---
title: "China mobile app filing and app governance"
canonical_url: "https://www.sorena.io/artifacts/apac/china-cybersecurity-law/mobile-app-filing-and-app-governance"
source_url: "https://www.sorena.io/artifacts/apac/china-cybersecurity-law/mobile-app-filing-and-app-governance"
author: "Sorena AI"
description: "Identify the China app sponsor, complete MIIT filing before service, and separate provider, platform, privacy, content, and security duties."
published_at: "2026-07-05"
updated_at: "2026-07-25"
keywords:
  - "China Cybersecurity Law"
  - "Data Security Law"
  - "Cybersecurity Review Measures"
  - "Mobile app filing"
  - "MLPS"
---
**[SORENA](https://www.sorena.io/)** - AI-Powered GRC Platform

[Home](https://www.sorena.io/) | [Solutions](https://www.sorena.io/solutions) | [Artifacts](https://www.sorena.io/artifacts) | [About Us](https://www.sorena.io/about-us) | [Contact](https://www.sorena.io/contact) | [Portal](https://app.sorena.io)

---

# China mobile app filing and app governance

Identify the China app sponsor, complete MIIT filing before service, and separate provider, platform, privacy, content, and security duties.

*Cybersecurity* *China*

## China Cybersecurity Law mobile app filing and app governance

Complete the MIIT filing for an app internet information service and keep it separate from provider and distribution-platform governance.

A new app must complete the applicable filing before service begins. Filing does not replace licences, content controls, data and personal-information duties, security assessment or platform review.

Complete the MIIT app filing before a new covered app starts service. Identify the app sponsor, app provider, network access provider, app distribution platform, and any smart-terminal manufacturer; then complete each role's separate filing, licence, review, content, data, personal-information, minors, complaint, and incident duties.

## Definitions

### MIIT mobile app filing

**Term:** MIIT app filing

The MIIT app filing is the record required by the Ministry of Industry and Information Technology's 2023 notice for an app sponsor providing an app internet information service in China. The sponsor files with the provincial communications administration for its place of residence through its network access provider or app distribution platform using the national internet basic-resource filing system.

**Why it matters here:** A new app subject to the notice must complete filing before service begins. The sponsor must display the filing number and required query link, keep the information accurate, and file changes or cancellation with the original filing authority.

Sources:

- [MIIT notice on mobile app filing work](https://www.miit.gov.cn/zwgk/zcwj/wjfb/tz/art/2023/art_920db564162e4312916a01bed6540ad8.html?ref=sorena.io)

### App distribution platform

An app distribution platform is an internet information service provider that offers app publication, download or dynamic-loading services. Under the 2022 app provisions, the category includes app stores, quick-app centres, internet mini-program platforms and browser plug-in platforms.

**Why it matters here:** The platform has its own filing with the provincial cyberspace authority within 30 days after going online, plus continuing provider-verification, listing and update review, monitoring, complaint, recordkeeping, suspension and takedown duties. This is separate from helping an app sponsor submit an MIIT filing.

Sources:

- [Mobile Internet Application Information Service Management Provisions](https://www.cac.gov.cn/2022-06/14/c_1656821626455324.htm?ref=sorena.io)
- [MIIT notice on mobile app filing work](https://www.miit.gov.cn/zwgk/zcwj/wjfb/tz/art/2023/art_920db564162e4312916a01bed6540ad8.html?ref=sorena.io)

### App sponsor for MIIT filing

**Term:** app sponsor

The app sponsor is the organisation or individual providing the app-based internet information service and named in the MIIT filing. The sponsor supplies truthful identity, network-resource, service, licence or approval, and contact information, displays the filing number and query link, and files changes or cancellation with the original filing authority.

**Why it matters here:** Do not assume the software developer, brand owner, app provider, access provider, or distribution platform is the sponsor without checking the filed service and legal entity. One entity may hold several roles, but the MIIT filing must identify the sponsor for the covered service.

