Cybersecurity 2026

CHINA Law and Practice Contributed by: Kate Yin, Sherman Deng, Yanjun Zhuang and Daniel Wang, Fangda Partners

Administration (NFRA), regulating banks and insur - ance companies, the People’s Bank of China (PBOC) regulating banks and payment agencies, and China Securities Regulatory Commission (CSRC), regulating security brokers and mutual funds. They have formu - lated appropriate sectoral rules on cybersecurity and data protection, such as the Administrative Measures on Data Security in the Business Scope of the Peo - ple’s Bank of China, the Administrative Measures on Data Security for Banking and Insurance Institutions, and the Measures for the Administration of Cyberse - curity and Information Security in the Securities and Futures Industry. 2. Critical Infrastructure Cybersecurity Regulation 2.1 Scope of Critical Infrastructure Cybersecurity Regulation In China, the framework of CII is primarily built upon a hierarchical structure of the CSL, CIIO Regulation and related national standards. The CSL stipulates operational security responsibili - ties and network information security responsibilities regarding CII. The CIIO Regulation stipulates the iden - tification for CII, the responsibilities of the CIIO, and how state organs safeguard and promote the opera - tion of CII. According to Article 33 of the CSL, CII refers to the important network facilities and information systems in important industries and fields such as public tel - ecommunications, information services, energy, trans - portation, water conservancy, finance, public services, e-government and national defence science, technol - ogy and industry, as well as other important network facilities and information systems which, in case of destruction, loss of function or leak of data, may result in serious damage to national security, the national economy, people’s livelihood and public interests. Legal entities that operate CIIs are CIIOs. Articles 8 and 10 of the CIIO Regulations further clarify that the specific identification of CII is not self-assessed by the operators but is designated by the Protection Authori - ties.

National standards include: the Information Secu - rity Technology – Guide to Security Inspection and Evaluation of Critical Information Infrastructure; the Information Security Technology – Indicator System of Critical Information Infrastructure Security Assurance; and the Information Security Technology – Cyberse - curity Requirements for Critical Information Infrastruc - ture Protection. 2.2 Critical Infrastructure Cybersecurity Requirements Articles 23 and 27 of the CSL set the “floor” of cyber - security requirements for all network operators, including implementing the MLPS and formulating contingency plans for cybersecurity incidents, as well as responsibilities related to network informa - tion security, such as log retention and audit, and the installation of firewalls, anti-virus software and intru - sion detection systems. For CIIOs, on top of the “floor” requirements, they must fulfill the following “stretched” cybersecurity obligations, as detailed below: • implement the following enhanced safeguarding obligations compared with network operators other than the CIIO: (a) setting up a dedicated security management body and appointing a person in charge of security management; (b) conducting regular cybersecurity education, technical training and skills assessment for employees; (c) performing disaster recovery backups for im - portant systems and databases; and (d) formulating contingency plans for cyberse - curity incidents and conducting regular drills. (Note: the stretched cybersecurity requirements described above were originally imposed only on CIIOs under the CSL. However, subsequent legislation, including the DSL and the PIPL, has broadened the scope of regulated entities to include network operators acting as data handlers); • when procuring network products and services, sign security and confidentiality agreements with providers, for the purpose of safeguarding impor - tant data against vulnerabilities;

78 CHAMBERS.COM

Powered by