China - Cybersecurity Law (2016)
Cybersecurity Law of the People's Republic of China
中华人民共和国网络安全法
China
RAI-CN-NA-CPRCXXX-2016The Cybersecurity Law (adopted 7 November 2016; effective 1 June 2017; amended 28 October 2025) establishes China’s primary legal framework for protecting network infrastructure, critical information infrastructure (CII), and network data. It imposes obligations on network operators regarding security protection, data handling (including localization for CII), incident reporting, real-name registration and cooperation with public security agencies, and sets penalties for non-compliance.
Summary
Read full text ↗Plain English
Overview
The Cybersecurity Law of the People’s Republic of China is the foundational national law setting out obligations for network security, operation safety, data governance and state supervision in the People’s Republic of China. Adopted by the Standing Committee of the National People’s Congress on 7 November 2016 and promulgated by Presidential Order No. 53, the law came into force on 1 June 2017. It establishes core principles such as cyberspace sovereignty and the coordinated pursuit of informatization and security and creates a layered protection framework (the network security graded protection system) and special treatment for Critical Information Infrastructure (CII). The full official Chinese text and promulgation are available from Chinese government sources such as the Cyberspace Administration of China and the State Council; see the law text at Cyberspace Administration of China - Cybersecurity Law and the presidential promulgation at The State Council / Government of China - Presidential Order No. 53. The law has been supplemented by subordinate regulations, standards and guidance, and was amended by decision of the NPC Standing Committee on 28 October 2025 (effective 1 January 2026); see the amendment announcement at CAC - NPCSC Decision (2025).
Definitions
Key defined or operational terms in the law include: "network" (the infrastructure and systems enabling data exchange and service provision), "network operator" (entities that construct, operate, maintain or use networks), "network product/service providers" (suppliers of hardware, software and services used in networks), "network security" (measures to protect network operation, data confidentiality, integrity and availability), "Critical Information Infrastructure / CII" (infrastructure in sectors where damage would seriously harm national security, economy or public interest, including public communications, energy, transport, water conservancy, finance, public services and e-government), "personal information" and "important data" (terms whose handling is regulated in cooperation with other laws such as the Personal Information Protection Law and Data Security Law). The law sets responsibilities for operators and regulators, and references other laws for detailed definitions of personal information and data categories.
Governance and Institutional Framework
The law assigns central coordination and supervisory roles to national-level institutions and establishes a cross-sector governance model. The principal coordinating body is the national cyberspace authority; sectoral regulators such as the Ministry of Industry and Information Technology (MIIT), public security organs and relevant State Council departments perform duties within their statutory functions. Local governments are charged with implementing network security work within their jurisdictions. The law authorizes national standards-setting, certification and testing frameworks, encourages industry self-regulation and socialized services (testing, certification, risk assessment) and mandates inter-agency cooperation on CII protection and security reviews. Official portals that publish the law and related guidance include the Cyberspace Administration of China (for central cybersecurity policy and implementation guidance) and the central government portal; see CAC - Cybersecurity Law Text and the State Council publication of the promulgation at Government of China - Presidential Order.
Key Focus Areas
The law’s substantive obligations fall into several clusters. First, network operation safety: operators must adopt graded protection measures under the network security graded protection framework (establish security management systems, appoint security officers, apply technical defenses, backup and disaster recovery, and log retention for not less than six months). Second, CII protection: operators of designated CIIs must establish specialized security management institutions, carry out background checks for critical personnel, conduct annual security assessments, and ensure domestic storage of personal information and important data generated or collected within China (with procedures for approved cross-border transfers). Third, product and service security: network products and security-specific products must meet mandatory national standards and pass qualified certification and security testing before sale or supply; vendors must eliminate malicious code, promptly fix detected vulnerabilities and provide continuing security maintenance. Fourth, data governance and personal information control: while the Cybersecurity Law provides high-level requirements (including domestic storage of CII data and procedures for security assessment for cross-border transfers), the detailed rules on personal data protection are coordinated with the Personal Information Protection Law (PIPL) and Data Security Law (DSL). Fifth, incident reporting, monitoring and emergency response: network operators must prepare contingency plans, report major incidents to competent authorities and to affected users, and cooperate in investigations. Sixth, law enforcement cooperation: the law requires technical support and assistance for public security and national security bodies conducting lawful investigations. These thematic obligations are described in the statutory text and in implementing measures published by regulators; see the law text at CAC - Cybersecurity Law and regulatory announcements.