Sources:

- [MIIT notice on mobile app filing work](https://www.miit.gov.cn/zwgk/zcwj/wjfb/tz/art/2023/art_920db564162e4312916a01bed6540ad8.html?ref=sorena.io)

### Public-opinion attributes or social-mobilisation capability

This phrase is the trigger used by Article 14 of the 2022 app provisions for a new technology, application, or function that must undergo a security assessment under the relevant national rules before launch. The app provisions do not provide a self-contained product-category list or universal assessment form.

**Why it matters here:** Document the feature and the applicable security-assessment rule before release. If the trigger or procedure is unclear, verify it with the competent authority or the current rule rather than treating every feature as exempt or assuming that the MIIT filing covers the assessment.

Sources:

- [Mobile Internet Application Information Service Management Provisions, Article 14](https://www.cac.gov.cn/2022-06/14/c_1656821626455324.htm?ref=sorena.io)

### Internet content provider filing

**Term:** ICP filing

ICP filing is the established filing record for a non-commercial internet information service such as a website. During the stock-app phase, the MIIT app notice allowed a sponsor that had already completed website filing to supplement its app information without resubmitting the sponsor's identity information.

**Why it matters here:** A website ICP filing is not the complete filing record for a new app. Keep the app-specific information, app filing number, display evidence, and later changes or cancellation with the website record where both exist.

Sources:

- [MIIT notice on mobile app filing work](https://www.miit.gov.cn/zwgk/zcwj/wjfb/tz/art/2023/art_920db564162e4312916a01bed6540ad8.html?ref=sorena.io)

### Internet Protocol addresses

**Term:** IP addresses

IP addresses are numerical network addresses used to identify endpoints and route internet traffic. The MIIT filing notice requires the app sponsor's domain names, IP addresses, and other network resources to comply with the cited network-resource management rules.

**Why it matters here:** Record the addresses used by the app service, the responsible access provider, and any change that affects the filed network-resource information. A material change may require an app-filing update.

Sources:

- [MIIT notice on mobile app filing work](https://www.miit.gov.cn/zwgk/zcwj/wjfb/tz/art/2023/art_920db564162e4312916a01bed6540ad8.html?ref=sorena.io)

### National internet basic-resource filing system

**Term:** national internet basic-resource management system

The MIIT notice identifies the national internet basic-resource management system as the ICP, IP-address, and domain-name information filing system used by network access providers and app distribution platforms to submit app-filing applications for sponsors.

**Why it matters here:** The app sponsor does not treat the distribution intermediary's submission as proof of completion. Retain the issued filing number, published record, in-app display, query link, and any change or cancellation result.

Sources:

- [MIIT notice on mobile app filing work](https://www.miit.gov.cn/zwgk/zcwj/wjfb/tz/art/2023/art_920db564162e4312916a01bed6540ad8.html?ref=sorena.io)

### App provider

The owner or operator of a mobile internet application that provides information services through the app. The app provider is responsible for app-level information-content and user-protection duties under the mobile-app provisions; it is distinct from the app sponsor named in an MIIT filing and from the distribution platform that lists the app.

**Why it matters here:** Identify the app provider separately from the filing sponsor and distribution platform because each role has different duties, even when one organization performs more than one role.

Sources:

- [Mobile Internet Application Information Service Management Provisions](https://www.cac.gov.cn/2022-06/14/c_1656821626455324.htm?ref=sorena.io)

### Network access provider

The connectivity intermediary that verifies an app filing applicant's identity and network-resource information and submits the filing information through the MIIT system. The MIIT notice also bars it from knowingly submitting inaccurate filing information or providing network access for a covered app that has not completed filing.

**Why it matters here:** Record which access provider submitted the filing and retain its verification records, because the access provider's role is separate from the app sponsor's duty to provide accurate information.

Sources:

- [MIIT notice on mobile app filing work](https://www.miit.gov.cn/zwgk/zcwj/wjfb/tz/art/2023/art_920db564162e4312916a01bed6540ad8.html?ref=sorena.io)

### Smart-terminal manufacturer

A manufacturer of phones or other smart terminals that preinstalls mobile applications. Under the MIIT filing notice, the manufacturer must not preinstall a covered app that has not completed filing and must participate in controls against apps that disseminate prohibited information.

