---
title: "China cybersecurity and data security requirements"
canonical_url: "https://www.sorena.io/artifacts/apac/china-cybersecurity-law/requirements"
source_url: "https://www.sorena.io/artifacts/apac/china-cybersecurity-law/requirements"
author: "Sorena AI"
description: "China cybersecurity requirements by actor: network operators, data processors, CII operators, platforms, app providers, and distribution platforms."
published_at: "2026-07-05"
updated_at: "2026-07-25"
keywords:
  - "China Cybersecurity Law"
  - "Data Security Law"
  - "Cybersecurity Review Measures"
  - "Mobile app filing"
  - "MLPS"
---
**[SORENA](https://www.sorena.io/)** - AI-Powered GRC Platform

[Home](https://www.sorena.io/) | [Solutions](https://www.sorena.io/solutions) | [Artifacts](https://www.sorena.io/artifacts) | [About Us](https://www.sorena.io/about-us) | [Contact](https://www.sorena.io/contact) | [Portal](https://app.sorena.io)

---

# China cybersecurity and data security requirements

China cybersecurity requirements by actor: network operators, data processors, CII operators, platforms, app providers, and distribution platforms.

*Cybersecurity* *China*

## China Cybersecurity Law cybersecurity and data security requirements

Requirements for network operators, data processors, CII operators, platforms, app providers, and app distribution platforms.

The requirements come from several instruments with different actors. Start with baseline network and data-security duties, then add CII, review, app, filing, export, or recommended-standard work only when its own trigger is met.

Start by identifying whether the entity is a network operator, network product or service provider, network data processor, important-data processor, CII operator, network platform operator, app provider, app distribution platform, or app sponsor. Apply the baseline duty for each role, then add review, filing, export, product-standard, or voluntary-label work only when its separate trigger is met.

## Definitions

### Network operator

Article 78 of the current Cybersecurity Law defines a network operator as the owner or administrator of a network or a network service provider. A network is a system of computers or other information terminals and related equipment that collects, stores, transmits, exchanges, or processes information under defined rules and procedures. The definition is broader than telecommunications carriers and public online platforms.

**Why it matters here:** The network operator is responsible for the Article 23 classified-protection baseline and Article 27 incident duties for the relevant network. Identify the system and operating role before assigning the requirements.

Sources:

- [PRC Cybersecurity Law, Articles 23, 27, and 78](https://www.cac.gov.cn/2025-12/29/c_1768735112911946.htm?ref=sorena.io)

### Critical information infrastructure

**Term:** CII

CII includes infrastructure in important sectors such as public communications and information services, energy, transport, water, finance, public services, and e-government, plus other infrastructure whose damage, loss of function, or data leakage could seriously harm national security, the national economy and people's livelihood, or the public interest. The competent protection department identifies CII under the applicable rules.

**Why it matters here:** CII status adds duties for a dedicated security function, key-personnel checks, training, disaster-recovery backup, exercises, annual assessment, domestic storage and export controls, and procurement review. It should not be inferred solely from network-operator status or sector name.

Sources:

- [PRC Cybersecurity Law, Articles 33-40](https://www.cac.gov.cn/2025-12/29/c_1768735112911946.htm?ref=sorena.io)

### Important data

Important data is data in a specific field, for a specific group or region, or reaching a specified precision or scale that, if tampered with, destroyed, leaked, illegally obtained, or illegally used, may directly endanger national security, economic operation, social stability, public health, or public safety. Relevant regions and departments identify it through specific catalogues and notification or publication; it is not a synonym for all personal information, sensitive information, or commercially valuable data.

**Why it matters here:** Processors of confirmed important data must designate a network-data security responsible person and management body, conduct periodic risk assessments, and submit reports describing the data, processing, risks, controls, and transfers. Data export requires a separate legal analysis.

Sources:

- [PRC Data Security Law, Articles 21 and 27-31](https://www.cac.gov.cn/2021-06/11/c_1624994566919140.htm?ref=sorena.io)
- [Network Data Security Management Regulations, Articles 29-33 and 62](https://www.cac.gov.cn/2024-09/30/c_1729384452307680.htm?ref=sorena.io)

### Network platform operator under the Cybersecurity Review Measures

**Term:** network platform operator

The Cybersecurity Review Measures apply to a network platform operator's data-processing activities when they affect or may affect national security. They also create a specific filing trigger when such an operator holds personal information of more than one million users and seeks a foreign listing. Other online services and overseas corporate events require their own trigger analysis.

