CHINA Law and Practice Contributed by: Kate Yin, Sherman Deng, Yanjun Zhuang and Daniel Wang, Fangda Partners
specialised cybersecurity products are sold or provid - ed without security certification or security testing, or if the security certification is unqualified or the security testing does not meet the relevant requirements, the competent authority has the right to order the suspen - sion of sales and confiscate illegal gains. 5. Security Certification for ICT Products, Services and Processes 5.1 Key Cybersecurity Certification Legislation The primary cybersecurity certification framework in China is the MLPS, which has been further developed and clarified by the Notice on Further Strengthening Cybersecurity Tiered Protection Work (Gongwang’an [2025] No 1001) and the Notice on Further Specify - ing Matters Related to Cybersecurity Tiered Protec - tion Work (Gongwang’an [2025] No 1846) in 2025. The current regime mandates a comprehensive and dynamic update of system filings between 8 March and 30 November 2025, applicable to all information systems classified at second-level or above. A sig - nificant expansion in this iteration is the integration of data governance into the certification process and operators are now legally required to complete a data survey questionnaire as part of the filing to map data assets and cross-border flows, thereby linking cyber - security directly with data security obligations. The framework classifies systems into five levels based on their relative importance to national secu - rity and social order. Fifth-level systems, defined as those where a breach would cause particularly seri - ous harm to national security, represent the highest assurance level and are subject to stringent oversight by provincial-level PSB. The certification assessment standards have shifted from static compliance to dynamic defence under the new Cybersecurity Level Evaluation Report Template (2025 Edition). A critical “Severe Risk Veto” process has been introduced: a system can only be deemed “Compliant” if it achieves a score of over 90% and contains no major risks or vulnerabilities. Conversely, systems with major risks cannot achieve full compliance status regardless of their numerical score, compelling operators to priori -
tise the rectification of substantive security gaps over paper compliance. Furthermore, the certification process now requires the formulation of a protection work plan for systems at third-level and above. Operators must submit these plans, detailing asset conditions, rectification strate - gies and future security schedules, to both PSB and sectoral regulators annually. For the current cycle, the initial batch of work plans must be submitted by 30 June 2025. This certification is not only a regulatory requirement but effectively serves as a market access licence; failure to obtain MLPS certification can pre - clude entities from public procurement opportunities and sector-specific licensing in critical industries such as finance and energy. 6. Cybersecurity in Other Regulations 6.1 Cybersecurity and Data Protection Under the PIPL, personal information handlers are required to take measures to ensure that their pro - cessing activities comply with laws and administra - tive regulations based on the purpose and means of processing, the categories of personal information to be processed, the impact on personal rights and interests, and the potential security risks. This compli - ance framework shall prevent unauthorised access to, as well as breach, tampering, or loss of any personal information. Specifically, handlers shall formulate an internal management system and operational proce - dures, implement classified management of personal information, adopt corresponding security technical measures such as encryption and de-identification, and reasonably determine the operational authority for processing. For a handler that processes personal information of over one million individuals, it shall designate a per - son in charge of personal information protection to supervise the processing activities and complete the corresponding filing obligations with CAC. This person is known as PIPO, equivalent to DPO under GDPR. To ensure proactive risk management, for processing activities that may have significant impacts on indi - viduals, handlers shall conduct a personal information
86 CHAMBERS.COM
Powered by FlippingBook