Skip to content
DCC · DATA COMPLIANCE CHINA China data law, for overseas counsel.
§ 091 · CYBERSECURITY-REVIEW

China Opens a Cybersecurity Review of Palo Alto Networks: The Micron Playbook, Now Pointed at Firewalls

The Cybersecurity Review Office's 6 August 2026 announcement (《关于对派拓公司在华销售产品启动网络安全审查的公告》) is an own-motion review under Article 16 of the Cybersecurity Review Measures, not a filing under Article 5 — which is why no company had to declare anything for it to start. Articles 21 and 10 explain why a firewall vendor was always in scope; Articles 11 and 14 set a 30 + 15 / 90 working-day clock; and CSL Article 67, as amended in 2025, prices a failed outcome at 1× to 10× the procurement amount.

On 6 August 2026 the Cybersecurity Review Office announced a cybersecurity review of Palo Alto Networks (派拓公司) products sold in China, citing the National Security Law, the Cybersecurity Law and the Cybersecurity Review Measures. DCC reads the announcement against the Measures themselves. The review is an Article 16 own-motion proceeding initiated by the working mechanism and cleared by the Central Cyberspace Affairs Commission — not the Article 5 pathway where a CIIO declares a procurement — so there is no applicant, no declared transaction, and the Article 11/14 clocks apply only by analogy. Article 21 puts cybersecurity equipment and cloud computing services squarely in scope; Article 10 supplies the risk factors that a cloud-synchronized firewall estate maps onto almost line by line. The operative question for overseas counsel is not what happens now — nothing does — but what a failed outcome would mean: CIIOs must stop procuring, and CSL Article 37/67 as amended in 2025 exposes a CIIO that keeps using un-passed products to a fine of 1× to 10× the procurement amount plus RMB 10,000–100,000 personally. Non-designated companies acquire no legal obligation at all. Based on commentary from 数据何规, checked against the official announcement and the Micron precedent.

Editor’s Note — DCC.

On 6 August 2026 the Cybersecurity Review Office (网络安全审查办公室) announced a cybersecurity review of Palo Alto Networks products sold in China. The notice is three sentences long. It names no product, alleges no vulnerability, and states no possible outcome.

This brief is built on a same-day commentary from 数据何规, which asked the two questions overseas counsel will be asked this week — why Palo Alto, and what should we do — and answered them against the text of the Cybersecurity Review Measures rather than the geopolitics. DCC has verified the announcement against the official CAC posting, and has added three things the original leaves implicit: the procedural pathway this review actually runs on, why that pathway makes the published time limits softer than they look, and what the 2025-amended Cybersecurity Law now prices a failed review at.

One sourcing note. The January 2026 instruction to replace foreign security software, discussed below, rests on foreign press reporting from unnamed sources. No Chinese instrument has ever published it. We treat it as reported background, not as law.

The announcement

The full text, in translation:

Announcement on the Initiation of a Cybersecurity Review of Products Sold in China by Palo Alto Networks

In order to safeguard the secure and stable operation of critical information infrastructure, guard against cybersecurity risks and hidden dangers, and maintain national security, and pursuant to the National Security Law of the People’s Republic of China and the Cybersecurity Law of the People’s Republic of China, the Cybersecurity Review Office is implementing a cybersecurity review, in accordance with the Cybersecurity Review Measures, of the products sold in China by Palo Alto Networks (派拓公司).

Notice is hereby given.

Cybersecurity Review Office 6 August 2026

The scope word is products sold in China (在华销售的产品) — not a transaction, not a customer, not a named SKU. That phrasing is inherited directly from the Micron announcement of 31 March 2023, and it is the first signal of which procedural track this is running on.

Article 16, not Article 5 — and why that matters

The Cybersecurity Review Measures describe two ordinary ways a review begins. Under Article 5, a critical information infrastructure operator that is buying network products or services pre-judges the national-security risk and declares the procurement to the Office. Under Article 7, a network platform operator holding the personal information of more than one million users declares before listing abroad. Both are applicant-initiated: there is a filing, a filer, and a specific transaction under review.

