- The Cybersecurity Review regime applies whenever a Critical Information Infrastructure (CII) operator procures network products or services that may affect national security — and foreign-invested enterprises supplying those products are squarely within scope.
当关键信息基础设施(CII)运营者采购可能影响国家安全的网络产品与服务时,网络安全审查制度即被触发;向这些运营者供应产品的外商投资企业同样被直接纳入监管视野。- The legal backbone is the Cybersecurity Law (2017), the Regulation on CII Protection (State Council Decree No. 745, 2021) and the Cybersecurity Review Measures (CAC Decree No. 8, 2022), now reinforced by active enforcement against foreign-made security products in 2026.
制度主干为《网络安全法》(2017)、《关键信息基础设施安全保护条例》(国务院令745号,2021)与《网络安全审查办法》(国家网信办等13部门令第8号,2022),并在2026年针对境外安全产品的执法中持续强化。- CII operators must “prioritise the procurement of secure and trustworthy” products and submit to security review before signing; using unreviewed or failed products triggers fines of 1–10 times the procurement value.
CII运营者须”优先采购安全可信的网络产品”,并在签约前申报审查;使用未申报或审查未通过的产品,将面临采购金额一倍以上十倍以下的罚款。- A supplier need not be a CII operator itself — providing products or services to a CII operator can independently trigger a review, as the August 2026 review of a US network-security vendor’s China-sold products illustrates.
供应商本身不必是CII运营者——仅为CII运营者提供产品即可能单独触发审查,2026年8月对某美国网络安全厂商在华销售产品的审查即为例证。- Foreign-invested enterprises should embed review-trigger analysis into procurement playbooks, vendor due diligence and contract clauses, and retain evidence of supplier commitments not to extract user data or interrupt supply.
外商投资企业应将”审查触发”分析嵌入采购流程、供应商尽调与合同条款,并留存供应商”不非法获取用户数据、不中断供应”的承诺证据。- The review is risk-based and time-bound (generally 30 + 15 working days, with a special procedure extending to about 90), and explicitly states it is not intended to restrict or discriminate against foreign products and services.
审查以风险为本且有明确时限(一般30+15个工作日,特别审查最长约90个工作日),并明确规定其目的不是限制或歧视国外产品与服务。
Cybersecurity Review and Critical Information Infrastructure Procurement Compliance for Foreign-Invested Enterprises | 网络安全审查与关键信息基础设施采购合规:外商投资企业的实务指南
Why this matters now
For a foreign-invested enterprise (FIE) selling network equipment, cloud services, security software or industrial control components into the China market, the question is no longer whether cybersecurity rules apply, but *when a procurement crosses the line into a national-security review*. China’s cybersecurity framework has matured from a set of principles into an operational, enforcement-driven regime. The clearest recent signal came on 6 August 2026, when the Cybersecurity Review Office announced a review of products sold in China by a US network-security vendor — the second time, after the 2023 review of a US memory-chip maker, that the measure was applied to specific foreign-made products rather than to entities. For FIEs on either side of a CII procurement — as the operator, the supplier, or both — the compliance calculus has sharpened.
This article explains the statutory triggers, the three pillars of the legal framework, what the review actually assesses, the 2026 enforcement signal, and the concrete steps an FIE should take. It does not address the separate (though related) regimes of data-export security assessment, standard contracts and certification, which are covered elsewhere on this site.
The statutory trigger: who and when
The trigger is defined in Article 2 of the Cybersecurity Review Measures: a CII operator procuring network products and services, or a platform operator conducting data-processing activities, that *may affect or may affect* national security must undergo cybersecurity review. The wording is deliberately forward-looking — the operator must pre-assess the risk before signing and file for review where the risk exists.
Two points matter for foreign suppliers in particular. First, the obligation to file sits with the CII operator (the buyer), not the supplier. Second, and often overlooked, a supplier can be pulled into a review even when it is not itself a CII operator: providing products or services *to* a CII operator is exactly the scenario the 2026 review targeted. The Measures (Article 21) also state that where foreign-investment security review or data-security review have separate rules, those apply alongside.
