Chinese Multi-Level Protection Scheme (Dengbao)

The Multi-Level Protection Scheme (dengji baohu zhidu, 等级保护制度), commonly known as dengbao, is China’s mandatory cybersecurity classification and protection framework. Established under the Cybersecurity Law (2017) and significantly updated in MLPS 2.0 (2019), the scheme requires information systems and network infrastructure to be classified into security levels and to implement corresponding security measures.

The legal basis for the multi-level protection scheme is established in Article 21 of the Cybersecurity Law, which requires that state-established cybersecurity classification system be implemented to protect network infrastructure and information systems. The MLPS is administered by the Ministry of Public Security (MPS), which issues standards, conducts evaluations, and enforces compliance.

The core standard for MLPS 2.0 is GB/T 22239-2019, which replaced the previous standard GB/T 22239-2008. MLPS 2.0 expanded the scope of the scheme from information systems to include all network infrastructure, cloud computing platforms, big data systems, industrial control systems, and Internet of Things (IoT) devices. The expansion reflected the changing technological landscape and the government’s determination to secure the full range of digital infrastructure.

Security Levels (1-5)

The MLPS defines five security levels based on the impact of a security incident on national security, economic development, social order, and public interest. Level 1 applies to systems where damage would cause limited damage to individual interests. Level 2 applies to systems where damage would cause substantial damage to individual interests or limited damage to social order. Level 3 applies to systems where damage would cause substantial damage to social order or limited damage to national security. Level 4 applies to systems where damage would cause substantial damage to national security. Level 5 applies to systems where damage would cause extremely serious damage to national security.

Level 1 systems are subject to the least stringent requirements, including basic security management and incident response. Level 2 systems must undergo evaluation by the operator itself or by an authorized evaluation body. Level 3 systems require mandatory evaluation by a qualified third-party evaluation body every year. Level 4 systems require evaluation every six months. Level 5 systems are subject to specialized supervision by national security authorities.

Requirements for Each Level

Each security level imposes specific technical and management requirements. The technical requirements include: physical security (data center access controls), network security (segmentation, firewalls, intrusion detection), host security (access controls, antivirus, patch management), application security (identity authentication, access controls, residual information protection), and data security (encryption, integrity verification, backup and recovery).

The management requirements include: security management institutions and personnel; security management systems and procedures; system development and acquisition security; system operation and maintenance management; incident response management; and business continuity management.

Level 3 systems — which cover most commercial enterprises’ core business systems — must implement all technical and management controls at the Level 3 standard, including: multi-factor authentication, encryption of data in transit and at rest, real-time security monitoring, incident response procedures, annual security evaluation by an authorized body, and designation of a security officer.

Classified Protection Evaluation

The classified protection evaluation (dengji baohu pinggu) process involves: system identification and classification by the network operator; filing of the system classification with the local public security authority; implementation of security measures according to the classification standard; third-party evaluation (for Levels 2-5); receipt of the evaluation report; and ongoing compliance monitoring.

The evaluation is conducted by authorized third-party evaluation bodies (pinggu jigou) that are licensed by the MPS. These bodies assess whether the operator’s technical and management controls meet the required standard and issue evaluation reports. The operator must submit the evaluation report to the relevant public security authority. Systems failing evaluation may be ordered to suspend operations or to implement corrective measures within a specified period.

The evaluation requirements have significant implications for foreign companies operating in China, which must classify and protect their systems according to Chinese standards. The evaluation process provides Chinese authorities with detailed information about foreign companies’ network architectures and security measures.

Enforcement Measures

The MPS and its local branches enforce the MLPS through inspections, audits, and administrative penalties. Operators who fail to comply with MLPS requirements may be subject to: rectification orders; fines (up to RMB 1 million under the Cybersecurity Law for serious violations); suspension of operations; revocation of licenses; and criminal liability for incidents resulting in serious consequences.

Enforcement has been increasingly active since the effectiveness of MLPS 2.0. The MPS has conducted nationwide inspections of critical information infrastructure operators and has imposed penalties for non-compliance. The MLPS applies extraterritorially to network operators outside China whose systems process data of Chinese citizens or affect Chinese national security. Foreign companies with operations in China must ensure that their China-related information systems comply with applicable MLPS requirements.