China’s public security cyberspace inspection regime gets a major upgrade from 1 October 2026

  • The Ministry of Public Security issued Order No. 176, the Measures for Public Security Organs’ Supervision and Inspection of Cyberspace Security, on 6 August 2026; the rules take effect on 1 October 2026 and repeal the 2018 Internet security inspection rules (Order No. 151).
    2026年8月6日,公安部发布《公安机关网络空间安全监督检查办法》(公安部令第176号),自2026年10月1日起施行,2018年发布的《公安机关互联网安全监督检查规定》(公安部令第151号)同时废止。
  • The new measures shift the scope from “internet security” to “cyberspace security”, defined as the combination of network security, data security and information security, and list eight categories of inspection targets including data processors and personal-information processors.
    新办法把监管口径从”互联网安全”升级为”网络空间安全”(即网络安全、数据安全、信息安全三位一体),并列出八类检查对象,数据处理者、个人信息处理者被明确纳入。
  • Routine on-site inspection of operators of Level-3-and-above classified-protection networks and critical information infrastructure operators is set at once a year, and results of inspections already conducted by other competent authorities in the same year are reused to avoid duplicate checks.
    对网络安全等级保护第三级(含)以上网络运营者、关键信息基础设施运营者,每年开展一次日常性现场检查;本年度其他主管部门已开展的现场检查,公安机关复用检查结果、不再重复检查。
  • Algorithm security is a newly added inspection item: public security organs will check whether entities have implemented their primary responsibility for algorithm safety, including recommender-system management institutions and technical safeguards.
    算法安全是新纳入的重点检查内容:公安机关将核查被检查对象是否依法落实算法安全主体责任、建立健全算法推荐管理制度和技术措施。
  • Inspection methods now include online patrol, vulnerability scanning and, for city-level-and-above organs, remote penetration testing with three working days’ advance notice; technical support may be outsourced to qualified security service providers under police command.
    检查方式升级为线上巡查、漏洞扫描,设区的市级以上公安机关可开展漏洞探测、渗透性测试等远程检测(提前三个工作日告知),并可委托具备能力的网络安全服务机构在民警指挥下提供技术支持。
  • For enterprises, the message is that data security and personal-information protection duties are now subject to direct routine supervision by public security organs, alongside traditional duties such as record-filing of networked units, log retention and classified-protection compliance.
    对企业的直接含义是:联网备案、日志留存、等级保护等传统义务之外,数据安全与个人信息保护义务也将接受公安机关常态化直接监管,合规准备应提前完成。

China’s public security cyberspace inspection regime gets a major upgrade from 1 October 2026 | 公安机关网络空间安全监督检查新规:2026年10月1日起全面升级

Overview

On 6 August 2026, the Ministry of Public Security (MPS) published the Measures for Public Security Organs’ Supervision and Inspection of Cyberspace Security (公安机关网络空间安全监督检查办法) as Order No. 176, adopted at the second MPS ministerial meeting on 1 July 2026. The Measures take effect on 1 October 2026, at which point the 2018 Provisions on Public Security Organs’ Inspection of Internet Security (Order No. 151) are repealed. For any organisation operating online in China — including the China subsidiaries of foreign enterprises, data processors and app or platform operators — the change is more than a renaming exercise: it redefines what public security organs may inspect, whom they may inspect, and how often.

What changed: from “internet security” to “cyberspace security”

The most fundamental change is conceptual. The old 2018 rules governed “internet security” in the narrow sense of protecting externally facing online business. Order No. 176 defines cyberspace security as the sum of network security, data security and information security, and states that the measures apply to supervision and inspection of whether network operators, data processors, personal-information processors and others have performed their statutory security obligations.

The practical effect is that internal systems, business networks that are not open to the public, data warehouses and employee or customer personal-information repositories all fall within the inspection remit. Being “not an internet company” is no longer a defence: the Measures explicitly cover data processing and personal-information processing activities wherever they occur.

Eight categories of inspection targets

Article 6 lists eight categories of entities that public security organs may inspect according to operational need:

  1. Internet service providers — access, data centres, content delivery, domain services and information services;
  2. Public internet access providers;
  3. Network operators and their constructors and maintainers;
  4. Critical information infrastructure (CII) operators and their constructors and maintainers;
  5. Providers of network products and services;
  6. Data processors;
  7. Personal-information processors;
  8. Other entities lawfully subject to inspection.