**Why it matters here:** Document the platform role, data-processing activity, user count, listing destination, and national-security risk analysis. If the specific foreign-listing trigger is met, file before the listing and retain the required materials and written decision.

Sources:

- [Cybersecurity Review Measures, Articles 2 and 7-10](https://www.cac.gov.cn/2022-01/04/c_1642894602182845.htm?ref=sorena.io)

### Mobile app distribution platform

**Term:** app distribution platform

Under the 2022 app provisions, an app distribution platform is an internet information service provider that publishes mobile apps or provides download or dynamic-loading distribution services. It verifies providers, reviews new and updated apps, manages listed apps, handles complaints and violations, and files with its provincial cyberspace administration within 30 days after the platform goes online.

**Why it matters here:** This platform filing and governance role is separate from MIIT app filing for the sponsor of an app-based internet information service. A business that operates both an app and a distribution platform must assess and evidence both roles.

Sources:

- [Mobile Internet Application Information Service Management Provisions, Articles 17-22 and 26](https://www.cac.gov.cn/2022-06/14/c_1656821626455324.htm?ref=sorena.io)
- [MIIT notice on mobile app filing work](https://www.miit.gov.cn/zwgk/zcwj/wjfb/tz/art/2023/art_920db564162e4312916a01bed6540ad8.html?ref=sorena.io)

### Network product and service provider

A network product and service provider supplies a product or service used to build, operate, maintain, or use a network. Article 24 requires the product or service to meet applicable mandatory national-standard requirements, prohibits malicious programs, and requires prompt remediation, user notice, authority reporting, and continuing security maintenance when security defects or vulnerabilities are found.

**Why it matters here:** This provider role is separate from the network operator that owns or administers a network or provides a network service, although one organisation may hold both roles. Keep product vulnerability, notice, reporting, and support-period evidence apart from the operator's Article 23 and 27 records.

Sources:

- [PRC Cybersecurity Law, Articles 11, 24, and 78](https://www.cac.gov.cn/2025-12/29/c_1768735112911946.htm?ref=sorena.io)

### Ministry of Industry and Information Technology app filing

**Term:** MIIT filing

MIIT filing is the filing for an app sponsor providing an app-based internet information service in China. A new covered app files before service begins through a network access provider or app distribution platform to the provincial communications administration for the sponsor's place of residence. The sponsor displays the filing number and query link and files later changes or cancellation.

**Why it matters here:** This sponsor filing is separate from app-provider operating duties and from the provincial cyberspace filing that an app distribution platform completes within 30 days after going online.

Sources:

- [MIIT notice on mobile app filing work](https://www.miit.gov.cn/zwgk/zcwj/wjfb/tz/art/2023/art_920db564162e4312916a01bed6540ad8.html?ref=sorena.io)
- [Mobile Internet Application Information Service Management Provisions, Article 17](https://www.cac.gov.cn/2022-06/14/c_1656821626455324.htm?ref=sorena.io)

### Recommended Chinese national standard designation

**Term:** GB/T

GB/T is the designation used for a recommended Chinese national standard. The official standards system lists recommended national standards separately from mandatory national standards. A GB/T standard can support a technical design, assessment, procurement, or contract, but the designation does not itself make the standard a statute or create automatic certification for every system or product.

**Why it matters here:** Record the exact standard number and edition, the system or product boundary, the basis for using it, the clauses applied, and the evidence and test results. Assess mandatory legal, approval, filing, and product routes separately.

