On 13 July 2026, the National Financial Regulatory Administration of China (“NFRA”) issued the Measures for Cybersecurity Management of the Banking and Insurance Industry (Draft for Comments)(“Measures”), with the public comment period closing on 10 August 2026. This represents a systematic upgrade of China’s financial cybersecurity regulatory framework – not piecemeal amendments, but a comprehensive architecture spanning “from governance to operations, from routine to emergency response, and from general requirements to critical information infrastructure”.
Two Measures, One Coherent Framework
The Measures are designed to establish a multi-layered cybersecurity defense line, ensuring the stable operation of financial services as they are empowered by emerging technologies such as artificial intelligence. Together with the Measures for Cybersecurity Management of the Financial Industry (Draft for Comments)(“Financial Industry Measures”) published on 3 July 2026, they form a complete institutional framework for financial cybersecurity. While promulgated by different authorities and serving distinct purposes, the two instruments are complementary.
The Financial Industry Measures serve as the “basic law”: jointly issued by the People’s Bank of China, the NFRA, the China Securities Regulatory Commission, and the State Administration of Foreign Exchange, comprising 5 chapters and 33 articles. They cover all financial practitioners – including banks, insurers, securities firms and payment institutions – and establish from an industry-wide perspective the general principles of cybersecurity management, including the cybersecurity responsibility system, classified protection, commercial cryptography usage, and data protection. These constitute the “baseline rules” that all institutions must observe.
The Measures serve as the “sector-specific implementing rules”: promulgated separately by the NFRA, comprising 8 chapters and 72 articles. Within the framework of the “basic law”, they are specifically tailored to the operational characteristics of banking and insurance institutions, translating general principles into actionable and quantifiable requirements – from “shall establish a cybersecurity responsibility system” to “the Party Committee/Board of Directors bears primary responsibility, with the principal responsible person of the institution as the primary responsible person”; from “shall conduct cybersecurity monitoring” to “incidents at Level III or above shall be reported within 2 hours”.
Core Requirements of the Measures
The Measures set forth explicit requirements across the following core areas: cybersecurity governance, cybersecurity construction and operations management, cybersecurity risk monitoring, cybersecurity incident response and handling, critical information infrastructure management, and supervisory oversight:
1. Cybersecurity Governance. The Measures require financial institutions to establish comprehensive cybersecurity governance structures, clarify that the Party Committee (Party Group) and the Board of Directors bear primary responsibility for cybersecurity, designate the principal responsible person of the institution as the primary responsible person, and establish assessment, reward and accountability mechanisms that are fully incorporated into the institution’s annual performance evaluation system.
2. Cybersecurity Construction and Operations Management. The Measures emphasize that security protections must be “planned simultaneously, constructed simultaneously, and used simultaneously” with information technology development, and require the classification, grading and unified management of cyber assets, with network access control policies strictly configured in accordance with the “minimum necessary” principle. In addition, institutions must establish system security baselines, ensure that cybersecurity-related logs are retained for no less than six months, and conduct graded classification assessments at least annually for networks rated at Class III or above under the classified protection regime, thereby reinforcing the defensive baseline through routine technical measures.
3. Cybersecurity Risk Monitoring. The Measures require financial institutions to establish and maintain multi-tiered, multi-channel early warning mechanisms, conduct real-time monitoring of system status, and proactively monitor threats such as phishing websites and counterfeit client applications. Financial institutions must conduct cybersecurity risk assessments and internet penetration tests covering headquarters, domestic and overseas branches, and affiliated institutions at least annually, and conduct cybersecurity audits at least once every three years, so as to achieve closed-loop risk management.
4. Cybersecurity Incident Response and Handling. The Measures establish stringent “timeframes”: for cybersecurity incidents classified as Level III (relatively major) or above, institutions must report to the regulator within 2 hours; for Level I (extremely major) incidents, immediate reporting is required, with progress updates every 2 hours. Following the incident, institutions must recover lost data, verify systems, and submit a summary report within 5 working days, with accountability pursued where management failures have led to Level III or above incidents.
5. Critical Information Infrastructure (“CII”) Management. The Measures explicitly require that the principal responsible person of a CII operator bears overall responsibility for security protection, that the network security protection level shall not be lower than Class III, and that critical technologies must be independently mastered. CII operators must not only operate and maintain CII within the territory of China and ensure that same-city and remote disaster recovery centers possess the capability to fully assume production operations and sustain long-term operation, but also establish cybersecurity monitoring and command centers operating on a 7×24-hour basis. For Level III or above cybersecurity incidents affecting CII, the reporting deadline to both the regulator and the public security authorities is compressed to “within 1 hour”, to prevent major security risks at critical financial nodes.
