Chinese Critical Information Infrastructure Protection

CII under the Cybersecurity Law

The protection of critical information infrastructure (CII) (guanjian xinxi jichu sheshi, 关键信息基础设施) is governed principally by Article 31 of the Cybersecurity Law of the People’s Republic of China (effective 1 June 2017). Article 31 provides that the State Council and relevant departments shall develop specific rules for the security protection of CII in “important industries and fields” including public communications and information services, energy, transport, water conservancy, finance, public services, electronic government affairs, and defence technology manufacturing.

The Cybersecurity Law establishes a baseline protection regime for CII operators. Article 31 requires CII operators to fulfil specified security protection obligations beyond those applicable to general network operators. The Law also requires CII operators established within China to store personal information and important data collected or generated during operations within China (Article 37), with cross-border data transfer subject to a security assessment conducted by the Cyberspace Administration of China (CAC).

CII Identification

The Measures for the Security Protection of Critical Information Infrastructure (Guanjian Xinxi Jichu Sheshi Anquan Baohu Tiaoli), issued by the State Council and effective 1 September 2021, established the rules for CII identification. The Measures designate sector-specific regulators — the CAC coordinates identification, while ministries including the Ministry of Public Security, the National Energy Administration, the People’s Bank of China, and others identify CII within their respective sectors.

The identification criteria include: (1) the extent to which the network or system is essential to national security, the national economy, people’s livelihoods, or public interests; (2) the extent of harm to national security, the national economy, or public interests if the network or system were incapacitated, damaged, or suffered a data breach; and (3) the network or system’s interconnectedness with other critical infrastructure. Operators notified of their CII designation must implement enhanced security measures within a prescribed period.

Security Protection Obligations

CII operators are subject to enhanced security obligations under the Cybersecurity Law and the 2021 Measures. Article 34 of the Cybersecurity Law lists the minimum obligations: establishing internal security management systems and operating rules; designating a CII security officer and establishing a dedicated security department; conducting regular cybersecurity education and training; conducting regular security risk assessments; formulating cybersecurity incident response plans; and conducting disaster recovery exercises.

The 2021 Measures add further obligations. CII operators must conduct a security risk assessment at least once per year and submit the assessment report to the relevant supervisory authority. The risk assessment must evaluate the effectiveness of security protection measures, the vulnerability of the CII to cybersecurity threats, and the adequacy of incident response capabilities. The Measures also require CII operators to purchase network products and services that “may affect national security” only after passing a national security review.

Annual Security Assessment

The annual security assessment requirement is implemented through the Regulations on the Security Assessment of Cross-border Data Transfer and the Measures on the Security Assessment of Network Products and Services. The CII operator must engage a qualified cybersecurity service provider to conduct the assessment, which reviews the operator’s cybersecurity management system, technical protection measures, physical security, personnel security, incident response capability, and supply chain security.

The assessment report must be submitted to the relevant sector regulator and to the CAC. Where the assessment identifies deficiencies, the operator must implement corrective measures within a prescribed time. Failure to conduct the annual assessment or to implement corrective measures exposes the operator to penalties including fines (up to RMB 1 million for the operator and up to RMB 100,000 for the responsible person), suspension of operations, and revocation of the operator’s business licence.

Cybersecurity Review

The Cybersecurity Review (Wangluo Anquan Shencha) regime, established by the Measures for Cybersecurity Review (effective 15 February 2022), requires a national security review of the procurement of network products and services by CII operators. The Review evaluates whether the procurement poses risks to the “security and controllability” (anquan kekong) of the CII, including the risk of supply chain disruption, embedded backdoors, data leakage, and foreign government interference.

The Cybersecurity Review applies to CII operators’ procurement of core network equipment, high-performance computing products, cloud computing services, and other products and services designated by the CAC. The review is conducted by the Cybersecurity Review Office within the CAC, which consults with the National Development and Reform Commission, the Ministry of Industry and Information Technology, the Ministry of Public Security, and other relevant agencies. The review may result in approval, conditional approval (with remedial measures), or prohibition of the procurement.

The Cybersecurity Review regime was applied in the Didi enforcement action (2022). The CAC launched a cybersecurity review of Didi Global Inc. shortly after its US IPO in June 2021, citing national security concerns about the potential access of US regulators to Chinese personal information and important data. The review resulted in Didi being ordered to delist from the NYSE (completed in 2022), to restructure its data management practices, and to pay a fine of RMB 8.026 billion (approximately USD 1.2 billion) for violations of the Cybersecurity Law, the Data Security Law, and the Personal Information Protection Law.

Measures for CII Security Protection (2021)

The Measures for the Security Protection of Critical Information Infrastructure (2021) are the principal implementing regulation for CII protection. The Measures establish a lifecycle protection framework covering identification, protection, detection and response, and recovery.

Protection requires CII operators to implement technical measures including: network segmentation and isolation; identity authentication and access control; data encryption; intrusion detection and prevention; security audit logging; and redundancy and backup. The Measures require CII operators to establish a security protection fund with an annual budget of at least 5% of the operator’s information technology expenditure.

Detection and response requires CII operators to monitor their networks for cybersecurity threats and to report incidents to the relevant authorities, the Ministry of Public Security, and the CAC within one hour of detection. The Measures require CII operators to conduct at least one cybersecurity incident response drill per year.

Recovery requires CII operators to maintain backup systems and disaster recovery capabilities. The Measures require critical CII to have a dedicated backup centre located at least 100 kilometres from the primary centre and to conduct recovery drills at least twice per year.

Conclusion

Chinese CII protection law establishes a comprehensive regulatory regime grounded in the Cybersecurity Law and implemented through sector-specific identification, enhanced security obligations, annual risk assessment, cybersecurity review, and the 2021 Measures. The regime is notable for its emphasis on national security, its application of the cybersecurity review mechanism to foreign procurement, and its integration with the data localisation and cross-border data transfer regimes. The Didi enforcement action demonstrated the regime’s capacity for extraterritorial application and its significance as a regulatory tool for asserting Chinese sovereignty over data and network infrastructure.