CybersecurityChina

China Cybersecurity Law cybersecurity and data security requirements

Requirements for network operators, data processors, CII operators, platforms, app providers, and app distribution platforms.

The requirements come from several instruments with different actors. Start with baseline network and data-security duties, then add CII, review, app, filing, export, or recommended-standard work only when its own trigger is met.

Author
Sorena AI
Published
Jul 5, 2026
Updated
Jul 25, 2026
Sections
4

Structured answer sets in this page tree.

Primary sources
10

Cited legal and guidance references.

Publication metadata
Sorena AI
Published Jul 5, 2026
Updated Jul 25, 2026
Overview

Start by identifying whether the entity is a , network product or service provider, network data processor, important-data processor, operator, , app provider, , or . Apply the baseline duty for each role, then add review, filing, export, product-standard, or voluntary-label work only when its separate trigger is met.

Section 1

Requirements by regulated actor

The Cybersecurity Law applies to constructing, operating, maintaining, and using networks in China. Amendments adopted in 2025 took effect on 1 January 2026. Article 23 requires network operators to establish internal rules and responsibility, take technical protective measures, monitor and record network operation and security events, retain network logs for at least six months, and apply measures such as data classification, important-data backup, and encryption. Article 27 adds incident planning, prompt risk handling, remediation, and reporting duties.

A has a separate Article 24 route: meet applicable mandatory national-standard requirements, do not install malicious programs, remediate and report security defects and vulnerabilities, notify users as required, and maintain security support for the required or agreed period. This provider role can apply alongside network-operator duties.

The Network Data Security Management Regulations have applied since 1 January 2025 to network data processing in China. A network data processor is the person or organisation that independently decides the purposes and methods of network data processing. The Regulations add operational detail for security management, incident response, transfers and entrusted processing. They define and require processors to identify and report it under the applicable rules; the relevant region or department then confirms the category by notice or publication.

An important-data processor must appoint a management-level network-data security responsible person and a management body, assess certain provision, entrusted-processing, or joint-processing arrangements before they occur, and complete an annual risk assessment and report. A network data processor handling personal information of more than 10 million people must also follow the Regulations' responsible-person and management-body requirements and its reporting rule for a merger, division, dissolution, or bankruptcy that may affect data security. Article 28 does not extend the separate annual important-data report duty to that threshold by itself.

adds duties only after the relevant infrastructure and operator fall within the CII regime. Articles 36 and 40 require a dedicated security function, personnel measures, disaster-recovery backup, incident exercises, and at least annual security assessment and reporting. Article 37 requires national security review when a CII operator's procurement of network products or services may affect national security. Article 39 applies domestic storage and an outbound-assessment route to personal information and collected or generated through CII operations in China; it is not a statement that every data set held anywhere by the corporate group must remain in China. The Cybersecurity Review Measures separately cover network platform operators' data-processing activities that affect or may affect national security and require a filing before a foreign listing where the operator holds personal information of more than one million users.

  • Network operators: implement Article 23 governance, technical protection, monitoring, log-retention, and data-protection measures.
  • Network operators: maintain an Article 27 incident plan, address vulnerabilities and other security risks promptly, activate remediation when an incident occurs, and report as required.
  • Network product and service providers: apply Article 24 mandatory-standard, malicious-code, vulnerability, user-notice, reporting, and continuing-security-maintenance duties.
  • : classify data, establish lifecycle security management, train staff, apply technical measures, monitor risks, and respond to incidents under Data Security Law Articles 21, 27, and 29.
  • Processors of : maintain the responsible person and management body, assess specified third-party processing arrangements, conduct the annual risk assessment, and submit the report required by the Data Security Law and Network Data Security Management Regulations.
  • Processors handling personal information of more than 10 million people: apply the Regulations' Article 30 governance and Article 32 reorganization or disposition duties, without treating that threshold as automatic classification of all their data as or as an independent annual-report trigger.
  • operators: implement the additional Article 36 controls, assess security at least annually under Article 40, apply Article 39 to personal information and collected or generated through CII operations in China, and run the procurement review screen before use.
  • Network platform operators: screen data-processing activities for national-security effects and file before a foreign listing when the operator holds personal information of more than one million users.
  • and app distribution platforms: apply the 2022 app provisions; a distribution platform must file with the provincial cyberspace administration within 30 days after going online and must verify providers, review apps, manage listings, handle complaints, preserve enforcement records, and report as required.
  • App sponsors: complete before a new app begins service, display the filing number, and process later changes or cancellation. Keep this record separate from app governance and personal-information compliance.
  • Connected-product teams: use standards as supporting technical references where applicable, while separately assessing mandatory telecom, radio, app, privacy, and network rules.
Sources for this answer
Section 2

