---
title: "China Opens a Cybersecurity Review of Palo Alto Networks: The Micron Playbook, Now Pointed at Firewalls"
author: "DCC Editorial"
published: 2026-08-07T03:00:00.000Z
url: https://datacompliancechina.com/posts/palo-alto-cybersecurity-review-article-16/
description: "On 6 August 2026 the Cybersecurity Review Office announced a cybersecurity review of Palo Alto Networks (派拓公司) products sold in China, citing the National Security Law, the Cybersecurity Law and the Cybersecurity Review Measures. DCC reads the announcement against the Measures themselves. The review is an Article 16 own-motion proceeding initiated by the working mechanism and cleared by the Central Cyberspace Affairs Commission — not the Article 5 pathway where a CIIO declares a procurement — so there is no applicant, no declared transaction, and the Article 11/14 clocks apply only by analogy. Article 21 puts cybersecurity equipment and cloud computing services squarely in scope; Article 10 supplies the risk factors that a cloud-synchronized firewall estate maps onto almost line by line. The operative question for overseas counsel is not what happens now — nothing does — but what a failed outcome would mean: CIIOs must stop procuring, and CSL Article 37/67 as amended in 2025 exposes a CIIO that keeps using un-passed products to a fine of 1× to 10× the procurement amount plus RMB 10,000–100,000 personally. Non-designated companies acquire no legal obligation at all. Based on commentary from 数据何规, checked against the official announcement and the Micron precedent."
tags: ["cybersecurity-review", "palo-alto-networks", "派拓", "micron", "critical-information-infrastructure", "ciio", "supply-chain-security", "national-security", "cac", "network-products-and-services", "csl", "procurement"]
laws_cited: ["cybersecurity-review-measures", "csl", "dsl", "cii-protection-regulations"]
domains: ["cybersecurity-review", "critical-information-infrastructure", "data-security"]
account: "data-he-gui"
original_title: "派拓被网络安全审查，为啥？企业咋办？"
original_author: "数据何规"
original_publication: "数据何规 WeChat Official Account"
original_url: "https://mp.weixin.qq.com/s/Ij41rNi4iCzNlun0ZSU0Pg"
source_language: "zh"
---

> **Source: Data Compliance China** — https://datacompliancechina.com/posts/palo-alto-cybersecurity-review-article-16/ · China data law, translated and annotated for overseas counsel. Cite as: Data Compliance China, "China Opens a Cybersecurity Review of Palo Alto Networks: The Micron Playbook, Now Pointed at Firewalls", https://datacompliancechina.com/posts/palo-alto-cybersecurity-review-article-16/
> *Editor's Note — DCC.*
>
> On **6 August 2026** the Cybersecurity Review Office (网络安全审查办公室)
> announced a cybersecurity review of Palo Alto Networks products sold in
> China. The notice is three sentences long. It names no product, alleges no
> vulnerability, and states no possible outcome.
>
> This brief is built on a same-day commentary from **数据何规**, which asked
> the two questions overseas counsel will be asked this week — *why Palo Alto,
> and what should we do* — and answered them against the text of
> [the Cybersecurity Review Measures](/laws/cybersecurity-review-measures/)
> rather than the geopolitics. DCC has verified the announcement against the
> official CAC posting, and has added three things the original leaves
> implicit: the procedural pathway this review actually runs on, why that
> pathway makes the published time limits softer than they look, and what the
> 2025-amended Cybersecurity Law now prices a failed review at.
>
> One sourcing note. The January 2026 instruction to replace foreign security
> software, discussed below, rests on foreign press reporting from unnamed
> sources. No Chinese instrument has ever published it. We treat it as
> reported background, not as law.

## The announcement

The full text, in translation:

> **Announcement on the Initiation of a Cybersecurity Review of Products Sold
> in China by Palo Alto Networks**
>
> In order to safeguard the secure and stable operation of critical
> information infrastructure, guard against cybersecurity risks and hidden
> dangers, and maintain national security, and pursuant to the *National
> Security Law of the People's Republic of China* and the *Cybersecurity Law
> of the People's Republic of China*, the Cybersecurity Review Office is
> implementing a cybersecurity review, in accordance with the *Cybersecurity
> Review Measures*, of the products sold in China by Palo Alto Networks
> (派拓公司).
>
> Notice is hereby given.
>
> Cybersecurity Review Office
> 6 August 2026

The scope word is **products sold in China** (在华销售的产品) — not a
transaction, not a customer, not a named SKU. That phrasing is inherited
directly from the Micron announcement of 31 March 2023, and it is the first
signal of which procedural track this is running on.