Entities that have previously suffered a network or data security incident, or that were administratively penalised for failing to perform statutory security obligations without rectifying as required, are flagged for key-focus inspection. Foreign-invested companies that operate cloud, data, e-commerce or software businesses in China should assume they fall within categories 5 to 7.

What is inspected: eleven core items plus special-event items

Article 7 sets out eleven focal points for routine inspection, including whether the entity has:

  • completed networked-unit record-filing and reported access-provider and user information and changes;
  • established and implemented network, data and information security management institutions and operating procedures;
  • recorded and retained user registration information and internet activity logs as required;
  • performed classified-protection (MLPS) obligations — level-setting filing, level testing, build-and-rectify and self-inspection;
  • performed CII security-protection obligations;
  • adopted technical measures against computer viruses, cyber attacks and intrusions;
  • rectified security vulnerabilities and eliminated risks;
  • taken preventive measures against content that laws and regulations prohibit;
  • implemented its primary responsibility for algorithm security, including recommender-system management institutions and technical measures (new);
  • performed data-security and personal-information-protection obligations (now enforceable directly by public security organs);
  • provided technical support and assistance to public security organs for national security, counter-terrorism and crime investigation.

During major national security-protection task periods (for example, major summits or events), Article 8 adds special-purpose inspection items covering security plans, risk assessments, emergency-response plans and drills, and incident reporting.

How inspection happens: layered methods with burden-reduction safeguards

The Measures deliberately combine stronger methods with burden-reduction for businesses:

  • Online patrol (Article 4): information-patrol, information-audit capability testing and vulnerability scanning conducted in ways that do not disrupt normal operations. Information-audit capability tests require three working days’ advance notice.
  • Remote detection: city-level-and-above public security organs may carry out vulnerability probing and penetration testing on network facilities and systems other than CII, again with three working days’ notice, without interference, and with coordination notices to cyberspace-administration and industry authorities.
  • On-site inspection (Articles 5, 11–12): conducted by county-level-and-above organs at the operator’s main place of operations; at least two police officers with police ID and an inspection notice; measures include entering premises, questioning responsible persons, reviewing and copying relevant information, and viewing security-protection measures.
  • Frequency cap (Article 9): for operators of Level-3-and-above MLPS networks and CII operators, routine on-site inspection is limited to once a year; if another competent authority has already conducted an on-site inspection in the same year, the public security organ reuses those results rather than repeating the check.
  • Inter-agency coordination (Articles 9–10): for daily inspections in sectors with their own regulators (telecom, energy, transport, water, finance, defence science and industry), the relevant regulators and cyberspace-administration bodies are informed five working days in advance, and joint inspections are preferred where proposed. Nationwide multi-sector campaigns require approval from the Central Cyberspace Affairs Commission.
  • Outsourced technical support (Article 13): public security organs may commission qualified security service providers, who must act under police command, sign confidentiality commitments and be subject to background vetting where penetration testing is involved.

Outcomes and enforcement

Article 14 forbids charging fees or requiring the purchase of designated products. Where risk hidden dangers are found, organs direct rectification (Article 16). Where problems do not yet constitute illegal activity, the organ may issue a public-security reminder letter, send a letter to the competent industry authority, or publish a public notice without naming the entity (Article 17). Legal representatives or principal responsible persons of operators may be summoned for talks where significant risks or incidents exist (Article 19). Breaches of statutory duties are pursued under the Cybersecurity Law, the Data Security Law, the Personal Information Protection Law, the CII Security Protection Regulations, the Network Data Security Administration Regulations and related rules (Article 16). Information obtained during inspection may be used only for cyberspace-security purposes and must be kept confidential (Article 20).