**Why it matters here:** Treat preinstallation as a distribution channel: the manufacturer must check filing status before a covered app is shipped on a device.

Sources:

- [MIIT notice on mobile app filing work](https://www.miit.gov.cn/zwgk/zcwj/wjfb/tz/art/2023/art_920db564162e4312916a01bed6540ad8.html?ref=sorena.io)

## 1. Separate the roles and filings

Identify the app sponsor that files the internet information service, the app provider that owns or operates the service, each network access provider, each app distribution platform and any smart-terminal manufacturer that preinstalls the app. One organisation may hold several roles, but the filings and evidence remain role-specific.

The MIIT app filing applies to an app sponsor providing an app internet information service in China. The 2022 app provisions separately regulate app providers and distribution services in China. An app distribution platform must file with its provincial cyberspace authority within 30 days after going online; that platform filing is not the sponsor's MIIT filing. The filing notice routes the sponsor to the provincial communications administration for its place of residence. If a proposed sponsor has no clear place of residence for that route, confirm the accepted filing entity and channel with the access provider, distribution platform, or relevant provincial administration before launch; the notice does not state a general foreign-sponsor exemption.

- Sponsor: files truthful identity, network-resource and service information and keeps the record current.
- Access provider or distribution platform: verifies identity and network-resource information and submits the sponsor's filing through the national system.
- App provider: operates the service and carries the applicable content, account, security, data, personal-information, minors and complaint duties.
- Distribution platform: completes its own provincial cyberspace filing and maintains provider verification, listing and update review, monitoring, suspension, takedown, recordkeeping and reporting controls.
- Smart-terminal manufacturer: does not preinstall an app that has not completed the applicable MIIT filing.

### Is an app sponsor's MIIT filing the same as an app distribution platform's provincial cyberspace filing?

No. The sponsor's MIIT filing covers the app internet information service and is submitted through an access provider or distribution platform to the sponsor's provincial communications administration. A distribution platform separately files with its provincial cyberspace authority within 30 days after the platform goes online.

Sources for this answer:

- [MIIT notice on mobile app filing work](https://www.miit.gov.cn/zwgk/zcwj/wjfb/tz/art/2023/art_920db564162e4312916a01bed6540ad8.html?ref=sorena.io) - Sections 2 and 3 establish sponsor filing, intermediary verification and submission, restrictions on unfiled apps, and the transition to long-term normalised administration from July 2024.
- [Mobile Internet Application Information Service Management Provisions](https://www.cac.gov.cn/2022-06/14/c_1656821626455324.htm?ref=sorena.io) - Articles 2, 17 and 26 define the regulated services and platform, and establish the platform's separate provincial cyberspace filing.

## 2. Complete and maintain the MIIT filing

Before a new covered app begins service, the app sponsor submits the filing through its network access provider or distribution platform to the provincial communications administration for the sponsor's place of residence. The filing uses the national internet basic-resource management system. Domain names, IP addresses and other network resources must satisfy the network-resource rules cited in the notice.

The sponsor submits the registration form and commitments. Apps providing news, publishing, education, film and television, religious or other services that require prior approval must also submit the relevant competent-department document. When materials are complete and accurate, the provincial communications administration has 20 working days to complete the filing, issue a filing number and publish the filing information. Incomplete or inaccurate materials are not filed, and the authority must give the reason.

The transition for apps already operating when the notice was issued ran from September 2023 through March 2024, followed by an inspection phase from April through June 2024. Since July 2024 the filing programme has operated as continuing administration. Those expired transition dates do not excuse a currently operating unfiled app.

- Before submission: verify the sponsor's identity, app name and service, domain and IP resources, access provider, distribution channels, required licences or approvals, and responsible contact.
- Submission evidence: retain the filed form and commitments, identity and network-resource verification, required sector approval documents, intermediary submission record, authority response, filing number, and public-record check.
- After issuance: display the filing number prominently in the app and place the required filing-system link below it so the public can check the record.
- Distribution display: each distribution platform prominently displays the filing number for the apps it distributes and reports required distribution information to the telecommunications authority.
- Changes and closure: submit change or cancellation procedures to the original filing authority when the filed information changes or service ends.
- Gatekeeping: access providers, distribution platforms and smart-terminal manufacturers must not provide access, distribution or preinstallation for an app that has not completed the required filing.

