---
title_en: "Provisions on the Security Assessment of Internet Information Services with Public Opinion Attributes or Social Mobilization Capacity"
title_zh: "具有舆论属性或社会动员能力的互联网信息服务安全评估规定"
abbreviation: "Security Assessment Provisions"
hierarchy: "rule"
issuing_body: "CAC + MPS"
adopted_date: 2018-11-15
effective_date: 2018-11-30
status: "effective"
related_laws: ["csl", "genai-services-interim-measures", "deep-synthesis-provisions", "algorithmic-recommendation-provisions", "ai-content-labeling-measures"]
domains: ["ai-governance", "data-security", "app-compliance"]
url: https://datacompliancechina.com/laws/public-opinion-security-assessment-provisions/
summary: "The 2018 CAC/MPS self-assessment-and-file regime for internet information services that carry 'public opinion attributes or social mobilization capacity' (具有舆论属性或社会动员能力) — forums, public accounts, short video, live streaming, mini-programs, and any service offering a public expression channel. Long treated as a content-governance formality, it is now the enforcement hook behind China's AI rules: Article 17 of the Generative AI Interim Measures and Article 20 of the Deep Synthesis Provisions both route their security-assessment duty through these Provisions. Five triggers (launch, material change, user-scale growth, spread of unlawful information, or written notice from a municipal-level authority); the report goes to the local CAC office and public security organ through the National Internet Security Management Service Platform."
---

> **Source: Data Compliance China** — https://datacompliancechina.com/laws/public-opinion-security-assessment-provisions/ · English rendering and annotations by DCC; the Chinese original governs. Cite as: Data Compliance China, "Provisions on the Security Assessment of Internet Information Services with Public Opinion Attributes or Social Mobilization Capacity", https://datacompliancechina.com/laws/public-opinion-security-assessment-provisions/
**Promulgated by:** Cyberspace Administration of China and Ministry of Public Security.
**Released November 15, 2018. Effective November 30, 2018.**

> *Translation note — DCC.* 舆论属性 is rendered "public opinion attributes"
> and 社会动员能力 "social mobilization capacity", tracking the official
> usage carried into the Generative AI Interim Measures. The assessment
> under these Provisions is a **self-assessment filed with the authorities**
> (自行开展安全评估), not a government approval — a distinction that matters
> when advising on sequencing, because the filing must precede launch.

---

**Article 1.** These Provisions are formulated in accordance with the
Cybersecurity Law of the People's Republic of China, the Measures for the
Administration of Internet Information Services, and the Measures for the
Administration of the Security Protection of the International Networking of
Computer Information Networks, in order to strengthen the security management
of internet information services with public opinion attributes or social
mobilization capacity and of related new technologies and new applications, to
regulate internet information service activities, and to safeguard national
security, social order and the public interest.

**Article 2.** Internet information services with public opinion attributes or
social mobilization capacity, as referred to in these Provisions, include the
following circumstances:

(1) operating information services such as forums, blogs, microblogs, chat
rooms, communication groups, public accounts, short video, live streaming,
information sharing, and mini-programs, or attaching corresponding functions;

(2) operating other internet information services that provide a channel for
the expression of public opinion or that have the capacity to mobilize members
of the public to engage in specific activities.

**Article 3.** An internet information service provider shall, where any of the
following circumstances applies, carry out a security assessment on its own in
accordance with these Provisions, and shall be responsible for the assessment
result:

(1) an information service with public opinion attributes or social
mobilization capacity is launched, or relevant functions are added to an
information service;

(2) the use of new technologies or new applications causes material changes to
the functional attributes, technical implementation method, or basic resource
allocation of the information service, resulting in a material change in its
public opinion attributes or social mobilization capacity;

(3) the scale of users increases significantly, resulting in a material change
in the public opinion attributes or social mobilization capacity of the
information service;

(4) unlawful or harmful information is disseminated and spread, indicating that
the existing security measures are inadequate to effectively prevent and control
cybersecurity risks;

(5) other circumstances in which a cyberspace administration department or
public security organ at or above the municipal level gives written notice that
a security assessment is required.

**Article 4.** An internet information service provider may carry out the
security assessment itself, or may entrust a third-party security assessment
institution to carry it out.

**Article 5.** In carrying out a security assessment, an internet information
service provider shall comprehensively assess the legality of the information
service and of the new technologies and new applications, the effectiveness of
its implementation of the security measures prescribed by laws, administrative
regulations, departmental rules and standards, and the effectiveness of its
prevention and control of security risks, and shall assess the following
matters as key items:

(1) the determination of a person responsible for security management and of
information review personnel commensurate with the services provided, or the
establishment of a security management body;

(2) measures for verifying users' true identities and for retaining
registration information;

(3) measures for retaining log information such as users' accounts, operation
times, operation types, network source addresses and destination addresses,
network source ports, and client hardware characteristics, as well as records of
information published by users;

(4) measures for preventing and disposing of unlawful and harmful information,
and for preserving relevant records, in user account and communication group
names, nicknames, profiles, remarks and identifiers, and in service functions
such as information publication, forwarding, commenting and communication
groups;

(5) technical measures for personal information protection and for preventing
the dissemination and spread of unlawful and harmful information and the risk of
loss of control over social mobilization functions;

(6) the establishment of complaint and reporting systems, the publication of
complaint and reporting channels and other information, and the timely
acceptance and handling of relevant complaints and reports;

(7) the establishment of a working mechanism to provide technical and data
support and assistance for cyberspace administration departments to perform
their supervision and administration duties over internet information services
in accordance with the law;

(8) the establishment of a working mechanism to provide technical and data
support and assistance for public security organs and state security organs to
safeguard national security and to investigate and handle unlawful and criminal
acts in accordance with the law.