Sources:

- [Official national standards record for GB/T 22239-2019](https://openstd.samr.gov.cn/bzgk/gb/newGbInfo?hcno=BAFB47E8874764186BDB7865E8344DAF&ref=sorena.io)
- [Official national standards record for GB/T 41387-2022](https://openstd.samr.gov.cn/bzgk/gb/newGbInfo?hcno=B1C14E854C0BA30D1C29FC376299761A&ref=sorena.io)

### China Cybersecurity Label

**Term:** cybersecurity label

The China Cybersecurity Label is a voluntary product label under measures effective 1 July 2026. It is available for internet-connected products through product directories and product-specific implementation rules. The rules define the applicable security requirements and one-, two-, or three-star capability level, testing, filing, label content, validity, and refiling conditions.

**Why it matters here:** A producer participates voluntarily but must follow the applicable implementation rule if it uses the label. The route is separate from GB/T mapping and from mandatory network, telecom, radio, app, privacy, or product requirements.

Sources:

- [Cybersecurity Label Administrative Measures](https://www.cac.gov.cn/2026-04/10/c_1777558393316312.htm?ref=sorena.io)

### Multi-Level Protection Scheme

**Term:** MLPS

MLPS is a common English label for China's network security classified-protection system. Article 23 of the current Cybersecurity Law places baseline classified-protection duties on network operators. GB/T 22239-2019 is a recommended national baseline standard used within that wider system.

**Why it matters here:** Define the network, operator, system boundary, classification method and level, rules, standard edition, controls, and tests. MLPS classification does not determine CII, important-data, cybersecurity-review, privacy, or app-filing status.

Sources:

- [PRC Cybersecurity Law, Articles 23 and 78](https://www.cac.gov.cn/2025-12/29/c_1768735112911946.htm?ref=sorena.io)
- [Official national standards record for GB/T 22239-2019](https://openstd.samr.gov.cn/bzgk/gb/newGbInfo?hcno=BAFB47E8874764186BDB7865E8344DAF&ref=sorena.io)

### App sponsor for MIIT filing

**Term:** app sponsor

The app sponsor is the organisation or individual providing the app-based internet information service and named in the MIIT filing. It supplies truthful identity, network-resource, service, approval, and contact information, displays the filing number and query link, and files changes or cancellation.

**Why it matters here:** Confirm the filed legal entity instead of assuming that the developer, brand owner, app provider, access provider, or distribution platform is the sponsor. One entity may hold several roles, but each role needs its own record.

Sources:

- [MIIT notice on mobile app filing work](https://www.miit.gov.cn/zwgk/zcwj/wjfb/tz/art/2023/art_920db564162e4312916a01bed6540ad8.html?ref=sorena.io)

### Mobile app provider

**Term:** App providers

A mobile app provider is the owner or operator of a mobile app that provides information services. Under the 2022 app provisions, the provider has role-specific duties for content, user identity in specified services, required licences, security defects, data and personal information, minors, management rules, user enforcement, complaints, and cooperation with supervision.

**Why it matters here:** This operating role is separate from the app sponsor named in the MIIT filing and from the app distribution platform. One entity may hold more than one role and must retain evidence for each.

Sources:

- [Mobile Internet Application Information Service Management Provisions, Articles 5-16 and 26](https://www.cac.gov.cn/2022-06/14/c_1656821626455324.htm?ref=sorena.io)

### Data processor under the Data Security Law

**Term:** Data processors

The Data Security Law applies to data-processing activities, which include the collection, storage, use, processing, transmission, provision, and disclosure of data. A data processor is the actor carrying out those activities and must establish lifecycle security management, organise training, take technical and other measures, monitor risks, and respond to incidents.

**Why it matters here:** Identify the legal entity and the specific data-processing activity. If important data is involved, add the responsible person and management body, periodic risk assessment and report, incident route, and export analysis.

Sources:

- [PRC Data Security Law, Articles 3, 27, 29, and 30](https://www.cac.gov.cn/2021-06/11/c_1624994566919140.htm?ref=sorena.io)

## Requirements by regulated actor

The Cybersecurity Law applies to constructing, operating, maintaining, and using networks in China. Amendments adopted in 2025 took effect on 1 January 2026. Article 23 requires network operators to establish internal rules and responsibility, take technical protective measures, monitor and record network operation and security events, retain network logs for at least six months, and apply measures such as data classification, important-data backup, and encryption. Article 27 adds incident planning, prompt risk handling, remediation, and reporting duties.