Sources for this answer:

- [MIIT notice on mobile app filing work](https://www.miit.gov.cn/zwgk/zcwj/wjfb/tz/art/2023/art_920db564162e4312916a01bed6540ad8.html?ref=sorena.io) - Section 2 covers the filing route, required information and approvals, 20-working-day authority process, number display and query link, changes and cancellation, and restrictions on unfiled apps.

## 3. Operate the app and distribution controls

Filing is only one launch condition. An app provider must maintain information-content controls, required user identity verification for information publishing or instant-messaging services, applicable service licences, security-defect response, full-lifecycle data security, personal-information rules, protections for minors, published management rules, complaint handling and records of user enforcement.

Before launching a new technology, application or function with public-opinion attributes or social-mobilisation capability, identify the national rule governing the Article 14 security assessment and record the decision and result. The app provisions state the trigger but do not supply a universal assessment form or category list. A distribution platform must verify provider identity, licences and any required security assessment; review new listings and updates; monitor listed apps; and preserve and report suspension or takedown actions.

- Provider evidence: content-review procedures, account and identity controls, licences, vulnerability and user-notification records, data-security measures, personal-information rules, minors controls, user agreement and complaint log.
- Feature evidence: product description, public-opinion or social-mobilisation assessment, required security-assessment record, approvals and release gate.
- Platform evidence: provider verification, displayed provider identity, service agreement, listing and update review, licence and assessment checks, ongoing monitoring, complaints, enforcement records and authority reports.
- Shared incident evidence: prohibited-content detection, immediate transmission stop and removal, containment, preserved records, report to the telecommunications authority and follow-up action.

### Does a filing number show that the app meets all China app rules?

No. The filing number records the app internet information service filing. It does not replace a required sector licence or approval, app-provider and distribution-platform duties under the 2022 provisions, personal-information and data-security compliance, a required security assessment, network security classified-protection work, or continuing monitoring and incident response.

Sources for this answer:

- [Mobile Internet Application Information Service Management Provisions](https://www.cac.gov.cn/2022-06/14/c_1656821626455324.htm?ref=sorena.io) - Articles 5-16 establish provider governance and security duties; Articles 17-22 establish platform filing, provider verification, listing and update review, monitoring, enforcement and complaint duties.
- [MIIT notice on mobile app filing work](https://www.miit.gov.cn/zwgk/zcwj/wjfb/tz/art/2023/art_920db564162e4312916a01bed6540ad8.html?ref=sorena.io) - Section 2(10) requires sponsors, access providers, distribution platforms and terminal manufacturers to detect and stop prohibited information, prevent its spread, preserve records and report to the telecommunications authority.

## 4. Keep a release and change record

For each release, link the app identifier and version to its sponsor, provider, network resources, distribution channels, filing number, licences, feature assessments, privacy and data controls, platform reviews and approval owner. Keep the actual filing receipt and displayed-number evidence, not only a spreadsheet entry.

Reopen the record when the sponsor, app name, service, domain or IP resources, licence, distribution channel, material feature, data processing, intended users or service status changes. File changes or cancellation where required and repeat platform or security review when the change affects those controls.

- Do not treat a website ICP filing as the complete app record; the MIIT notice allowed an existing website filer to supplement app information during the stock-app phase.
- Do not confuse the sponsor's MIIT filing with the distribution platform's provincial cyberspace filing.
- Do not release a material feature before checking licensing and the public-opinion or social-mobilisation security-assessment trigger.
- Do not treat filing as proof of continuing content, data, personal-information, minors or platform compliance.

Related resources:

- [MLPS classified protection evidence map](/artifacts/apac/china-cybersecurity-law/mlps-classified-protection-evidence-map.md): Build the separate classified-protection evidence for the networks and systems supporting the app.
- [Critical information infrastructure and network operator role triage](/artifacts/apac/china-cybersecurity-law/critical-information-infrastructure-and-network-operators.md): Identify the network operator and determine whether enhanced critical-information-infrastructure duties apply to the supporting service.

