- China operates a mandatory, tiered cybersecurity regime (MLPS + CII) that FIEs cannot opt out of; MLPS is the baseline obligation for virtually every network operator.
中国实行强制、分层的网络安全制度(等保+关键信息基础设施),外商投资企业无法退出;等保几乎适用于所有网络运营者,是合规底线。- MLPS 2.0 (GB/T 22239-2019, effective 1 December 2019) has five steps: grading, filing, remediation, graded assessment, and supervision.
等保2.0(GB/T 22239-2019,2019年12月1日施行)含定级、备案、建设整改、等级测评、监督检查五步骤。- Systems are graded into five levels (L1–L5); most foreign commercial operations land at Level 2 or 3, with Level 3 requiring an annual assessment.
系统分为五级(第一至第五级);多数外资商业运营落在二级或三级,三级须每年测评。- CII operators (telecom, finance, energy, transport, etc.) must localize important data and personal information, pass a CAC cross-border security assessment, and meet duties beyond MLPS.
关键信息基础设施运营者(电信、金融、能源、交通等)须境内存储重要数据和个人信息、通过网信办跨境安全评估,并承担对等保之外的额外义务。- The China subsidiary (not the overseas HQ) is normally the MLPS filing party; material changes such as new data types or M&A can reset the grading.
备案主体通常为境内子公司(非境外总部);新数据类型、并购等重大变更可重置系统定级。- Enforcement is active—non-compliance can block a product launch, trigger fines, and intersect with PIPL and the Data Security Law.
执法真实且日趋活跃——不合规可阻断产品上线、招致罚款,并与《个人信息保护法》及《数据安全法》相交叠。
Cybersecurity & MLPS (等保) for FIEs | 网络安全与等保(外资适用)
Overview
China operates a tiered, legally mandated cybersecurity regime that foreign-invested enterprises (FIEs) cannot opt out of. Two concepts sit at its centre: the Multi-Level Protection Scheme (MLPS, 网络安全等级保护, often called “等保”) and Critical Information Infrastructure (CII, 关键信息基础设施). MLPS is the baseline obligation for virtually every network operator in China; CII is a higher, security-hardened subset applied to systems whose disruption would threaten national security, the economy, or public welfare. Both rest on the Cybersecurity Law (effective 1 June 2017) and are administered by the public-security authorities (MLPS) and the cyberspace regulator (CII identification).
This article explains how MLPS 2.0 works, what the five grading levels mean for an FIE, how CII is designated and what extra duties it triggers, and the practical steps a foreign company should take to stay compliant.
MLPS 2.0: the graded-protection baseline
MLPS 2.0 is the current generation of China’s graded cybersecurity protection system, anchored by the national standard GB/T 22239-2019 (“Baseline for Graded Cybersecurity Protection”), released in May 2019 and effective 1 December 2019. It replaced the 1.0 framework and expanded coverage from traditional IT systems to cloud computing, mobile internet, IoT, industrial control systems, and big data.
The scheme has five steps: (1) grading (定级) — the operator assesses the impact of a breach and assigns a level; (2) filing/registration (备案) — the grading is submitted to and recorded by the public-security bureau; (3) construction and remediation (建设整改) — the system is brought up to the standard’s technical and management controls; (4) graded assessment (等级测评) — an accredited third-party evaluator tests compliance; and (5) supervision and review (监督检查) — ongoing oversight by the public-security authority.
Under the Cybersecurity Law, network operators that fail to implement MLPS face rectification orders, fines, and — for serious cases — penalties against responsible individuals. For an FIE, MLPS compliance is typically a precondition for launching customer-facing systems, passing partner security reviews, and obtaining the data-export and licensing approvals described in related articles.
The five protection levels
MLPS divides systems into five levels by the harm that a breach would cause:
- Level 1 (自主保护级): damage limited to the legitimate interests of citizens, legal persons, or other organizations, with no harm to the state, social order, or public interest. Often self-assessed.
- Level 2 (指导保护级): serious damage to those interests, or harm to social order/public interest, but no harm to national security. Requires filing; generally assessed periodically (commonly every two years).
- Level 3 (监督保护级): serious harm to social order/public interest, or harm to national security. The most common level for commercial systems of meaningful scale; requires filing and an annual graded assessment.
- Level 4 (强制保护级): particularly serious harm to social order/public interest, or serious harm to national security — typical of core finance, energy, and transport systems; assessed at least every six months.
- Level 5 (专控保护级): particularly serious harm to national security — state-controlled, rarely seen in the private sector.
Most foreign-invested commercial operations land at Level 2 or Level 3. A practical rule: if the system handles large numbers of users, payment data, or personal information, expect Level 3 and an annual assessment obligation.