Apply special triggers independently

Assign each duty to the actor named by the controlling instrument. A company-wide security policy does not show whether the procurement, platform listing, important-data, app-platform filing, or trigger was assessed.

Keep mandatory legal and filing duties separate from recommended standards. A standard mapping can support technical evidence. It does not prove compliance with every applicable law or create an automatic certification duty. The voluntary scheme effective from 1 July 2026 is a separate route governed by product directories and implementation rules.

  • : identify the applicable national, regional, departmental, industry, or sector catalogue and record the responsible person, management body, periodic assessment, report, incident route, and export analysis.
  • procurement: determine whether the operator has been identified within the CII regime, then assess before use whether the procurement may affect national security and whether a cybersecurity-review filing is required.
  • Network platform activity: assess whether data processing affects or may affect national security; separately apply the mandatory filing trigger for a holding personal information of more than one million users that seeks a foreign listing.
  • App services: apply provider duties under the 2022 app provisions, MIIT app filing for the sponsor, and the provincial cyberspace filing and governance duties for an as separate workstreams.
  • Connected products: record whether a standard or the voluntary China route is being used, and keep that decision separate from mandatory network, telecom, radio, app, privacy, and product rules.
  • Reassess when a system boundary, data category, listing plan, procurement, , distribution platform, supplier, or product architecture changes.
Section 3

Evidence to keep before launch or change approval

Keep evidence showing that the China decision was made before the launch, transfer, filing, procurement, disposal, or product change went live.

Keep the record understandable to an external reviewer: decision owner, official source citation, product, app, data-flow, or vendor identifier, approval date, and the trigger for reopening the decision.

  • Network and role inventory tied to each system, service, app, platform, product, procurement, and data activity.
  • Article 23 control map and operating evidence, including samples showing at least six months of network-log retention.
  • Article 24 product or service security file covering standards, malicious-code controls, vulnerability response, user notices, authority reports, and support period.
  • Article 27 incident plan, exercises, risk and incident records, remediation, user notices, and required reports.
  • Important-data screening rationale, responsible person and body, periodic risk assessment and report, incident record, and export decision.
  • status record, additional controls, annual assessment and report, procurement review screen, supplier commitments, submission, notices, and decision.
  • MIIT app filing, filing-number display, change or cancellation records, and separate app-provider or distribution-platform governance evidence.
  • or smart-home standard mapping with the system or product boundary, edition, clauses, tests, exceptions, remediation, and retest evidence.
Section 4

Boundary with nearby China regimes

Keep Personal Information Protection Law processing rights and personal-information export route selection in the privacy guide; keep telecom network access, radio approval, and mobile terminal app removal rules in the telecom and wireless guide.

When one launch triggers several regimes, link the shared facts such as model number, app package, data flow, supplier, or release date, but keep the legal conclusions separate.

  • Assuming every China technology launch is only a privacy project; network security, app filing, , and review questions may sit outside the Personal Information Protection Law.
  • Calling a supplier review complete before checking cybersecurity review triggers for procurement or large platform scenarios.
  • Using one generic security policy as proof of classified protection, important-data, and app-governance compliance.
Primary sources

References and citations

cac.gov.cn
Referenced sections
  • Use for the voluntary participation rule, directory and implementation-rule structure, testing and filing process, change-triggered refiling, and 1 July 2026 effective date.
cac.gov.cn
Referenced sections
  • Use for cybersecurity review scope, CII procurement filing, platform operator review triggers, review materials, special review, and 15 February 2022 effective date.
miit.gov.cn
Referenced sections
  • Supports the separate MIIT app-filing process, verification, filing-number display, and change or cancellation handling.
cac.gov.cn
Referenced sections
  • Use for current important-data identification, management-body and responsible-person duties, annual important-data risk assessment, third-party processing assessment, and the narrower Article 30 and 32 duties for processors handling more than 10 million people's personal information.
cac.gov.cn
Referenced sections
  • Current source for network, product, CII, and personal-information duties and their boundaries with other China regimes.
cac.gov.cn
Referenced sections
  • Use for data classification and graded protection, important-data risk assessment, security management, incident response, outbound important-data context, penalties, and 1 September 2021 effective date.
Related guides

