Does Craft CMS Work in China? ICP Filing, Data Residency & Visitor-Data Rules
Craft CMS is a self-hostable, source-available PHP CMS, so you can run it in-country in China — but a China-facing site needs an ICP filing bound to mainland hosting, and the visitor data it collects (form submissions, user accounts, analytics) must stay in-country, a PIPL cross-border matter if hosted offshore. A compliance-first look at the ICP, hosting-residency and visitor-data path.
Does Craft CMS work in China?
Because Craft CMS is a self-hostable, source-available PHP CMS, it CAN run in China lawfully — but a China-facing site needs an ICP filing bound to mainland hosting, and the visitor data it collects must stay in-country, which is a PIPL cross-border matter if the CMS is hosted offshore.
Craft is a PHP application you install and run yourself (also offered as managed Craft Cloud), holding your content plus the visitor personal information your site collects — contact-form submissions, registered-user accounts, comments and the analytics behind the page. A public site served to mainland visitors is an internet information service, so an ICP filing bound to a mainland hosting resource is the lead door; because Craft is self-hostable, deploying it in-country is the residency lever that satisfies it. Host the CMS offshore instead and the visitor data it collects becomes a cross-border transfer. The lawful lever is to host Craft in-country, ICP-file the site, and keep the visitor data in the mainland — not to make an offshore site reachable.
This is a risk map, not a verdict — settle the specifics with counsel. Our China team can map your exposure →
What Craft CMS's own documentation says about China
| Fact | Primary source |
|---|---|
| Craft CMS is a self-hostable PHP application you run on your own server. Craft's own documentation Requirements page lists the server specs you provide — PHP 8.2+, a MySQL, MariaDB or PostgreSQL database, Composer, and server memory and disk — and states Craft "will run on most modern hosting environments." Because you choose the host, an in-country, China-resident deployment is achievable. | Craft CMS Documentation — Requirements (retrieved 2026-10-11) |
| Craft is source-available and self-hosted by default, with an optional managed cloud — not a region-locked SaaS. Its source is public on GitHub under the commercial Craft License (a free Solo edition and paid Team and Pro editions), and the vendor also offers Craft Cloud, its own managed hosting platform. Self-hosting means the hosting location — including inside mainland China — is your choice, not the vendor's. | craftcms.com — Licensing & Editions (retrieved 2026-10-11) |
| A website or app served to the public in mainland China is an internet information service and carries an ICP filing (备案) duty bound to a mainland hosting resource. You cannot file a site that is hosted offshore — the filing attaches to in-country hosting, which a self-hosted, China-resident Craft can provide and an offshore deployment cannot. | 21YunBox — How to get an ICP filing for China (retrieved 2026-10-11) |
| Visitor data a Craft site collects from mainland users is personal information; holding it offshore is a cross-border transfer under PIPL Articles 38–40. It carries the Article 13/23 notice-and-consent, and for a CIIO or high-volume handler, Cybersecurity Law Article 39 (formerly Article 37) requires China-collected personal information to be stored in the mainland. | 21YunBox — Cross-border data transfers under PIPL (retrieved 2026-10-11) |
Sources verified by the 21YunBox compliance team on 2026-10-11.
For a team running Craft CMS for a mainland-China audience, the question is not whether the site paints quickly from Shanghai. It is where the CMS is hosted and where the visitor data it collects comes to rest — and because Craft is self-hostable, running it in China lawfully is achievable rather than off the table. Craft is a source-available PHP application you install and run yourself (public on GitHub under the commercial Craft License — a free Solo edition and paid Team and Pro editions); the vendor also offers Craft Cloud, its own managed hosting. That deployment choice is the whole story: a self-hosted Craft can live on China-resident infrastructure, while an offshore one cannot. Four prongs decide it — an ICP filing for the public China-facing site, bound to mainland hosting; self-hosting as the residency lever; the visitor personal information it collects, a cross-border transfer if Craft is hosted offshore; and compliant in-country delivery in front of the Craft you already run.
