---
title_en: "Guide to the Classification and Grading of Industrial Data (Trial)"
title_zh: "工业数据分类分级指南（试行）"
abbreviation: "Industrial Data Classification and Grading Guide"
hierarchy: "rule"
issuing_body: "General Office of the Ministry of Industry and Information Technology"
adopted_date: 2020-02-27
effective_date: 2020-02-27
status: "effective"
related_laws: ["miit-industrial-data-security-measures", "industrial-data-security-risk-assessment-rules", "industrial-data-security-incident-emergency-plan", "industrial-data-security-capability-plan-2024-2026", "ics-cybersecurity-protection-guide", "data-classification-grading-rules", "dsl", "csl"]
domains: ["industrial", "data-security"]
url: https://datacompliancechina.com/laws/industrial-data-classification-grading-guide/
summary: "Issued by the General Office of the Ministry of Industry and Information Technology on February 27, 2020 as 工信厅信发〔2020〕6号 (Gong Xin Ting Xin Fa [2020] No. 6), this trial Guide was the first MIIT instrument to tell industrial enterprises and Industrial Internet platform enterprises how to sort their data into categories and grade it by consequence. It defines industrial data as lifecycle data from research and development, production, operations and maintenance, management and platform operation, and grades it into three levels (一级/二级/三级) according to the potential impact of tampering, destruction, leakage or illegal use on production safety, economic loss, cascading effects and recovery cost, with Level 3 data subject to the strictest protection, sharing and reporting duties. This impact-based three-tier scheme is the origin of the industrial-data grading that MIIT carried into the 2022 Administrative Measures for Data Security in the Field of Industry and Information Technology, where the three levels were re-labelled general, important and core data and anchored to the Data Security Law; the Level 1 criteria here reappear almost verbatim as the general-data criteria in the Measures. For overseas counsel, the Guide explains the pedigree of the classification lists that MIIT-regulated suppliers and joint ventures still maintain."
---

> **Source: Data Compliance China** — https://datacompliancechina.com/laws/industrial-data-classification-grading-guide/ · English rendering and annotations by DCC; the Chinese original governs. Cite as: Data Compliance China, "Guide to the Classification and Grading of Industrial Data (Trial)", https://datacompliancechina.com/laws/industrial-data-classification-grading-guide/
**Promulgated by:** General Office of the Ministry of Industry and Information Technology.  
**Document No.:** 工信厅信发〔2020〕6号 (Gong Xin Ting Xin Fa [2020] No. 6).  
**Issued February 27, 2020. Effective February 27, 2020.**

> *Translation note — DCC. Translated in full from the official Chinese text
> (issuing notice of the MIIT General Office and the annexed Guide, sixteen
> articles in four chapters). Terminology follows DCC's bilingual glossary. The
> three-level grading introduced here is the precursor of the general / important /
> core data grades in the [Administrative Measures for Data Security in the Field
> of Industry and Information Technology (Trial)](/laws/miit-industrial-data-security-measures/);
> the "Guide to Information Security Protection for Industrial Control Systems"
> cited in Articles 1 and 14 is the 2016 predecessor of the 2024
> [Guide to Cybersecurity Protection for Industrial Control Systems](/laws/ics-cybersecurity-protection-guide/).*

---

## Notice of the General Office of the Ministry of Industry and Information Technology on Issuing the Guide to the Classification and Grading of Industrial Data (Trial)

工信厅信发〔2020〕6号

To the industry and information technology authorities of all provinces, autonomous regions and municipalities directly under the Central Government and of the Xinjiang Production and Construction Corps, and to the relevant central enterprises:

The Guide to the Classification and Grading of Industrial Data (Trial) is hereby issued to you. Please implement it conscientiously in light of actual conditions.

General Office of the Ministry of Industry and Information Technology  
February 27, 2020

---

## Guide to the Classification and Grading of Industrial Data (Trial)

## Chapter I General Provisions

**Article 1.** This Guide is formulated in order to implement the relevant requirements of the Action Outline for Promoting the Development of Big Data and the Big Data Industry Development Plan (2016–2020), to better promote the adoption of the Data Management Capability Maturity Assessment Model (GB/T 36073-2018) and the implementation of the Guide to Information Security Protection for Industrial Control Systems, to guide enterprises in improving their industrial data management capabilities, to promote the use, flow and sharing of industrial data, to release the latent value of data, and to empower the high-quality development of the manufacturing industry.

**Article 2.** Industrial data as referred to in this Guide means data generated and applied over the full lifecycle of products and services in the industrial sector, including but not limited to data generated and used by industrial enterprises in research and development design, production and manufacturing, business management, operation and maintenance services and other stages, and data generated and used by Industrial Internet platform enterprises (hereinafter, platform enterprises) in the course of equipment access, platform operation, industrial app application and other processes.

**Article 3.** This Guide applies to the classification and grading of industrial data carried out by industry and information technology authorities, industrial enterprises, platform enterprises and the like. Industrial data involving State secret information shall comply with the provisions of laws and regulations on the protection of State secrets, and this Guide does not apply to it.