Explore more topics

China App Filing vs Personal Information Rules
Decide whether a China mobile app needs MIIT filing, personal-information controls, or both, with current triggers, duties, dates, and evidence.
China cybersecurity compliance checklist
A China cybersecurity checklist for scoping network duties, data security, CII procurement review, app rules, MIIT filing, and supporting standards.
China cybersecurity deadlines and compliance calendar
Separate China cybersecurity commencement dates from recurring duties, filing lead times, review periods, and event-driven response deadlines.
China Cybersecurity Law FAQ
Practical answers on China network-operator scope, MLPS evidence, important data, cybersecurity review, app filing and governance, and smart-home standards under the law in force from 1 January 2026.
China Cybersecurity Law vs EU Cyber Resilience Act
Compare China's network-operator rules with the EU CRA's product duties, including scope, actors, evidence, reporting dates, and launch decisions.
China Cybersecurity Law vs EU NIS2 Directive
Compare China's network-operator duties with NIS2 entity duties, including scope, management accountability, incident reporting, evidence, and enforcement.
China cybersecurity penalties and fines
Compare current China Cybersecurity Law and Data Security Law fines by actor, breach, severity, and enforcement consequence.
China Cybersecurity Review vs Data Export Assessment
Separate China's cybersecurity-review triggers from CAC data-export assessment triggers, thresholds, filings, evidence, timing, and reapplication rules.
China cybersecurity review workflow
Determine whether CII procurement, platform data processing, or a qualifying foreign listing triggers China's Cybersecurity Review Measures.
China mobile app filing and app governance
Identify the China app sponsor, complete MIIT filing before service, and separate provider, platform, privacy, content, and security duties.
China Smart-Home Security vs Telecom and Radio Approval
Separate GB/T 41387-2022 smart-home security evidence from China telecom network-access and radio approval decisions for connected products.
CII and network operator role triage
How to separate ordinary network operator duties from CII, procurement, and review-risk questions under China cybersecurity sources.
Does an app need MIIT filing and CAC app governance review?
An app sponsor providing internet information services through an app in China must complete MIIT filing. CAC rules separately govern app providers and distribution platforms without creating one routine CAC approval for every app.
GB/T 22239-2019 classified protection baseline
How to scope and document a GB/T 22239-2019 classified protection baseline without treating the recommended standard as a standalone law.
GB/T 41387-2022 smart home security standard
How connected-device teams can scope and document GB/T 41387-2022 without treating it as an automatic certification or product-approval duty.
How do smart home security standards fit with China cybersecurity law?
GB/T 41387-2022 can organize smart-home security evidence, but it is a recommended standard, not a product approval. Check app, data, MLPS, telecom access, and radio requirements separately.
How does important data change China cybersecurity obligations?
Once data is officially identified as important data, the processor needs named governance, periodic risk assessments and reports, incident controls, and a separate export decision. An internal sensitivity label alone does not establish the legal category.
Is every company a network operator under China Cybersecurity Law?
No. Under China's Cybersecurity Law, a network operator is an owner or administrator of a network or a network service provider. Apply that definition to each China network or service, then test CII and other roles separately.
MLPS classified protection evidence map
Classify a China network under MLPS, complete level 2 or above filing, map controls, and retain assessment, remediation, and change evidence.
What is MLPS classified protection evidence?
MLPS evidence shows how a defined China network or system was graded and protected. Keep the scope, grading rationale, filing or assessment records where applicable, control mapping, test results, remediation, and reassessment history.
When does China cybersecurity review apply?
China cybersecurity review applies to CII procurement or network-platform data processing that affects or may affect national security, plus a mandatory pre-filing trigger for certain foreign listings involving more than one million users' personal information.