A network product and service provider has a separate Article 24 route: meet applicable mandatory national-standard requirements, do not install malicious programs, remediate and report security defects and vulnerabilities, notify users as required, and maintain security support for the required or agreed period. This provider role can apply alongside network-operator duties.

The Network Data Security Management Regulations have applied since 1 January 2025 to network data processing in China. A network data processor is the person or organisation that independently decides the purposes and methods of network data processing. The Regulations add operational detail for security management, incident response, transfers and entrusted processing. They define important data and require processors to identify and report it under the applicable rules; the relevant region or department then confirms the category by notice or publication.

An important-data processor must appoint a management-level network-data security responsible person and a management body, assess certain provision, entrusted-processing, or joint-processing arrangements before they occur, and complete an annual risk assessment and report. A network data processor handling personal information of more than 10 million people must also follow the Regulations' responsible-person and management-body requirements and its reporting rule for a merger, division, dissolution, or bankruptcy that may affect data security. Article 28 does not extend the separate annual important-data report duty to that threshold by itself.

CII adds duties only after the relevant infrastructure and operator fall within the CII regime. Articles 36 and 40 require a dedicated security function, personnel measures, disaster-recovery backup, incident exercises, and at least annual security assessment and reporting. Article 37 requires national security review when a CII operator's procurement of network products or services may affect national security. Article 39 applies domestic storage and an outbound-assessment route to personal information and important data collected or generated through CII operations in China; it is not a statement that every data set held anywhere by the corporate group must remain in China. The Cybersecurity Review Measures separately cover network platform operators' data-processing activities that affect or may affect national security and require a filing before a foreign listing where the operator holds personal information of more than one million users.

- Network operators: implement Article 23 governance, technical protection, monitoring, log-retention, and data-protection measures.
- Network operators: maintain an Article 27 incident plan, address vulnerabilities and other security risks promptly, activate remediation when an incident occurs, and report as required.
- Network product and service providers: apply Article 24 mandatory-standard, malicious-code, vulnerability, user-notice, reporting, and continuing-security-maintenance duties.
- Data processors: classify data, establish lifecycle security management, train staff, apply technical measures, monitor risks, and respond to incidents under Data Security Law Articles 21, 27, and 29.
- Processors of important data: maintain the responsible person and management body, assess specified third-party processing arrangements, conduct the annual risk assessment, and submit the report required by the Data Security Law and Network Data Security Management Regulations.
- Processors handling personal information of more than 10 million people: apply the Regulations' Article 30 governance and Article 32 reorganization or disposition duties, without treating that threshold as automatic classification of all their data as important data or as an independent annual-report trigger.
- CII operators: implement the additional Article 36 controls, assess security at least annually under Article 40, apply Article 39 to personal information and important data collected or generated through CII operations in China, and run the procurement review screen before use.
- Network platform operators: screen data-processing activities for national-security effects and file before a foreign listing when the operator holds personal information of more than one million users.
- App providers and app distribution platforms: apply the 2022 app provisions; a distribution platform must file with the provincial cyberspace administration within 30 days after going online and must verify providers, review apps, manage listings, handle complaints, preserve enforcement records, and report as required.
- App sponsors: complete MIIT filing before a new app begins service, display the filing number, and process later changes or cancellation. Keep this record separate from app governance and personal-information compliance.
- Connected-product teams: use GB/T standards as supporting technical references where applicable, while separately assessing mandatory telecom, radio, app, privacy, and network rules.

Sources for this answer:

