Law / China

National Cybersecurity Incident Reporting Measures

Measures for the Administration of National Cybersecurity Incident Reporting (Cyberspace Administration of China, issued September 11, 2025) Arts. 2, 4, 5, 8, 9, 12, 14

A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.

What follows is LexLint's own research summary of this law, not legal advice.

In force 11 months, effective 1 November 2025.

A vulnerability and incident reporting rule binding public and private bodies.

As of 20 September 2026.

What it requires

  • This binds a network operator, meaning the owner, manager, or network service provider of a network, that builds or operates a network, or provides a service through a network, inside China; because that reaches almost any organization running a system, this instrument flags on every activity and role this corpus can express rather than a narrower guess.
  • On discovering or becoming aware of a cybersecurity incident affecting your own operations, grade it against China's four-tier National Cybersecurity Incident Classification and Grading Guide (especially major, major, relatively major, ordinary), and report only where you grade it relatively major or above; an ordinary incident carries no report duty under this instrument.
  • Where the incident involves critical information infrastructure, report to your sector's protection-work department and to the public security organ within 1 hour of discovering or becoming aware of the incident.
  • Where you are a department of a central or state organ, or a directly affiliated unit of one, report to your own department's cyberspace affairs unit within 2 hours of discovering or becoming aware of the incident.
  • Every other network operator must report to the cyberspace administration department of its own province within 4 hours of discovering or becoming aware of the incident.
  • A major or especially major incident additionally triggers an escalation between government bodies up to the national cyberspace administration after you report; that further escalation is not a step you perform yourself.
  • Where your industry carries its own reporting rule, also report as your industry's regulator requires, and report a suspected crime to the public security organ promptly.
  • Where an organization or individual provides you network-security or system-operation-and-maintenance services under contract, require that provider by contract to promptly report to you any cybersecurity incident it discovers through monitoring, and to assist your own reporting under these Measures; this is the paragraph that reaches a cloud host, managed-security vendor, or AI operator serving you as its customer.
  • Within 30 days of completing disposal of a relatively major incident or above, submit a summary report covering the incident's cause, your emergency response, the harm caused, accountability, remediation, and lessons learned, through the same channel you used for the original report.
  • Taking reasonable and necessary protective measures, disposing of the incident under your emergency plan, effectively reducing its impact, and reporting it as required can draw a lighter consequence, or none at all, for a reporting shortfall elsewhere in the same incident.

If you get it wrong

Criminal exposureNo

Criminal exposure note

Article 10 refers a violation of this reporting duty to the competent department for punishment under other law, and aggravates only administratively, a heavier penalty on the operator and its responsible persons, where late, missed, false, or concealed reporting caused major harm; the Measures name no criminal offense of their own for a reporting failure.

Who enforces it

Enforcement body

The competent department with jurisdiction over the network operator penalizes a reporting failure under other law. Day-to-day intake and coordination run through the national cyberspace administration department, which coordinates cybersecurity incident report management nationwide, and each province's cyberspace administration department, which coordinates it within its own administrative region.

Settledness

The Cyberspace Administration's own Q&A page restates the same clocks and channels Article 4 states and does not resolve the open question above; no court has construed this instrument and it is not under challenge as of the date shown.

As of
20 September 2026
Guidance link
https://www.cac.gov.cn/2025-09/15/c_1759583021718167.htm
Guidance body
Cyberspace Administration of China, official Q&A on the Measures for the Administration of National Cybersecurity Incident Reporting
Open questions
Does Article 4's critical-information-infrastructure reporting channel require the reporting network operator to itself be the designated critical-information-infrastructure operator under the separate Critical Information Infrastructure Security Protection Regulation, or does it also reach a network operator whose own-unit incident merely touches critical information infrastructure that a different entity operates?

What it reaches

Obligation class

Reporting, Security

What this law does

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

A network operator that builds or operates a network, or provides a service through a network, within the territory of China must report a cybersecurity incident under these Measures. These Measures define a network operator as the owner, manager, or network service provider of a network.

These Measures also define a cybersecurity incident as an event that, due to human causes, a network attack, a network vulnerability or hidden danger, a hardware or software defect or malfunction, force majeure, or another factor, harms a network or information system or the data and business applications within it and has a negative impact on the state, society, or the economy.

On discovering or becoming aware of an incident involving its own unit, a network operator must grade the incident against the annexed National Cybersecurity Incident Classification and Grading Guide and report only where the grade is relatively major or above. Where the incident involves critical information infrastructure, the operator must report to the sector's protection-work department and to the public security organ within 1 hour of discovering or becoming aware of it.

A network operator that is a department of a central or state organ, or a directly affiliated unit of one, must report to its own department's cyberspace affairs unit within 2 hours. Every other network operator must report to the cyberspace administration department of its own province within 4 hours.

A major or especially major incident escalates further between the government bodies that received the operator's report, up to the national cyberspace administration, without imposing any additional step on the reporting operator itself.

A network operator must require, by contract, any organization or individual providing it network-security or system-operation-and-maintenance services to promptly report to it any cybersecurity incident that provider discovers through monitoring, and to assist the operator's own reporting under these Measures.

Within 30 days of completing disposal of a relatively major incident or above, the operator must submit a summary report on the incident's cause, its emergency response, the harm caused, accountability, remediation, and lessons learned, through the same channel used for the original report.

A failure to report as required draws a penalty under other law, and reporting late, missing a report, or filing a false or concealed report that causes major harm draws a heavier penalty on the operator and its responsible persons. An operator that took reasonable and necessary protective measures, disposed of the incident under its emergency plan, effectively reduced the incident's impact, and reported it as required may be treated leniently or not held accountable at all.

A report involving a state secret follows the rules of the relevant department instead of the general channel described here.

When LexLint raises it

  • crawls_web
  • trains_models
  • generates_content
  • deploys_chatbot
  • automated_outreach
  • high_risk_decisions
  • processes_voice
  • processes_biometrics
  • publishes_adult_content
  • operates_social_platform
  • serves_minors
  • operates_app_store
  • ships_mobile_app
  • aggregates_content
  • distributes_software_product
  • handles_health_records
  • provides_financial_services
  • operates_essential_service
  • is_listed_company
  • provides_telecom_services

Read the law

Official text
cac.gov.cn (published via China Cyberspace, 中国网信网), Measures for the Administration of National Cybersecurity Incident Reporting

Every line above is drawn from the primary source linked here, read on the date shown. This is a research summary, not legal advice.

Back to the example  ·  Lint your app