China’s Critical Information Infrastructure Security Protection Regulations take effect today, setting detailed obligations for operators of critical systems.
Key points
- Operators must establish dedicated security management bodies.
- Background checks are required for key personnel.
- Annual security assessments must be carried out.
- Procurement of network products and services is subject to security review.
UK suppliers to Chinese critical operators, in sectors such as finance, energy and telecoms, should expect enhanced security reviews and contractual obligations. Critical operators are also subject to data localisation and cross-border transfer assessments under the Cybersecurity Law, so supplier access to systems and data from outside China may be restricted.
Need help understanding what this change means for your organisation? Get in touch for a pragmatic, no-obligation conversation.