Cybersecurity duties compared: EU, United States and China
How do EU NIS2, US financial security rules and Chinese cybersecurity law compare?
All three regimes ask for measures, an incident report and a named accountable person. They differ in who is covered and how fast the report has to leave the building.
Rows read against the registers 2026-08-26.
European Union
- NIS2 — Directive (EU) 2022/2555, 32022L2555: Covers named essential and important entities, with management accountability and staged incident reporting.
Open the European Union register
United States
- NYDFS Cybersecurity Regulation, 23 NYCRR Part 500: Applies to entities licensed in New York: written programme, CISO reporting and 72 hour notification.
- GLBA Safeguards Rule, 16 CFR Part 314: Requires a written information security programme for financial institutions, with a qualified individual in charge.
Open the United States register
China
- Cybersecurity Law of the People's Republic of China, Cybersecurity Law, adopted 7 November 2016: Sets graded protection duties, network operator obligations and incident response requirements.
- Data Security Law of the People's Republic of China, Data Security Law, adopted 10 June 2021: Classifies data by importance and attaches handling and reporting duties to each class.
What they ask for in common
- All three ask for a written security programme rather than a set of tools.
- All three name a person or a body accountable to management.
- All three require incidents to be reported to an authority within a stated window.
Where they differ
- NIS2 scope follows sector and company size. The US rules follow the licence or the sector.
- China grades the network and the data, which decides the level of the duty.
- Reporting windows differ, so the same incident can carry two clocks at once.
What companies usually do first
- Map which entities in the group are in scope in each jurisdiction.
- Write one incident procedure with the shortest applicable clock at the top.
- Keep the evidence of measures in a form an auditor can read without a walkthrough.
This page describes what the registers say and what is common practice. It is a reading of published sources, not legal advice, and it is not a compliance verdict.
Does this apply to us
- Do cybersecurity rules apply to an online marketplace?
- Do cybersecurity rules apply to an online seller?
- Do cybersecurity rules apply to a manufacturer?
- Do cybersecurity rules apply to an importer?
- Do cybersecurity rules apply to a cloud provider?
Related comparisons
- AI rules compared: EU, United States and China
- Personal data compared: GDPR, CCPA/CPRA and PIPL
- Cross-border data transfers compared: EU, United States and China
- Health data compared: GDPR, HIPAA and PIPL
- Online platform duties compared: EU, United States and China
- Online consumer rights compared: EU and United States
- Product safety and market access compared: EU and China
- Climate and emissions reporting compared: United States and the EU
- Export controls compared: China and the EU market side
ExploreWorldAI is operated by Valkiv Ventures AB (Reg. no. 556995-1311), Kungsgatan 8, 111 43 Stockholm, Sweden. EU-hosted, with data processing assessed against the GDPR. Contact: hello@exploreworldai.com.
Machine-readable summaries for AI agents: /llms.txt and /llms-full.txt.