- [PRC Cybersecurity Law, current text](https://www.cac.gov.cn/2025-12/29/c_1768735112911946.htm?ref=sorena.io) - Official consolidated text; Articles 23, 24, 27, 33-40, and 78 support the network-operator, product-provider, incident, CII, annual-assessment, procurement-review, and actor requirements.
- [NPC report on adoption of the PRC Cybersecurity Law amendment](https://www.npc.gov.cn/npc/c2/c30834/202510/t20251028_449076.html?ref=sorena.io) - Official report confirming adoption on 28 October 2025 and entry into force on 1 January 2026.
- [PRC Data Security Law](https://www.cac.gov.cn/2021-06/11/c_1624994566919140.htm?ref=sorena.io) - Use for data classification and graded protection, important-data risk assessment, security management, incident response, outbound important-data context, penalties, and 1 September 2021 effective date.
- [Network Data Security Management Regulations](https://www.cac.gov.cn/2024-09/30/c_1729384452307680.htm?ref=sorena.io) - Official regulations effective 1 January 2025; use for the network-data-processor role, important-data definition and identification, governance, third-party processing assessment, annual important-data risk assessment, and the narrower duties imported by the 10-million-personal-information threshold.
- [Cybersecurity Review Measures](https://www.cac.gov.cn/2022-01/04/c_1642894602182845.htm?ref=sorena.io) - Use for cybersecurity review scope, CII procurement filing, platform operator review triggers, review materials, special review, and 15 February 2022 effective date.
- [Mobile Internet Application Information Service Management Provisions](https://www.cac.gov.cn/2022-06/14/c_1656821626455324.htm?ref=sorena.io) - Supports app-provider and distribution-platform duties, including platform filing within 30 days after going online.
- [MIIT notice on mobile app filing work](https://www.miit.gov.cn/zwgk/zcwj/wjfb/tz/art/2023/art_920db564162e4312916a01bed6540ad8.html?ref=sorena.io) - Supports the separate MIIT app-filing process, verification, filing-number display, and change or cancellation handling.

## Apply special triggers independently

Assign each duty to the actor named by the controlling instrument. A company-wide security policy does not show whether the CII procurement, platform listing, important-data, app-platform filing, or MIIT filing trigger was assessed.

Keep mandatory legal and filing duties separate from recommended GB/T standards. A standard mapping can support technical evidence. It does not prove compliance with every applicable law or create an automatic certification duty. The voluntary cybersecurity label scheme effective from 1 July 2026 is a separate route governed by product directories and implementation rules.

- Important data: identify the applicable national, regional, departmental, industry, or sector catalogue and record the responsible person, management body, periodic assessment, report, incident route, and export analysis.
- CII procurement: determine whether the operator has been identified within the CII regime, then assess before use whether the procurement may affect national security and whether a cybersecurity-review filing is required.
- Network platform activity: assess whether data processing affects or may affect national security; separately apply the mandatory filing trigger for a network platform operator holding personal information of more than one million users that seeks a foreign listing.
- App services: apply provider duties under the 2022 app provisions, MIIT app filing for the sponsor, and the provincial cyberspace filing and governance duties for an app distribution platform as separate workstreams.
- Connected products: record whether a GB/T standard or the voluntary China Cybersecurity Label route is being used, and keep that decision separate from mandatory network, telecom, radio, app, privacy, and product rules.
- Reassess when a system boundary, data category, listing plan, procurement, app sponsor, distribution platform, supplier, or product architecture changes.

Sources for this answer:

- [PRC Cybersecurity Law, current text](https://www.cac.gov.cn/2025-12/29/c_1768735112911946.htm?ref=sorena.io) - Use Articles 23, 24, 27, and 33-40 for baseline, product, incident, CII, annual-assessment, storage, export, and procurement requirements.
- [PRC Data Security Law](https://www.cac.gov.cn/2021-06/11/c_1624994566919140.htm?ref=sorena.io) - Use for data classification and graded protection, important-data risk assessment, security management, incident response, outbound important-data context, penalties, and 1 September 2021 effective date.
- [Network Data Security Management Regulations](https://www.cac.gov.cn/2024-09/30/c_1729384452307680.htm?ref=sorena.io) - Use for current important-data identification, management-body and responsible-person duties, annual important-data risk assessment, third-party processing assessment, and the narrower Article 30 and 32 duties for processors handling more than 10 million people's personal information.
- [Cybersecurity Review Measures](https://www.cac.gov.cn/2022-01/04/c_1642894602182845.htm?ref=sorena.io) - Use for cybersecurity review scope, CII procurement filing, platform operator review triggers, review materials, special review, and 15 February 2022 effective date.
- [Cybersecurity Label Administrative Measures](https://www.cac.gov.cn/2026-04/10/c_1777558393316312.htm?ref=sorena.io) - Use for the voluntary participation rule, directory and implementation-rule structure, testing and filing process, change-triggered refiling, and 1 July 2026 effective date.

