- The Measures for Network Data Security Risk Assessment, jointly issued by the CAC, MIIT and MPS, took effect on 20 August 2026.
由国家网信办、工业和信息化部、公安部联合制定的《网络数据安全风险评估办法》于 2026 年 8 月 20 日起施行。
- Important data processors must conduct a risk assessment at least once a year; when the security status of important data changes materially, a targeted assessment is required for the changed parts.
重要数据处理者应当每年至少开展一次风险评估;重要数据安全状态发生重大变化时,还须针对变动部分及时开展专项评估。
- Network data processors may conduct assessments themselves or entrust third-party institutions; in high-risk situations authorities may require assessment by a certified evaluation institution.
网络数据处理者可自行开展风险评估,也可委托第三方机构;存在较大安全风险等情形时,有关部门可要求其委托通过认证的评估机构开展评估。
- Important data processors must submit the risk assessment report to the relevant authority within 20 working days after completing the annual assessment.
重要数据处理者应当在年度风险评估完成后的 20 个工作日内,按照有关主管部门要求报送风险评估报告。
- The measures create a cross-department special working mechanism and prohibit repeated assessment of the same risk, easing the burden of multiple supervisors on the same data.
办法建立跨部门专项工作机制,并规定对同一风险不得重复评估,化解多头监管、重复检查问题。
- For foreign-invested enterprises that handle important data, the measures add a recurring compliance obligation that intersects with data classification, cybersecurity multilevel protection and cross-border data rules.
对处理重要数据的外资企业而言,办法增加了一项周期性合规义务,并与数据分类分级、网络安全等级保护及跨境数据规则相互交织。
Network Data Security Risk Assessment: The New Annual Obligation for Important Data Processors (Effective 20 August 2026) | 网络数据安全风险评估:重要数据处理者新增的年度义务(2026 年 8 月 20 日施行)
Why this matters now
On 20 August 2026, the Measures for Network Data Security Risk Assessment (《网络数据安全风险评估办法》) came into force. They were jointly formulated by the Cyberspace Administration of China (CAC), the Ministry of Industry and Information Technology (MIIT) and the Ministry of Public Security (MPS), and issued as Decree No. 24. The Measures institutionalise a recurring “health check” on network data and data-processing activities: important data processors must now conduct a risk assessment at least annually, report the outcome, and adjust when the security posture of important data changes. For foreign-invested enterprises (FIEs) that operate critical systems, hold important data, or sit within supply chains that handle it, the Measures add a standing, time-sensitive compliance obligation on top of data classification, multilevel protection (MLPS) and cross-border transfer rules.
What the Measures require
The Measures define network data security risk assessment as the identification, analysis and evaluation of security risks in network data and network data-processing activities. The core duties are as follows. First, important data processors must conduct an assessment at least once a year; if the security status of important data changes materially in a way that could adversely affect data security, they must promptly assess the changed part. Second, ordinary processors are encouraged to assess at least once every three years. Third, assessment may be performed in-house or by an entrusted third-party institution; where there is a larger security risk that could harm national security or the public interest, or where a data security incident has occurred, the authorities may require the processor to entrust a certified evaluation institution. Fourth, important data processors must submit the assessment report to the competent authority within 20 working days of completing the annual assessment; where no competent authority is identified, the report goes to the provincial or national cyberspace administration.
The Measures also build an institutional layer. Under the national data-security coordination mechanism, the CAC, together with the telecom and public-security authorities, will establish a special working mechanism to guide and supervise risk-assessment work. Assessment institutions are encouraged to obtain certification; the CAC Data and Technology Support Centre, the Third Research Institute of the MPS and Taier Certification have registered the Data Security Risk Assessment Service Certification Rules with the Certification and Accreditation Administration. A key procedural protection for business: the same risk must not be assessed repeatedly, which addresses the long-standing problem of overlapping checks by different regulators.
How it affects foreign-invested enterprises
For FIEs, the practical question is whether the company is an “important data processor” — a status driven by the Data Security Law’s framework of classified and graded data protection, industry rules on important-data catalogues and MLPS filing levels. A foreign-invested manufacturer with industrial control data, a data centre operator, a platform handling large volumes of personal information, or a company designated by a regulator as holding important data will likely fall within scope. For such companies, the annual assessment is a recurring milestone that should be embedded in the compliance calendar alongside MLPS level tests, data-export security assessments and PIPL audits. The assessment covers the entire lifecycle of the data — collection, storage, use, processing, transmission, provision, disclosure and deletion — so it overlaps with personal-information protection measures for platform operators. The report-submission duty (20 working days) and the possibility of being ordered to use a certified third party create real deadlines that HR, legal, IT and security functions need to coordinate.
Practical steps
- Determine whether you are an important data processor. Map data assets against the important-data catalogues of your sector and confirm classification and grading; treat MLPS filing level and regulator designation as strong signals.
- Establish an annual assessment cycle. Fix a yearly risk-assessment date, decide whether to use an in-house team or a certified third party, and align it with other compliance milestones.
- Trigger targeted assessments. Monitor for material changes — new data categories, new systems, security incidents, significant cross-border flows — and assess the changed parts promptly.
- Manage the report obligation. Prepare the assessment report and submit within 20 working days to the competent authority, or to the provincial/national CAC where the authority is unclear; keep records of the self-assessment basis.
- Coordinate with cross-border and MLPS work. Use the same data inventory for risk assessment, security assessment of outbound transfers, standard-contract filings and MLPS grading to avoid duplicative but divergent analysis.