Practical steps for foreign-invested companies

  • Treat 1 October 2026 as a compliance deadline. Run an internal gap assessment before the Measures take effect, covering MLPS level-setting and testing validity, log retention, vulnerability management and the completeness of security-management documentation.
  • Extend the compliance scope to data and personal information. Document data classification and grading, important-data protection measures, risk assessments and personal-information-protection impact assessments, because these duties are now directly inspectable by public security organs rather than being treated as cyber-office-only matters.
  • Review algorithm practices. If the business operates content recommendation, search or ranking algorithms, confirm that algorithm primary-responsibility institutions and recommender-management technical safeguards are in place and properly documented.
  • Prepare an inspection kit. Designate a responsible manager and point of contact for inspections; keep complete records of record-filing certificates, testing reports, rectification logs, incident and drill records.
  • Leverage the coordination safeguards. If another regulator (e.g. the Cyberspace Administration of China or an industry authority) has already inspected the entity this year, be ready to cite that inspection to avoid duplicate on-site checks.
  • If a security firm is engaged by the authority, co-operate under the rules: technical supporters act under police command and must sign confidentiality commitments covering trade secrets and personal information.

Sources

  • 中国网(据公安部网站消息)— 网安监督检查新规明确检查内容等 10月1日起施行: https://news.china.com.cn/2026-08/07/content_118638649.shtml
  • 安全内参 — 《公安机关网络空间安全监督检查办法》出台,企业合规面临哪些新变化?: https://www.secrss.com/articles/92931
  • 微博专栏(2026年8月国内网络安全领域重要政策及标准速览,收录176号令要点): https://weibo.com/ttarticle/p/show?id=2309405339428934779056

Related reading

  • see also: how MLPS and CII obligations apply to foreign-invested enterprises (37-cybersecurity-mlps-fie)

公安机关网络空间安全监督检查新规:2026年10月1日起全面升级

概述

2026年8月6日,公安部公布《公安机关网络空间安全监督检查办法》(公安部令第176号)。该办法已于2026年7月1日经公安部第2次部务会议审议通过,自2026年10月1日起施行,2018年发布的《公安机关互联网安全监督检查规定》(公安部令第151号)同时废止。对任何在中国境内开展线上业务的组织——包括外资企业在华子公司、数据处理者、APP与平台运营者——这次调整不是简单的改名:它重新定义了公安机关可以检查什么、检查谁、多久查一次。

变化核心:从”互联网安全”到”网络空间安全”

最根本的变化在理念层面。旧版2018年规则治理的是狭义”互联网安全”,即对外在线业务防护。176号令把网络空间安全定义为网络安全、数据安全、信息安全三者的总和,并明确本办法适用于对网络运营者、数据处理者、个人信息处理者等履行法定安全义务情况开展的监督检查。

实际效果是:内网系统、不对公开放网的业务系统、数据仓库、员工或客户个人信息库,全部落入监管视野。”我们不是互联网公司”不再是挡箭牌——办法明确覆盖一切数据与个人信息处理活动,无论其发生在何处。

八类检查对象

第六条规定,公安机关可根据维护网络空间安全需要,对以下对象依法开展监督检查:

  1. 提供互联网接入、数据中心、内容分发、域名服务、信息服务等的互联网服务提供者;
  2. 公共上网服务提供者;
  3. 网络运营者及其建设者、维护者;
  4. 关键信息基础设施运营者及其建设者、维护者;
  5. 网络产品、服务的提供者;
  6. 数据处理者;
  7. 个人信息处理者;
  8. 其他依法可以监督检查的对象。

曾发生网络安全、数据安全等事件,或曾因未履行法定义务被行政处罚且未按要求整改的,列为重点监督检查对象。在华从事云、数据、电商或软件业务的外资企业,应默认自身落在第5至第7类范围内。

查什么:十一项重点内容加重大活动专项

第七条列出日常检查十一项重点,包括是否:依法办理联网单位备案并报送接入单位和用户信息及变更情况;依法制定并落实网络、数据、信息安全管理制度和操作规程;依法记录并留存用户注册信息和上网日志;依法履行等级保护(定级备案、等级测评、建设整改、自查);依法履行关键信息基础设施安全保护义务;依法采取防范病毒、攻击、入侵的技术措施;针对漏洞隐患采取整改措施;依法对法律法规禁止发布或传输的信息采取防范措施;依法落实算法安全主体责任、建立健全算法推荐管理制度和技术措施(新增);依法履行数据安全与个人信息保护义务(现由公安机关直接监管);依法为国家安全、反恐、侦查犯罪提供技术支持与协助。

