• About Us
  • People
    • Matthew Murphy
    • Ellen Wang
    • Yu Du
    • Xia Yu
    • Sarah Xuan
  • Practice Areas
    • Intellectual Property
    • Technology
    • Corporate
    • International Trade
    • International Arbitration
  • Insights
  • Accolades
  • Locations
  • Contact Us
  • 中文

China Releases New Measures on Cyber Data Security Risk Assessments

Published 22 June 2026 Yu Du
On 18 June 2026, the Cyberspace Administration of China (“CAC”) released the Measures on Cyber Data Security Risk Assessments (the “Measures”), jointly formulated with the Ministry of Industry and Information Technology and the Ministry of Public Security.
The Measures provide implementing rules for the risk assessment obligations under the Data Security Law and the Regulations on the Administration of Cyber Data Security, which require processors of important data to conduct annual risk assessments of their cyber data processing activities. The Measures will take effect on 20 August 2026.
Set out below is a summary of the key requirements under the Measures.
1. Scope of Application
The Measures apply to cyber data security risk assessment activities carried out within the territory of the People’s Republic of China.
A “cyber data security risk assessment” refers to the identification, analysis and evaluation of risks relating to cyber data and cyber data processing activities.
2. Who Must Conduct Risk Assessments
Processors of important data are required to conduct a cyber data security risk assessment every year. Where there is a material change in the security status of important data that may adversely affect data security, the relevant processor must conduct a timely risk assessment of the changed matters and their impact.
For processors of general data, the Measures encourage, but do not mandate, a risk assessment at least once every three years.
The Measures do not set out a standalone test for determining whether a company is an important data processor. Instead, they proceed on the basis that a processor handling important data will be subject to the annual assessment and reporting obligations, while processors of general data are only encouraged to conduct assessments periodically. In practice, companies will still need to assess their data processing activities by reference to applicable data classification rules, important data catalogues and sector-specific regulatory guidance.
3. Self-Assessment or Third-Party Assessment
Cyber data processors may conduct risk assessments by themselves or engage a third-party assessment institution.
Where a processor conducts the assessment internally, it must designate responsible personnel. Where a third-party institution is engaged, the parties should define their respective rights and obligations through a contract or other legally effective document.
The Measures also encourage assessment institutions to obtain certification, and require them to act objectively and independently. Assessment institutions are responsible for the authenticity, validity and completeness of the risk assessment reports they issue.
4. Requirements for Third-Party Assessment Institutions
The Measures impose several restrictions on third-party assessment institutions. In particular:
 An assessment institution may not subcontract the risk assessment work to another institution. The same assessment institution and its affiliates may not conduct annual risk assessments for the same cyber data processor more than three consecutive times. If an assessment institution identifies significant data security risks during the assessment, it must promptly notify the cyber data processor. Assessment institutions and their staff must keep confidential any data, trade secrets and confidential business information obtained during the assessment, and must delete or properly handle such information after the assessment is completed.
5. Risk Assessment Reports and Submission Obligations
Processors of important data must prepare risk assessment reports in accordance with the requirements of the relevant competent authority. If no specific requirements have been issued by the competent authority, processors may refer to applicable national standards on data security risk assessment.
Risk assessment reports must be retained for at least three years.
Processors of important data must submit the risk assessment report to the relevant competent authority within 20 working days after completing the annual risk assessment. If the competent authority is unclear, the report should be submitted to the provincial cyberspace administration or the CAC.
The relevant competent authority must receive the report and notify the cyberspace administration at the same level within 10 working days. The CAC will then consolidate relevant reports and share them with other competent authorities, including telecommunications, public security and national security authorities.
6. Regulatory Review and Verification
Provincial-level or higher cyberspace, telecommunications, public security, national security and other competent authorities may review and verify the authenticity and accuracy of risk assessment reports submitted by processors of important data.
Where regulators identify higher-risk circumstances, they may require the cyber data processor to engage a certified assessment institution. Such circumstances include:
 data processing activities that present relatively high security risks and may endanger national security or public interests; cyber data security incidents involving the leakage or theft of important data or large-scale personal information; or other circumstances prescribed by relevant authorities.
For the same cyber data security incident or risk, regulators may not repeatedly require the processor to engage an assessment institution.
7. Rectification and Consequences of Non-Compliance
If regulators find that important data processing activities may endanger national security or public interests, they may order the processor to rectify the issue.
If the processor refuses to rectify, or fails to meet the rectification requirements, regulators may require it to suspend the processing of important data.
Cyber data processors that fail to conduct risk assessments as required may be subject to enforcement action under the Data Security Law, the Regulations on the Administration of Cyber Data Security and other applicable laws and regulations. Assessment institutions that violate the Measures may also face legal consequences.
8. Special Rules for Core Data, Encryption and State Secrets
The risk assessment of processors handling core data will be subject to separate national rules.
Where technical measures such as encryption of important data are involved, the processor must also comply with requirements on commercial cryptography application security assessments.
Risk assessments involving state secrets or work secrets must comply with the Law on Guarding State Secrets and other applicable secrecy-related laws and regulations.
Comment
The Measures clarify how the existing annual assessment requirement for important data processors should be carried out, reported and supervised. For companies operating in data-intensive sectors, the first practical step is to determine whether they process important data by reference to applicable data classification rules, important data catalogues and sector-specific regulatory guidance. Where they do, companies should establish a repeatable annual assessment mechanism with clear internal responsibility, proper documentation and report retention, as well as procedures for regulatory verification, rectification and follow-up.
© 2026 - All rights reserved.

We use cookies to enable essential functionality on our website, and analyze website traffic. By clicking Accept you consent to our use of cookies. Cookies and Privacy Policy.

Your Cookie Settings

We use cookies to enable essential functionality on our website and analyze website traffic. For more information, read our Cookies and Privacy Policy below..

Cookie Categories
Essential

These cookies are strictly necessary to provide you with services available through our websites.

Analytics

These cookies collect information that is used in aggregate and in an anonymized form to help us understand how our website is being used and how effectively our site is performing.