TLDR; Below is the English-translated version of China’s Regulations on the Security Protection of Critical Information Infrastructure (关键信息基础设施安全保护条例, State Council Order No. 745), promulgated July 30, 2021 and in effect since September 1, 2021.
If your company is designated an operator of critical information infrastructure (CII) in mainland China, these Regulations are the source of the heaviest obligations in the country’s cybersecurity regime — a dedicated security management body, annual testing and risk assessment, incident reporting, and a mandatory security review of certain network-product procurement. Issued under the Cybersecurity Law, they define what counts as CII, how operators are identified, and the duties that follow; procurement that may affect national security must additionally clear the review set out in the Cybersecurity Review Measures. Because CII status is also what pulls an operator into data-localization requirements, confirming whether you fall within scope is one of the first questions international businesses should raise with qualified counsel.
Regulations on the Security Protection of Critical Information Infrastructure (Promulgated July 30, 2021 by Order No. 745 of the State Council; effective September 1, 2021)
Chapter I — General Provisions
Article 1. These Regulations are formulated in accordance with the “Cybersecurity Law of the People’s Republic of China” in order to safeguard the security of critical information infrastructure and to maintain cybersecurity.
Article 2. “Critical information infrastructure” as referred to in these Regulations means important network facilities, information systems, and the like in important industries and fields — such as public communications and information services, energy, transportation, water conservancy, finance, public services, e-government, and the national defense science, technology, and industry sector — as well as others that, once destroyed, rendered nonfunctional, or subjected to a data leak, may seriously endanger national security, the national economy and people’s livelihood, or the public interest.
Article 3. Under the overall coordination of the national cyberspace administration department, the public security department of the State Council is responsible for guiding and supervising the work of security protection of critical information infrastructure. The telecommunications authority of the State Council and other relevant departments are responsible, within their respective scopes of duties, for the security protection and the supervision and administration of critical information infrastructure in accordance with these Regulations and the provisions of relevant laws and administrative regulations.
The relevant departments of the people’s governments at the provincial level carry out security protection and supervision and administration of critical information infrastructure in accordance with their respective duties.
Article 4. The security protection of critical information infrastructure shall adhere to comprehensive coordination, division of responsibilities, and protection in accordance with law; shall strengthen and implement the principal responsibility of operators of critical information infrastructure (hereinafter referred to as “operators”); and shall give full play to the roles of the government and all sectors of society in jointly protecting the security of critical information infrastructure.
Article 5. The State implements key protection of critical information infrastructure, and takes measures to monitor, defend against, and handle cybersecurity risks and threats originating both within and outside the territory of the People’s Republic of China, so as to protect critical information infrastructure from attack, intrusion, interference, and sabotage, and to punish in accordance with law the unlawful and criminal activities that endanger the security of critical information infrastructure.
No individual or organization may engage in activities that illegally intrude upon, interfere with, or sabotage critical information infrastructure, or that endanger the security of critical information infrastructure.
Article 6. Operators shall, in accordance with these Regulations, the provisions of relevant laws and administrative regulations, and the mandatory requirements of national standards, and on the basis of the cybersecurity multi-level protection scheme, take technical protection measures and other necessary measures to respond to cybersecurity incidents, guard against cyberattacks and unlawful and criminal activities, ensure the secure and stable operation of critical information infrastructure, and maintain the integrity, confidentiality, and availability of data.
Article 7. Entities and individuals that achieve remarkable results or make outstanding contributions in the work of security protection of critical information infrastructure shall be commended in accordance with relevant State provisions.
Chapter II — Identification of Critical Information Infrastructure
Article 8. The competent departments and the supervision and administration departments of the important industries and fields covered by Article 2 of these Regulations are the departments responsible for the work of security protection of critical information infrastructure (hereinafter referred to as “protection work departments”).
Article 9. Protection work departments shall, in light of the actual conditions of their industry or field, formulate rules for the identification of critical information infrastructure, and file them with the public security department of the State Council for the record.
