People's Republic of China (with overseas liability under Article 77 as amended)

China Cybersecurity Law (CSL)

47 controls. 6 other frameworks in our corpus share controls with it. Here is all of it, and how much of it you are already doing.

Page built . This page is derived from the framework corpus, which changes when the corpus is extended rather than daily.

47 controls 6 frameworks share controls with it People's Republic of China (with overseas liability under Article 77 as amended) verified against its source document

Every control below is one this framework asks for. The right hand column counts how many other frameworks in our corpus carry the same control, which is the difference between doing this work once and doing it again for the next standard.

China Cybersecurity Law (CSL) Evidence & Implementation Kit

47 controls is the documentation set somebody has to write. This is that set, already written: an adopt-ready artifact for every control in policy and procedure text you edit rather than draft, and the evidence checklist an auditor asks for against each.

See what is in it, $249

The same set every buyer of this kit receives. Nothing here is produced on request.

What you already have

Frameworks whose controls overlap this one, most first. If you run any of them, the count is roughly what you have already evidenced.

Every control

CodeControlAlso in
CSL-Art1Scope, Cyberspace Sovereignty and Definitions (Art. 1-2, 76)0
CSL-Art2025AI2025 Amendment - AI Governance and Development0
CSL-Art21Multi-Level Protection Scheme (MLPS) - Art. 212
CSL-Art22Security of Network Products and Services - Art. 221
CSL-Art23Critical Network Equipment Certification - Art. 230
CSL-Art24Real-Name Registration - Art. 240
CSL-Art27Prohibition on Illegal Network Intrusion - Art. 270
CSL-Art31Critical Information Infrastructure Designation - Art. 311
CSL-Art34CII Operator Security Obligations - Art. 341
CSL-Art35CII Procurement Security Review - Art. 350
CSL-Art37CII Data Localization and Cross-Border Assessment - Art. 373
CSL-Art38CII Annual Security Inspection - Art. 381
CSL-Art40Confidentiality of User Information - Art. 403
CSL-Art41Lawful Collection of Personal Information - Art. 411
CSL-Art42Personal Information Protection and Breach Handling - Art. 422
CSL-Art43Right to Correction and Deletion - Art. 431
CSL-Art47Content Management Obligations - Art. 470
CSL-Art49Complaints and Reporting Mechanism - Art. 490
CSL-Art51Cybersecurity Monitoring and Early Warning - Art. 511
CSL-Art56Cybersecurity Risk Talks (Regulatory Interview) - Art. 560
CSL-Art59Penalties for Network Operators - Art. 59-680
CSL-Art66Penalties for Cross-Border / Localization Violations - Art. 660
23Art. 23 Ranked cybersecurity protection (MLPS): management system and responsible persons, technical defences, monitoring with logs kept six months, data categorisation, backup and0
24Art. 24 Network products and services: mandatory standards, no malicious programs, defect remediation with user notice and reporting, continuous security maintenance, consent for u0
25Art. 25 Key network equipment and specialised cybersecurity products certified or tested before sale0
26Art. 26 Real identity of users for network access, domain registration, telephone services, information publication and instant messaging0
27Art. 27 Emergency response plans, prompt handling of vulnerabilities, viruses, attacks and intrusions, activation and reporting on incidents0
28-29Art. 28-29 Certification, testing, assessment and vulnerability disclosure under state rules; no attacks, no attack tools, no assistance to attackers0
30Art. 30 Technical support and assistance to public security and national security agencies0
35-36Art. 35-36 Critical information infrastructure: security built in simultaneously, a specialised security body with vetted responsible persons, training and assessments, disaster re0
37-38Art. 37-38 CII procurement: national security review where national security may be affected, and security and secrecy agreements with providers0
39Art. 39 Personal information and important data collected by CII operators stored within China; security assessment before any provision abroad0
40Art. 40 At least one security testing and assessment per year, results and improvements submitted to the protection department0
42-43Art. 42-43 User information kept secret under a protection system; personal information collected lawfully, legitimately and necessarily, with public rules, stated purposes and con0
44-45Art. 44-45 No disclosure, tampering or damage; no provision to others without consent unless irreversibly de-identified; security measures; breach remediation with user notice and 0
46Art. 46 No theft, unlawful acquisition, sale or provision of personal information0
48Art. 48 No websites, groups or postings for fraud, criminal instruction or prohibited items0
49-50Art. 49-50 Manage user-published information: stop prohibited content, delete it, keep records and report; no malicious programs or prohibited information in electronic messages an0
51Art. 51 Complaint and reporting mechanism for network information security, published and promptly handled; cooperate with supervision and inspection0
57-58Art. 57-58 On incidents, take the technical and other measures the departments require; on regulatory interviews, rectify and eliminate hidden dangers0
CIIChapter III Section 2: Critical information infrastructure (Articles 35 to 40)0
INFOChapter IV: Network information security (Articles 42 to 51)0
LAWThe Cybersecurity Law as amended in 2025: what it is, what changed, what is held0
OPSChapter III Section 1: Network operations security, general (Articles 23 to 30)0
PENLegal liability as amended (Articles 61 to 75)0
RESPChapter V: Emergency response duties on operators (Articles 57 and 58)0
STATEThe state's role, the regulators, monitoring and early warning, and the definitions (Articles 3 to 9, 14 to 22, 31 to 34, 41, 52 to 56, 59, 60, 76 to 80)0

Tell me when China Cybersecurity Law (CSL) files something new

One email when a public company newly discloses something this framework governs, naming the company and what our corpus says it puts in scope. Nothing else, and one click to stop.

What an auditor will ask you to produce

The artefacts named on the failure modes this framework speaks to.

  • Incident response plan
  • Incident response plan and playbooks
  • Incident records, post-incident reviews and reporting to authorities
  • Exercises/drills (including OT scenarios)
  • Incident response plan following the four phases
  • Ship-shore coordination and escalation procedures

How programmes fail on this

Failure modes named by this framework and others. Each opens the full record.

What this page is

A control-level reference for China Cybersecurity Law (CSL), drawn from our framework corpus. Control codes and titles are references to the standard, not reproductions of it. The overlap counts and the auditor artefacts are our own work and are the part you will not find elsewhere.

Measure this against what you already run · All frameworks · Today's edition