CII itself is defined broadly in the Regulation on CII Protection: public communications and information services, energy, transport, water conservancy, finance, public services, e-government, defence science and industry, and other networks/systems whose disruption or data breach would seriously endanger national security, the public interest or social stability. Telecom, finance, energy, transport, healthcare and government IT are the obvious sectors — precisely the sectors where foreign technology is most often deployed.
The three pillars of the legal framework
Pillar one — the Cybersecurity Law (adopted 2016, effective 2017). Article 35 imposes the core duty: a CII operator procuring network products and services that may affect national security shall pass the security review organised by the cyberspace authority and relevant departments. Article 37 separately restricts CII operators from storing personal information and important data overseas or providing it abroad without assessment.
Pillar two — the Regulation on CII Protection (State Council Decree No. 745, effective 1 September 2021). This fills in the duty-holder detail: operators must build a dedicated security-management organ, conduct at least one security testing and risk assessment per year, and — critically for procurement — “prioritise the procurement of secure and trustworthy network products and services” and put any potentially security-affecting procurement through the national cybersecurity review. Article 19 makes this a positive legal obligation, not mere guidance.
Pillar three — the Cybersecurity Review Measures (CAC Decree No. 8, effective 15 February 2022). Thirteen departments jointly issued the Measures, which specify the review objects (core network devices, important communications products, high-performance computers and servers, large-capacity storage, large databases and application software, network-security devices, cloud-computing services, and other products/services materially affecting CII, network and data security). They set the 45-working-day baseline (30 + 15, with a special procedure of about 90 working days) and the penalty ladder.
What the review assesses
Article 10 of the Measures lists the national-security risk factors the review weighs:
- the risk that products/services, once in use, lead to illegal control of, interference with or destruction of CII;
- the risk that supply interruption harms the business continuity of CII;
- the security, openness, transparency and source diversity of the product/service, and the risk of supply interruption for political, diplomatic or trade reasons;
- the provider’s compliance with Chinese laws, administrative regulations and departmental rules;
- the risk of core data, important data or large volumes of personal information being stolen, leaked, destroyed, illegally used or illegally exported;
- for listings abroad, the risk that CII, core data, important data or large volumes of personal information fall under foreign-government influence or control; and
- other factors endangering CII, network and data security.
For a foreign supplier, the most relevant factors are supply-chain continuity, transparency of the product’s architecture, and — increasingly — whether the product could become a vector for data extraction or remote control. The 2026 enforcement action against a foreign security vendor centred precisely on the paradox that a security product can itself become a security risk if compromised or externally controlled.
The 2026 enforcement signal
On 6 August 2026 the Cybersecurity Review Office announced a review, under the Cybersecurity Law and the Measures, of products sold in China by a US network-security company, citing the need to safeguard CII and prevent cybersecurity risks. Chinese regulators had, earlier in 2026, directed domestic institutions to stop using certain US and Israeli security products and to complete migration to domestic alternatives within the first half of the year. The pattern is consistent: reviews now target *products* (not just entities), focus on CII supply-chain security, and operate alongside a broader “secure and trustworthy” procurement preference in sensitive sectors.
The practical takeaway for FIEs is not panic but preparation. The Measures explicitly state the review is “not intended to restrict or discriminate against foreign products and services,” and China continues to welcome foreign products into its market. The differentiator is demonstrable supply-chain resilience, source transparency and contractual commitments.
Practical compliance steps for FIEs
- Map your exposure. Identify whether your customers include CII operators or platform operators handling large-scale personal information. If so, your products are in the review’s line of sight even when you are not the filer.
- Build review-trigger analysis into the sales cycle. Equip local teams to recognise when a customer’s procurement will require a filing, and pre-empt delays by surfacing the issue early.