In formulating identification rules, the following factors shall be primarily considered:
(1) the degree of importance of the network facilities, information systems, and the like to the key and core operations of that industry or field;
(2) the degree of harm that may be brought about once the network facilities, information systems, and the like are destroyed, rendered nonfunctional, or subjected to a data leak;
(3) the associated impact on other industries and fields.
Article 10. Protection work departments are responsible, in accordance with the identification rules, for organizing the identification of critical information infrastructure in their industry or field, promptly notifying operators of the identification results, and reporting them to the public security department of the State Council.
Article 11. Where a critical information infrastructure undergoes a relatively major change that may affect the result of its identification, the operator shall promptly report the relevant circumstances to the protection work department. The protection work department shall complete the re-identification within 3 months from the date of receiving the report, notify the operator of the identification result, and report it to the public security department of the State Council.
Chapter III — Responsibilities and Obligations of Operators
Article 12. Security protection measures shall be planned, constructed, and put into use simultaneously with the critical information infrastructure.
Article 13. Operators shall establish and improve cybersecurity protection systems and responsibility systems, and shall ensure the investment of human, financial, and material resources. The principal person in charge of an operator bears overall responsibility for the security protection of critical information infrastructure, leads the security protection of critical information infrastructure and the handling of major cybersecurity incidents, and organizes the study and resolution of major cybersecurity problems.
Article 14. Operators shall establish a dedicated security management body, and shall conduct security background reviews of the person in charge of the dedicated security management body and of personnel in key positions. When such reviews are conducted, the public security organs and the state security organs shall provide assistance.
Article 15. The dedicated security management body is specifically responsible for the work of security protection of its entity’s critical information infrastructure, and performs the following duties:
(1) establishing and improving cybersecurity management and evaluation and assessment systems, and drawing up the security protection plan for the critical information infrastructure;
(2) organizing and promoting the development of cybersecurity protection capabilities, and carrying out cybersecurity monitoring, testing, and risk assessment;
(3) formulating the entity’s own emergency response plan in accordance with the State and industry cybersecurity incident emergency response plans, regularly conducting emergency drills, and handling cybersecurity incidents;
(4) identifying key cybersecurity positions, organizing and carrying out assessments of cybersecurity work, and putting forward recommendations for rewards and punishments;
(5) organizing cybersecurity education and training;
(6) performing responsibilities for the protection of personal information and data security, and establishing and improving systems for the protection of personal information and data security;
(7) implementing security management over services such as the design, construction, operation, and maintenance of the critical information infrastructure;
(8) reporting cybersecurity incidents and important matters in accordance with regulations.
Article 16. Operators shall ensure the operating funds of the dedicated security management body and provide it with corresponding personnel, and personnel of the dedicated security management body shall participate in the making of decisions related to cybersecurity and informatization.
Article 17. Operators shall, on their own or by entrusting a cybersecurity service institution, conduct cybersecurity testing and risk assessment of their critical information infrastructure at least once a year, promptly rectify any security problems discovered, and report the situation as required by the protection work department.
Article 18. When a major cybersecurity incident occurs in, or a major cybersecurity threat is discovered to, critical information infrastructure, the operator shall report it to the protection work department and the public security organs in accordance with relevant provisions.
When an especially major cybersecurity incident occurs — such as the overall interruption of operation or failure of the main functions of critical information infrastructure, a leak of national basic information or other important data, a relatively large-scale leak of personal information, the causing of relatively large economic losses, or the relatively widespread dissemination of unlawful information — or an especially major cybersecurity threat is discovered, the protection work department shall, after receiving the report, promptly report it to the national cyberspace administration department and the public security department of the State Council.
Article 19. Operators shall give priority to procuring secure and trustworthy network products and services; where the procurement of network products and services may affect national security, it shall pass a security review in accordance with State cybersecurity provisions.
Article 20. When procuring network products and services, operators shall, in accordance with relevant State provisions, conclude a security and confidentiality agreement with the provider of the network products and services, specifying the provider’s obligations and responsibilities for technical support and for security and confidentiality, and shall supervise the performance of those obligations and responsibilities.