## Article 16, not Article 5 — and why that matters

The Cybersecurity Review Measures describe two ordinary ways a review begins.
Under **Article 5**, a critical information infrastructure operator that is
buying network products or services pre-judges the national-security risk and
declares the procurement to the Office. Under **Article 7**, a network
platform operator holding the personal information of more than one million
users declares before listing abroad. Both are *applicant-initiated*: there is
a filing, a filer, and a specific transaction under review.

Neither describes what happened on 6 August. No CIIO declared a Palo Alto
purchase. The announcement is instead an **Article 16** proceeding:

> Where a member of the cybersecurity review working mechanism believes that a
> network product or service or data processing activity affects or may affect
> national security, the Office of Cybersecurity Review shall report the same
> to the Central Cyberspace Affairs Commission for approval under procedures,
> and then conduct review in accordance with the present Measures.

Three consequences follow, and they are the ones worth carrying into a client
call.

**First, there is no applicant.** The review's subject is a vendor's product
line in the abstract, which is why the announcement can be addressed to the
public rather than to a party. Palo Alto is the object of the review, not a
declarant, and the working mechanism — the CAC plus twelve ministries — is the
moving party.

**Second, it has already cleared the top of the system.** Article 16 requires
the matter to be reported to the **Central Cyberspace Affairs Commission** for
approval *before* the review begins. An Article 16 announcement is therefore
not an opening bid. The decision to look has been taken at the political
level; only the finding remains open.

**Third, the published clocks apply only by analogy.** Article 11 gives the
Office 30 working days for preliminary review, extendable by 15 for
complicated cases, and Article 14 gives special review procedures 90 working
days — but each of those periods runs "from the date when it issues a written
notice to *the party*." In an own-motion review with no declarant, the
trigger date is not public. The honest answer to "how long?" is therefore not
the statutory arithmetic but the **Micron precedent**: review announced 31
March 2023, failure announced 21 May 2023 — about seven weeks.

Article 16 carries one more sentence that counsel should not skip: during the
review, "the party shall take measures to prevent and mitigate risks in
accordance with the requirements of the cybersecurity review." Interim
requirements can attach before any finding is published.

## Why a firewall vendor was always in scope

数据何规's most useful move is to show that nothing about this target is
jurisdictionally novel. **Article 21** defines the reviewable universe:

> core network equipment, important communication products, high-performance
> computers and servers, mass storage devices, large databases and application
> software, **cybersecurity equipment, cloud computing services**, and other
> network products and services that have a significant impact on the security
> of critical information infrastructure.

Firewalls and intrusion-prevention systems sit at the network boundary of a
CII estate and can inspect, filter or sever traffic outright. They are
cybersecurity equipment in the plainest sense, and they are exactly the
category the drafters had in mind.

The commentary also makes a point that matters for scoping the review:
**the Measures do not separate hardware from software.** The object is the
complete network product or service. For a physical PA-series firewall, that
means the appliance, its embedded operating-system firmware, *and* the
cloud-delivered updates and remote maintenance service behind it. For
VM-series virtual firewalls and the cloud security platforms, the software
system and the service are reviewed as one whole. The author's own mapping of
the China product line — PA-series next-generation firewalls with Panorama
central management, VM-series virtual firewalls, container security, the
Prisma cloud-security and Cortex security-operations platforms, plus threat
subscription licences — is his reconstruction, not the regulator's; CAC named
nothing.

Run that estate against **Article 10**, which lists what the review assesses,
and the fit is uncomfortably close:

| Article 10 risk factor | What it touches in a modern security stack |
|---|---|
| (I) Illegal control, interference or destruction of CII through use of the product | Remote maintenance and firmware push into a boundary device |
| (II) Harm to business continuity from supply interruption | An expired subscription silently degrades protection |
| (III) Supply interruption from political, diplomatic or trade factors | The live question in 2026 |
| (V) Theft, disclosure, damage, illegal use or **cross-border transfer** of core data, important data or large volumes of personal information | Global telemetry upload and cloud threat-intelligence sync |

数据何规 notes an analyst view — his framing, not an official finding — that
Western security platforms depend heavily on cloud threat-intelligence
synchronization and worldwide telemetry upload, and that this combination of
real-time callback and remote control is what drives supply-chain concern
about covert access. Whether or not one credits that reading, it explains what
the announcement means by "guard against cybersecurity risks and hidden
dangers": the firmware-update, threat-subscription and remote-operations
channels are precisely where Article 10's factors intersect.