**Article 4.** The classification and grading of industrial data takes the enhancement of enterprises' data management capabilities as its objective, and adheres to the combination of problem orientation, goal orientation and result orientation; the combination of enterprises as the principal actors, industry guidance and territorial supervision; and the combination of classification labeling, grading category by category, and graded management.

## Chapter II Data Classification

**Article 5.** Industrial enterprises, in light of their production and manufacturing models, and platform enterprises, in light of their service operation models, shall analyze and sort out their business processes and system equipment, take into account industry requirements, business scale, data complexity and other actual conditions, classify, sort out and label their industrial data, and form an enterprise industrial data classification list.

**Article 6.** The classification dimensions for the industrial data of industrial enterprises include but are not limited to the research and development data domain (research and development design data, development and testing data, etc.), the production data domain (control information, operating-condition status, process parameters, system logs, etc.), the operation and maintenance data domain (logistics data, product after-sales service data, etc.), the management data domain (system and equipment asset information, customer and product information, product supply chain data, business statistics, etc.), and the external data domain (data shared with other entities, etc.).

**Article 7.** The classification dimensions for the industrial data of platform enterprises include but are not limited to the platform operation data domain (Internet-of-Things collected data, knowledge base and model library data, research and development data, etc.) and the enterprise management data domain (customer data, business cooperation data, personnel and financial data, etc.).

## Chapter III Data Grading

**Article 8.** According to the potential impact that different categories of industrial data may have on industrial production, economic benefits and the like after being tampered with, destroyed, leaked or illegally used, industrial data is divided into three levels: Level 1, Level 2 and Level 3.

**Article 9.** Data whose potential impact meets one of the following conditions is Level 3 data:

(I) it is liable to trigger an especially significant production safety accident or environmental emergency, or to cause especially huge direct economic losses;

(II) it causes serious impact on the national economy, industry development, the public interest, social order or even national security.

**Article 10.** Data whose potential impact meets one of the following conditions is Level 2 data:

(I) it is liable to trigger a relatively significant or significant production safety accident or environmental emergency, to cause relatively significant adverse impact on the enterprise, or to cause relatively significant direct economic losses;

(II) the cascading effect it triggers is evident, the scope of impact involves multiple industries, regions or multiple enterprises within an industry, or the duration of impact is long, or it may lead to a large number of supplier and customer resources being illegally obtained or a large amount of personal information being leaked;

(III) the cost of restoring the industrial data or eliminating the adverse impact is relatively high.

**Article 11.** Data whose potential impact meets one of the following conditions is Level 1 data:

(I) it has relatively minor impact on the normal production and operation of industrial control systems and equipment, Industrial Internet platforms and the like;

(II) it causes relatively minor adverse impact on the enterprise, or relatively minor direct economic losses;

(III) the number of affected users and enterprises is relatively small, the affected production and living area is relatively small, and the duration is relatively short;

(IV) the cost of restoring the industrial data or eliminating the adverse impact is relatively low.

## Chapter IV Graded Management

**Article 12.** The Ministry of Industry and Information Technology is responsible for formulating the system and specifications for industrial data classification and grading, and for guiding and coordinating the conduct of industrial data classification and grading work. Local industry and information technology authorities are responsible for guiding and promoting industrial data classification and grading work within their jurisdictions. The competent authorities of relevant industries and fields may refer to this Guide in guiding and promoting industrial data classification and grading work in their own industries and fields.

**Article 13.** Industrial enterprises, platform enterprises and other enterprises bear primary responsibility for industrial data management, and shall establish and improve relevant management systems, implement classified and graded management of industrial data and conduct annual reviews, and promptly update the classification and grading results when major changes occur in the enterprise's systems, business and the like. Enterprises with the necessary conditions may, in light of actual circumstances, set up a data management body and staff it with full-time personnel.

**Article 14.** Enterprises shall, in accordance with the requirements of the Guide to Information Security Protection for Industrial Control Systems and the like, and in light of the grading of their industrial data, carry out protection work.

The protective measures an enterprise adopts for Level 3 data shall be capable of withstanding large-scale malicious attacks from State-level hostile organizations; the protective measures adopted for Level 2 data shall be capable of withstanding large-scale, relatively strong malicious attacks; and the protective measures adopted for Level 1 data shall be capable of withstanding ordinary malicious attacks.

**Article 15.** Enterprises are encouraged, on the premise of sound data management, to appropriately share Level 1 and Level 2 data so as to fully release the latent value of industrial data. Level 2 data shall be opened only to authorized institutions and relevant personnel that genuinely need to obtain data of that level. Level 3 data shall in principle not be shared; where sharing is truly necessary, the scope of persons with knowledge of it shall be strictly controlled.

**Article 16.** Where industrial data is tampered with, destroyed, leaked or illegally used, the enterprise shall immediately carry out emergency response in accordance with the emergency response plan formulated in advance. Where Level 3 data is involved, the enterprise shall also promptly report the incident to the industry and information technology authority of the province where the data is located, and shall supplement the report with the handling of the incident within 30 days after the conclusion of the emergency work.