- Prepare for certification demands. If your sector is under scrutiny, consider obtaining a certified evaluation institution early so you can respond quickly if the authorities require an independent assessment.
Compliance notes
The Measures do not create a new licensing regime; they formalise an obligation that already exists in substance under the Data Security Law and the Regulations on the Administration of Network Data Security. Failure to conduct the required assessment, or producing false reports, can attract enforcement under those laws, including orders to stop processing important data. Foreign parent groups should also note that risk assessment results feed into the same supervisory picture as cross-border transfers, so deficiencies identified here can surface in export-security assessments. Finally, the “no repeated assessment” rule protects companies from redundant checks but assumes the company can evidence its own assessment; documentation quality is therefore a compliance asset.
网络数据安全风险评估:重要数据处理者新增的年度义务(2026 年 8 月 20 日施行)/ Network Data Security Risk Assessment: The New Annual Obligation for Important Data Processors (Effective 20 August 2026)
为什么当下重要
2026 年 8 月 20 日,《网络数据安全风险评估办法》正式施行。该办法由国家互联网信息办公室、工业和信息化部、公安部联合制定,以三部门令第 24 号发布。办法将网络数据及数据处理活动的”定期体检”制度化:重要数据处理者必须每年至少开展一次风险评估、报送结果,并在重要数据安全态势变化时动态调整。对运营关键系统、持有重要数据、或身处处理重要数据的供应链中的外资企业而言,办法在数据分类分级、等级保护与跨境传输规则之上,新增了一项常设、有时限的合规义务。
办法要求什么
办法将网络数据安全风险评估界定为对网络数据和网络数据处理活动的安全风险进行识别、分析和评价。核心义务如下。其一,重要数据处理者应当每年至少开展一次评估;重要数据安全状态发生重大变化、可能对数据安全造成不利影响时,还须针对变化部分及时开展专项评估。其二,鼓励一般数据处理者至少每 3 年开展一次评估。其三,评估既可自行开展,也可委托第三方机构;当存在可能危害国家安全、公共利益等较大安全风险,或发生数据安全事件时,有关部门可要求数据处理者委托通过认证的评估机构开展评估。其四,重要数据处理者应当在年度评估完成后的 20 个工作日内,按有关主管部门要求报送评估报告;主管部门不明确的,向省级或国家网信部门报送。
办法还构建了制度层。在国家数据安全工作协调机制指导下,国家网信部门会同电信、公安等部门建立网络数据安全风险评估专项工作机制,指导监督评估工作。评估机构鼓励通过认证;国家网信办数据与技术保障中心、公安部第三研究所、泰尔认证中心等已向国家认证认可监督管理委员会备案《数据安全风险评估服务认证规则》。对企业的一项关键程序保护:对同一风险不得重复评估,破解了此前多头监管、重复检查的突出问题。
对外资企业的影响
对外资企业,首要问题是判定是否属于”重要数据处理者”——该身份由《数据安全法》的分类分级框架、行业重要数据目录规则与等级保护备案级别共同决定。拥有工业控制数据的外资制造企业、数据中心运营方、处理大量个人信息的平台,或被监管认定持有重要数据的企业,很可能落入范围。此类公司的年度评估是一项周期性里程碑,应嵌入合规日历,与等级保护测评、数据出境安全评估和 PIPL 审计并列。评估覆盖数据全生命周期——收集、存储、使用、加工、传输、提供、公开、删除——因此与平台运营者的个人信息保护措施相互重叠。报告报送义务(20 个工作日)以及被要求委托认证第三方评估的可能,形成了 HR、法务、IT 与安全部门需要协同的真实时限。
操作步骤
- 判定是否属于重要数据处理者。 对照本行业重要数据目录梳理数据资产并确认分类分级;将等级保护备案级别与监管认定视为强信号。
- 建立年度评估周期。 固定每年评估日期,决定使用内部团队还是认证第三方,并与其他合规节点对齐。
- 触发专项评估。 监测重大变化——新增数据类别、新系统、安全事件、重大跨境流动——并及时评估变化部分。
- 管理报告义务。 编制评估报告并在 20 个工作日内报送主管部门,或报送省级/国家网信部门;留存自评估依据的记录。
- 与跨境与等保工作协同。 使用同一数据台账开展风险评估、出境安全评估、标准合同备案与等保定级,避免重复但口径不一的分析。
- 为认证要求做好准备。 若所在行业受重点监管,可提前确定认证评估机构,以便监管要求独立评估时快速响应。
合规提示
办法不创设新的许可制度,而是将《数据安全法》与《网络数据安全管理条例》下已实质存在的义务成文化。未按规定开展评估或出具虚假报告,可能依据这些法律受到处理,包括责令停止处理重要数据。境外母公司还应注意,风险评估结果与跨境传输同处一套监管图景,此处发现的缺陷可能出现在出境安全评估中。最后,”不得重复评估”规则保护企业免于冗余检查,但前提是企业能证明自身评估;因此文档质量本身就是一项合规资产。
Sources
- 国家网信办《〈网络数据安全风险评估办法〉实施有关事项答记者问》(2026-08-20):https://www.cac.gov.cn/2026-08/20/c_1788889498173657.htm
- 央视网《制度护航!〈网络数据安全风险评估办法〉为数字经济健康发展划定安全边界》(2026-08-20):https://news.cctv.cn/2026/08/20/ARTIt9Y6eWXDcCSc36BtTici260820.shtml
- 人民日报(中国网转载)《〈网络数据安全风险评估办法〉8月20日施行 公安部有关负责人答记者问》(2026-08-21):https://zw.china.com.cn/2026-08/21/content_118657914.shtml
