Does Amazon CloudFront Work in China? ICP, Cross-Border & a Retiring CDN
Amazon CloudFront ran inside mainland China only through AWS's separate, ICP-gated China partition — which AWS is now retiring — while global CloudFront serves China from offshore edges that cannot be ICP-filed. A compliance-first look at the ICP, cross-border and continuity questions.
Does Amazon CloudFront work in China?
Whether Amazon CloudFront can legally deliver your site from inside mainland China is an ICP-filing and continuity question, not a speed one — and the native in-country option is now being retired. CloudFront's content reaches China fine; the open questions are where it is served from and whether that path is licensed and durable.
CloudFront did run inside the mainland, but only through the separate AWS China partition: by AWS's own description its four in-country edge locations in Beijing, Shanghai, Zhongwei and Shenzhen connect to the China Regions operated by Sinnet and NWCD — a partition you reach with a Chinese entity, a separate account and an ICP recordal. AWS now states it will "discontinue support for Amazon CloudFront in the Amazon Web Services China (Ningxia) region" on May 31, 2027, with no new customers accepted after September 30, 2026. A distribution on global CloudFront, meanwhile, has no mainland edge and serves China viewers from offshore — a cross-border transfer of personal information PIPL governs on infrastructure that cannot be ICP-filed. The table below is AWS's own wording and the rules each path triggers.
This is a risk and continuity picture, not a verdict — your obligations turn on your data, your role and your users. Our China team can map your exposure and a durable, ICP-filed path with you →
What AWS Cloudfront's documentation says, and what we measured from inside China
| Fact | Primary source |
|---|---|
| Amazon CloudFront does run inside mainland China — but only in the separate AWS China partition. In AWS's own words, "CloudFront China has Edge locations in Beijing, Shanghai, Zhongwei, and Shenzhen," and those "four Edge locations are connected by private network directly to Amazon Web Services China (Beijing) Region operated by Sinnet and Amazon Web Services China (Ningxia) Region operated by NWCD." Reaching that partition means a separate AWS (China) account under a Chinese entity plus an ICP recordal — the same two-door structure AWS sets out for its China Regions (see Does AWS work in China?). "We're already on CloudFront" does not carry over. | Amazon CloudFront (amazonaws.cn/en/cloudfront), retrieved 2026-10-07 |
| AWS is retiring its own in-country CloudFront. On its China product page AWS states: "On May 31, 2027, we will discontinue support for Amazon CloudFront in the Amazon Web Services China (Ningxia) region," including "the decommissioning of all four Points of Presence (PoPs) in Shenzhen (SZX), Shanghai (PVG), Ningxia (ZHY), and Beijing (BJS)," and "No new customers will be accepted after September 30, 2026." AWS directs existing users to "alternate CDN solutions." So the native in-country door is closing — lawful in-mainland delivery now has to be rebuilt on infrastructure that stays ICP-filed and durable. | Amazon CloudFront — End of support notice (amazonaws.cn/en/cloudfront and /cloudfront/faqs), retrieved 2026-10-07 |
| Delivering a public site from inside mainland China requires an ICP filing bound to the operator. AWS China's own guidance: "the domains without ICP recordal or ICP license shall not provide Internet information service," and "if your domain name is publicly accessed through the servers of NWCD or SINNET, you should apply for ICP recordal by SINNET or NWCD" — the regime under State Council Order No. 292 (Art. 4) and MIIT Order No. 33. No CDN routing substitutes for it. How ICP filing works → | Amazon Web Services Support — ICP Recordal (amazonaws.cn/en/support/icp), retrieved 2026-10-07; State Council Order No. 292, Art. 4; MIIT Order No. 33 |
| On global CloudFront, mainland viewers are served from outside the mainland. AWS places the four in-mainland edge locations in the China partition (via Sinnet/NWCD); a distribution on the global, commercial CloudFront publishes no edge inside mainland China (inference from AWS's own placement of the mainland PoPs in the China partition — no official statement that the commercial partition lacks mainland edges was located), so China viewers are answered from offshore edges. Where that traffic carries personal data — IP addresses, cookies, request logs — routing it abroad is a cross-border transfer under PIPL (notice, separate consent, a transfer mechanism; Articles 38–39), and an offshore edge cannot hold an ICP filing. For a CIIO or large-volume handler, personal information collected in China must be stored in the mainland (CSL Art. 37; PIPL Art. 40). | Amazon CloudFront (amazonaws.cn/en/cloudfront), retrieved 2026-10-07; PIPL Chapter III, Articles 38–40; Cybersecurity Law Article 39 (formerly Article 37) |
| Reachability isn't the issue — AWS's own CloudFront product page loads fine from inside China. From a datacenter probe inside mainland China (Alibaba Cloud cn-zhangjiakou), aws.amazon.com/cloudfront completed 3 of 3 page loads on 2026-08-28 (median time to first byte 665ms, median largest-contentful-paint 4,028ms); from a Beijing residential broadband line on 2026-08-30 it again completed 3 of 3 (median first byte 718ms, median LCP 2,180ms). The marketing page arriving says nothing about whether CloudFront can legally deliver your site from inside the mainland — which is the real question. | 21YunBox — China delivery measurement, measured from inside mainland China (datacenter probe and Beijing residential broadband) |
Sources verified by the 21YunBox compliance team on 2026-10-07.
