China Cybersecurity Law (CSL)
Evidence request list. 22 controls, 22 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 11 September 2026. Published by The Art of Service.
China CSL: Critical Information Infrastructure
The State implements key protection for critical information infrastructure (CII) in sectors such as public communications, energy, transport, water, finance, public services and e-government, whose damage would seriously endanger national security or public interest.
- assessment of whether the organisation operates CII in a designated sector
- engagement with the CII protection regime
- CII status not assessed where sector is in scope
CII operators must, beyond Art. 21, establish a specialised security management body and responsible person, conduct background checks, provide security training, back up critical data, and have an incident response plan.
- dedicated security management body and responsible person
- personnel background checks and training
- critical data backup and incident response plan
- no dedicated CII security function
- critical data not backed up
- no incident response plan
CII operators procuring network products and services that may affect national security must pass a national security review organised by the Cyberspace Administration of China and relevant departments.
- national security review for CII procurement that may affect national security
- CII procurement not subjected to required security review
Personal information and important data collected/generated by CII operators in the PRC must be stored within China; cross-border transfer for business necessity requires a security assessment.
- in-China storage of personal information and important data by CII operators
- security assessment before any cross-border transfer
- CII data stored or transferred abroad without a security assessment
CII operators must conduct, at least annually, a security inspection and risk assessment of their networks (themselves or via a service body) and report results to the relevant authority.
- annual security inspection / risk assessment of CII
- reporting of results to authorities
- no annual CII security inspection
China CSL: General Provisions and Support
CSL Chapter I: scope (construction, operation, maintenance and use of networks within the PRC), cyberspace sovereignty, and key definitions including network operator and critical information infrastructure.
- determination of whether the organisation is a network operator or CII operator under the CSL
- scope assessment for PRC operations
- CSL applicability not assessed
- network-operator status undetermined
The October 2025 amendment to the CSL (effective 1 January 2026) added provisions promoting the safe development and governance of artificial intelligence within the cybersecurity framework.
- awareness of and alignment with the 2025 CSL amendment AI-governance provisions
- 2025 AI-governance amendment not considered
China CSL: Monitoring, Early Warning and Liability
The State establishes a cybersecurity monitoring, early-warning and information-notification system; operators participate in monitoring and information sharing as required.
- participation in cybersecurity monitoring and information sharing
- internal monitoring and early-warning capability
- no monitoring/early-warning participation where required
Where significant security risks exist or incidents occur, regulators may summon the legal representative of the operator for a risk-talk (interview); the operator must rectify and eliminate the risks.
- process for responding to a regulatory risk-talk and rectifying identified risks
- no process to respond to a regulator interview/rectification order
Legal liability and administrative penalties (warnings, rectification orders, fines on the entity and responsible persons, suspension of business, website closure, licence revocation) for failing to perform security-protection obligations.
- awareness of CSL penalty exposure
- process for responding to rectification orders
- no process for regulatory enforcement response
CII operators that store data abroad or transfer it abroad in violation of Art. 37 face rectification orders, warnings, confiscation of gains and fines, and possible suspension/closure.
- controls ensuring compliance with Art. 37 localization to avoid Art. 66 penalties
- cross-border violations exposing the operator to Art. 66 penalties
China CSL: Network Information Security
Network operators must keep strictly confidential the user information they collect and establish and improve a user-information protection system.
- user-information protection system
- confidentiality controls over collected user data
- no user-information protection system
Network operators collecting/using personal information must follow the principles of lawfulness, legitimacy and necessity, publicly disclose collection/use rules, state the purpose, means and scope, and obtain the consent of the person.
- published collection/use rules stating purpose, means and scope
- consent records
- necessity/minimisation of collection
- collection without consent
- purpose/scope not disclosed
- over-collection
Network operators must not disclose, tamper with or destroy collected personal information, nor provide it to others without consent; they must adopt technical measures to ensure security and, upon a breach, take remedial measures and notify users and authorities.
- technical and management measures protecting personal information
- breach remediation and notification to users and authorities
- PI disclosed/provided without consent
- breaches not remediated or notified
Individuals may request deletion of their personal information where it was collected/used in violation of law or agreement, and correction of errors; network operators must take measures to delete or correct.
- process to action deletion and correction requests
- deletion/correction requests not actioned
Network operators must strengthen management of information published by users; on discovering prohibited information they must stop transmission, take disposal measures (e.g. deletion), keep records and report to authorities.
- mechanisms to detect and dispose of legally prohibited information
- record-keeping and reporting
- no process to handle prohibited information
Network operators must establish network-information security complaint and reporting systems and handle complaints in a timely manner.
- complaint/reporting channels and timely handling records
- no complaint-handling mechanism
China CSL: Network Operations Security
Network operators must perform security-protection obligations according to the requirements of the network security graded (multi-level) protection system: internal security management, technical measures to prevent malware/attacks, monitoring and logging (>=6 months), data classification, backup and encryption.
- MLPS grading determination and filing for in-scope systems
- internal security management system and responsible person
- technical measures (anti-malware, intrusion prevention), >=6-month log retention, backup and encryption of important data
- no MLPS grading/filing
- logs retained less than 6 months
- important data not backed up/encrypted
Network products and services must meet mandatory national standards, must not contain malicious programs, and providers must remedy security flaws/vulnerabilities and inform users (and report) in a timely manner.
- conformity of products/services to national standards
- vulnerability remediation and user notification process
- products not conforming to mandatory standards
- vulnerabilities not remediated or disclosed
Critical network equipment and specialised cybersecurity products must obtain certification or meet the requirements of a security inspection by a qualified body before sale or provision.
- certification/inspection evidence for critical network equipment and security products used/sold
- uncertified critical network equipment deployed
Network operators handling network access, domain registration, fixed/mobile phone or instant-messaging services must require users to provide real-identity information; service may be refused without it.
- real-identity verification process for applicable services
- services provided without required real-name verification
Prohibition on illegally intruding into others networks, disrupting their normal function, stealing network data, or providing tools/assistance for such activities.
- policies prohibiting unauthorised access/penetration of third-party networks
- controls against providing intrusion tools
- no policy against unauthorised access activities
Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the China Cybersecurity Law (CSL) framework page.