Article 21. Where an operator undergoes a merger, division, dissolution, or the like, it shall promptly report to the protection work department, and shall dispose of the critical information infrastructure as required by the protection work department so as to ensure security.
Chapter IV — Safeguards and Promotion
Article 22. Protection work departments shall formulate security plans for critical information infrastructure in their industry or field, specifying the protection objectives, basic requirements, work tasks, and specific measures.
Article 23. The national cyberspace administration department shall coordinate the relevant departments in establishing a cybersecurity information sharing mechanism, and shall promptly compile, analyze and assess, share, and release information on cybersecurity threats, vulnerabilities, incidents, and the like, so as to promote the sharing of cybersecurity information among the relevant departments, the protection work departments, operators, cybersecurity service institutions, and others.
Article 24. Protection work departments shall establish and improve a cybersecurity monitoring and early-warning system for critical information infrastructure in their industry or field, keep timely track of the operational status and security posture of critical information infrastructure in their industry or field, issue early warnings and notifications of cybersecurity threats and hidden dangers, and guide the carrying out of security precautions.
Article 25. Protection work departments shall, in accordance with the requirements of the State cybersecurity incident emergency response plan, establish and improve cybersecurity incident emergency response plans for their industry or field, and regularly organize emergency drills; they shall guide operators in responding to and handling cybersecurity incidents, and organize the provision of technical support and assistance as needed.
Article 26. Protection work departments shall regularly organize cybersecurity inspections and testing of critical information infrastructure in their industry or field, and shall guide and supervise operators in promptly rectifying hidden security dangers and improving security measures.
Article 27. The national cyberspace administration department shall coordinate the public security department of the State Council and the protection work departments in conducting cybersecurity inspections and testing of critical information infrastructure and in putting forward improvement measures.
When conducting cybersecurity inspections of critical information infrastructure, the relevant departments shall strengthen coordination, cooperation, and information communication, and avoid unnecessary inspections and overlapping, duplicative inspections. No fees may be charged for inspection work, and the entity being inspected may not be required to purchase products or services of a designated brand or from a designated producer or seller.
Article 28. Operators shall cooperate with the cybersecurity inspection and testing work on critical information infrastructure carried out by the protection work departments, as well as with the cybersecurity inspection work on critical information infrastructure carried out in accordance with law by the relevant departments for public security, state security, the administration of secrecy, cryptography management, and the like.
Article 29. In the work of security protection of critical information infrastructure, the national cyberspace administration department, the telecommunications authority of the State Council, the public security department of the State Council, and others shall, according to the needs of the protection work departments, promptly provide technical support and assistance.
Article 30. The relevant departments such as cyberspace administration departments, public security organs, and protection work departments, as well as cybersecurity service institutions and their staff, may use information obtained in the work of security protection of critical information infrastructure only for the purpose of maintaining cybersecurity, and shall strictly ensure the security of such information in accordance with the requirements of relevant laws and administrative regulations; they may not disclose, sell, or illegally provide such information to others.
Article 31. Without the approval of the national cyberspace administration department or the public security department of the State Council, or the authorization of the protection work department or the operator, no individual or organization may carry out against critical information infrastructure such activities as vulnerability probing or penetration testing that may affect or endanger the security of the critical information infrastructure. Activities such as vulnerability probing and penetration testing carried out against basic telecommunications networks shall be reported in advance to the telecommunications authority of the State Council.
Article 32. The State takes measures to give priority to safeguarding the secure operation of critical information infrastructure in sectors such as energy and telecommunications.
The energy and telecommunications industries shall take measures to provide key safeguards for the secure operation of critical information infrastructure in other industries and fields.
Article 33. The public security organs and the state security organs shall, in accordance with their respective duties and in accordance with law, strengthen the security defense of critical information infrastructure, and guard against and crack down on unlawful and criminal activities that are directed at, or that make use of, critical information infrastructure.