Implementation Framework
Implementation relies on a layered mix of national law, sectoral regulations, standards and administrative measures. The national cybersecurity authority and sectoral ministries issue more detailed rules (for example, regulations on identifying and protecting CII, measures on security certification, and measures for security assessment of cross-border data transfers). The law encourages a market for certified security services (testing, certification, risk assessments) and creates mandatory certification or testing requirements for specified security-sensitive products. CII identification and designation processes are governed by State Council rules, and affected operators are required to complete annual self-assessments and, where necessary, arrange third-party testing or specialized audits. For cross-border data flows, network operators must follow security assessment processes where specified; those processes are implemented in subordinate rulemaking by the Cyberspace Administration and other ministries. The 2025 amendment introduced explicit provisions referencing AI research support and ethical governance to align cybersecurity oversight with emerging AI-related risks; see the amendment notice at CAC - NPCSC Decision (2025).
Monitoring and Evaluation
The law mandates monitoring, logging and incident collection by network operators and authorizes regulators to conduct inspections, assessments and spot-checks. Monitoring includes operational logs (retained a minimum of six months by operators), vulnerability reporting and submission of assessment results for CII operators. Regulators may require rectification orders and can demand technical measures be taken. The law also supports the development of national standards and performance indicators and requires reporting of major incidents to competent authorities. Interagency coordination mechanisms are used for national-level monitoring, early warning and emergency response. Performance evaluation is realized through mandatory certification regimes, periodic assessments for CII and supervisory audits by sectoral regulators and CAC.
Penalties, Liability, and Appeals
The law provides administrative remedies and civil-liability pathways. Competent authorities can order correction, issue warnings, impose fines, suspend business or services, and revoke relevant permits. Article-level penalties were revised under the NPCSC decision of 28 October 2025 which updated prescribed fine ranges for general network operators and for CII operators (see the NPCSC decision at CAC - NPCSC Decision (2025) and the Presidential Order at gov.cn - Presidential Order No. 61). Individuals directly responsible for violations can also be fined. Affected parties have administrative and judicial remedies under PRC administrative procedure and civil litigation rules; appeal and review rights must be pursued according to ordinary administrative procedure law channels.
Relationship to Other Instruments
The Cybersecurity Law operates within a larger legislative ecosystem. It complements and interrelates with: the Personal Information Protection Law (PIPL) for individual data protection, the Data Security Law (DSL) for important data governance and classification, the National Intelligence Law and National Security Law for national-security-related obligations, and sectoral rules (telecommunications, finance, energy) that impose additional controls for critical sectors. Implementing and subsidiary measures (security certification rules, CII identification regulations, cross-border data transfer measures, vulnerability disclosure rules) elaborate the law’s operative obligations. For international businesses and cross-border activities, the Cybersecurity Law’s requirements on localization and security reviews interact closely with PIPL and DSL mechanisms for export and transfer of data across borders.
International Alignment
The law advances a model that emphasizes national cyberspace sovereignty, sectoral CII protection, domestic security review and controlled cross-border data flows. While the law’s goals (network resilience, data security and user protection) align with international cybersecurity objectives, specific measures (data localization for CII, security reviews of product procurement and cross-border transfers) differ in approach from some international data-flow liberalization frameworks. China’s regulatory architecture emphasizes state-oriented security review and extra-territorial controls in certain contexts; international stakeholders should map obligations against other regimes such as the EU’s NIS and GDPR frameworks to identify differences in scope, procedural safeguards and permitted cross-border channels. For official statements and coordination references see the Cyberspace Administration of China and State Council publications, e.g. CAC and the 2025 NPCSC decision at CAC (2025 amendment).