Neither describes what happened on 6 August. No CIIO declared a Palo Alto purchase. The announcement is instead an Article 16 proceeding:

Where a member of the cybersecurity review working mechanism believes that a network product or service or data processing activity affects or may affect national security, the Office of Cybersecurity Review shall report the same to the Central Cyberspace Affairs Commission for approval under procedures, and then conduct review in accordance with the present Measures.

Three consequences follow, and they are the ones worth carrying into a client call.

First, there is no applicant. The review’s subject is a vendor’s product line in the abstract, which is why the announcement can be addressed to the public rather than to a party. Palo Alto is the object of the review, not a declarant, and the working mechanism — the CAC plus twelve ministries — is the moving party.

Second, it has already cleared the top of the system. Article 16 requires the matter to be reported to the Central Cyberspace Affairs Commission for approval before the review begins. An Article 16 announcement is therefore not an opening bid. The decision to look has been taken at the political level; only the finding remains open.

Third, the published clocks apply only by analogy. Article 11 gives the Office 30 working days for preliminary review, extendable by 15 for complicated cases, and Article 14 gives special review procedures 90 working days — but each of those periods runs “from the date when it issues a written notice to the party.” In an own-motion review with no declarant, the trigger date is not public. The honest answer to “how long?” is therefore not the statutory arithmetic but the Micron precedent: review announced 31 March 2023, failure announced 21 May 2023 — about seven weeks.

Article 16 carries one more sentence that counsel should not skip: during the review, “the party shall take measures to prevent and mitigate risks in accordance with the requirements of the cybersecurity review.” Interim requirements can attach before any finding is published.

Why a firewall vendor was always in scope

数据何规’s most useful move is to show that nothing about this target is jurisdictionally novel. Article 21 defines the reviewable universe:

core network equipment, important communication products, high-performance computers and servers, mass storage devices, large databases and application software, cybersecurity equipment, cloud computing services, and other network products and services that have a significant impact on the security of critical information infrastructure.

Firewalls and intrusion-prevention systems sit at the network boundary of a CII estate and can inspect, filter or sever traffic outright. They are cybersecurity equipment in the plainest sense, and they are exactly the category the drafters had in mind.

The commentary also makes a point that matters for scoping the review: the Measures do not separate hardware from software. The object is the complete network product or service. For a physical PA-series firewall, that means the appliance, its embedded operating-system firmware, and the cloud-delivered updates and remote maintenance service behind it. For VM-series virtual firewalls and the cloud security platforms, the software system and the service are reviewed as one whole. The author’s own mapping of the China product line — PA-series next-generation firewalls with Panorama central management, VM-series virtual firewalls, container security, the Prisma cloud-security and Cortex security-operations platforms, plus threat subscription licences — is his reconstruction, not the regulator’s; CAC named nothing.

Run that estate against Article 10, which lists what the review assesses, and the fit is uncomfortably close:

Article 10 risk factorWhat it touches in a modern security stack
(I) Illegal control, interference or destruction of CII through use of the productRemote maintenance and firmware push into a boundary device
(II) Harm to business continuity from supply interruptionAn expired subscription silently degrades protection
(III) Supply interruption from political, diplomatic or trade factorsThe live question in 2026
(V) Theft, disclosure, damage, illegal use or cross-border transfer of core data, important data or large volumes of personal informationGlobal telemetry upload and cloud threat-intelligence sync

数据何规 notes an analyst view — his framing, not an official finding — that Western security platforms depend heavily on cloud threat-intelligence synchronization and worldwide telemetry upload, and that this combination of real-time callback and remote control is what drives supply-chain concern about covert access. Whether or not one credits that reading, it explains what the announcement means by “guard against cybersecurity risks and hidden dangers”: the firmware-update, threat-subscription and remote-operations channels are precisely where Article 10’s factors intersect.

