sources for this answer:

- [MPS guidance on implementing classified protection and CII protection](https://www.dhlc.gov.cn/jtj/Web/_F0_0_63FGXV347805E5AE44ED49D184.htm?ref=sorena.io) - Official implementation guidance for annual assessment of level 3 and above networks, pre-operation assessment of new level 3 and above networks, report submission, and standards-based construction and remediation.

## 4. Keep MLPS separate from nearby decisions

MLPS answers how a network is classified and protected. It does not by itself decide whether a system is CII, whether a procurement requires cybersecurity review, whether data is important data, whether a personal-information or important-data export route applies, or whether an app needs MIIT filing.

Reuse verified system, architecture, data and supplier facts, but keep each scope decision and its evidence separate. For CII, classified protection is the baseline on top of which the enhanced CII duties apply.

- Do not describe GB/T 22239-2019 as a certification or approval of a specific system.
- Do not use a high MLPS level as proof that the protection department has identified the system as CII.
- Do not use an MLPS filing or assessment report as a substitute for cybersecurity review, data-export or app-filing analysis.
- Do not keep stale evidence after material architecture, function, data or hosting changes.

Related resources:

- [CII and network operator role triage](/artifacts/apac/china-cybersecurity-law/critical-information-infrastructure-and-network-operators.md): Determine whether the network remains under baseline operator duties or has been identified for enhanced CII protection.
- [Cybersecurity review workflow](/artifacts/apac/china-cybersecurity-law/cybersecurity-review-workflow.md): Run the separate review analysis for CII procurement, platform data processing or a qualifying listing abroad.

Sources for this answer:

- [Regulations on the Security Protection of Critical Information Infrastructure](https://www.cac.gov.cn/2021-08/17/c_1630785976988160.htm?ref=sorena.io) - Article 6 states that CII operators apply additional necessary protection measures on the basis of classified protection; Articles 8-10 establish the separate authority-led CII recognition process.
- [Amended PRC Cybersecurity Law](https://www.cac.gov.cn/2025-12/29/c_1768735112911946.htm?ref=sorena.io) - Articles 23 and 33 distinguish the general classified-protection baseline from enhanced protection for CII.

*Apply the requirement*

*Placement: Before primary sources*

## Build the China network security evidence file

Turn the MLPS classification into named owners, filed records, clause-level controls, assessment evidence and tracked remediation.

- [Map official sources to evidence](/solutions/research-copilot.md): Connect the official source, classification, owner, retained evidence and change history.
- [Review the China route](/contact.md): Check the China Cybersecurity Law scope decision and unresolved launch questions with Sorena.

## Primary sources

- [GB/T 22239 classified protection baseline requirements](https://openstd.samr.gov.cn/bzgk/gb/newGbInfo?hcno=BAFB47E8874764186BDB7865E8344DAF&ref=sorena.io) - Current GB/T 22239-2019 national standard record for level 1-4 baseline and technology-extension control mapping; effective 1 December 2019.
- [GB/T 22240-2020 classification guide](https://openstd.samr.gov.cn/bzgk/std/newGbInfo?hcno=63B89FFF7CC97EBBBED8A403396F0F00&refer=outter&ref=sorena.io) - Current national standard record for classified-protection level determination; effective 1 November 2020.
- [Amended PRC Cybersecurity Law](https://www.cac.gov.cn/2025-12/29/c_1768735112911946.htm?ref=sorena.io) - Current consolidated law, effective 1 January 2026, including Article 23 classified-protection duties and Article 33 enhanced CII protection.
- [MPS guidance on implementing classified protection and CII protection](https://www.dhlc.gov.cn/jtj/Web/_F0_0_63FGXV347805E5AE44ED49D184.htm?ref=sorena.io) - Official implementation guidance for inventory, classification, level 2 and above filing, level 3 and above annual assessment, construction and remediation.
- [Information Security Classified Protection Management Measures](https://www.miit.gov.cn/jgsj/xxjsfzs/xxgk/art/2020/art_a981907528694176a61b5b52c2d19895.html?ref=sorena.io) - Official filing procedure for level 2 or above information systems, including the 30-day deadlines and additional level 3 or above filing materials.

