China Cybersecurity Law (CSL)
What is China Cybersecurity Law (CSL)?
The Cybersecurity Law of the People's Republic of China (effective 1 June 2017) is China's foundational cybersecurity legislation. It imposes obligations on network operators and operators of critical information infrastructure (CII) to implement a multi‑level protection scheme (MLPS), conduct security assessments of network products and services, ensure data localization for personal information and important data, protect personal information, and cooperate with government security inspections. It comprises 22 controls organised across 5 domains, and applies in China.
How China Cybersecurity Law (CSL) maps to other frameworks
All 22 controls, each one mapped to the equivalent requirement in other standards, with the evidence that carries across and the mappings that were judged and rejected shown alongside. No account needed to look.
See the control mappings →The 5 domains China Cybersecurity Law (CSL) groups its controls into
Where China Cybersecurity Law (CSL) overlaps with the standards you already hold
What China Cybersecurity Law (CSL) means in your sector
What China Cybersecurity Law (CSL) means for your job
Questions people ask about China Cybersecurity Law (CSL)
What is China Cybersecurity Law?
How many controls does China Cybersecurity Law have?
Where does China Cybersecurity Law apply?
What frameworks does China Cybersecurity Law map to?
How do I get started with China Cybersecurity Law compliance?
Query China Cybersecurity Law (CSL) programmatically
China Cybersecurity Law (CSL), its 22 controls and every mapping into other standards are available over a REST endpoint and an MCP server, so an agent can read them directly. The free tier is 10 calls a day and needs no signup.
China Cybersecurity Law (CSL) API reference and MCP config →What China Cybersecurity Law (CSL) requires, control by control
Each page carries the requirement text for one China Cybersecurity Law (CSL) control and what an assessor expects to see as evidence.
- CSL-ART21 Multi-Level Protection Scheme (MLPS) - Art. 21
- CSL-ART22 Security of Network Products and Services - Art. 22
- CSL-ART31 Critical Information Infrastructure Designation - Art. 31
- CSL-ART34 CII Operator Security Obligations - Art. 34
- CSL-ART37 CII Data Localization and Cross-Border Assessment - Art. 37
- CSL-ART38 CII Annual Security Inspection - Art. 38
- CSL-ART40 Confidentiality of User Information - Art. 40
- CSL-ART41 Lawful Collection of Personal Information - Art. 41
- CSL-ART42 Personal Information Protection and Breach Handling - Art. 42
- CSL-ART43 Right to Correction and Deletion - Art. 43
How ready are you for China Cybersecurity Law (CSL)?
Answer 25 questions and get a professional readiness report with gap analysis, maturity scores, and prioritised action items. Results in 5 minutes.