Short answer: if your company runs an information system, website, app, or network in mainland China, MLPS — the Cybersecurity Multi-Level Protection Scheme (网络安全等级保护制度, commonly “等保”, děngbǎo) — is not optional. It is the baseline cybersecurity-compliance regime mandated by Article 23 of the Cybersecurity Law, and it reaches essentially every network operator, domestic or foreign. Most systems run by international businesses are graded Level 2 or Level 3, and Level 3 is where the obligations become materially heavier. This page explains what MLPS is, how grading works, whether you need it, and what the process involves — anchored to the primary sources so you can confirm each point with qualified counsel and a licensed assessment body.

This is orientation, not legal advice. MLPS is a classic “does it work in China?” question whose real axis is compliance, not speed: a system can be fast and still be unlawful to operate if it has not met its protection level.

What MLPS is

MLPS is the system that requires every network operator to classify each of its systems by security-impact level and then meet the protection requirements set for that level. It is not a certification you buy once; it is an ongoing obligation to grade, file, test, and maintain.

The current generation is “MLPS 2.0” (等保2.0), built on the national standard GB/T 22239-2019, Information Security Technology — Baseline for Classified Protection of Cybersecurity (信息安全技术 网络安全等级保护基本要求), in effect since December 1, 2019. MLPS 2.0 widened the scope from traditional information systems to cloud platforms, mobile internet, the Internet of Things, industrial control systems, and big-data platforms — so modern SaaS, cloud, and app architectures are squarely covered.

The legal basis is Article 23 of the Cybersecurity Law, which we translate in full on our Cybersecurity Law page:

The State implements a cybersecurity multi-level protection scheme. Network operators shall, in accordance with the requirements of the cybersecurity multi-level protection scheme, perform the following security protection obligations, so as to safeguard networks from interference, sabotage, or unauthorized access and to prevent network data from being leaked, stolen, or tampered with.

A related provision, Article 33, layers critical information infrastructure (CII) protection on top of the MLPS baseline — so if you are designated CII, MLPS is the floor, not the ceiling.

The five levels

A system’s level is determined by how much harm damage to it would cause — to (a) the lawful rights and interests of citizens, legal persons, and other organizations; (b) public order and the public interest; and (c) national security.

LevelChineseHarm if compromisedOversightTypical systems
1自主保护Harm to individuals/organizations onlySelf-managedSmall, low-impact sites
2指导保护Serious harm to individuals/orgs, or harm to public interestGuidance; filingMany general commercial systems
3监督保护Serious harm to public interest, or harm to national securitySupervision; annual assessmentSystems handling significant personal information or important business
4强制保护Especially serious harm to public interest, or serious harm to national securityMandatory oversightCore industry / CII-adjacent systems
5专控保护Especially serious harm to national securitySpecialized controlRare; critical state systems

In practice, most systems operated by international companies land at Level 2 or Level 3. Level 3 is the common threshold once a system processes a meaningful volume of personal information or supports important business operations — and it is the point at which grading requires expert review and assessment becomes a recurring, at-least-annual exercise.

Do you need it?

Almost certainly, if you operate a system in mainland China. Article 23 frames MLPS as a duty of every network operator — it is not triggered by company size or sector; it is the baseline everyone is expected to meet.

It is also tightly coupled to hosting in China:

  • Data-localization pressure (Cybersecurity Law Article 37 for CII, and the broader Network Data Security Management Regulations) pushes international businesses to run systems on in-China infrastructure — and those in-China systems are exactly what MLPS grades.
  • Standing up compliant China hosting and completing your ICP filing go hand in hand with MLPS grading and filing; they are parts of the same “lawful to operate” checklist, not separate tracks.
  • If your systems are designated critical information infrastructure, MLPS is the floor beneath the heavier CII regime.

The process: grading → filing → assessment → rectification

  1. Grading (定级). Classify the system’s protection level. For Level 3 and above, the proposed grade must pass expert review (专家评审) before it can be filed.
  2. Filing (备案). File the graded system with the local public security authority (公安机关). The procedural framework comes from the Administrative Measures for Information Security Multi-Level Protection (信息安全等级保护管理办法, 公通字〔2007〕43号), under which filing is generally made within 30 days.
  3. Assessment (测评). A testing institution recognized by the authorities evaluates the system against the GB/T 22239-2019 requirements. For Level 3, this assessment is required at least once a year.
  4. Rectification (整改). Remediate the gaps the assessment identifies, and maintain the controls on an ongoing basis — MLPS is a continuing obligation, not a one-time pass.

What it involves in practice

GB/T 22239-2019 organizes the requirements into a technical set and a management set:

  • Technical — secure physical environment, secure communications network, secure area boundary, secure computing environment, and security management center: in plain terms, boundary protection, access control, intrusion prevention, audit logging, data integrity and backup, and (at higher levels) stronger identity and encryption controls.
  • Management — security policies, a security-management organization and personnel, and construction- and operations-management procedures.

Higher levels inherit the lower-level requirements and add more. We do not reproduce the standard here — it is a copyrighted national standard — but it is the authoritative source for the exact controls your assessor will test against.

How MLPS fits the rest of your China compliance

MLPS does not stand alone. For an international business it sits in one connected picture:

  • Cybersecurity Law — Article 23 mandates MLPS; Article 37 drives data localization that puts your systems in China in the first place.
  • ICP filing — the permission to serve a site from inside China; filed in parallel with MLPS.
  • CII Regulations — if you are designated CII, MLPS is the baseline and heavier duties stack on top.
  • PIPL and the cross-border data regime — govern the personal information those graded systems hold and move.

Which gate applies to your specific architecture is exactly the kind of question to settle with counsel before you build — because it is an architectural decision, not a paperwork one.

How 21YunBox helps

21YunBox provides the compliant, in-China delivery and hosting foundation that your MLPS-graded systems run on, and we help international clients stand up that infrastructure and coordinate the grading, filing, and assessment process with the right local parties. We are not a licensed MLPS assessment institution — the testing is performed by an authorized body — but getting your China presence onto compliant infrastructure is the groundwork that makes grading and filing tractable rather than a scramble.

Compliance is the decision that governs whether your service may lawfully operate in China at all. Talk to our compliance team about how your stack maps to MLPS and the rest of the regime.


Primary sources & further reading

  • Cybersecurity Law of the People’s Republic of China, Articles 23 and 33 — full English translation on our site: /china-cybersecurity-law.html (primary source: npc.gov.cn).
  • GB/T 22239-2019, Information Security Technology — Baseline for Classified Protection of Cybersecurity (信息安全技术 网络安全等级保护基本要求), effective December 1, 2019 — the MLPS 2.0 requirements standard.
  • Administrative Measures for Information Security Multi-Level Protection (信息安全等级保护管理办法, 公通字〔2007〕43号, 2007) — the grading/filing/assessment procedure, issued by the Ministry of Public Security and other departments.

A dedicated State Council Regulation on the Multi-Level Protection of Cybersecurity (网络安全等级保护条例) has so far been released only as a draft for public comment and is not yet in force; until it is, the operative requirements remain those set out in the Cybersecurity Law, GB/T 22239-2019, and the 2007 Administrative Measures above.

This page is provided for orientation only and is not legal advice. Confirm your system’s level, obligations, and process with qualified counsel and a recognized MLPS assessment institution.

Ready to try 21YunBox?

Get Started