Implications for Foreign-Funded Financial Institutions
In relation to cross-border and foreign-related matters, the Measures articulate the following three rules:
1. Foreign-funded Institutions Apply Mutatis Mutandis. The Measures apply not only to financial institutions lawfully established within the territory of China; foreign bank branches, foreign insurance company branches, and similar entities shall also apply them mutatis mutandis.
2. Comprehensive Group-wide Coverage. Financial institutions must uniformly incorporate the cybersecurity work of their domestic and overseas branches and affiliated institutions into their overall cybersecurity management system.
3. Cross-border Assessment Requirement. In routine monitoring and assessment, the cybersecurity risk assessments and internet penetration tests that financial institutions must conduct at least annually shall comprehensively cover the institution itself as well as its domestic and overseas branches and affiliated institutions.
Comparison with International Regulatory Frameworks
The EU Digital Operational Resilience Act (“DORA”) (which entered into force in 2023 and has been fully applicable since 17 January 2025) establishes a unified digital operational resilience regime for the entire EU financial sector. It covers 20 categories of financial entities, including banks, insurers, investment firms, payment institutions, and crypto-asset service providers, and extends even to third-party ICT service providers that supply critical services to these institutions. DORA’s institutional design revolves around five pillars: ICT risk management, incident reporting, digital operational resilience testing, third-party risk management, and information sharing. The most notable innovation is the direct supervisory power over third-party service providers – EU supervisory authorities are empowered to conduct direct supervision, on-site inspections, and even impose fines on “critical” multinational technology cloud service providers (such as AWS and Azure), a groundbreaking institutional arrangement globally. In terms of incident reporting, DORA adopts a “three-phase standardized timeline”: preliminary notification of major incidents must be submitted within 4 hours of classification, an interim report within 72 hours, and a final investigation report within 1 month. This approach emphasizes “accurate classification before precise reporting,” contrasting sharply with China’s “expedited reporting” framework. In terms of resilience testing, DORA mandates that critical financial entities conduct “threat-led penetration testing” (“TLPT”) at least once every three years – a highly operational, combat-style attack-defense exercise that simulates real-world hacking techniques to assess institutions’ defensive and recovery capabilities under extreme conditions. By contrast, the Measures place greater emphasis on compliance verification through graded classification assessments and commercial cryptography application security assessments, rather than combat-style exercises. DORA’s core concern is: “What if the entire financial system relies on a handful of cloud service providers, and something goes wrong with them?” It therefore grants regulatory authorities the power of direct oversight of service providers while using stringent combat-style tests to compel institutions to enhance their actual defensive capabilities.
Unlike China and the EU, the United States does not have a single comprehensive federal law governing financial cybersecurity. Its regulatory system comprises three tiers:
1. At the federal statutory level, the Gramm-Leach-Bliley Act (“GLBA”) and its Safeguards Rule set minimum standards for all financial institutions – requiring written information security programmers, risk assessments, and service provider oversight. The Securities and Exchange Commission’s cybersecurity disclosure rules require listed companies to disclose material cybersecurity incidents within 4 business days of determining materiality. In 2021, the OCC, FRB, and FDIC jointly issued a rule requiring banks to report “notifiable events” that pose a significant threat to financial stability to their primary regulators within 36 hours.
2. At the industry guidance level, the Federal Financial Institutions Examination Council (“FFIEC”) publishes the IT Examination Handbook providing detailed examination guidance, though its Cybersecurity Assessment Tool (“CAT”) was retired in August 2025. The industry is now fully transitioning to the National Institute of Standards and Technology (“NIST”) Cybersecurity Framework (“CSF”) version 2.0 (published in February 2024). CSF 2.0 adds the “Govern” function, emphasizing the integration of cybersecurity into corporate strategy, and has become the de facto standard for financial institutions in building their cybersecurity systems.
3. At the state regulatory level, the New York State Department of Financial Services (“NYDFS”) 23 NYCRR Part 500 is widely recognized as the most stringent financial cybersecurity regulation in the United States. It mandates multi-factor authentication, written asset inventories, encryption, and other measures; cybersecurity incidents must be reported within 72 hours, and ransomware payments within 24 hours; annual compliance certifications must be signed by both the CEO and CISO, with responsible signatories facing civil and criminal liability in the event of false certification. NYDFS has imposed fines as high as USD 30 million on non-compliant institutions.
