Cybersecurity Law of the People's Republic of China
Cybersecurity Law of the People's Republic of China (Cybersecurity Law, adopted 7 November 2016) is in force in China. This page holds what the official text states: dates, the named requirements, who supervises it and where the text is published.
- Cybersecurity Law of the People's Republic of China names graded network protection, critical information infrastructure, storage inside china and incident handling.
- Cybersecurity Law of the People's Republic of China does not settle whether a single shipment, transfer or service meets the requirement; that follows from the facts of the case and from the supervising body.
- Supervised by Standing Committee of the National People's Congress, Cyberspace Administration of China and Ministry of Industry and Information Technology. Published by National People's Congress.
- EU: NIS2 — Directive (EU) 2022/2555. Both texts set security duties graded by how critical the entity is.
- US: NYDFS Part 500. Both texts require a written security programme and incident reporting.
Identity
| Name in Chinese | 网络安全法 |
|---|---|
| Identifier | Cybersecurity Law, adopted 7 November 2016 |
| Adopted | 2016-11-07 |
| Applies from | 2017-06-01 |
| Status as published | The law applies since 1 June 2017 and is the base text for network operator duties. |
| Supervision | Standing Committee of the National People's Congress, Cyberspace Administration of China, Ministry of Industry and Information Technology |
| Areas named | Personal data |
| Read against the source | 2026-08-17 |
Requirements in the text
- Graded network protection — Reference: CSL Article 21. Security obligations graded by the classification of the network.
- Critical information infrastructure — Reference: CSL Article 31. Extra duties for operators of infrastructure named as critical.
- Storage inside China — Reference: CSL Article 37. Personal information and important data of CII operators stored inside China.
- Incident handling — Reference: CSL Article 25. Emergency plan, reporting and remedial measures after a security incident.
Compared with the EU register
- NIS2 — Directive (EU) 2022/2555: Both texts set security duties graded by how critical the entity is.
Compared with the US register
- NYDFS Part 500: Both texts require a written security programme and incident reporting.
Official sources
- 中华人民共和国网络安全法 — National People's Congress
The register states what the official texts say. It is not advice and it is not a verdict on any company.
ExploreWorldAI is operated by Valkiv Ventures AB (Reg. no. 556995-1311), Kungsgatan 8, 111 43 Stockholm, Sweden. EU-hosted, with data processing assessed against the GDPR. Contact: hello@exploreworldai.com.
Machine-readable summaries for AI agents: /llms.txt and /llms-full.txt.