Article 34. The State formulates and improves security standards for critical information infrastructure to guide and standardize the work of security protection of critical information infrastructure.
Article 35. The State takes measures to encourage specialized cybersecurity personnel to engage in the work of security protection of critical information infrastructure, and incorporates the training of operators’ security management personnel and security technical personnel into the national continuing education system.
Article 36. The State supports technological innovation and industrial development in the security protection of critical information infrastructure, and organizes forces to undertake key technical research on the security of critical information infrastructure.
Article 37. The State strengthens the development and administration of cybersecurity service institutions, formulates administrative requirements and strengthens supervision and guidance, continuously raises the capability levels of such service institutions, and gives full play to their role in the security protection of critical information infrastructure.
Article 38. The State strengthens military-civilian integration in cybersecurity, with the military and civilian sides cooperating to protect the security of critical information infrastructure.
Chapter V — Legal Liability
Article 39. Where an operator is in any of the following circumstances, the relevant competent department shall, in accordance with its duties, order corrections and give a warning; where it refuses to make corrections or where consequences such as endangering cybersecurity result, a fine of not less than 100,000 yuan and not more than 1,000,000 yuan shall be imposed, and a fine of not less than 10,000 yuan and not more than 100,000 yuan shall be imposed on the directly responsible person in charge:
(1) failing to promptly report the relevant circumstances to the protection work department when the critical information infrastructure undergoes a relatively major change that may affect the result of its identification;
(2) failing to plan, construct, and put into use security protection measures simultaneously with the critical information infrastructure;
(3) failing to establish and improve cybersecurity protection systems and responsibility systems;
(4) failing to establish a dedicated security management body;
(5) failing to conduct security background reviews of the person in charge of the dedicated security management body and of personnel in key positions;
(6) making decisions related to cybersecurity and informatization without the participation of personnel of the dedicated security management body;
(7) where the dedicated security management body fails to perform the duties provided for in Article 15 of these Regulations;
(8) failing to conduct cybersecurity testing and risk assessment of the critical information infrastructure at least once a year, failing to promptly rectify security problems discovered, or failing to report the situation as required by the protection work department;
(9) procuring network products and services without concluding a security and confidentiality agreement with the provider of the network products and services in accordance with relevant State provisions;
(10) undergoing a merger, division, dissolution, or the like without promptly reporting to the protection work department, or without disposing of the critical information infrastructure as required by the protection work department.
Article 40. Where, when a major cybersecurity incident occurs in or a major cybersecurity threat is discovered to critical information infrastructure, an operator fails to report it to the protection work department and the public security organs in accordance with relevant provisions, the protection work department and the public security organs shall, in accordance with their duties, order corrections and give a warning; where it refuses to make corrections or where consequences such as endangering cybersecurity result, a fine of not less than 100,000 yuan and not more than 1,000,000 yuan shall be imposed, and a fine of not less than 10,000 yuan and not more than 100,000 yuan shall be imposed on the directly responsible person in charge.
Article 41. Where an operator procures network products and services that may affect national security without undergoing a security review in accordance with State cybersecurity provisions, the national cyberspace administration department and other relevant competent departments shall, in accordance with their duties, order corrections, impose a fine of not less than one time and not more than ten times the procurement amount, and impose a fine of not less than 10,000 yuan and not more than 100,000 yuan on the directly responsible person in charge and other directly responsible persons.
Article 42. Where an operator fails to cooperate with the cybersecurity inspection and testing work on critical information infrastructure carried out by the protection work department, or with the cybersecurity inspection work on critical information infrastructure carried out in accordance with law by the relevant departments for public security, state security, the administration of secrecy, cryptography management, and the like, the relevant competent department shall order corrections; where it refuses to make corrections, a fine of not less than 50,000 yuan and not more than 500,000 yuan shall be imposed, and a fine of not less than 10,000 yuan and not more than 100,000 yuan shall be imposed on the directly responsible person in charge and other directly responsible persons; where the circumstances are serious, corresponding legal liability shall be pursued in accordance with law.