**Article 6.** Where an internet information service provider discovers a
security hazard in the course of a security assessment, it shall rectify it
promptly, until the relevant security hazard is eliminated.

Where, having undergone the security assessment, the service conforms to laws,
administrative regulations, departmental rules and standards, a security
assessment report shall be prepared. The security assessment report shall
include the following:

(1) basic particulars of the internet information service, including its
functions, service scope, software and hardware facilities and deployment
locations, and the status of the acquisition of relevant licences and
certificates;

(2) the implementation of security management systems and technical measures,
and the effectiveness of risk prevention and control;

(3) the conclusion of the security assessment;

(4) other relevant matters that should be explained.

**Article 7.** An internet information service provider shall submit the
security assessment report, through the National Internet Security Management
Service Platform, to the cyberspace administration department and the public
security organ at or above the municipal level in the place where it is located.

Where circumstance (1) or (2) of Article 3 of these Provisions applies, the
internet information service provider shall submit the security assessment
report **before** the information service or the new technology or new
application goes online or the function is added; where circumstance (3), (4) or
(5) of Article 3 of these Provisions applies, it shall submit the security
assessment report within 30 working days from the date on which the relevant
circumstance arises.

**Article 8.** Cyberspace administration departments and public security organs
at or above the municipal level shall conduct a documentary review of security
assessment reports in accordance with their respective duties.

Where it is found that the content or items of a security assessment report are
missing, or that the security assessment method is manifestly improper, they
shall order the internet information service provider to conduct the assessment
again within a specified period.

Where it is found that the content of a security assessment report is unclear,
they may order the internet information service provider to provide a
supplementary explanation.

**Article 9.** Where, on the basis of the documentary review of a security
assessment report, the cyberspace administration department and the public
security organ consider it necessary, they shall conduct an on-site inspection
of the internet information service provider in accordance with their respective
duties.

On-site inspections by cyberspace administration departments and public security
organs shall in principle be carried out jointly, and shall not interfere with
the normal business activities of the internet information service provider.

**Article 10.** For an internet information service that presents relatively
large security risks and may affect national security, social order or the
public interest, the cyberspace administration department and the public
security organ at or above the provincial level shall organize experts to
conduct a review, and may, where necessary, carry out an on-site inspection
together with the relevant local departments.

**Article 11.** On-site inspections by cyberspace administration departments and
public security organs shall be conducted in accordance with the provisions of
the relevant laws, administrative regulations and departmental rules.

**Article 12.** Cyberspace administration departments and public security organs
shall establish monitoring and management systems, strengthen cybersecurity risk
management, and urge internet information service providers to perform their
cybersecurity obligations in accordance with the law.

Where it is found that a provider of an internet information service with public
opinion attributes or social mobilization capacity has not carried out a
security assessment in accordance with these Provisions, the cyberspace
administration department and the public security organ shall notify it to carry
out a security assessment in accordance with these Provisions.

**Article 13.** Where a cyberspace administration department or public security
organ finds that a provider of an internet information service with public
opinion attributes or social mobilization capacity refuses to carry out a
security assessment in accordance with these Provisions, it shall, through the
National Internet Security Management Service Platform, alert the public that
the internet information service presents security risks, and shall supervise
and inspect the internet information service in accordance with its respective
duties; where unlawful acts are found to exist, it shall handle them in
accordance with the law.

**Article 14.** Cyberspace administration departments shall coordinate the
security assessment work for internet information services with public opinion
attributes or social mobilization capacity, and public security organs shall
periodically report their security assessment work to the cyberspace
administration departments.

**Article 15.** Cyberspace administration departments, public security organs
and their staff shall strictly keep confidential any state secrets, trade
secrets and personal information of which they become aware in the performance
of their duties, and shall not divulge, sell or unlawfully provide the same to
others.

**Article 16.** The security assessment of new technologies and new applications
of internet news information services shall be carried out in accordance with
the Provisions on the Administration of Security Assessment of New Technologies
and New Applications of Internet News Information Services.

**Article 17.** These Provisions take effect on November 30, 2018.

---

## Why this 2018 rule matters now

For most of its life this instrument was read as a content-governance
formality — the filing you made before launching a forum or a public account.
Two later rules turned it into the enforcement hook for AI:

- **Article 17 of the [Generative AI Interim
  Measures](/laws/genai-services-interim-measures/)** requires a provider of
  GenAI services with public opinion attributes or social mobilization capacity
  to carry out a security assessment "in accordance with the relevant
  provisions of the State" — these Provisions.
- **Article 20 of the [Deep Synthesis
  Provisions](/laws/deep-synthesis-provisions/)** imposes the same duty on deep
  synthesis providers launching new products, applications or functions with
  those attributes.

Neither AI rule contains its own assessment procedure. The procedure, the
triggers, the report contents, and the filing channel all live here. In the
CAC's September 2026 enforcement batch, two of the ten cases were charged in
part under these Provisions — one of them resulting in an order to take a
mini-program offline. See [the DCC brief on that
batch](/posts/cac-enforcement-cases-september-2026/).

**Source:** [www.gov.cn](https://www.gov.cn/zhengce/zhengceku/2018-11/30/content_5457763.htm) ·
[www.cac.gov.cn](https://www.cac.gov.cn/2018-11/15/c_1123716072.htm)
