China introduces new requirements for network data security risk assessments
知识亮点 27 August 2026
On 20 August 2026, China’s Measures for Network Data Security Risk Assessment (Order No. 24) came into effect (“Measures”). The Measures, issued by Cyberspace Administration of China (“CAC”), the Ministry of Industry and Information Technology, and the Ministry of Public Security and adopted on 1 June 2026, are the first joint departmental rules dedicated specifically to data security risk assessment activities.
The Measures implement the Data Security Law, the Cybersecurity Law, and the Regulations on Network Data Security Management, and convert what had previously been a general statutory obligation into a defined process with identified obligors, fixed timelines, reporting channels, quality controls on assessment service providers, and administrative consequences.
For businesses processing important data in China, the practical significance is that the annual risk assessment is no longer merely an internal governance exercise, but a formal reporting obligation subject to more detailed procedures and regulatory scrutiny. The resulting assessment report must be submitted to the relevant authorities, retained as evidence of compliance, and is subject to verification.
This article provides an overview of the key data security risk assessment requirements set out in the Measures.
Key assessment requirements
Frequency
China’s Data Security Law establishes a three-tier data protection framework comprising general data, important data, and core data, with more stringent protection requirements applying as the importance of the data increases. The specific identification and cataloguing of important data is further developed through national, sectoral, and regional rules.
Processors of important data (“Important Data Processors”) must conduct a risk assessment every year. Where the security status of important data changes materially in a way that may adversely affect data security, the Important Data Processor must promptly assess the changed portion and its impact, without waiting for the annual cycle. Processors of general data are encouraged, but not required, to conduct an assessment at least once every three years.
This means the threshold question for any network data processor operating in China is whether it processes data that has been identified as important data. Companies that have not yet completed important data identification against national, sector, and regional catalogues will find it difficult to determine which regime applies to them, and identification work should be prioritised before determining the applicable assessment and reporting timeframe.
Conduct
Network data processors may conduct assessments themselves - in which case a dedicated responsible person must be designated - or engage a third-party assessment institution under a contract or other legally effective document specifying the parties’ respective rights and obligations. Certification of assessment institutions is encouraged and follows the Regulations on Certification and Accreditation.
Critically, under Article 17, provincial-level or higher cyberspace, telecommunications, and public security authorities may require a processor to engage a certified assessment institution where: (i) its data processing activities present relatively significant security risks that may endanger national security or the public interest; (ii) a network data security incident has occurred resulting in leakage or theft of important data or large-scale personal information; or (iii) other circumstances prescribed by the authorities apply. The Measures expressly prohibit repeated demands for a third-party assessment in respect of the same incident or risk.
Where an assessment is conducted at the authorities’ direction, the processor must provide the necessary access to data facilities, data, systems and operation logs; complete the assessment within the prescribed period (extendable with approval where circumstances are complex); submit the report signed by the institution’s principal and the assessment leader and bearing the institution’s seal; and submit a rectification report within 15 working days after completing the required rectification. Processors are prohibited from requiring or hinting that an institution should issue an untrue or improper report.
Separately, the Measures confirm that risk assessment for core data processors follows separate national rules, and that where encryption or similar technical measures apply to important data, a commercial cryptography application security assessment must also be conducted under applicable cryptography laws and regulations.
Timelines
Important Data Processors must submit the annual risk assessment report to the competent authority within 20 working days of completing the assessment. Where no competent authority is clearly identified, the report should be provided to the provincial or national cyberspace authority. The receiving authority must forward the report to the cyberspace authority at the same level within 10 working days, and CAC aggregates reports and shares them with telecommunications, public security and state security authorities.
Annual risk assessment reports prepared by Important Data Processors must be retained for at least three years, and authorities at provincial level or above may check and verify the authenticity and accuracy of the report, with the processor obliged to cooperate. This effectively converts the report into a compliance record that must withstand later scrutiny - the underlying evidence base (that is, asset inventories, logs, and prior assessment materials) should be retained for the same timeframe. Although the Measures do not expressly impose the same three-year retention period on the underlying evidence base, it would be prudent to retain relevant materials for a corresponding period.
Restrictions
Assessment institutions may not sub-delegate assessment work. The same institution and its affiliates may not conduct three or more consecutive annual assessments for the same processor, effectively introducing a rotation requirement modelled on audit independence norms. Assessment institutions must promptly notify the processor of any major data security risks identified during the assessment, keep confidential the data, trade secrets, and confidential business information obtained in the course of the assessment, and delete or properly dispose of such information after the assessment.
For multinational groups, these confidentiality and disposal requirements should be addressed in engagement documentation, particularly where the assessment involves group-shared systems or data transfers to offshore recipients. Any offshore access to or transfer of assessment data must also be separately assessed under China’s applicable data export and confidentiality requirements.
Penalties
Where a risk assessment identifies that an Important Data Processor’s data processing activities may endanger national security or the public interest, the relevant authority must order the processor to rectify the identified risks. If the processor refuses to rectify or fails to meet the rectification requirements, the authority may require it to cease processing important data. Failure to conduct a risk assessment as required may result in enforcement action under the Data Security Law and the Regulations on Network Data Security Management.