What companies should actually do: nothing, yet

The short answer in the original is the right one. At this stage no action is required of anyone. A review has been announced; no product has failed anything, and no procurement restriction is in force. The value of the moment is preparation, and it divides cleanly.

If a failed outcome arrives, CIIOs are the ones with a legal problem. Article 37 of the Cybersecurity Law requires CIIOs to put national-security- relevant network procurement through review; the 2025 amendment sharpened what happens if they don’t. Article 67 now reads:

Where operators of critical information infrastructure, in violation of Article 37 of this Law, use network products or services that have not undergone security review or have not passed security review, the competent authorities shall order corrections within a time limit, order cessation of use, eliminate the impact on national security, and impose a fine of not less than one time but not more than ten times the procurement amount, and a fine of not less than RMB 10,000 but not more than RMB 100,000 shall be imposed on the person-in-charge directly responsible and other directly liable persons.

That is the number to put in front of a Chinese subsidiary’s board. The exposure scales with the size of the deployment rather than sitting under a fixed cap, it attaches to continued use and not merely to fresh purchasing, and it reaches named individuals. Contractual and technical controls — supply agreements, undertakings, procurement gating — are the mechanism for stopping further acquisition, though as 数据何规 observes drily, most state-invested CIIOs stopped buying foreign network-security products some time ago.

If a company has not been notified that it is a CIIO, nothing follows. This is the point most often lost in the coverage. The Article 37/67 duty attaches to designated operators, and designation is a notified status under the CII regime, not a self-assessment — DCC has set out how that determination works, and how it interacts with important-data handler status. An ordinary enterprise that has never received a designation notice acquires no obligation from this announcement. It may still choose to prefer alternative vendors on supply-continuity grounds, which is a procurement judgment rather than a compliance one.

The original closes with an observation worth repeating to any foreign multinational in China: for a local entity that has been carrying headquarters-mandated global security tooling it never chose, a review outcome is leverage. The localization argument that lost every year on cost may win this one on law.

The escalation is the story, not the target.

In January 2026, foreign outlets reported — citing people familiar, never a published instrument — that Chinese authorities had told domestic organizations to stop using cybersecurity products from more than a dozen US and Israeli vendors, Palo Alto among them alongside Fortinet, Check Point, Broadcom’s VMware, CrowdStrike and Mandiant, and to substitute domestic technology during the first half of 2026. Whatever its status, guidance of that kind produces no reviewable decision, no defined procedure and no appealable finding.

The 6 August announcement converts that posture into a statutory proceeding with a named legal basis, a defined process, and an outcome that binds CIIOs by operation of the Cybersecurity Law. That is a different instrument entirely, and it is the one overseas counsel can actually plan against.

It is also worth situating precisely. Cybersecurity review is one of four distinct security-review regimes a single company can face in China, and it is an ex-ante, admission-style review with veto power rather than a penalty proceeding — DCC has mapped all four regimes and how they differ. The finality point from that analysis carries directly here: review decisions are generally treated as final administrative acts, with no realistic route through administrative reconsideration or litigation. Cooperation during the review is not one strategy among several. It is the strategy.

For now the file stays open, the clock is unpublished, and the only defensible advice is the boring one: establish whether the entity is a designated CIIO, inventory the affected estate, and wait.


Source: 数据何规, 《派拓被网络安全审查,为啥?企业咋办?》, WeChat Official Account, 6 August 2026 — original. The announcement text is translated by DCC from the official posting by the Cybersecurity Review Office via the Cyberspace Administration of China, 6 August 2026. Article 10, 11, 14, 16 and 21 quotations are from DCC’s translation of the Cybersecurity Review Measures; Articles 37 and 67 from the Cybersecurity Law as amended in 2025.

— Not legal advice.

— Not legal advice.


§ SUBSCRIBE

The Monday brief.

One short email every Monday. New briefs on Chinese data-compliance rules from the previous week, with the source law cited.

Opt-in only. Unsubscribe anytime by replying "unsubscribe" to any issue.

SUPPORT DCC

Keep the publication free to read. Suggested support is $19.99, or choose your own amount.

Support →