- Harden the supplier commitments. The Measures let CII operators require providers to promise not to illegally obtain user data, not to illegally control or manipulate user equipment, and not to interrupt supply without just cause. Put these in writing and be able to evidence them.
- Localise where it reduces risk. Source diversity, in-country support, transparent architecture and local data handling are exactly the factors the review rewards. A wholly import-dependent supply chain is the weakest posture.
- Keep contracts review-aware. Where a contract is signed before review, include a condition that it takes effect only after the product passes review, to avoid the “use unreviewed product” penalty of 1–10 times procurement value.
- Coordinate with the FIE’s data-export posture. Cybersecurity review overlaps with data-export security assessment and PIPL compliance; treat them as one programme rather than three silos.
Related reading
- Critical information infrastructure recognition and the annual self-assessment obligation.
- Data-export pathways: security assessment, standard contract and certification compared.
- PIPL compliance for foreign-invested enterprises operating in China.
网络安全审查与关键信息基础设施采购合规:外商投资企业的实务指南
为何重要
对于向中国市销售网络设备、云服务、安全软件或工业控制部件的外商投资企业(FIE)而言,问题已不再是”网络安全规则是否适用”,而是”一项采购何时越过红线、进入国家安全审查”。中国的网络安全框架已从原则性规定,发展为可操作、强执法的制度体系。最清晰的近期信号出现在2026年8月6日——网络安全审查办公室宣布对某美国网络安全厂商在华销售产品启动审查,这是继2023年对某美国存储芯片企业之后,第二次将审查直接指向特定境外制造的产品而非实体。无论外商投资企业处于CII采购的哪一端——作为运营者、供应商或兼而有之——合规逻辑都已显著收紧。
本文阐释法定触发条件、法律框架的三大支柱、审查究竟评估什么、2026年的执法信号,以及外商投资企业应采取的具体步骤。数据出境安全评估、标准合同与认证等相对独立(但相关)的制度,不在本文讨论范围,本站点另有专文。
法定触发:谁、何时
触发条件规定于《网络安全审查办法》第二条:关键信息基础设施运营者采购网络产品与服务,或网络平台运营者开展可能影响国家安全的数据处理活动,应当进行网络安全审查。措辞具有前瞻性——运营者须在签约前预判风险,并在风险存在时申报审查。
有两点对外国供应商尤为重要。其一,申报义务落在CII运营者(买方)身上,而非供应商。其二(也最常被忽视):供应商即便自身不是CII运营者,也可能被卷入审查——仅为CII运营者提供产品,正是2026年审查所针对的情形。《办法》第二十一条还规定,外商投资安全审查、数据安全审查另有规定的,应一并适用。
CII的定义见于《关键信息基础设施安全保护条例》,范围宽泛:公共通信和信息服务、能源、交通、水利、金融、公共服务、电子政务、国防科技工业,以及其他一旦遭到破坏、丧失功能或数据泄露可能严重危害国家安全、公共利益或社会稳定的网络设施与信息系统。电信、金融、能源、交通、医疗与政府IT是最典型的行业——也正是外国技术最常部署的领域。
