Law / China

Cybersecurity Law, Network Product and Service Security Duties

Cybersecurity Law of the People's Republic of China (as amended by the Decision of October 28, 2025, effective January 1, 2026), Art. 24

A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.

In force 8 months, effective 1 January 2026.

A product security requirements rule binding private bodies.

As of 12 September 2026.

What it requires

  • This binds a provider of a network product or service, not the broader network-operator classification the same Law uses elsewhere and which this corpus cannot yet flag against.
  • Meet the mandatory requirements of the applicable national standard for your product or service, and do not embed a malicious program in it.
  • On discovering a security defect, vulnerability, or other risk in your product or service, immediately take remedial measures, notify affected users as provided, and report the defect or vulnerability to the competent authority; the statute states no numeric clock for this notice, only immediacy.
  • Provide continuous security maintenance for your product or service and do not terminate it within the period fixed by regulation or agreed with your user.
  • Where your product or service collects user information, disclose that collection and obtain consent, and where personal information is involved, also follow this Law's and the Personal Information Protection Law's personal-information rules, already this jurisdiction's privacy row.

If you get it wrong

Criminal exposureNo

Criminal exposure note

Article 62 attaches only administrative fines, escalating on cross-reference to Article 61's third paragraph, to a violation of this duty; the Law's general residual clause, Article 76, reaches criminal liability only for conduct that independently constitutes a crime under other law, not for this duty by itself.

Penalty structure

Article 62's own ceiling for an ordinary violation (embedding a malicious program, failing to remediate and report a known defect or vulnerability, or prematurely ending security maintenance) is a fine of 50,000 to 500,000 yuan, plus 10,000 to 100,000 yuan against the directly responsible manager, once the provider refuses to correct the violation or the violation endangers network security; a first violation with no such aggravating fact draws only a corrective order and a warning. Article 62's second paragraph cross-references Article 61's third paragraph for a violation that causes a large-scale data leak or critical information infrastructure's loss of a local function (500,000 to 2,000,000 yuan) or loss of a primary function (2,000,000 to 10,000,000 yuan), which this structure does not carry a separate field for.

Rule
Fixed only
As of
12 September 2026
Currency
CNY
Fixed cap
500,000

Who enforces it

Enforcement body

The competent department with jurisdiction over the provider, acting within the national coordination the Cyberspace Administration of China exercises over network-security work under Article 9 of the Law.

What it reaches

Obligation class

Security, Governance, Reporting

What this law does

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

A provider of a network product or service must ensure the product or service meets the mandatory requirements of the relevant national standard and must not embed a malicious program in it. On discovering that its product or service has a security defect, vulnerability, or other risk, the provider must immediately take remedial measures and, as provided, promptly notify users and report to the competent authority.

The provider must continuously maintain the product's or service's security and must not terminate that maintenance within the period fixed by regulation or agreed with the user. Where the product or service collects user information, the provider must disclose that collection and obtain consent, and, where personal information is involved, comply with this Law's and the Personal Information Protection Law's rules on personal information.

An ordinary violation draws a corrective order, a warning, and a fine of 50,000 to 500,000 yuan if the provider refuses to correct or the violation endangers network security, with a further escalation, cross-referenced from Article 61's third paragraph, of 500,000 to 2,000,000 yuan for causing a large-scale data leak or the loss of a local function of critical information infrastructure, and 2,000,000 to 10,000,000 yuan where critical information infrastructure loses a primary function.

When LexLint raises it

  • distributes_software_product
  • ships_mobile_app

Read the law

Official consolidated text
cac.gov.cn (sourced to the National People's Congress website), Cybersecurity Law of the People's Republic of China as amended

Back to the example  ·  Lint your app