CSL-Art1 | Scope, Cyberspace Sovereignty and Definitions (Art. 1-2, 76) | 0 |
CSL-Art2025AI | 2025 Amendment - AI Governance and Development | 0 |
CSL-Art21 | Multi-Level Protection Scheme (MLPS) - Art. 21 | 2 |
CSL-Art22 | Security of Network Products and Services - Art. 22 | 1 |
CSL-Art23 | Critical Network Equipment Certification - Art. 23 | 0 |
CSL-Art24 | Real-Name Registration - Art. 24 | 0 |
CSL-Art27 | Prohibition on Illegal Network Intrusion - Art. 27 | 0 |
CSL-Art31 | Critical Information Infrastructure Designation - Art. 31 | 1 |
CSL-Art34 | CII Operator Security Obligations - Art. 34 | 1 |
CSL-Art35 | CII Procurement Security Review - Art. 35 | 0 |
CSL-Art37 | CII Data Localization and Cross-Border Assessment - Art. 37 | 3 |
CSL-Art38 | CII Annual Security Inspection - Art. 38 | 1 |
CSL-Art40 | Confidentiality of User Information - Art. 40 | 3 |
CSL-Art41 | Lawful Collection of Personal Information - Art. 41 | 1 |
CSL-Art42 | Personal Information Protection and Breach Handling - Art. 42 | 2 |
CSL-Art43 | Right to Correction and Deletion - Art. 43 | 1 |
CSL-Art47 | Content Management Obligations - Art. 47 | 0 |
CSL-Art49 | Complaints and Reporting Mechanism - Art. 49 | 0 |
CSL-Art51 | Cybersecurity Monitoring and Early Warning - Art. 51 | 1 |
CSL-Art56 | Cybersecurity Risk Talks (Regulatory Interview) - Art. 56 | 0 |
CSL-Art59 | Penalties for Network Operators - Art. 59-68 | 0 |
CSL-Art66 | Penalties for Cross-Border / Localization Violations - Art. 66 | 0 |
23 | Art. 23 Ranked cybersecurity protection (MLPS): management system and responsible persons, technical defences, monitoring with logs kept six months, data categorisation, backup and | 0 |
24 | Art. 24 Network products and services: mandatory standards, no malicious programs, defect remediation with user notice and reporting, continuous security maintenance, consent for u | 0 |
25 | Art. 25 Key network equipment and specialised cybersecurity products certified or tested before sale | 0 |
26 | Art. 26 Real identity of users for network access, domain registration, telephone services, information publication and instant messaging | 0 |
27 | Art. 27 Emergency response plans, prompt handling of vulnerabilities, viruses, attacks and intrusions, activation and reporting on incidents | 0 |
28-29 | Art. 28-29 Certification, testing, assessment and vulnerability disclosure under state rules; no attacks, no attack tools, no assistance to attackers | 0 |
30 | Art. 30 Technical support and assistance to public security and national security agencies | 0 |
35-36 | Art. 35-36 Critical information infrastructure: security built in simultaneously, a specialised security body with vetted responsible persons, training and assessments, disaster re | 0 |
37-38 | Art. 37-38 CII procurement: national security review where national security may be affected, and security and secrecy agreements with providers | 0 |
39 | Art. 39 Personal information and important data collected by CII operators stored within China; security assessment before any provision abroad | 0 |
40 | Art. 40 At least one security testing and assessment per year, results and improvements submitted to the protection department | 0 |
42-43 | Art. 42-43 User information kept secret under a protection system; personal information collected lawfully, legitimately and necessarily, with public rules, stated purposes and con | 0 |
44-45 | Art. 44-45 No disclosure, tampering or damage; no provision to others without consent unless irreversibly de-identified; security measures; breach remediation with user notice and | 0 |
46 | Art. 46 No theft, unlawful acquisition, sale or provision of personal information | 0 |
48 | Art. 48 No websites, groups or postings for fraud, criminal instruction or prohibited items | 0 |
49-50 | Art. 49-50 Manage user-published information: stop prohibited content, delete it, keep records and report; no malicious programs or prohibited information in electronic messages an | 0 |
51 | Art. 51 Complaint and reporting mechanism for network information security, published and promptly handled; cooperate with supervision and inspection | 0 |
57-58 | Art. 57-58 On incidents, take the technical and other measures the departments require; on regulatory interviews, rectify and eliminate hidden dangers | 0 |
CII | Chapter III Section 2: Critical information infrastructure (Articles 35 to 40) | 0 |
INFO | Chapter IV: Network information security (Articles 42 to 51) | 0 |
LAW | The Cybersecurity Law as amended in 2025: what it is, what changed, what is held | 0 |
OPS | Chapter III Section 1: Network operations security, general (Articles 23 to 30) | 0 |
PEN | Legal liability as amended (Articles 61 to 75) | 0 |
RESP | Chapter V: Emergency response duties on operators (Articles 57 and 58) | 0 |
STATE | The state's role, the regulators, monitoring and early warning, and the definitions (Articles 3 to 9, 14 to 22, 31 to 34, 41, 52 to 56, 59, 60, 76 to 80) | 0 |