## Related Topic Guides

- [China App Filing vs Personal Information Rules](/artifacts/apac/china-cybersecurity-law/mobile-app-filing-vs-app-personal-information-rules.md): Decide whether a China mobile app needs MIIT filing, personal-information controls, or both, with current triggers, duties, dates, and evidence.
- [China cybersecurity and data security requirements](/artifacts/apac/china-cybersecurity-law/requirements.md): China cybersecurity requirements by actor: network operators, data processors, CII operators, platforms, app providers, and distribution platforms.
- [China cybersecurity compliance checklist](/artifacts/apac/china-cybersecurity-law/checklist.md): A China cybersecurity checklist for scoping network duties, data security, CII procurement review, app rules, MIIT filing, and supporting standards.
- [China cybersecurity deadlines and compliance calendar](/artifacts/apac/china-cybersecurity-law/deadlines-and-compliance-calendar.md): Separate China cybersecurity commencement dates from recurring duties, filing lead times, review periods, and event-driven response deadlines.
- [China Cybersecurity Law FAQ](/artifacts/apac/china-cybersecurity-law/faq.md): Practical answers on China network-operator scope, MLPS evidence, important data, cybersecurity review, app filing and governance, and smart-home standards under the law in force from 1 January 2026.
- [China Cybersecurity Law vs EU Cyber Resilience Act](/artifacts/apac/china-cybersecurity-law/china-cybersecurity-law-vs-eu-cyber-resilience-act.md): Compare China's network-operator rules with the EU CRA's product duties, including scope, actors, evidence, reporting dates, and launch decisions.
- [China Cybersecurity Law vs EU NIS2 Directive](/artifacts/apac/china-cybersecurity-law/china-cybersecurity-law-vs-nis2.md): Compare China's network-operator duties with NIS2 entity duties, including scope, management accountability, incident reporting, evidence, and enforcement.
- [China cybersecurity penalties and fines](/artifacts/apac/china-cybersecurity-law/penalties-and-fines.md): Compare current China Cybersecurity Law and Data Security Law fines by actor, breach, severity, and enforcement consequence.
- [China Cybersecurity Review vs Data Export Assessment](/artifacts/apac/china-cybersecurity-law/cybersecurity-review-vs-data-export-security-assessment.md): Separate China's cybersecurity-review triggers from CAC data-export assessment triggers, thresholds, filings, evidence, timing, and reapplication rules.
- [China cybersecurity review workflow](/artifacts/apac/china-cybersecurity-law/cybersecurity-review-workflow.md): Determine whether CII procurement, platform data processing, or a qualifying foreign listing triggers China's Cybersecurity Review Measures.
- [China mobile app filing and app governance](/artifacts/apac/china-cybersecurity-law/mobile-app-filing-and-app-governance.md): Identify the China app sponsor, complete MIIT filing before service, and separate provider, platform, privacy, content, and security duties.
- [China Smart-Home Security vs Telecom and Radio Approval](/artifacts/apac/china-cybersecurity-law/smart-home-security-vs-telecom-wireless-launch.md): Separate GB/T 41387-2022 smart-home security evidence from China telecom network-access and radio approval decisions for connected products.
- [CII and network operator role triage](/artifacts/apac/china-cybersecurity-law/critical-information-infrastructure-and-network-operators.md): How to separate ordinary network operator duties from CII, procurement, and review-risk questions under China cybersecurity sources.
- [Does an app need MIIT filing and CAC app governance review?](/artifacts/apac/china-cybersecurity-law/faq/does-an-app-need-miit-filing-and-cac-app-governance-review.md): An app sponsor providing internet information services through an app in China must complete MIIT filing. CAC rules separately govern app providers and distribution platforms without creating one routine CAC approval for every app.
- [GB/T 22239-2019 classified protection baseline](/artifacts/apac/china-cybersecurity-law/classified-protection-baseline.md): How to scope and document a GB/T 22239-2019 classified protection baseline without treating the recommended standard as a standalone law.
- [GB/T 41387-2022 smart home security standard](/artifacts/apac/china-cybersecurity-law/smart-home-security-standard.md): How connected-device teams can scope and document GB/T 41387-2022 without treating it as an automatic certification or product-approval duty.
- [How do smart home security standards fit with China cybersecurity law?](/artifacts/apac/china-cybersecurity-law/faq/how-do-smart-home-security-standards-fit-with-china-cybersecurity-law.md): GB/T 41387-2022 can organize smart-home security evidence, but it is a recommended standard, not a product approval. Check app, data, MLPS, telecom access, and radio requirements separately.
- [How does important data change China cybersecurity obligations?](/artifacts/apac/china-cybersecurity-law/faq/how-does-important-data-change-cybersecurity-obligations.md): Once data is officially identified as important data, the processor needs named governance, periodic risk assessments and reports, incident controls, and a separate export decision. An internal sensitivity label alone does not establish the legal category.
- [Is every company a network operator under China Cybersecurity Law?](/artifacts/apac/china-cybersecurity-law/faq/is-every-company-a-network-operator-under-china-cybersecurity-law.md): No. Under China's Cybersecurity Law, a network operator is an owner or administrator of a network or a network service provider. Apply that definition to each China network or service, then test CII and other roles separately.
- [What is MLPS classified protection evidence?](/artifacts/apac/china-cybersecurity-law/faq/what-is-mlps-classified-protection-evidence.md): MLPS evidence shows how a defined China network or system was graded and protected. Keep the scope, grading rationale, filing or assessment records where applicable, control mapping, test results, remediation, and reassessment history.
- [When does China cybersecurity review apply?](/artifacts/apac/china-cybersecurity-law/faq/when-does-china-cybersecurity-review-apply.md): China cybersecurity review applies to CII procurement or network-platform data processing that affects or may affect national security, plus a mandatory pre-filing trigger for certain foreign listings involving more than one million users' personal information.


---

[Privacy Policy](https://www.sorena.io/privacy.md) | [Terms of Use](https://www.sorena.io/terms-of-use.md) | [DMCA](https://www.sorena.io/dmca.md) | [About Us](https://www.sorena.io/about-us.md)

(c) 2026 Sorena AB (559573-7338). All rights reserved.

Source: https://www.sorena.io/artifacts/apac/china-cybersecurity-law/mlps-classified-protection-evidence-map.md