## What companies should actually do: nothing, yet

The short answer in the original is the right one. **At this stage no action
is required of anyone.** A review has been announced; no product has failed
anything, and no procurement restriction is in force. The value of the moment
is preparation, and it divides cleanly.

**If a failed outcome arrives, CIIOs are the ones with a legal problem.**
Article 37 of the Cybersecurity Law requires CIIOs to put national-security-
relevant network procurement through review; the [2025 amendment](/posts/compliance-talker-csl-2025-amendment-ai-and-penalties/)
sharpened what happens if they don't. Article 67 now reads:

> Where operators of critical information infrastructure, in violation of
> Article 37 of this Law, use network products or services that have not
> undergone security review or **have not passed security review**, the
> competent authorities shall order corrections within a time limit, order
> cessation of use, eliminate the impact on national security, and impose a
> fine of **not less than one time but not more than ten times the procurement
> amount**, and a fine of not less than RMB 10,000 but not more than RMB
> 100,000 shall be imposed on the person-in-charge directly responsible and
> other directly liable persons.

That is the number to put in front of a Chinese subsidiary's board. The
exposure scales with the size of the deployment rather than sitting under a
fixed cap, it attaches to *continued use* and not merely to fresh purchasing,
and it reaches named individuals. Contractual and technical controls — supply
agreements, undertakings, procurement gating — are the mechanism for stopping
further acquisition, though as 数据何规 observes drily, most state-invested
CIIOs stopped buying foreign network-security products some time ago.

**If a company has not been notified that it is a CIIO, nothing follows.**
This is the point most often lost in the coverage. The Article 37/67 duty
attaches to designated operators, and designation is a notified status under
the CII regime, not a self-assessment — DCC has set out
[how that determination works, and how it interacts with important-data handler
status](/posts/assessing-cii-operator-important-data-handler-status/). An
ordinary enterprise that has never received a designation notice acquires no
obligation from this announcement. It may still choose to prefer alternative
vendors on supply-continuity grounds, which is a procurement judgment rather
than a compliance one.

The original closes with an observation worth repeating to any foreign
multinational in China: for a local entity that has been carrying
headquarters-mandated global security tooling it never chose, a review outcome
is leverage. The localization argument that lost every year on cost may win
this one on law.

## The signal: informal guidance became a legal instrument

The escalation is the story, not the target.

In **January 2026**, foreign outlets reported — citing people familiar, never
a published instrument — that Chinese authorities had told domestic
organizations to stop using cybersecurity products from more than a dozen US
and Israeli vendors, Palo Alto among them alongside Fortinet, Check Point,
Broadcom's VMware, CrowdStrike and Mandiant, and to substitute domestic
technology during the first half of 2026. Whatever its status, guidance of
that kind produces no reviewable decision, no defined procedure and no
appealable finding.

The 6 August announcement converts that posture into a statutory proceeding
with a named legal basis, a defined process, and an outcome that binds CIIOs
by operation of the Cybersecurity Law. That is a different instrument
entirely, and it is the one overseas counsel can actually plan against.

It is also worth situating precisely. Cybersecurity review is one of four
distinct security-review regimes a single company can face in China, and it is
an *ex-ante, admission-style* review with veto power rather than a penalty
proceeding — DCC has mapped
[all four regimes and how they differ](/posts/china-four-security-review-matrices/).
The finality point from that analysis carries directly here: review decisions
are generally treated as final administrative acts, with no realistic route
through administrative reconsideration or litigation. Cooperation during the
review is not one strategy among several. It is the strategy.

For now the file stays open, the clock is unpublished, and the only defensible
advice is the boring one: establish whether the entity is a designated CIIO,
inventory the affected estate, and wait.

---

**Source:** 数据何规, 《派拓被网络安全审查，为啥？企业咋办？》, WeChat Official
Account, 6 August 2026 —
[original](https://mp.weixin.qq.com/s/Ij41rNi4iCzNlun0ZSU0Pg). The announcement
text is translated by DCC from the official posting by the Cybersecurity Review
Office via the Cyberspace Administration of China, 6 August 2026. Article 10,
11, 14, 16 and 21 quotations are from DCC's translation of
[the Cybersecurity Review Measures](/laws/cybersecurity-review-measures/);
Articles 37 and 67 from [the Cybersecurity Law as amended in 2025](/laws/csl/).

— Not legal advice.