Article 43. Where activities that illegally intrude upon, interfere with, or sabotage critical information infrastructure and endanger its security do not yet constitute a crime, the public security organs shall, in accordance with the relevant provisions of the “Cybersecurity Law of the People’s Republic of China,” confiscate the unlawful gains and impose detention of not more than 5 days, and may also impose a fine of not less than 50,000 yuan and not more than 500,000 yuan; where the circumstances are relatively serious, detention of not less than 5 days and not more than 15 days shall be imposed, and a fine of not less than 100,000 yuan and not more than 1,000,000 yuan may also be imposed.
Where an entity commits an act described in the preceding paragraph, the public security organs shall confiscate the unlawful gains, impose a fine of not less than 100,000 yuan and not more than 1,000,000 yuan, and punish the directly responsible person in charge and other directly responsible persons in accordance with the provisions of the preceding paragraph.
Persons who violate the provisions of the second paragraph of Article 5 and of Article 31 of these Regulations and who receive a public security administration penalty may not engage in key positions in cybersecurity management or network operations for 5 years; persons who receive a criminal penalty may not engage in key positions in cybersecurity management or network operations for life.
Article 44. Where cyberspace administration departments, public security organs, protection work departments, and other relevant departments and their staff fail to perform their duties for the security protection and the supervision and administration of critical information infrastructure, or are derelict in their duties, abuse their powers, or engage in malpractice for personal gain, the directly responsible persons in charge and other directly responsible persons shall be given sanctions in accordance with law.
Article 45. Where the public security organs, protection work departments, and other relevant departments charge fees in the course of carrying out cybersecurity inspection work on critical information infrastructure, or require the entity being inspected to purchase products or services of a designated brand or from a designated producer or seller, their higher-level organ shall order corrections and the return of the fees charged; where the circumstances are serious, the directly responsible persons in charge and other directly responsible persons shall be given sanctions in accordance with law.
Article 46. Where the relevant departments such as cyberspace administration departments, public security organs, and protection work departments, or cybersecurity service institutions and their staff, use information obtained in the work of security protection of critical information infrastructure for other purposes, or disclose, sell, or illegally provide it to others, the directly responsible persons in charge and other directly responsible persons shall be given sanctions in accordance with law.
Article 47. Where a major or especially major cybersecurity incident occurs in critical information infrastructure and is determined upon investigation to be a liability accident, in addition to ascertaining and pursuing the operator’s liability in accordance with law, the liability of the relevant cybersecurity service institutions and relevant departments shall also be ascertained, and where there is neglect of duty, dereliction of duty, or other unlawful conduct, liability shall be pursued in accordance with law.
Article 48. Where an operator of e-government critical information infrastructure fails to perform the cybersecurity protection obligations provided for in these Regulations, the matter shall be handled in accordance with the relevant provisions of the “Cybersecurity Law of the People’s Republic of China.”
Article 49. Where a violation of the provisions of these Regulations causes harm to others, civil liability shall be borne in accordance with law.
Where a violation of the provisions of these Regulations constitutes an act in violation of public security administration, a public security administration penalty shall be imposed in accordance with law; where it constitutes a crime, criminal liability shall be pursued in accordance with law.
Chapter VI — Supplementary Provisions
Article 50. The security protection of critical information infrastructure that stores or processes information involving state secrets shall additionally comply with the provisions of laws and administrative regulations on secrecy.
The use and management of cryptography in critical information infrastructure shall additionally comply with the provisions of relevant laws and administrative regulations.
Article 51. These Regulations shall take effect as of September 1, 2021.
Closing
The original document was published in Chinese by the State Council of the People’s Republic of China; we translated it into English, which is what you read above. This translation is provided for quick comprehension only and should be used at your own discretion and risk — always confirm the current requirements with qualified legal counsel.
If you need further help from our team, contact us today, and our experts will help you keep your presence in China compliant from the ground up.