## Evidence to keep before launch or change approval

Keep evidence showing that the China decision was made before the launch, transfer, filing, procurement, disposal, or product change went live.

Keep the record understandable to an external reviewer: decision owner, official source citation, product, app, data-flow, or vendor identifier, approval date, and the trigger for reopening the decision.

- Network and role inventory tied to each system, service, app, platform, product, procurement, and data activity.
- Article 23 control map and operating evidence, including samples showing at least six months of network-log retention.
- Article 24 product or service security file covering standards, malicious-code controls, vulnerability response, user notices, authority reports, and support period.
- Article 27 incident plan, exercises, risk and incident records, remediation, user notices, and required reports.
- Important-data screening rationale, responsible person and body, periodic risk assessment and report, incident record, and export decision.
- CII status record, additional controls, annual assessment and report, procurement review screen, supplier commitments, submission, notices, and decision.
- MIIT app filing, filing-number display, change or cancellation records, and separate app-provider or distribution-platform governance evidence.
- MLPS or smart-home standard mapping with the system or product boundary, edition, clauses, tests, exceptions, remediation, and retest evidence.

Sources for this answer:

- [PRC Cybersecurity Law, current text](https://www.cac.gov.cn/2025-12/29/c_1768735112911946.htm?ref=sorena.io) - Current source for network-operation, product-provider, incident, CII, annual-assessment, and procurement evidence.
- [PRC Data Security Law](https://www.cac.gov.cn/2021-06/11/c_1624994566919140.htm?ref=sorena.io) - Use for data classification and graded protection, important-data risk assessment, security management, incident response, outbound important-data context, penalties, and 1 September 2021 effective date.

## Boundary with nearby China regimes

Keep Personal Information Protection Law processing rights and personal-information export route selection in the privacy guide; keep telecom network access, radio approval, and mobile terminal app removal rules in the telecom and wireless guide.

When one launch triggers several regimes, link the shared facts such as model number, app package, data flow, supplier, or release date, but keep the legal conclusions separate.

- Assuming every China technology launch is only a privacy project; network security, app filing, MLPS, and review questions may sit outside the Personal Information Protection Law.
- Calling a supplier review complete before checking cybersecurity review triggers for CII procurement or large platform scenarios.
- Using one generic security policy as proof of classified protection, important-data, and app-governance compliance.

Sources for this answer:

- [PRC Cybersecurity Law, current text](https://www.cac.gov.cn/2025-12/29/c_1768735112911946.htm?ref=sorena.io) - Current source for network, product, CII, and personal-information duties and their boundaries with other China regimes.
- [PRC Data Security Law](https://www.cac.gov.cn/2021-06/11/c_1624994566919140.htm?ref=sorena.io) - Use for data classification and graded protection, important-data risk assessment, security management, incident response, outbound important-data context, penalties, and 1 September 2021 effective date.

*Apply the requirement*

*Placement: Before primary sources*

## Build the China network security evidence file

Separate Article 23, Article 24, data-security, CII, review, app-filing, and product-standard duties by actor and trigger.

- [Map official sources to evidence](/solutions/research-copilot.md): Connect each regulated actor and trigger to the controlling article, operating evidence, filing or review result, and reassessment event.
- [Review the China route](/contact.md): Check the China Cybersecurity Law scope decision and unresolved launch questions with Sorena.