Critical Information Infrastructure (CII)
Beyond MLPS, the Cybersecurity Law requires the state to identify Critical Information Infrastructure — networks and systems in key industries (telecom, energy, transport, water, finance, public services, e-government, and national defence) whose impairment or data leakage would cause serious harm to national security, the national economy, people’s livelihoods, or the public interest. CII is designated by the relevant industry regulator and coordinated by the CAC.
CII operators owe duties that go well beyond MLPS: they must (a) store important data and personal information collected/generated in China on domestic soil; (b) pass a CAC security assessment before any cross-border transfer (see the PIPL article); (c) conduct regular security testing and risk assessment; (d) engage only vendors and products that meet CII security requirements; and (e) comply with dedicated CII security-protection regulations (the State Council’s 2021 CII Security Protection Regulation). An FIE in a sensitive sector — a cloud operator, a payment institution, a large platform, or a utility-linked business — should assume it may be designated CII and plan accordingly.
Obligations and enforcement for foreign-invested enterprises
For an FIE, the key compliance actions are: confirm which Chinese entity owns each system (the in-China subsidiary, not the overseas parent, is usually the filing party); grade and file every internet-facing or data-bearing system with the local public-security bureau; remediate to GB/T 22239-2019; and commission an accredited assessor. Level 3+ systems need recurring annual assessments, and any material change (new data type, new region, M&A) can reset the grading.
Enforcement is real and increasingly active. Public-security authorities conduct spot checks, and regulators share findings across the MLPS–CII–data-export stack. Non-compliance can block a product launch, trigger fines, and — where personal information or important data is involved — intersect with PIPL and the Data Security Law. Foreign groups should treat MLPS as a continuing programme owned by a local accountable executive, not a one-time certificate.
What to do next
- Inventory your systems in China and assign a business owner to each; the China subsidiary (not the HQ) is normally the MLPS filing party.
- Grade every system honestly against GB/T 22239-2019; expect Level 2–3 for user-facing or data-bearing systems.
- File and remediate with an accredited evaluator, and schedule the recurring assessment (annual for Level 3).
- Assess CII exposure if you operate in telecom, finance, energy, transport, or platform services; prepare for domestic storage and CAC assessment.
- Build a running compliance programme (policies, logs, drills) rather than a one-off audit, and coordinate with your PIPL and data-export obligations.
Sources
- National People’s Congress (NPC) — 全国人民代表大会 — Cybersecurity Law (网络安全法, effective 1 June 2017): Article 21 (MLPS) and Article 31 (CII).
- Ministry of Public Security (MPS) — 公安部 — Administers the Multi-Level Protection Scheme and system filing (official portal).
- SAMR National Standards Information Platform — 全国标准信息公共服务平台 — GB/T 22239-2019 “Baseline for Graded Cybersecurity Protection” (official standard portal).
- Cyberspace Administration of China (CAC) — 国家互联网信息办公室 — CII identification and cross-border security assessment (official portal).
- State Council — 中国政府网 — Regulations on Security Protection of Critical Information Infrastructure (2021).
Related reading
- see also: PIPL compliance for foreign companies — CII and threshold processors must localize and pass CAC assessment before export.
- see also: Anti-monopoly & merger control filing — M&A can reset system grading and trigger new filings.
- see also: VIE structures & regulatory trends — data-security review of offshore listings.
