China’s New Data Security Rule Starts Today. A Risk Assessment Is No Longer Just an Internal Document.
China’s new rules for network-data security risk assessments took effect on 20 August 2026. For organisations that process data in China, the important change is not simply another assessment obligation. The result may now have to leave the security team, carry named accountability, and reach a regulator on a fixed timetable.
The Cyberspace Administration of China, the Ministry of Industry and Information Technology, and the Ministry of Public Security jointly issued the Measures for Network Data Security Risk Assessment on 18 June. The measures were adopted on 1 June and became effective on 20 August. A CAC implementation notice published as the rules took effect confirms that processors of important data must conduct an annual risk assessment and submit the resulting report within 20 working days.
The assessment becomes a regulatory artefact
Security risk assessments often remain internal documents: useful to management, auditors and incident-response teams, but not automatically sent outside the organisation. The new Chinese framework changes that assumption for important-data processors.
The measures define a network-data security risk assessment as the identification, analysis and evaluation of risks arising from data and the activities used to process it. The expected report is broader than a technical vulnerability review. It can cover the organisation responsible for the processing, the data involved, the purpose and methods of processing, where the data is stored, how long it is retained, which safeguards are deployed, security incidents, onward sharing, outsourced or joint processing, and cross-border transfers.
Where assessors identify problems, the processor must remediate them. The final report must be signed by the head of the assessment organisation and the assessment lead, and formally sealed. If remediation is requested after review, the processor must report the result within 15 working days.
That turns the assessment into evidence. Statements about encryption, access control, authentication, backups, data classification and incident handling can be compared with technical reality, supplier arrangements and later breach findings. Weak evidence or optimistic language is no longer only an internal governance problem.
The scope follows the data, not just the company
The most immediate obligation falls on processors of important data. China uses sectoral and regional catalogues to identify data whose compromise, destruction, leakage, illegal acquisition or misuse could endanger national security, economic operations, social stability, public health or public safety. Organisations cannot safely assume that the label applies only to state-owned enterprises or obviously strategic datasets.
Foreign-headquartered groups can still be affected through Chinese subsidiaries, joint ventures, local cloud environments, connected products, outsourced operations or suppliers that handle covered data. The practical inventory therefore has to include data flows across legal entities and service providers. A corporate map is not a data map.
The rules also give authorities leverage when an assessment identifies risks to national security or the public interest. Regulators may order corrective action and, where necessary, require important-data processing to stop. Violations can be handled under China’s Data Security Law and the Network Data Security Management Regulations.
What defenders should do now
- Confirm the data classification. Identify whether Chinese operations process data that appears in an applicable important-data catalogue. Record the basis for the conclusion, including cases where the answer is no.
- Build a defensible data-flow inventory. Map collection, storage, access, sharing, outsourcing, joint processing and exports. Include cloud services, backup locations, analytics pipelines and supplier access.
- Test the controls described in the report. Evidence encryption, key management, access reviews, privileged activity, authentication, backup recovery, classification labels and monitoring. A policy document is not proof that a control works.
- Reconcile security and legal narratives. The assessment should match contracts, privacy notices, cross-border transfer filings, incident records and statements made to other regulators.
- Prepare the submission clock. Important-data processors need an annual assessment process that can produce an approved report and submit it within 20 working days. Remediation ownership should be assigned before findings arrive.
- Review assessors and attestations. Whether work is performed internally or with an external institution, define independence, evidence retention, sign-off authority and responsibility for inaccurate statements.
A control test with consequences
The strategic change is the conversion of security posture into a formal regulatory claim. Organisations that have treated risk assessments as periodic compliance exercises now need a repeatable evidence process linking inventories, technical testing, supplier assurance, incident history and executive sign-off.
The rules do not mean that every company operating in China must submit the same report. Classification and sectoral requirements remain crucial. But any organisation that could hold important data should be able to explain, with evidence, what it processes, how the classification decision was reached, and how it would meet the annual assessment and submission timetable.
Sources
- Cyberspace Administration of China, Measures for Network Data Security Risk Assessment, published 18 June 2026 at 17:00 China Standard Time.
- Cyberspace Administration of China, implementation questions and answers, published 20 August 2026 at 10:00 China Standard Time.
- Ministry of Industry and Information Technology, network-data security assessment reporting guidance, published 23 March 2026 at 08:59 China Standard Time.
- CMS, China releases measures for network data security risk assessment, published 1 July 2026. No publication time was provided.
Continue the series: APAC Cyber & Digital Law Series index


