Don’t do SECURITY. Do business SECURELY.

China’s critical information infrastructure regulations take effect

China’s Critical Information Infrastructure Security Protection Regulations set enhanced security duties for critical operators.

China’s Critical Information Infrastructure Security Protection Regulations take effect today, setting detailed obligations for operators of critical systems.

Key points

  • Operators must establish dedicated security management bodies.
  • Background checks are required for key personnel.
  • Annual security assessments must be carried out.
  • Procurement of network products and services is subject to security review.

UK suppliers to Chinese critical operators, in sectors such as finance, energy and telecoms, should expect enhanced security reviews and contractual obligations. Critical operators are also subject to data localisation and cross-border transfer assessments under the Cybersecurity Law, so supplier access to systems and data from outside China may be restricted.

Source: Critical Information Infrastructure Security Protection Regulations, State Council Order No. 745 (gov.cn)

Need help understanding what this change means for your organisation? Get in touch for a pragmatic, no-obligation conversation.

Get our weekly insights by emailA free weekly threat and vulnerability round-up with our threat log spreadsheet, plus legal, regulatory, standards, and AI updates.
Subscribe free

More insights