法律框架的三大支柱
支柱一——《网络安全法》(2016通过,2017施行)。 第三十五条规定核心义务:CII运营者采购可能影响国家安全的网络产品与服务,应当通过国家网信部门会同有关部门组织的国家安全审查。第三十七条另限制CII运营者未经评估不得将个人信息与重要数据境外存储或提供境外。
支柱二——《关键信息基础设施安全保护条例》(国务院令745号,2021年9月1日施行)。 细化义务主体:运营者须设立专门安全管理机构、每年至少开展一次网络安全检测与风险评估,且——对采购尤为关键——”优先采购安全可信的网络产品”,并将任何可能影响安全的采购纳入国家网络安全审查。第十九条将其确立为积极的法定义务,而非软性指引。
支柱三——《网络安全审查办法》(国家网信办等13部门令第8号,2022年2月15日施行)。 该办法明确审查对象(核心网络设备、重要通信产品、高性能计算机与服务器、大容量存储设备、大型数据库与应用软件、网络安全设备、云计算服务,以及对CII、网络与数据安全有重要影响的其他产品服务),设定45个工作日的基准时限(30+15,特别审查约90个工作日),并规定罚则梯度。
审查评估什么
《办法》第十条列举审查权衡的国家安全风险因素:
- 产品服务投入使用后导致CII被非法控制、干扰或破坏的风险;
- 供应中断损害CII业务连续性的风险;
- 产品服务的安全性、开放性、透明性、来源多样性,以及因政治、外交、贸易因素导致供应中断的风险;
- 提供者遵守中国法律、行政法规与部门规章的情况;
- 核心数据、重要数据或大量个人信息被窃取、泄露、毁损、非法利用或非法出境的风险;
- 赴国外上市情形下,CII、核心数据、重要数据或大量个人信息受外国政府影响或控制的风险;
- 其他危害CII、网络与数据安全的因素。
对外国供应商而言,最相关的因素依次是供应链连续性、产品架构的透明度,以及——日益重要——产品是否会成为数据提取或远程控制的载体。2026年对某外国安全厂商的执法,恰恰聚焦于”安全产品本身可能因其被控制或存在后门而转化为安全风险”这一悖论。
2026年的执法信号
2026年8月6日,网络安全审查办公室依据《网络安全法》与《办法》,宣布对某美国网络安全公司在华销售产品启动审查,理由为保障CII安全、防范网络安全风险。在此之前的2026年内,中国监管部门已要求境内机构停止使用该厂商等部分美国、以色列安全产品,并在上半年内完成向国产替代的迁移。脉络一致:审查如今指向*产品*(而非仅实体),聚焦CII供应链安全,并与敏感行业”安全可信”采购偏好并行推进。
对外商投资企业的实务启示不是恐慌,而是准备。《办法》明确审查”不是要限制或歧视国外产品和服务”,中国仍欢迎国外产品进入市场。差异点在于可证明的供应链韧性、来源透明度与合同承诺。
外商投资企业的实务步骤
- 梳理暴露面。 识别客户是否包含CII运营者或处理大规模个人信息的平台运营者。若是,即便你不是申报方,产品也已进入审查视野。
- 将审查触发分析嵌入销售周期。 让本地团队能够识别客户采购何时需要申报,并及早暴露问题以避免延误。
- 夯实供应商承诺。 《办法》允许CII运营者要求提供者承诺不非法获取用户数据、不非法控制或操纵用户设备、无正当理由不中断供应。将这些承诺书面化并备可佐证材料。
- 以本地化降低风险。 来源多样性、本地支持、透明架构与本地数据处理,正是审查所鼓励的因素。完全依赖进口供应链是最弱姿态。
- 让合同”审查友好”。 若合同在审查前签署,应附条件约定”经审查通过后方可生效”,以规避”使用未审查产品”面临的采购金额一倍以上十倍以下罚款。
- 与数据出境合规协同。 网络安全审查与数据出境安全评估、个保法合规相互重叠,应作为一个整体项目而非三座孤岛来管理。
延伸阅读
- 关键信息基础设施认定与年度自评估义务。
- 数据出境路径比较:安全评估、标准合同与认证。
- 外商投资企业在华的个保法合规。
Sources
- 国家互联网信息办公室等十三部门:《网络安全审查办法》(令 第8号,2022年2月15日施行)— https://www.cac.gov.cn/2022-01/04/c_1642894602182845.htm
- 《关键信息基础设施安全保护条例》(国务院令 第745号,2021年9月1日施行)— https://www.cac.gov.cn/2021-08/17/c_1630785976988160.htm
- 《中华人民共和国网络安全法》(主席令 第五十三号,2017年6月1日施行)— http://www.npc.gov.cn/npc/c2/c12435/c12488/201905/t20190521_270249.html
