CybersecurityChina

China Cybersecurity Law mobile app filing and app governance

Complete the MIIT filing for an app internet information service and keep it separate from provider and distribution-platform governance.

A new app must complete the applicable filing before service begins. Filing does not replace licences, content controls, data and personal-information duties, security assessment or platform review.

Author
Sorena AI
Published
Jul 5, 2026
Updated
Jul 25, 2026
Sections
4

Structured answer sets in this page tree.

Primary sources
2

Cited legal and guidance references.

Publication metadata
Sorena AI
Published Jul 5, 2026
Updated Jul 25, 2026
Overview

Complete the before a new covered app starts service. Identify the , , , , and any ; then complete each role's separate filing, licence, review, content, data, personal-information, minors, complaint, and incident duties.

Section 1

1. Separate the roles and filings

Identify the that files the internet information service, the that owns or operates the service, each , each and any that preinstalls the app. One organisation may hold several roles, but the filings and evidence remain role-specific.

The applies to an providing an app internet information service in China. The 2022 app provisions separately regulate app providers and distribution services in China. An must file with its provincial cyberspace authority within 30 days after going online; that platform filing is not the sponsor's MIIT filing. The filing notice routes the sponsor to the provincial communications administration for its place of residence. If a proposed sponsor has no clear place of residence for that route, confirm the accepted filing entity and channel with the access provider, distribution platform, or relevant provincial administration before launch; the notice does not state a general foreign-sponsor exemption.

Is an 's MIIT filing the same as an 's provincial cyberspace filing?

No. The sponsor's MIIT filing covers the app internet information service and is submitted through an access provider or distribution platform to the sponsor's provincial communications administration. A distribution platform separately files with its provincial cyberspace authority within 30 days after the platform goes online.

  • Sponsor: files truthful identity, network-resource and service information and keeps the record current.
  • Access provider or distribution platform: verifies identity and network-resource information and submits the sponsor's filing through the national system.
  • : operates the service and carries the applicable content, account, security, data, personal-information, minors and complaint duties.
  • Distribution platform: completes its own provincial cyberspace filing and maintains provider verification, listing and update review, monitoring, suspension, takedown, recordkeeping and reporting controls.
  • : does not preinstall an app that has not completed the applicable MIIT filing.
Section 2

2. Complete and maintain the MIIT filing

Before a new covered app begins service, the submits the filing through its or distribution platform to the provincial communications administration for the sponsor's place of residence. The filing uses the . Domain names, and other network resources must satisfy the network-resource rules cited in the notice.

The sponsor submits the registration form and commitments. Apps providing news, publishing, education, film and television, religious or other services that require prior approval must also submit the relevant competent-department document. When materials are complete and accurate, the provincial communications administration has 20 working days to complete the filing, issue a filing number and publish the filing information. Incomplete or inaccurate materials are not filed, and the authority must give the reason.

The transition for apps already operating when the notice was issued ran from September 2023 through March 2024, followed by an inspection phase from April through June 2024. Since July 2024 the filing programme has operated as continuing administration. Those expired transition dates do not excuse a currently operating unfiled app.

  • Before submission: verify the sponsor's identity, app name and service, domain and IP resources, access provider, distribution channels, required licences or approvals, and responsible contact.
  • Submission evidence: retain the filed form and commitments, identity and network-resource verification, required sector approval documents, intermediary submission record, authority response, filing number, and public-record check.
  • After issuance: display the filing number prominently in the app and place the required filing-system link below it so the public can check the record.
  • Distribution display: each distribution platform prominently displays the filing number for the apps it distributes and reports required distribution information to the telecommunications authority.
  • Changes and closure: submit change or cancellation procedures to the original filing authority when the filed information changes or service ends.
  • Gatekeeping: access providers, distribution platforms and smart-terminal manufacturers must not provide access, distribution or preinstallation for an app that has not completed the required filing.
Section 3

3. Operate the app and distribution controls

Filing is only one launch condition. An must maintain information-content controls, required user identity verification for information publishing or instant-messaging services, applicable service licences, security-defect response, full-lifecycle data security, personal-information rules, protections for minors, published management rules, complaint handling and records of user enforcement.

Before launching a new technology, application or function with , identify the national rule governing the Article 14 security assessment and record the decision and result. The app provisions state the trigger but do not supply a universal assessment form or category list. A distribution platform must verify provider identity, licences and any required security assessment; review new listings and updates; monitor listed apps; and preserve and report suspension or takedown actions.

Does a filing number show that the app meets all China app rules?

No. The filing number records the app internet information service filing. It does not replace a required sector licence or approval, app-provider and distribution-platform duties under the 2022 provisions, personal-information and data-security compliance, a required security assessment, network security classified-protection work, or continuing monitoring and incident response.

