[Editor to fill: 200-word domain overview.]
Cybersecurity Review.
网络安全审查
The cybersecurity review regime for critical information infrastructure operators and large data processors — including overseas listings.
The legal corpus.
6 laws.
- CII Regulations Security Protection Regulations for Critical Information Infrastructure 关键信息基础设施安全保护条例
- RULE Cybersecurity Review Measures 网络安全审查办法
- Incident Reporting Measures Measures for the Administration of National Cybersecurity Incident Reporting 国家网络安全事件报告管理办法
- Healthcare Cybersecurity Measures Measures for the Cybersecurity Management of Healthcare Institutions 医疗卫生机构网络安全管理办法
- Financial Sector Cybersecurity Measures (Draft) Measures for Cybersecurity Management in the Financial Sector (Draft for Comment) 金融业网络安全管理办法(征求意见稿)
- FISR Measures Measures for the Security Review of Foreign Investments 外商投资安全审查办法
In this domain.
4 briefs.
- § 01 · CYBERSECURITY-REVIEW
China Opens a Cybersecurity Review of Palo Alto Networks: The Micron Playbook, Now Pointed at Firewalls
On 6 August 2026 the Cybersecurity Review Office announced a cybersecurity review of Palo Alto Networks (派拓公司) products sold in China, citing the National Security Law, the Cybersecurity Law and the Cybersecurity Review Measures. DCC reads the announcement against the Measures themselves. The review is an Article 16 own-motion proceeding initiated by the working mechanism and cleared by the Central Cyberspace Affairs Commission — not the Article 5 pathway where a CIIO declares a procurement — so there is no applicant, no declared transaction, and the Article 11/14 clocks apply only by analogy. Article 21 puts cybersecurity equipment and cloud computing services squarely in scope; Article 10 supplies the risk factors that a cloud-synchronized firewall estate maps onto almost line by line. The operative question for overseas counsel is not what happens now — nothing does — but what a failed outcome would mean: CIIOs must stop procuring, and CSL Article 37/67 as amended in 2025 exposes a CIIO that keeps using un-passed products to a fine of 1× to 10× the procurement amount plus RMB 10,000–100,000 personally. Non-designated companies acquire no legal obligation at all. Based on commentary from 数据何规, checked against the official announcement and the Micron precedent.
- § 02 · SECURITY-REVIEW
One Company, Four Reviews: JunHe Maps China's Security-Review 'Matrix' in the Security-First Era
With the Measures for Network Data Security Risk Assessment (Order No. 24) in place, China's security-review architecture has four operating pillars: foreign investment security review (NDRC + MOFCOM), cybersecurity review (CAC + 12 departments), data export security assessment (CAC), and the new normalized network data security risk assessment (CAC coordination + sectoral authorities). JunHe lawyer Chen Sijia walks each regime through the same five questions — who reviews, what is reviewed, when review is triggered, and with what legal consequences — and lands on two points overseas counsel should not miss. First, the four regimes differ in kind: the first three are ex-ante, admission-style reviews with veto power, while the risk assessment is an annual, improvement-oriented 'physical exam.' Second, review decisions are effectively final — the mainstream view treats them as final administrative acts with no administrative reconsideration or litigation available — so cooperation during the review is the only real strategy. A closing lifecycle walkthrough shows how a single AI-model company can trip all four lines in sequence: FDI review at fundraising, cybersecurity review at GPU procurement, export assessment at model training, cybersecurity review again at foreign listing, and the annual risk assessment as a standing duty.
- § 03 · FOREIGN-INVESTMENT-SECURITY-REVIEW
Why China Used Foreign Investment Security Review on Manus — Not Tech or Data Export
Hong Yanqing on Beijing's banning of Meta's Manus acquisition. The regulator's choice of pathway — Foreign Investment Security Review, not Technology or Data Export — signals a shift from 'transaction-level' to 'capability-level' oversight of frontier AI projects, with implications for any overseas tech investment touching China.
- § 04 · CSL
China's Cybersecurity Law Just Got Teeth — The 2025 Amendment and What Changed
On October 28, 2025, the NPC Standing Committee adopted the first amendment to China's Cybersecurity Law since 2017, effective January 1, 2026. Compliance Talker's global legal policy team walks through what changed across 14 amendments: a new framework provision on AI safety and development, harmonization with PIPL and the Civil Code on personal information, sharply increased penalties (10× cap on top fines), expanded application of the dual-penalty system to individual officers, and broader extraterritorial reach. For overseas teams, the operational takeaway is that cybersecurity compliance is now an executive-level risk, not a documentation exercise.