Sources for this answer:

- [MIIT notice on mobile app filing work](https://www.miit.gov.cn/zwgk/zcwj/wjfb/tz/art/2023/art_920db564162e4312916a01bed6540ad8.html?ref=sorena.io) - The notice distinguishes the completed stock-app phase from pre-service filing for new apps, requires changes and cancellation, and places filing administration on a long-term normalised footing from July 2024.
- [Mobile Internet Application Information Service Management Provisions](https://www.cac.gov.cn/2022-06/14/c_1656821626455324.htm?ref=sorena.io) - The provisions, effective 1 August 2022, establish continuing duties that remain separate from the later MIIT filing programme.

*Apply the requirement*

*Placement: Before primary sources*

## Build the China network security evidence file

Turn app filing and governance duties into named owners, release gates, filed records and continuing evidence.

- [Map official sources to evidence](/solutions/research-copilot.md): Connect the app sponsor, MIIT filing, displayed number, provincial platform filing, feature assessment, release and later changes.
- [Review the China route](/contact.md): Check the China Cybersecurity Law scope decision and unresolved launch questions with Sorena.

## Primary sources

- [MIIT notice on mobile app filing work](https://www.miit.gov.cn/zwgk/zcwj/wjfb/tz/art/2023/art_920db564162e4312916a01bed6540ad8.html?ref=sorena.io) - Official notice for sponsor filing, intermediary verification and submission, authority processing, filing-number display, changes, cancellation, unfiled-app restrictions and the filing programme's phases.
- [Mobile Internet Application Information Service Management Provisions](https://www.cac.gov.cn/2022-06/14/c_1656821626455324.htm?ref=sorena.io) - Provisions effective 1 August 2022 for app-provider and distribution-platform scope, governance, security, platform filing, verification, review, monitoring and complaints.

