Skip to content

Evidence request lists

China Cybersecurity Law (CSL)

Evidence request list. 22 controls, 22 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 11 September 2026. Published by The Art of Service.

China CSL: Critical Information Infrastructure

CSL-Art31
Critical Information Infrastructure Designation - Art. 31

The State implements key protection for critical information infrastructure (CII) in sectors such as public communications, energy, transport, water, finance, public services and e-government, whose damage would seriously endanger national security or public interest.

Artefacts an auditor will ask for
  • assessment of whether the organisation operates CII in a designated sector
  • engagement with the CII protection regime
Where this commonly fails
  • CII status not assessed where sector is in scope
CSL-Art34
CII Operator Security Obligations - Art. 34

CII operators must, beyond Art. 21, establish a specialised security management body and responsible person, conduct background checks, provide security training, back up critical data, and have an incident response plan.

Artefacts an auditor will ask for
  • dedicated security management body and responsible person
  • personnel background checks and training
  • critical data backup and incident response plan
Where this commonly fails
  • no dedicated CII security function
  • critical data not backed up
  • no incident response plan
CSL-Art35
CII Procurement Security Review - Art. 35

CII operators procuring network products and services that may affect national security must pass a national security review organised by the Cyberspace Administration of China and relevant departments.

Artefacts an auditor will ask for
  • national security review for CII procurement that may affect national security
Where this commonly fails
  • CII procurement not subjected to required security review
CSL-Art37
CII Data Localization and Cross-Border Assessment - Art. 37

Personal information and important data collected/generated by CII operators in the PRC must be stored within China; cross-border transfer for business necessity requires a security assessment.

Artefacts an auditor will ask for
  • in-China storage of personal information and important data by CII operators
  • security assessment before any cross-border transfer
Where this commonly fails
  • CII data stored or transferred abroad without a security assessment
CSL-Art38
CII Annual Security Inspection - Art. 38

CII operators must conduct, at least annually, a security inspection and risk assessment of their networks (themselves or via a service body) and report results to the relevant authority.

Artefacts an auditor will ask for
  • annual security inspection / risk assessment of CII
  • reporting of results to authorities
Where this commonly fails
  • no annual CII security inspection

China CSL: General Provisions and Support

CSL-Art1
Scope, Cyberspace Sovereignty and Definitions (Art. 1-2, 76)

CSL Chapter I: scope (construction, operation, maintenance and use of networks within the PRC), cyberspace sovereignty, and key definitions including network operator and critical information infrastructure.

Artefacts an auditor will ask for
  • determination of whether the organisation is a network operator or CII operator under the CSL
  • scope assessment for PRC operations
Where this commonly fails
  • CSL applicability not assessed
  • network-operator status undetermined
CSL-Art2025AI
2025 Amendment - AI Governance and Development

The October 2025 amendment to the CSL (effective 1 January 2026) added provisions promoting the safe development and governance of artificial intelligence within the cybersecurity framework.

Artefacts an auditor will ask for
  • awareness of and alignment with the 2025 CSL amendment AI-governance provisions
Where this commonly fails
  • 2025 AI-governance amendment not considered

China CSL: Monitoring, Early Warning and Liability

CSL-Art51
Cybersecurity Monitoring and Early Warning - Art. 51

The State establishes a cybersecurity monitoring, early-warning and information-notification system; operators participate in monitoring and information sharing as required.

Artefacts an auditor will ask for
  • participation in cybersecurity monitoring and information sharing
  • internal monitoring and early-warning capability
Where this commonly fails
  • no monitoring/early-warning participation where required
CSL-Art56
Cybersecurity Risk Talks (Regulatory Interview) - Art. 56

Where significant security risks exist or incidents occur, regulators may summon the legal representative of the operator for a risk-talk (interview); the operator must rectify and eliminate the risks.

Artefacts an auditor will ask for
  • process for responding to a regulatory risk-talk and rectifying identified risks
Where this commonly fails
  • no process to respond to a regulator interview/rectification order
CSL-Art59
Penalties for Network Operators - Art. 59-68

Legal liability and administrative penalties (warnings, rectification orders, fines on the entity and responsible persons, suspension of business, website closure, licence revocation) for failing to perform security-protection obligations.

Artefacts an auditor will ask for
  • awareness of CSL penalty exposure
  • process for responding to rectification orders
Where this commonly fails
  • no process for regulatory enforcement response
CSL-Art66
Penalties for Cross-Border / Localization Violations - Art. 66

CII operators that store data abroad or transfer it abroad in violation of Art. 37 face rectification orders, warnings, confiscation of gains and fines, and possible suspension/closure.