网络安全与等保(外资适用)
概述
中国建立了分层、法定的网络安全制度,外商投资企业(FIE)无法选择退出。其两大核心概念是网络安全等级保护制度(MLPS,”等保”)与关键信息基础设施(CII)。等保几乎适用于中国境内每一个网络运营者,是合规底线;关键信息基础设施则是在等保之上、针对一旦遭到破坏将危害国家安全、经济或公共利益的系统所施加的更高安全等级。二者均以《网络安全法》(2017 年 6 月 1 日施行)为依据,分别由公安机关(等保)与网信部门(CII 认定)主管。
本文说明等保 2.0 的运作方式、五个保护等级对外资企业的含义、CII 如何认定及其附加义务,以及外资企业落地合规的实务步骤。
等保 2.0:分级保护的底线
等保 2.0 是中国网络安全等级保护制度的现行版本,以国家标准 GB/T 22239-2019《信息安全技术 网络安全等级保护基本要求》 为锚点,该标准于 2019 年 5 月发布、2019 年 12 月 1 日施行,替代 1.0 框架,并将保护范围从传统信息系统扩展至云计算、移动互联、物联网、工业控制系统与大数据。
该制度包含五个步骤:(一)定级——运营者评估系统被破坏后的危害程度并划定等级;(二)备案——将定级结果报送公安机关登记;(三)建设整改——按标准的技术与管理要求补齐短板;(四)等级测评——由具备资质的第三方测评机构验证合规;(五)监督检查——公安机关持续监督。
依《网络安全法》,未落实等保的运营者将面临责令改正、罚款,严重者追究直接责任人员的责任。对外资企业而言,等保合规通常是上线面向用户系统、通过合作方安全审查、以及取得数据出境与许可审批(见相关文章)的前置条件。
五个保护等级
等保按系统被破坏后的危害程度分为五级:
- 第一级(自主保护级):对公民、法人或其他组织合法权益造成损害,但不损害国家、社会秩序或公共利益,通常自主定级。
- 第二级(指导保护级):对相关权益造成严重损害,或危害社会秩序、公共利益,但不危害国家安全;须备案,一般定期测评(常见每两年一次)。
- 第三级(监督保护级):严重危害社会秩序、公共利益,或危害国家安全;有相当规模的商业系统最常见,须备案并每年测评。
- 第四级(强制保护级):特别严重危害社会秩序、公共利益,或严重危害国家安全——多见于金融、能源、交通核心系统,至少每半年测评一次。
- 第五级(专控保护级):特别严重危害国家安全——国家专控,民企罕见。
多数外资商业运营落在二级或三级。实务经验:若系统处理大量用户、支付或个人信息,应预期为三级并承担年度测评义务。
关键信息基础设施(CII)
在等保之外,《网络安全法》第三十一条要求国家认定关键信息基础设施——电信、能源、交通、水利、金融、公共服务、电子政务、国防科技工业等重要行业和领域中,一旦遭到破坏、丧失功能或数据泄露,可能严重危害国家安全、国计民生、公共利益 networks and systems。CII 由相关行业主管部门认定、网信办统筹协调。
CII 运营者的义务远超等保:须(一)将在境内收集、产生的重要数据和个人信息存储在境内;(二)任何跨境提供前通过网信办安全评估(见 PIPL 文章);(三)定期开展安全检测与风险评估;(四)仅采购满足 CII 安全要求的产品与服务;(五)遵守专门的 CII 安全保护法规(2021 年国务院《关键信息基础设施安全保护条例》)。处于敏感行业的外资企业——云服务商、支付机构、大型平台、与公用设施关联的业务——应假设自身可能被认定为 CII 并提前规划。
外资企业的义务与执法
对外资企业,关键合规动作包括:确认各系统的中国境内责任主体(通常是境内子公司,而非境外母公司,作为备案主体);就每个面向互联网或承载数据的系统向当地公安机关定级备案;按 GB/T 22239-2019 整改;并委托具备资质的测评机构测评。三级及以上系统须持续年度测评,任何重大变更(新数据类型、新区域、并购)都可能重置定级。
执法真实且日趋活跃。公安机关开展抽查,监管发现会在等保—CII—数据出境体系间共享。不合规可能阻断产品上线、招致罚款,并在涉及个人信息或重要数据时与 PIPL、《数据安全法》相交叠。外资集团应将等保视为由本地问责高管持续负责的常设项目,而非一次性证书。
下一步建议
- 盘点中国境内系统并为每个系统指定业务责任人;备案主体通常为境内子公司(非总部)。
- 对照 GB/T 22239-2019 如实定级;面向用户或承载数据的系统应预期二级至三级。
- 备案与整改并委托具备资质的测评机构,安排周期性测评(三级每年一次)。
- 评估 CII 暴露面:若经营电信、金融、能源、交通或平台业务,须为境内存储与网信办评估做准备。
- 建立常态化合规项目(制度、日志、演练)而非一次性审计,并与 PIPL 和数据出境义务统筹。
来源
- 全国人民代表大会(NPC) — 《网络安全法》(2017 年 6 月 1 日施行):第二十一条(等保)与第三十一条(CII)。
- 公安部 — 主管网络安全等级保护与系统备案(官方门户)。
- 全国标准信息公共服务平台(SAMR) — GB/T 22239-2019《网络安全等级保护基本要求》(官方标准门户)。
- 国家互联网信息办公室(CAC) — CII 认定与跨境安全评估(官方门户)。
- 中国政府网(国务院) — 2021 年《关键信息基础设施安全保护条例》。
相关阅读
- 参见:外资企业的个人信息保护法合规 — CII 与达到阈值处理者须境内存储并通过网信办评估方可出境。
- 参见:反垄断与经营者集中申报 — 并购可能重置系统定级并触发新备案。
- 参见:VIE 架构与监管趋势 — 境外上市的数据安全审查。