The US system has long adhered to the principles of “technological neutrality” and “process orientation”, rarely restricting the country of origin of procured technology or physical operational locations, instead focusing regulatory emphasis on whether institutions have established robust third-party risk management processes and clear service provider exit strategies – a hallmark of operational resilience. The US regulatory philosophy is one of decentralization and market orientation – the federal government sets the minimum floor, the industry develops best practice frameworks, states may impose higher standards, and institutions have autonomy in selecting technical solutions for process compliance.
Compared with these two models, the Measures embody a distinctly different institutional logic:
1. Speed priority. The Measures set out reporting deadlines – 2 hours for Level III or above incidents for banking and insurance institutions, 1 hour for Level III or above incidents affecting CII, with immediate reporting and 2-hour rolling updates for Level I incidents. This design reflects the regulator’s strong imperative for “early detection and rapid response” to cybersecurity incidents, requiring risk posture awareness and emergency activation to be achieved in the shortest possible time.
2. Sovereignty priority. The Measures impose mandatory requirements on CII operators, including “operation and maintenance within the territory of China” and “independent mastery of critical technologies”, directly linking cybersecurity with supply chain security and national security. This differs from DORA’s “direct supervisory” approach – DORA focuses on service provider concentration risk, whereas the Measures focus on technological sovereignty and physical controllability of supply chains.
3. Compliance orientation. In resilience testing, the Measures rely on two major institutional instruments – “classified protection assessments” and “commercial cryptography application security assessments” – conducting annual compliance verification cycles. This is fundamentally different from DORA’s “combat-style” testing – the former emphasizes “conformity with standards”, while the latter emphasizes “ability to withstand attacks”.
4. Accountability penetration. The Measures penetrate accountability down to the principal responsible person’s individual annual performance review, using performance mechanisms to compel responsibility implementation; NYDFS uses personal criminal liability as a deterrent; DORA places responsibility on the overall governance obligations of the board of directors and senior management.
Conclusion
The Measures are not an isolated regulatory instrument, but a critical component of China’s financial cybersecurity institutional framework. Together with the Financial Industry Measures, they form a complete chain from “general principles” to “sector-specific implementing rules”, marking the entry of China’s financial cybersecurity regulation into a new phase of systematization, refinement, and enforceability.
Two Measures, One Coherent Framework
The Measures are designed to establish a multi-layered cybersecurity defense line, ensuring the stable operation of financial services as they are empowered by emerging technologies such as artificial intelligence. Together with the Measures for Cybersecurity Management of the Financial Industry (Draft for Comments)(“Financial Industry Measures”) published on 3 July 2026, they form a complete institutional framework for financial cybersecurity. While promulgated by different authorities and serving distinct purposes, the two instruments are complementary.
The Financial Industry Measures serve as the “basic law”: jointly issued by the People’s Bank of China, the NFRA, the China Securities Regulatory Commission, and the State Administration of Foreign Exchange, comprising 5 chapters and 33 articles. They cover all financial practitioners – including banks, insurers, securities firms and payment institutions – and establish from an industry-wide perspective the general principles of cybersecurity management, including the cybersecurity responsibility system, classified protection, commercial cryptography usage, and data protection. These constitute the “baseline rules” that all institutions must observe.
The Measures serve as the “sector-specific implementing rules”: promulgated separately by the NFRA, comprising 8 chapters and 72 articles. Within the framework of the “basic law”, they are specifically tailored to the operational characteristics of banking and insurance institutions, translating general principles into actionable and quantifiable requirements – from “shall establish a cybersecurity responsibility system” to “the Party Committee/Board of Directors bears primary responsibility, with the principal responsible person of the institution as the primary responsible person”; from “shall conduct cybersecurity monitoring” to “incidents at Level III or above shall be reported within 2 hours”.
Core Requirements of the Measures
The Measures set forth explicit requirements across the following core areas: cybersecurity governance, cybersecurity construction and operations management, cybersecurity risk monitoring, cybersecurity incident response and handling, critical information infrastructure management, and supervisory oversight:
1. Cybersecurity Governance. The Measures require financial institutions to establish comprehensive cybersecurity governance structures, clarify that the Party Committee (Party Group) and the Board of Directors bear primary responsibility for cybersecurity, designate the principal responsible person of the institution as the primary responsible person, and establish assessment, reward and accountability mechanisms that are fully incorporated into the institution’s annual performance evaluation system.