  • Provider evidence: content-review procedures, account and identity controls, licences, vulnerability and user-notification records, data-security measures, personal-information rules, minors controls, user agreement and complaint log.
  • Feature evidence: product description, public-opinion or social-mobilisation assessment, required security-assessment record, approvals and release gate.
  • Platform evidence: provider verification, displayed provider identity, service agreement, listing and update review, licence and assessment checks, ongoing monitoring, complaints, enforcement records and authority reports.
  • Shared incident evidence: prohibited-content detection, immediate transmission stop and removal, containment, preserved records, report to the telecommunications authority and follow-up action.
Section 4

4. Keep a release and change record

For each release, link the app identifier and version to its sponsor, provider, network resources, distribution channels, filing number, licences, feature assessments, privacy and data controls, platform reviews and approval owner. Keep the actual filing receipt and displayed-number evidence, not only a spreadsheet entry.

Reopen the record when the sponsor, app name, service, domain or IP resources, licence, distribution channel, material feature, data processing, intended users or service status changes. File changes or cancellation where required and repeat platform or security review when the change affects those controls.

  • Do not treat a website as the complete app record; the MIIT notice allowed an existing website filer to supplement app information during the stock-app phase.
  • Do not confuse the sponsor's MIIT filing with the distribution platform's provincial cyberspace filing.
  • Do not release a material feature before checking licensing and the public-opinion or social-mobilisation security-assessment trigger.
  • Do not treat filing as proof of continuing content, data, personal-information, minors or platform compliance.
Primary sources

References and citations

miit.gov.cn
Referenced sections
  • The notice distinguishes the completed stock-app phase from pre-service filing for new apps, requires changes and cancellation, and places filing administration on a long-term normalised footing from July 2024.
Related guides

Explore more topics

China App Filing vs Personal Information Rules
Decide whether a China mobile app needs MIIT filing, personal-information controls, or both, with current triggers, duties, dates, and evidence.
China cybersecurity and data security requirements
China cybersecurity requirements by actor: network operators, data processors, CII operators, platforms, app providers, and distribution platforms.
China cybersecurity compliance checklist
A China cybersecurity checklist for scoping network duties, data security, CII procurement review, app rules, MIIT filing, and supporting standards.
China cybersecurity deadlines and compliance calendar
Separate China cybersecurity commencement dates from recurring duties, filing lead times, review periods, and event-driven response deadlines.
China Cybersecurity Law FAQ
Practical answers on China network-operator scope, MLPS evidence, important data, cybersecurity review, app filing and governance, and smart-home standards under the law in force from 1 January 2026.
China Cybersecurity Law vs EU Cyber Resilience Act
Compare China's network-operator rules with the EU CRA's product duties, including scope, actors, evidence, reporting dates, and launch decisions.
China Cybersecurity Law vs EU NIS2 Directive
Compare China's network-operator duties with NIS2 entity duties, including scope, management accountability, incident reporting, evidence, and enforcement.
China cybersecurity penalties and fines
Compare current China Cybersecurity Law and Data Security Law fines by actor, breach, severity, and enforcement consequence.
China Cybersecurity Review vs Data Export Assessment
Separate China's cybersecurity-review triggers from CAC data-export assessment triggers, thresholds, filings, evidence, timing, and reapplication rules.
China cybersecurity review workflow
Determine whether CII procurement, platform data processing, or a qualifying foreign listing triggers China's Cybersecurity Review Measures.
China Smart-Home Security vs Telecom and Radio Approval
Separate GB/T 41387-2022 smart-home security evidence from China telecom network-access and radio approval decisions for connected products.
CII and network operator role triage
How to separate ordinary network operator duties from CII, procurement, and review-risk questions under China cybersecurity sources.
Does an app need MIIT filing and CAC app governance review?
An app sponsor providing internet information services through an app in China must complete MIIT filing. CAC rules separately govern app providers and distribution platforms without creating one routine CAC approval for every app.
GB/T 22239-2019 classified protection baseline
How to scope and document a GB/T 22239-2019 classified protection baseline without treating the recommended standard as a standalone law.
GB/T 41387-2022 smart home security standard
How connected-device teams can scope and document GB/T 41387-2022 without treating it as an automatic certification or product-approval duty.
How do smart home security standards fit with China cybersecurity law?
GB/T 41387-2022 can organize smart-home security evidence, but it is a recommended standard, not a product approval. Check app, data, MLPS, telecom access, and radio requirements separately.
How does important data change China cybersecurity obligations?
Once data is officially identified as important data, the processor needs named governance, periodic risk assessments and reports, incident controls, and a separate export decision. An internal sensitivity label alone does not establish the legal category.
Is every company a network operator under China Cybersecurity Law?
No. Under China's Cybersecurity Law, a network operator is an owner or administrator of a network or a network service provider. Apply that definition to each China network or service, then test CII and other roles separately.
MLPS classified protection evidence map
Classify a China network under MLPS, complete level 2 or above filing, map controls, and retain assessment, remediation, and change evidence.
What is MLPS classified protection evidence?
MLPS evidence shows how a defined China network or system was graded and protected. Keep the scope, grading rationale, filing or assessment records where applicable, control mapping, test results, remediation, and reassessment history.
When does China cybersecurity review apply?
China cybersecurity review applies to CII procurement or network-platform data processing that affects or may affect national security, plus a mandatory pre-filing trigger for certain foreign listings involving more than one million users' personal information.