China Cybersecurity Law cybersecurity and data security requirements
Requirements for network operators, data processors, CII operators, platforms, app providers, and app distribution platforms.
The requirements come from several instruments with different actors. Start with baseline network and data-security duties, then add CII, review, app, filing, export, or recommended-standard work only when its own trigger is met.
Start by identifying whether the entity is a , network product or service provider, network data processor, important-data processor, operator, , app provider, , or . Apply the baseline duty for each role, then add review, filing, export, product-standard, or voluntary-label work only when its separate trigger is met.
1
Section 1
Requirements by regulated actor
The Cybersecurity Law applies to constructing, operating, maintaining, and using networks in China. Amendments adopted in 2025 took effect on 1 January 2026. Article 23 requires network operators to establish internal rules and responsibility, take technical protective measures, monitor and record network operation and security events, retain network logs for at least six months, and apply measures such as data classification, important-data backup, and encryption. Article 27 adds incident planning, prompt risk handling, remediation, and reporting duties.
A has a separate Article 24 route: meet applicable mandatory national-standard requirements, do not install malicious programs, remediate and report security defects and vulnerabilities, notify users as required, and maintain security support for the required or agreed period. This provider role can apply alongside network-operator duties.
The Network Data Security Management Regulations have applied since 1 January 2025 to network data processing in China. A network data processor is the person or organisation that independently decides the purposes and methods of network data processing. The Regulations add operational detail for security management, incident response, transfers and entrusted processing. They define and require processors to identify and report it under the applicable rules; the relevant region or department then confirms the category by notice or publication.
An important-data processor must appoint a management-level network-data security responsible person and a management body, assess certain provision, entrusted-processing, or joint-processing arrangements before they occur, and complete an annual risk assessment and report. A network data processor handling personal information of more than 10 million people must also follow the Regulations' responsible-person and management-body requirements and its reporting rule for a merger, division, dissolution, or bankruptcy that may affect data security. Article 28 does not extend the separate annual important-data report duty to that threshold by itself.
adds duties only after the relevant infrastructure and operator fall within the CII regime. Articles 36 and 40 require a dedicated security function, personnel measures, disaster-recovery backup, incident exercises, and at least annual security assessment and reporting. Article 37 requires national security review when a CII operator's procurement of network products or services may affect national security. Article 39 applies domestic storage and an outbound-assessment route to personal information and collected or generated through CII operations in China; it is not a statement that every data set held anywhere by the corporate group must remain in China. The Cybersecurity Review Measures separately cover network platform operators' data-processing activities that affect or may affect national security and require a filing before a foreign listing where the operator holds personal information of more than one million users.
Network operators: maintain an Article 27 incident plan, address vulnerabilities and other security risks promptly, activate remediation when an incident occurs, and report as required.
Network product and service providers: apply Article 24 mandatory-standard, malicious-code, vulnerability, user-notice, reporting, and continuing-security-maintenance duties.
: classify data, establish lifecycle security management, train staff, apply technical measures, monitor risks, and respond to incidents under Data Security Law Articles 21, 27, and 29.
Processors of : maintain the responsible person and management body, assess specified third-party processing arrangements, conduct the annual risk assessment, and submit the report required by the Data Security Law and Network Data Security Management Regulations.
Processors handling personal information of more than 10 million people: apply the Regulations' Article 30 governance and Article 32 reorganization or disposition duties, without treating that threshold as automatic classification of all their data as or as an independent annual-report trigger.
operators: implement the additional Article 36 controls, assess security at least annually under Article 40, apply Article 39 to personal information and collected or generated through CII operations in China, and run the procurement review screen before use.
Network platform operators: screen data-processing activities for national-security effects and file before a foreign listing when the operator holds personal information of more than one million users.
and app distribution platforms: apply the 2022 app provisions; a distribution platform must file with the provincial cyberspace administration within 30 days after going online and must verify providers, review apps, manage listings, handle complaints, preserve enforcement records, and report as required.
App sponsors: complete before a new app begins service, display the filing number, and process later changes or cancellation. Keep this record separate from app governance and personal-information compliance.
Connected-product teams: use standards as supporting technical references where applicable, while separately assessing mandatory telecom, radio, app, privacy, and network rules.
Assign each duty to the actor named by the controlling instrument. A company-wide security policy does not show whether the procurement, platform listing, important-data, app-platform filing, or trigger was assessed.
Keep mandatory legal and filing duties separate from recommended standards. A standard mapping can support technical evidence. It does not prove compliance with every applicable law or create an automatic certification duty. The voluntary scheme effective from 1 July 2026 is a separate route governed by product directories and implementation rules.
: identify the applicable national, regional, departmental, industry, or sector catalogue and record the responsible person, management body, periodic assessment, report, incident route, and export analysis.
procurement: determine whether the operator has been identified within the CII regime, then assess before use whether the procurement may affect national security and whether a cybersecurity-review filing is required.
Network platform activity: assess whether data processing affects or may affect national security; separately apply the mandatory filing trigger for a holding personal information of more than one million users that seeks a foreign listing.
App services: apply provider duties under the 2022 app provisions, MIIT app filing for the sponsor, and the provincial cyberspace filing and governance duties for an as separate workstreams.
Connected products: record whether a standard or the voluntary China route is being used, and keep that decision separate from mandatory network, telecom, radio, app, privacy, and product rules.
Reassess when a system boundary, data category, listing plan, procurement, , distribution platform, supplier, or product architecture changes.
Keep evidence showing that the China decision was made before the launch, transfer, filing, procurement, disposal, or product change went live.
Keep the record understandable to an external reviewer: decision owner, official source citation, product, app, data-flow, or vendor identifier, approval date, and the trigger for reopening the decision.
Network and role inventory tied to each system, service, app, platform, product, procurement, and data activity.
Article 23 control map and operating evidence, including samples showing at least six months of network-log retention.
Article 24 product or service security file covering standards, malicious-code controls, vulnerability response, user notices, authority reports, and support period.
Article 27 incident plan, exercises, risk and incident records, remediation, user notices, and required reports.
Important-data screening rationale, responsible person and body, periodic risk assessment and report, incident record, and export decision.
status record, additional controls, annual assessment and report, procurement review screen, supplier commitments, submission, notices, and decision.
MIIT app filing, filing-number display, change or cancellation records, and separate app-provider or distribution-platform governance evidence.
or smart-home standard mapping with the system or product boundary, edition, clauses, tests, exceptions, remediation, and retest evidence.
Keep Personal Information Protection Law processing rights and personal-information export route selection in the privacy guide; keep telecom network access, radio approval, and mobile terminal app removal rules in the telecom and wireless guide.
When one launch triggers several regimes, link the shared facts such as model number, app package, data flow, supplier, or release date, but keep the legal conclusions separate.
Assuming every China technology launch is only a privacy project; network security, app filing, , and review questions may sit outside the Personal Information Protection Law.
Calling a supplier review complete before checking cybersecurity review triggers for procurement or large platform scenarios.
Using one generic security policy as proof of classified protection, important-data, and app-governance compliance.
Use for the voluntary participation rule, directory and implementation-rule structure, testing and filing process, change-triggered refiling, and 1 July 2026 effective date.
Use for cybersecurity review scope, CII procurement filing, platform operator review triggers, review materials, special review, and 15 February 2022 effective date.
Use for current important-data identification, management-body and responsible-person duties, annual important-data risk assessment, third-party processing assessment, and the narrower Article 30 and 32 duties for processors handling more than 10 million people's personal information.
Use for data classification and graded protection, important-data risk assessment, security management, incident response, outbound important-data context, penalties, and 1 September 2021 effective date.