2. Cybersecurity Construction and Operations Management. The Measures emphasize that security protections must be “planned simultaneously, constructed simultaneously, and used simultaneously” with information technology development, and require the classification, grading and unified management of cyber assets, with network access control policies strictly configured in accordance with the “minimum necessary” principle. In addition, institutions must establish system security baselines, ensure that cybersecurity-related logs are retained for no less than six months, and conduct graded classification assessments at least annually for networks rated at Class III or above under the classified protection regime, thereby reinforcing the defensive baseline through routine technical measures.
3. Cybersecurity Risk Monitoring. The Measures require financial institutions to establish and maintain multi-tiered, multi-channel early warning mechanisms, conduct real-time monitoring of system status, and proactively monitor threats such as phishing websites and counterfeit client applications. Financial institutions must conduct cybersecurity risk assessments and internet penetration tests covering headquarters, domestic and overseas branches, and affiliated institutions at least annually, and conduct cybersecurity audits at least once every three years, so as to achieve closed-loop risk management.
4. Cybersecurity Incident Response and Handling. The Measures establish stringent “timeframes”: for cybersecurity incidents classified as Level III (relatively major) or above, institutions must report to the regulator within 2 hours; for Level I (extremely major) incidents, immediate reporting is required, with progress updates every 2 hours. Following the incident, institutions must recover lost data, verify systems, and submit a summary report within 5 working days, with accountability pursued where management failures have led to Level III or above incidents.
5. Critical Information Infrastructure (“CII”) Management. The Measures explicitly require that the principal responsible person of a CII operator bears overall responsibility for security protection, that the network security protection level shall not be lower than Class III, and that critical technologies must be independently mastered. CII operators must not only operate and maintain CII within the territory of China and ensure that same-city and remote disaster recovery centers possess the capability to fully assume production operations and sustain long-term operation, but also establish cybersecurity monitoring and command centers operating on a 7×24-hour basis. For Level III or above cybersecurity incidents affecting CII, the reporting deadline to both the regulator and the public security authorities is compressed to “within 1 hour”, to prevent major security risks at critical financial nodes.
Implications for Foreign-Funded Financial Institutions
In relation to cross-border and foreign-related matters, the Measures articulate the following three rules:
1. Foreign-funded Institutions Apply Mutatis Mutandis. The Measures apply not only to financial institutions lawfully established within the territory of China; foreign bank branches, foreign insurance company branches, and similar entities shall also apply them mutatis mutandis.
2. Comprehensive Group-wide Coverage. Financial institutions must uniformly incorporate the cybersecurity work of their domestic and overseas branches and affiliated institutions into their overall cybersecurity management system.
3. Cross-border Assessment Requirement. In routine monitoring and assessment, the cybersecurity risk assessments and internet penetration tests that financial institutions must conduct at least annually shall comprehensively cover the institution itself as well as its domestic and overseas branches and affiliated institutions.
Comparison with International Regulatory Frameworks
The EU Digital Operational Resilience Act (“DORA”) (which entered into force in 2023 and has been fully applicable since 17 January 2025) establishes a unified digital operational resilience regime for the entire EU financial sector. It covers 20 categories of financial entities, including banks, insurers, investment firms, payment institutions, and crypto-asset service providers, and extends even to third-party ICT service providers that supply critical services to these institutions. DORA’s institutional design revolves around five pillars: ICT risk management, incident reporting, digital operational resilience testing, third-party risk management, and information sharing. The most notable innovation is the direct supervisory power over third-party service providers – EU supervisory authorities are empowered to conduct direct supervision, on-site inspections, and even impose fines on “critical” multinational technology cloud service providers (such as AWS and Azure), a groundbreaking institutional arrangement globally. In terms of incident reporting, DORA adopts a “three-phase standardized timeline”: preliminary notification of major incidents must be submitted within 4 hours of classification, an interim report within 72 hours, and a final investigation report within 1 month. This approach emphasizes “accurate classification before precise reporting,” contrasting sharply with China’s “expedited reporting” framework. In terms of resilience testing, DORA mandates that critical financial entities conduct “threat-led penetration testing” (“TLPT”) at least once every three years – a highly operational, combat-style attack-defense exercise that simulates real-world hacking techniques to assess institutions’ defensive and recovery capabilities under extreme conditions. By contrast, the Measures place greater emphasis on compliance verification through graded classification assessments and commercial cryptography application security assessments, rather than combat-style exercises. DORA’s core concern is: “What if the entire financial system relies on a handful of cloud service providers, and something goes wrong with them?” It therefore grants regulatory authorities the power of direct oversight of service providers while using stringent combat-style tests to compel institutions to enhance their actual defensive capabilities.
