China's product-security and cyber-resilience law rests on the Cybersecurity Law of the People's Republic of China, substantively amended by a decision of the Standing Committee of the National People's Congress adopted October 28, 2025 and promulgated the same day by Presidential Order No. 61, with the amended text in force since January 1, 2026, read together with the Data Security Law, in force since September 1, 2021.
Article 24 of the amended Cybersecurity Law binds a provider of a network product or service, a role a manufacturer or software distributor occupies and distinct from the broader network-operator classification the same law also uses, to meet the mandatory requirements of the applicable national standard, refrain from embedding a malicious program, and, on discovering a security defect or vulnerability, immediately take remedial measures, notify affected users, and report to the competent authority, while providing continuous security maintenance for the product's or service's stated support period; the statute states no numeric clock for that notice, only immediacy.
Articles 27 and 29 of the Data Security Law impose a parallel, sector-neutral pair of duties on any organization or individual engaging in a data-processing activity: a full-process data-security management system with staff education and training (Article 27), and a duty to strengthen risk monitoring, remediate a discovered data-security defect or vulnerability immediately, and, on an actual data-security incident, take disposal measures and notify users and the competent authority (Article 29), again with no numeric clock in the text.
Article 30 of the same law additionally requires a processor of important data (an official classification of data whose compromise could harm national security, the economy, or public health and safety, not an activity a developer declares) to conduct a periodic risk assessment of its data-processing activities and file the report with the competent authority; because that duty attaches to the important-data classification rather than to any activity in the corpus vocabulary, it is not flagged as its own instrument here.
Two further regimes bind by a classification the vocabulary cannot express and are recorded here rather than flagged.
The Cybersecurity Law's own classified-protection system (Article 23, referred to in practice as the multi-level protection scheme and implemented in more technical detail by the national standard GB/T 22239-2019, colloquially 'MLPS 2.0') and its critical-information-infrastructure operator provisions (Articles 33 to 41, elaborated by the Regulation on the Security Protection of Critical Information Infrastructure, State Council Order No. 745, approved April 27, 2021 and effective September 1, 2021) both bind a network operator or a critical-information-infrastructure operator by classification, so neither is raised as an instrument.
A standalone administrative regulation intended to elevate the classified-protection system above departmental-rule status, the Regulation on the Classified Protection of Cybersecurity, has been in drafting since the Ministry of Public Security's 2018 public-comment draft; secondary reporting places it on the State Council's legislative-preparation list for both 2025 and 2026, but no promulgated text was located, so it remains unenacted.
The National Cybersecurity Incident Reporting Measures (国家网络安全事件报告管理办法, "Measures for the Administration of National Cybersecurity Incident Reporting"), issued by the Cyberspace Administration of China on September 11, 2025 and in force since November 1, 2025, supply the operative reporting clock once an incident occurs, and are raised below as their own instrument.
They bind a network operator, meaning any organization that owns or manages a network or provides services over one, so the instrument flags every activity and every role rather than a narrower class and states that scope condition in its first duty line.
The Regulation on Network Data Security Management (State Council Order No. 790, adopted August 30, 2024, in force since January 1, 2025) elaborates the Data Security Law's important-data duties, requiring a network data processor to identify and file important data against a catalogue, designate a data-security officer and a managing body, and, as an important-data processor, complete an annual risk assessment; this summary draws on the Cyberspace Administration of China's own published account of the Regulation, since the Regulation's own text serves only a JavaScript shell, and the same account's provisions on personal information and cross-border data flow are this jurisdiction's privacy row rather than repeated here.
China's breach-notification duty for personal information sits at Article 57 of the Personal Information Protection Law, already this jurisdiction's privacy row. An unauthorized-access or system-destruction offense against a network sits at Articles 285 and 286 of the Criminal Law, already this jurisdiction's scraping row (the computer_misuse family) and not a security-topic presence on its own.
Enforcement of the duties described here is administrative only, by the competent department with jurisdiction over the network operator or the product or service provider, coordinated nationally by the Cyberspace Administration of China; neither the Cybersecurity Law nor the Data Security Law creates a distinct private right of action, though both preserve an injured party's ordinary civil claim for damages caused by a violation, and a breach that also constitutes a crime, most sharply a violation of the national core data management system under Data Security Law Article 45, can draw criminal liability.