## Related Topic Guides

- [China App Filing vs Personal Information Rules](/artifacts/apac/china-cybersecurity-law/mobile-app-filing-vs-app-personal-information-rules.md): Decide whether a China mobile app needs MIIT filing, personal-information controls, or both, with current triggers, duties, dates, and evidence.
- [China cybersecurity and data security requirements](/artifacts/apac/china-cybersecurity-law/requirements.md): China cybersecurity requirements by actor: network operators, data processors, CII operators, platforms, app providers, and distribution platforms.
- [China cybersecurity compliance checklist](/artifacts/apac/china-cybersecurity-law/checklist.md): A China cybersecurity checklist for scoping network duties, data security, CII procurement review, app rules, MIIT filing, and supporting standards.
- [China cybersecurity deadlines and compliance calendar](/artifacts/apac/china-cybersecurity-law/deadlines-and-compliance-calendar.md): Separate China cybersecurity commencement dates from recurring duties, filing lead times, review periods, and event-driven response deadlines.
- [China Cybersecurity Law FAQ](/artifacts/apac/china-cybersecurity-law/faq.md): Practical answers on China network-operator scope, MLPS evidence, important data, cybersecurity review, app filing and governance, and smart-home standards under the law in force from 1 January 2026.
- [China Cybersecurity Law vs EU Cyber Resilience Act](/artifacts/apac/china-cybersecurity-law/china-cybersecurity-law-vs-eu-cyber-resilience-act.md): Compare China's network-operator rules with the EU CRA's product duties, including scope, actors, evidence, reporting dates, and launch decisions.
- [China Cybersecurity Law vs EU NIS2 Directive](/artifacts/apac/china-cybersecurity-law/china-cybersecurity-law-vs-nis2.md): Compare China's network-operator duties with NIS2 entity duties, including scope, management accountability, incident reporting, evidence, and enforcement.
- [China cybersecurity penalties and fines](/artifacts/apac/china-cybersecurity-law/penalties-and-fines.md): Compare current China Cybersecurity Law and Data Security Law fines by actor, breach, severity, and enforcement consequence.
- [China Cybersecurity Review vs Data Export Assessment](/artifacts/apac/china-cybersecurity-law/cybersecurity-review-vs-data-export-security-assessment.md): Separate China's cybersecurity-review triggers from CAC data-export assessment triggers, thresholds, filings, evidence, timing, and reapplication rules.
- [China cybersecurity review workflow](/artifacts/apac/china-cybersecurity-law/cybersecurity-review-workflow.md): Determine whether CII procurement, platform data processing, or a qualifying foreign listing triggers China's Cybersecurity Review Measures.
- [China Smart-Home Security vs Telecom and Radio Approval](/artifacts/apac/china-cybersecurity-law/smart-home-security-vs-telecom-wireless-launch.md): Separate GB/T 41387-2022 smart-home security evidence from China telecom network-access and radio approval decisions for connected products.
- [CII and network operator role triage](/artifacts/apac/china-cybersecurity-law/critical-information-infrastructure-and-network-operators.md): How to separate ordinary network operator duties from CII, procurement, and review-risk questions under China cybersecurity sources.
- [Does an app need MIIT filing and CAC app governance review?](/artifacts/apac/china-cybersecurity-law/faq/does-an-app-need-miit-filing-and-cac-app-governance-review.md): An app sponsor providing internet information services through an app in China must complete MIIT filing. CAC rules separately govern app providers and distribution platforms without creating one routine CAC approval for every app.
- [GB/T 22239-2019 classified protection baseline](/artifacts/apac/china-cybersecurity-law/classified-protection-baseline.md): How to scope and document a GB/T 22239-2019 classified protection baseline without treating the recommended standard as a standalone law.
- [GB/T 41387-2022 smart home security standard](/artifacts/apac/china-cybersecurity-law/smart-home-security-standard.md): How connected-device teams can scope and document GB/T 41387-2022 without treating it as an automatic certification or product-approval duty.
- [How do smart home security standards fit with China cybersecurity law?](/artifacts/apac/china-cybersecurity-law/faq/how-do-smart-home-security-standards-fit-with-china-cybersecurity-law.md): GB/T 41387-2022 can organize smart-home security evidence, but it is a recommended standard, not a product approval. Check app, data, MLPS, telecom access, and radio requirements separately.
- [How does important data change China cybersecurity obligations?](/artifacts/apac/china-cybersecurity-law/faq/how-does-important-data-change-cybersecurity-obligations.md): Once data is officially identified as important data, the processor needs named governance, periodic risk assessments and reports, incident controls, and a separate export decision. An internal sensitivity label alone does not establish the legal category.
- [Is every company a network operator under China Cybersecurity Law?](/artifacts/apac/china-cybersecurity-law/faq/is-every-company-a-network-operator-under-china-cybersecurity-law.md): No. Under China's Cybersecurity Law, a network operator is an owner or administrator of a network or a network service provider. Apply that definition to each China network or service, then test CII and other roles separately.
- [MLPS classified protection evidence map](/artifacts/apac/china-cybersecurity-law/mlps-classified-protection-evidence-map.md): Classify a China network under MLPS, complete level 2 or above filing, map controls, and retain assessment, remediation, and change evidence.
- [What is MLPS classified protection evidence?](/artifacts/apac/china-cybersecurity-law/faq/what-is-mlps-classified-protection-evidence.md): MLPS evidence shows how a defined China network or system was graded and protected. Keep the scope, grading rationale, filing or assessment records where applicable, control mapping, test results, remediation, and reassessment history.
- [When does China cybersecurity review apply?](/artifacts/apac/china-cybersecurity-law/faq/when-does-china-cybersecurity-review-apply.md): China cybersecurity review applies to CII procurement or network-platform data processing that affects or may affect national security, plus a mandatory pre-filing trigger for certain foreign listings involving more than one million users' personal information.


---

[Privacy Policy](https://www.sorena.io/privacy.md) | [Terms of Use](https://www.sorena.io/terms-of-use.md) | [DMCA](https://www.sorena.io/dmca.md) | [About Us](https://www.sorena.io/about-us.md)

(c) 2026 Sorena AB (559573-7338). All rights reserved.

Source: https://www.sorena.io/artifacts/apac/china-cybersecurity-law/mobile-app-filing-and-app-governance.md