Unlike China and the EU, the United States does not have a single comprehensive federal law governing financial cybersecurity. Its regulatory system comprises three tiers:
1. At the federal statutory level, the Gramm-Leach-Bliley Act (“GLBA”) and its Safeguards Rule set minimum standards for all financial institutions – requiring written information security programmers, risk assessments, and service provider oversight. The Securities and Exchange Commission’s cybersecurity disclosure rules require listed companies to disclose material cybersecurity incidents within 4 business days of determining materiality. In 2021, the OCC, FRB, and FDIC jointly issued a rule requiring banks to report “notifiable events” that pose a significant threat to financial stability to their primary regulators within 36 hours.
2. At the industry guidance level, the Federal Financial Institutions Examination Council (“FFIEC”) publishes the IT Examination Handbook providing detailed examination guidance, though its Cybersecurity Assessment Tool (“CAT”) was retired in August 2025. The industry is now fully transitioning to the National Institute of Standards and Technology (“NIST”) Cybersecurity Framework (“CSF”) version 2.0 (published in February 2024). CSF 2.0 adds the “Govern” function, emphasizing the integration of cybersecurity into corporate strategy, and has become the de facto standard for financial institutions in building their cybersecurity systems.
3. At the state regulatory level, the New York State Department of Financial Services (“NYDFS”) 23 NYCRR Part 500 is widely recognized as the most stringent financial cybersecurity regulation in the United States. It mandates multi-factor authentication, written asset inventories, encryption, and other measures; cybersecurity incidents must be reported within 72 hours, and ransomware payments within 24 hours; annual compliance certifications must be signed by both the CEO and CISO, with responsible signatories facing civil and criminal liability in the event of false certification. NYDFS has imposed fines as high as USD 30 million on non-compliant institutions.
The US system has long adhered to the principles of “technological neutrality” and “process orientation”, rarely restricting the country of origin of procured technology or physical operational locations, instead focusing regulatory emphasis on whether institutions have established robust third-party risk management processes and clear service provider exit strategies – a hallmark of operational resilience. The US regulatory philosophy is one of decentralization and market orientation – the federal government sets the minimum floor, the industry develops best practice frameworks, states may impose higher standards, and institutions have autonomy in selecting technical solutions for process compliance.
Compared with these two models, the Measures embody a distinctly different institutional logic:
1. Speed priority. The Measures set out reporting deadlines – 2 hours for Level III or above incidents for banking and insurance institutions, 1 hour for Level III or above incidents affecting CII, with immediate reporting and 2-hour rolling updates for Level I incidents. This design reflects the regulator’s strong imperative for “early detection and rapid response” to cybersecurity incidents, requiring risk posture awareness and emergency activation to be achieved in the shortest possible time.
2. Sovereignty priority. The Measures impose mandatory requirements on CII operators, including “operation and maintenance within the territory of China” and “independent mastery of critical technologies”, directly linking cybersecurity with supply chain security and national security. This differs from DORA’s “direct supervisory” approach – DORA focuses on service provider concentration risk, whereas the Measures focus on technological sovereignty and physical controllability of supply chains.
3. Compliance orientation. In resilience testing, the Measures rely on two major institutional instruments – “classified protection assessments” and “commercial cryptography application security assessments” – conducting annual compliance verification cycles. This is fundamentally different from DORA’s “combat-style” testing – the former emphasizes “conformity with standards”, while the latter emphasizes “ability to withstand attacks”.
4. Accountability penetration. The Measures penetrate accountability down to the principal responsible person’s individual annual performance review, using performance mechanisms to compel responsibility implementation; NYDFS uses personal criminal liability as a deterrent; DORA places responsibility on the overall governance obligations of the board of directors and senior management.
Conclusion
The Measures are not an isolated regulatory instrument, but a critical component of China’s financial cybersecurity institutional framework. Together with the Financial Industry Measures, they form a complete chain from “general principles” to “sector-specific implementing rules”, marking the entry of China’s financial cybersecurity regulation into a new phase of systematization, refinement, and enforceability.