Whether Amazon CloudFront “works” in mainland China is a question of licensing and continuity before it is one of performance. CloudFront did reach inside the mainland — but only through AWS’s separate China partition, behind a Chinese entity, a separate account and an ICP filing — and AWS is now winding that in-country service down. Keep serving China from global CloudFront instead, and your viewers are answered from edges outside the mainland. AWS states each of these in its own words.
Amazon CloudFront in China at a glance
| What decides it | In AWS's own terms |
|---|---|
| Where it runs in-country | Four edge locations — Beijing, Shanghai, Zhongwei and Shenzhen — inside the separate AWS China partition, “connected by private network directly to” the Beijing Region operated by Sinnet and the Ningxia Region operated by NWCD. This is not part of global, commercial CloudFront. |
| Entity & account | Reaching that partition needs an AWS (China) account under “a valid Chinese business license,” distinct and separate from your global AWS account — the same gate AWS sets for its China Regions. |
| Being retired | AWS will “discontinue support for Amazon CloudFront in the Amazon Web Services China (Ningxia) region” on May 31, 2027, decommission all four points of presence, and accept “no new customers … after September 30, 2026.” |
| Serving the public | A domain “without ICP recordal or ICP license shall not provide Internet information service,” filed through Sinnet or NWCD. |
| On global CloudFront | No edge inside the mainland: China viewers are served from offshore — a cross-border transfer of personal information PIPL governs, on infrastructure that cannot be ICP-filed. |
Door one — in-country CloudFront lives in AWS’s separate China partition
Amazon CloudFront does reach inside mainland China, but not from the account you already run. In AWS’s own description, “CloudFront China has Edge locations in Beijing, Shanghai, Zhongwei, and Shenzhen,” and those “four Edge locations are connected by private network directly to Amazon Web Services China (Beijing) Region operated by Sinnet and Amazon Web Services China (Ningxia) Region operated by NWCD.” They belong to the separate China partition — not to global, commercial CloudFront.
Reaching that partition means the same gate AWS sets for its China Regions: an AWS (China) account “distinct and separate from other Amazon Web Services global Accounts,” registered against “a valid Chinese business license issued by the Bureau of Industry and Commerce,” and — to serve a public-facing site — an ICP filing, since a domain “without ICP recordal or ICP license shall not provide Internet information service,” applied for “by SINNET or NWCD.” So “we’re already on CloudFront” does not carry into China; it is a Chinese entity, a separate account and an ICP filing, the two-door structure AWS sets out in full for its China Regions (see Does AWS work in China?).
The door is closing — AWS is retiring its in-country CloudFront
The in-country option is not a stable foundation to build on, because AWS is ending it. Its own notice states that on May 31, 2027 it will “discontinue support for Amazon CloudFront in the Amazon Web Services China (Ningxia) region,” including “the decommissioning of all four Points of Presence (PoPs) in Shenzhen (SZX), Shanghai (PVG), Ningxia (ZHY), and Beijing (BJS),” and that “no new customers will be accepted after September 30, 2026.” AWS directs existing users to “alternate CDN solutions.”
That turns continuity into part of the compliance question, not a footnote to it. A China delivery plan resting on AWS’s own in-country CDN now has an expiry date, and lawful in-mainland delivery has to be rebuilt on infrastructure that stays ICP-filed and durable past it.
Door two — global CloudFront serves China from offshore edges
Keep serving the mainland from a distribution on global, commercial CloudFront and there is no edge inside China to answer from — a reasonable inference from AWS placing every one of its mainland points of presence in the China partition, with no mainland edge published for the commercial service — so your China viewers are served from offshore. Where that traffic carries personal information — IP addresses, cookies, request logs — moving it across the border is a cross-border transfer under the Personal Information Protection Law: the handler (you, not AWS) must give notice, obtain separate consent, and satisfy one transfer mechanism — a CAC security assessment, the CAC standard contract, or certification (PIPL Articles 38–39). An offshore edge also cannot hold an ICP filing. And for a CIIO or a large-volume handler, personal information collected in China must be stored in the mainland (Cybersecurity Law Article 39 (formerly Article 37); PIPL Article 40) — which an offshore edge cannot do.
None of this is a verdict that CloudFront is “blocked” or “illegal.” It is a risk-and-continuity map: which path fits turns on your entity, the personal data your distribution carries, your role under Chinese law, and who your users are — and with AWS’s own in-country CDN winding down, it is worth settling with counsel before your delivery depends on it.
Where 21YunBox fits — a compliant overlay, not a migration
You keep building on AWS and CloudFront. We add the piece AWS is now handing back to you: compliant, ICP-filed delivery from inside the mainland, set in front of your existing origin — no rebuild, no second codebase, and no move off your global stack. Our China team maps which path fits, assesses your PIPL cross-border and data-residency exposure for your entity and data volumes, and stands up the durable, in-country delivery a compliant China presence requires now that AWS is retiring its own China CloudFront.
Related reading:
- Does AWS work in China? ICP, data residency and the two doors
- How to get an ICP filing for China
- Cross-border data transfers under PIPL