## Primary sources

- [PRC Cybersecurity Law, current text](https://www.cac.gov.cn/2025-12/29/c_1768735112911946.htm?ref=sorena.io) - Official consolidated text; use Articles 23-27, 33-40, and 78 for network, product, incident, CII, procurement, annual-assessment, and actor requirements.
- [PRC Data Security Law](https://www.cac.gov.cn/2021-06/11/c_1624994566919140.htm?ref=sorena.io) - Use for data classification and graded protection, important-data risk assessment, security management, incident response, outbound important-data context, penalties, and 1 September 2021 effective date.
- [Network Data Security Management Regulations](https://www.cac.gov.cn/2024-09/30/c_1729384452307680.htm?ref=sorena.io) - Current regulations effective 1 January 2025 for network data processing, important-data identification and governance, annual important-data risk assessment, third-party processing assessment, and the narrower duties triggered by processing more than 10 million people's personal information.
- [Cybersecurity Review Measures](https://www.cac.gov.cn/2022-01/04/c_1642894602182845.htm?ref=sorena.io) - Use for cybersecurity review scope, CII procurement filing, platform operator review triggers, review materials, special review, and 15 February 2022 effective date.
- [Mobile Internet Application Information Service Management Provisions](https://www.cac.gov.cn/2022-06/14/c_1656821626455324.htm?ref=sorena.io) - Use for app provider and app distribution platform governance, content/security/data duties, platform filing and verification, and 1 August 2022 effective date.
- [MIIT notice on mobile app filing work](https://www.miit.gov.cn/zwgk/zcwj/wjfb/tz/art/2023/art_920db564162e4312916a01bed6540ad8.html?ref=sorena.io) - Use for MIIT mobile app filing phases, registration, supervision, normalization, and operational filing evidence.
- [GB/T 22239 classified protection baseline requirements](https://openstd.samr.gov.cn/bzgk/gb/newGbInfo?hcno=BAFB47E8874764186BDB7865E8344DAF&ref=sorena.io) - Use as the MLPS/classified protection baseline standard reference for control evidence mapping and the 1 December 2019 implementation date.
- [GB/T smart home general security specification](https://openstd.samr.gov.cn/bzgk/gb/newGbInfo?hcno=B1C14E854C0BA30D1C29FC376299761A&ref=sorena.io) - Use as the smart-home security specification reference for connected appliance evidence mapping and the 1 November 2022 implementation date.
- [Cybersecurity Label Administrative Measures](https://www.cac.gov.cn/2026-04/10/c_1777558393316312.htm?ref=sorena.io) - Use for voluntary participation, the product-directory and implementation-rule model, testing and filing, and the 1 July 2026 effective date.