Implementation Timeline
| Event | Date | Reference |
|---|---|---|
| Adoption by NPC Standing Committee | 2016-11-07 | Promulgation (Presidential Order No. 53) |
| Entry into force | 2017-06-01 | Promulgation |
| Major implementing measures and standards (iterative) | 2017–2025 | Various CAC/MIIT/sectoral releases (see Sources) |
| NPCSC amendment adopted | 2025-10-28 | NPCSC Decision (2025) & Presidential Order No. 61 |
| Amendment effective date | 2026-01-01 | Presidential Order |
Compliance Checklist
| Requirement | Action for Operators |
|---|---|
| Graded protection (等级保护) | Classify network systems by grade; implement required technical and management controls. |
| CII identification and obligations | Determine whether designated CII; establish dedicated security management; perform background checks and annual assessments. |
| Log retention | Retain network operation logs (at least six months) and supply logs to authorities when lawfully requested. |
| Data localization for CII | Store personal information and important data collected or produced within China on domestic servers; follow approved procedures for cross-border transfer. |
| Product/service security | Ensure network products meet mandatory national standards; remediate vulnerabilities promptly and notify users and regulators as required. |
| Incident preparedness | Adopt and exercise incident response plans; report major incidents to competent authorities and affected users. |
Sources and References
China's Cybersecurity Law, effective since June 1, 2017, and recently amended, establishes the foundational rules for network security and data protection for virtually any entity operating a network within the country.
This broad law applies to "network operators" – essentially anyone who builds, operates, maintains, or uses networks in China, including companies that supply network products and services. A particularly strict set of requirements applies to "Critical Information Infrastructure" (CII) operators, which include sectors vital to national security and public interest like public communications, energy, finance, and e-government.
Key obligations for these operators include: - Implementing a "graded protection system" based on the importance of their networks, which means establishing robust security management, technical defenses, and retaining network operation logs for at least six months. - CII operators face a significant data localization rule, requiring them to store personal information and "important data" collected in China on servers within the country. Any cross-border transfers of this data require specific security assessments and approvals. - All network products and services must meet mandatory national security standards and pass qualified certification or testing before being sold or supplied. - Operators must also prepare for and report major security incidents, and crucially, provide technical support and assistance to Chinese public security and national security agencies for lawful investigations.
Penalties for non-compliance can be severe, ranging from warnings and fines for both the company and responsible individuals, to the suspension of business or even the revocation of operating permits. The law was updated on October 28, 2025, with amendments effective January 1, 2026, which included revisions to these fine ranges.
A practical pitfall for many international businesses is the law's broad scope and the mandatory requirement to assist Chinese authorities with investigations, which can raise complex questions about data access and sovereignty.
Plain-English rewrite by Regulations.ai — not legal advice. Verify against the official text.
What you must do — compliance checklist
0 / 9 marked completePlain-English obligations under China - Cybersecurity Law (2016). Not legal advice — verify against the official text before relying on it.
- #1Critical⏰ Ongoing
Applies to: Network operators (including those operating AI systems)
“operators must adopt graded protection measures under the network security graded protection framework”
- #2Critical⏰ Ongoing
Applies to: Network operators (including those operating AI systems)
“establish security management systems, appoint security officers”
- #3Critical⏰ Ongoing
Applies to: Network operators (including those operating AI systems)
“log retention for not less than six months”
- #4Critical⏰ Annually
Applies to: Operators of Critical Information Infrastructure (CII), including those operating AI systems designated as CII
“operators of designated CIIs must establish specialized security management institutions, carry out background checks for critical personnel, conduct annual security assessments”
- #5Critical⏰ Ongoing
Applies to: Operators of Critical Information Infrastructure (CII), including those operating AI systems designated as CII
“ensure domestic storage of personal information and important data generated or collected within China”
- #6Critical⏰ Before placing on market
Applies to: Providers of network products and services (including AI systems as products/services)
“network products and security-specific products must meet mandatory national standards and pass qualified certification and security testing”
- #7Critical⏰ Ongoing
Applies to: Providers of network products and services (including AI systems as products/services)
“vendors must eliminate malicious code, promptly fix detected vulnerabilities and provide continuing security maintenance”
- #8Critical⏰ Ongoing
Applies to: Network operators (including those operating AI systems)
“network operators must prepare contingency plans, report major incidents to competent authorities and to affected users”
- #9Critical⏰ Upon request
Applies to: Network operators (including those operating AI systems)
“the law requires technical support and assistance for public security and national security bodies conducting lawful investigations.”
Related Regulations
Data Security Law of the People's Republic of China
China93% similar
Personal Information Protection Law of the People's Republic of China (PIPL)
China91% similar
Regulations on Network Data Security Management (网络数据安全管理条例)
China90% similar
Interim Measures for the Administration of Generative AI Services (Generative AI Services Management Interim Measures)
China89% similar
Cybersecurity Law
Vietnam89% similar
© Regulations.AI — created on 13-Jun-2026