Artefacts an auditor will ask for
  • controls ensuring compliance with Art. 37 localization to avoid Art. 66 penalties
Where this commonly fails
  • cross-border violations exposing the operator to Art. 66 penalties

China CSL: Network Information Security

CSL-Art40
Confidentiality of User Information - Art. 40

Network operators must keep strictly confidential the user information they collect and establish and improve a user-information protection system.

Artefacts an auditor will ask for
  • user-information protection system
  • confidentiality controls over collected user data
Where this commonly fails
  • no user-information protection system
CSL-Art41
Lawful Collection of Personal Information - Art. 41

Network operators collecting/using personal information must follow the principles of lawfulness, legitimacy and necessity, publicly disclose collection/use rules, state the purpose, means and scope, and obtain the consent of the person.

Artefacts an auditor will ask for
  • published collection/use rules stating purpose, means and scope
  • consent records
  • necessity/minimisation of collection
Where this commonly fails
  • collection without consent
  • purpose/scope not disclosed
  • over-collection
CSL-Art42
Personal Information Protection and Breach Handling - Art. 42

Network operators must not disclose, tamper with or destroy collected personal information, nor provide it to others without consent; they must adopt technical measures to ensure security and, upon a breach, take remedial measures and notify users and authorities.

Artefacts an auditor will ask for
  • technical and management measures protecting personal information
  • breach remediation and notification to users and authorities
Where this commonly fails
  • PI disclosed/provided without consent
  • breaches not remediated or notified
CSL-Art43
Right to Correction and Deletion - Art. 43

Individuals may request deletion of their personal information where it was collected/used in violation of law or agreement, and correction of errors; network operators must take measures to delete or correct.

Artefacts an auditor will ask for
  • process to action deletion and correction requests
Where this commonly fails
  • deletion/correction requests not actioned
CSL-Art47
Content Management Obligations - Art. 47

Network operators must strengthen management of information published by users; on discovering prohibited information they must stop transmission, take disposal measures (e.g. deletion), keep records and report to authorities.

Artefacts an auditor will ask for
  • mechanisms to detect and dispose of legally prohibited information
  • record-keeping and reporting
Where this commonly fails
  • no process to handle prohibited information
CSL-Art49
Complaints and Reporting Mechanism - Art. 49

Network operators must establish network-information security complaint and reporting systems and handle complaints in a timely manner.

Artefacts an auditor will ask for
  • complaint/reporting channels and timely handling records
Where this commonly fails
  • no complaint-handling mechanism

China CSL: Network Operations Security

CSL-Art21
Multi-Level Protection Scheme (MLPS) - Art. 21

Network operators must perform security-protection obligations according to the requirements of the network security graded (multi-level) protection system: internal security management, technical measures to prevent malware/attacks, monitoring and logging (>=6 months), data classification, backup and encryption.

Artefacts an auditor will ask for
  • MLPS grading determination and filing for in-scope systems
  • internal security management system and responsible person
  • technical measures (anti-malware, intrusion prevention), >=6-month log retention, backup and encryption of important data
Where this commonly fails
  • no MLPS grading/filing
  • logs retained less than 6 months
  • important data not backed up/encrypted
CSL-Art22
Security of Network Products and Services - Art. 22

Network products and services must meet mandatory national standards, must not contain malicious programs, and providers must remedy security flaws/vulnerabilities and inform users (and report) in a timely manner.

Artefacts an auditor will ask for
  • conformity of products/services to national standards
  • vulnerability remediation and user notification process
Where this commonly fails
  • products not conforming to mandatory standards
  • vulnerabilities not remediated or disclosed
CSL-Art23
Critical Network Equipment Certification - Art. 23

Critical network equipment and specialised cybersecurity products must obtain certification or meet the requirements of a security inspection by a qualified body before sale or provision.

Artefacts an auditor will ask for
  • certification/inspection evidence for critical network equipment and security products used/sold
Where this commonly fails
  • uncertified critical network equipment deployed
CSL-Art24
Real-Name Registration - Art. 24

Network operators handling network access, domain registration, fixed/mobile phone or instant-messaging services must require users to provide real-identity information; service may be refused without it.

Artefacts an auditor will ask for
  • real-identity verification process for applicable services
Where this commonly fails
  • services provided without required real-name verification
CSL-Art27
Prohibition on Illegal Network Intrusion - Art. 27

Prohibition on illegally intruding into others networks, disrupting their normal function, stealing network data, or providing tools/assistance for such activities.

Artefacts an auditor will ask for
  • policies prohibiting unauthorised access/penetration of third-party networks
  • controls against providing intrusion tools
Where this commonly fails
  • no policy against unauthorised access activities
Assembled from the framework's own control set. Every line traces to a control in the graph, so this pack is regenerated rather than written, and stays current as the graph does.

Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the China Cybersecurity Law (CSL) framework page.