## Related Topic Guides

- [China App Filing vs Personal Information Rules](/artifacts/apac/china-cybersecurity-law/mobile-app-filing-vs-app-personal-information-rules.md): Decide whether a China mobile app needs MIIT filing, personal-information controls, or both, with current triggers, duties, dates, and evidence.
- [China cybersecurity compliance checklist](/artifacts/apac/china-cybersecurity-law/checklist.md): A China cybersecurity checklist for scoping network duties, data security, CII procurement review, app rules, MIIT filing, and supporting standards.
- [China cybersecurity deadlines and compliance calendar](/artifacts/apac/china-cybersecurity-law/deadlines-and-compliance-calendar.md): Separate China cybersecurity commencement dates from recurring duties, filing lead times, review periods, and event-driven response deadlines.
- [China Cybersecurity Law FAQ](/artifacts/apac/china-cybersecurity-law/faq.md): Practical answers on China network-operator scope, MLPS evidence, important data, cybersecurity review, app filing and governance, and smart-home standards under the law in force from 1 January 2026.
- [China Cybersecurity Law vs EU Cyber Resilience Act](/artifacts/apac/china-cybersecurity-law/china-cybersecurity-law-vs-eu-cyber-resilience-act.md): Compare China's network-operator rules with the EU CRA's product duties, including scope, actors, evidence, reporting dates, and launch decisions.
- [China Cybersecurity Law vs EU NIS2 Directive](/artifacts/apac/china-cybersecurity-law/china-cybersecurity-law-vs-nis2.md): Compare China's network-operator duties with NIS2 entity duties, including scope, management accountability, incident reporting, evidence, and enforcement.
- [China cybersecurity penalties and fines](/artifacts/apac/china-cybersecurity-law/penalties-and-fines.md): Compare current China Cybersecurity Law and Data Security Law fines by actor, breach, severity, and enforcement consequence.
- [China Cybersecurity Review vs Data Export Assessment](/artifacts/apac/china-cybersecurity-law/cybersecurity-review-vs-data-export-security-assessment.md): Separate China's cybersecurity-review triggers from CAC data-export assessment triggers, thresholds, filings, evidence, timing, and reapplication rules.
- [China cybersecurity review workflow](/artifacts/apac/china-cybersecurity-law/cybersecurity-review-workflow.md): Determine whether CII procurement, platform data processing, or a qualifying foreign listing triggers China's Cybersecurity Review Measures.
- [China mobile app filing and app governance](/artifacts/apac/china-cybersecurity-law/mobile-app-filing-and-app-governance.md): Identify the China app sponsor, complete MIIT filing before service, and separate provider, platform, privacy, content, and security duties.
- [China Smart-Home Security vs Telecom and Radio Approval](/artifacts/apac/china-cybersecurity-law/smart-home-security-vs-telecom-wireless-launch.md): Separate GB/T 41387-2022 smart-home security evidence from China telecom network-access and radio approval decisions for connected products.
- [CII and network operator role triage](/artifacts/apac/china-cybersecurity-law/critical-information-infrastructure-and-network-operators.md): How to separate ordinary network operator duties from CII, procurement, and review-risk questions under China cybersecurity sources.
- [Does an app need MIIT filing and CAC app governance review?](/artifacts/apac/china-cybersecurity-law/faq/does-an-app-need-miit-filing-and-cac-app-governance-review.md): An app sponsor providing internet information services through an app in China must complete MIIT filing. CAC rules separately govern app providers and distribution platforms without creating one routine CAC approval for every app.
- [GB/T 22239-2019 classified protection baseline](/artifacts/apac/china-cybersecurity-law/classified-protection-baseline.md): How to scope and document a GB/T 22239-2019 classified protection baseline without treating the recommended standard as a standalone law.
- [GB/T 41387-2022 smart home security standard](/artifacts/apac/china-cybersecurity-law/smart-home-security-standard.md): How connected-device teams can scope and document GB/T 41387-2022 without treating it as an automatic certification or product-approval duty.
- [How do smart home security standards fit with China cybersecurity law?](/artifacts/apac/china-cybersecurity-law/faq/how-do-smart-home-security-standards-fit-with-china-cybersecurity-law.md): GB/T 41387-2022 can organize smart-home security evidence, but it is a recommended standard, not a product approval. Check app, data, MLPS, telecom access, and radio requirements separately.
- [How does important data change China cybersecurity obligations?](/artifacts/apac/china-cybersecurity-law/faq/how-does-important-data-change-cybersecurity-obligations.md): Once data is officially identified as important data, the processor needs named governance, periodic risk assessments and reports, incident controls, and a separate export decision. An internal sensitivity label alone does not establish the legal category.
- [Is every company a network operator under China Cybersecurity Law?](/artifacts/apac/china-cybersecurity-law/faq/is-every-company-a-network-operator-under-china-cybersecurity-law.md): No. Under China's Cybersecurity Law, a network operator is an owner or administrator of a network or a network service provider. Apply that definition to each China network or service, then test CII and other roles separately.
- [MLPS classified protection evidence map](/artifacts/apac/china-cybersecurity-law/mlps-classified-protection-evidence-map.md): Classify a China network under MLPS, complete level 2 or above filing, map controls, and retain assessment, remediation, and change evidence.
- [What is MLPS classified protection evidence?](/artifacts/apac/china-cybersecurity-law/faq/what-is-mlps-classified-protection-evidence.md): MLPS evidence shows how a defined China network or system was graded and protected. Keep the scope, grading rationale, filing or assessment records where applicable, control mapping, test results, remediation, and reassessment history.
- [When does China cybersecurity review apply?](/artifacts/apac/china-cybersecurity-law/faq/when-does-china-cybersecurity-review-apply.md): China cybersecurity review applies to CII procurement or network-platform data processing that affects or may affect national security, plus a mandatory pre-filing trigger for certain foreign listings involving more than one million users' personal information.


---

[Privacy Policy](https://www.sorena.io/privacy.md) | [Terms of Use](https://www.sorena.io/terms-of-use.md) | [DMCA](https://www.sorena.io/dmca.md) | [About Us](https://www.sorena.io/about-us.md)

(c) 2026 Sorena AB (559573-7338). All rights reserved.

Source: https://www.sorena.io/artifacts/apac/china-cybersecurity-law/requirements.md