在国家重大安全保卫任务期间,第八条增加专项检查内容,覆盖安保工作方案与责任分工、风险评估与风险管控、应急预案与演练、应急设施有效性及事件报告处置情况。

怎么查:多元手段叠加”减负”机制

办法有意把更强的手段与为企业减负的制度结合起来:

  • 线上巡查(第四条):网络信息巡查、信息审核能力测试、漏洞扫描等不影响正常业务运行的方式。开展信息审核能力测试须提前三个工作日告知。
  • 远程检测:设区的市级以上公安机关可通过漏洞探测、渗透性测试,对关键信息基础设施以外的网络设施和信息系统进行远程检测,同样提前三个工作日告知,不得干扰破坏,并通报同级网信与行业主管部门。
  • 现场检查(第五、十一、十二条):由运营机构所在地县级以上公安机关实施;民警不少于二人并出示警官证与监督检查通知书;措施包括进入场所、问询负责人、查阅复制信息、查看安全保护技术措施运行情况、开展技术检测。
  • 频次上限(第九条):对等保三级(含)以上网络运营者与关基运营者,日常性现场检查每年一次;本年度其他主管部门已现场检查的,公安机关复用结果、不再重复检查。
  • 跨部门协同(第九、十条):对电信、能源、交通、水利、金融、国防科技工业等行业开展日常性现场检查,应提前五个工作日告知网信与行业主管部门,对方提出联合检查的应联合开展;公安部部署跨行业跨部门检查须报中央网络安全和信息化委员会审批。
  • 委托技术支持(第十三条):公安机关可委托具备能力的网络安全服务机构或专门人员提供技术支持,受托方须在民警指挥下开展工作、签署保密承诺书;涉及渗透测试的机构及人员须经背景审查并全流程安全管理。

结果运用与法律责任

第十四条禁止向被检查对象收取费用或要求购买指定产品服务。发现风险隐患的,督促指导整改(第十六条)。问题尚不构成犯罪的,可发放公安提示函、向行业主管部门发函或向社会发布不点名通告(第十七条)。存在较大风险或发生安全事件的,可对法定代表人、主要负责人进行约谈(第十九条)。未履行法定义务的,依据《网络安全法》《数据安全法》《个人信息保护法》《关键信息基础设施安全保护条例》《网络数据安全管理条例》等追究法律责任(第十六条)。检查获取的信息只能用于维护网络空间安全之目的,并须保密(第二十条)。

外资企业实务建议

  • 把2026年10月1日当作合规时点。 在办法施行前完成内部差距评估,覆盖等保定级与测评有效性、日志留存、漏洞闭环整改、安全管理制度文档完整性。
  • 把合规范围扩展到数据与个人信息。 数据分类分级、重要数据保护措施、风险评估、个人信息保护影响评估等文档要备齐,因为上述义务现在由公安机关直接检查,不再是”网信部门的事”。
  • 审查算法实践。 若经营内容推荐、搜索或排序算法业务,确认算法安全主体责任机构与推荐管理技术措施到位并可举证。
  • 准备迎检资料包。 指定责任人与迎检对接人;备案证书、测评报告、整改记录、事件与演练记录等完整留存。
  • 善用协同减负机制。 若本年度网信部门或行业主管部门已检查过,准备引用检查结论以避免重复现场检查。
  • 配合技术支持机构时注意边界。 受托机构在民警指挥下工作并签保密承诺书,涉商业秘密与个人信息事项须谨慎配合。

来源

  • 中国网(据公安部网站消息)— 网安监督检查新规明确检查内容等 10月1日起施行: https://news.china.com.cn/2026-08/07/content_118638649.shtml
  • 安全内参 — 《公安机关网络空间安全监督检查办法》出台,企业合规面临哪些新变化?: https://www.secrss.com/articles/92931
  • 微博专栏(2026年8月国内网络安全领域重要政策及标准速览,收录176号令要点): https://weibo.com/ttarticle/p/show?id=2309405339428934779056

相关阅读

  • 见:外资企业的等保与关基义务如何适用(37-cybersecurity-mlps-fie)