Craft CMS in China at a glance
| What decides it | In Craft CMS's own terms — and China's law |
|---|---|
| What it holds | Two things China's law cares about. Your content — entries, categories, assets and the structured fields your team builds in Craft, plus the control-panel accounts your editors sign in with. And the visitor personal information the site collects: contact-form submissions, registered-user accounts and profiles, comments, and the analytics, cookies and tracking behind the page. For a mainland audience, that visitor data is personal information under PIPL. |
| Self-hostable, so you choose where it runs | Craft is a source-available PHP application you install and run yourself — its Requirements page lists the server specs you provide (PHP 8.2+, a MySQL/MariaDB/PostgreSQL database, Composer), and it "will run on most modern hosting environments." A managed option, Craft Cloud, exists, but self-hosting puts the location in your hands — including inside the mainland. That makes an in-country, China-resident deployment achievable, which is the whole lever. |
| ICP filing — the lead door | A public site served to mainland visitors is an internet information service, so it carries an ICP filing (备案) duty bound to a mainland hosting resource. You cannot file a site hosted offshore — the filing attaches to in-country hosting. A self-hosted, China-resident Craft gives you a mainland resource to file against; an offshore deployment offers none. |
| Visitor-data residency & cross-border | Host Craft offshore and the form submissions, accounts, comments and analytics it collects from mainland visitors rest abroad — a cross-border transfer (数据出境) under PIPL Articles 38–40, layered on the Article 13/23 notice-and-consent (and cookie/tracking consent). For a critical information infrastructure operator or a high-volume handler, Cybersecurity Law Article 39 (formerly Article 37) requires China-collected personal information to be stored in the mainland. |
| Reachability is not the axis | Whether a Craft page paints quickly from the mainland is an operational matter, not the compliance question. What decides it is where the CMS is hosted and where the visitor data lives. 21YunBox helps you host Craft in-country, file the ICP, keep the visitor data in the mainland, and deliver the site compliantly — the 21YunBox Optimizer — in front of the install you already run. |
What it actually holds — your content and your visitors’ data
Craft CMS sits behind a public website or app and holds two kinds of data China’s law cares about. The first is your content: the entries, categories, assets and the structured fields and Matrix blocks your team models in Craft, plus the control-panel accounts your editors sign in with. The second — the half a speed test never sees — is the visitor personal information the site collects: contact-form submissions, registered-user accounts and profiles, comments, and the analytics, cookies and tracking that sit behind the page. For a mainland-China audience, all of that visitor data is personal information under Chinese law. And because Craft is self-hostable — a source-available PHP application you install and run, its source public on GitHub under the commercial Craft License (a free Solo edition and paid Team and Pro editions) — wherever you deploy it is where the content and the visitor data live. The vendor also offers Craft Cloud, its own managed hosting; but nothing in the product forces your deployment offshore, and that is exactly what makes the China question answerable in your favor.
The doors: ICP, self-hosting as the residency lever, and visitor data
The lead door is the ICP filing. A website or app served to the public in mainland China is an internet information service, so it carries an ICP filing (ICP 备案) duty, and the filing must attach to a hosting resource physically inside the mainland. You cannot file a site that is hosted offshore — and this is where self-hosting earns its keep: a Craft install you run on China-resident infrastructure gives you a mainland resource the filing can bind to, while an offshore deployment leaves nothing on Chinese soil to file against.
Self-hosting is also the residency lever for the data. Because you choose where Craft runs, you can keep the content and the visitor personal information inside the mainland by design — the opposite of a managed SaaS with “no China region,” where the path is closed to you. The risk here is the default, not the ceiling: teams run Craft on an offshore PaaS or VM out of habit, and then the visitor data their China site collects is processed and stored abroad.
That offshore storage is what turns a hosting choice into a cross-border question. The contact-form submissions, user accounts, comments and analytics a Craft site collects from mainland visitors are personal information under China’s Personal Information Protection Law, and holding them offshore is a cross-border transfer (数据出境). The duty lands on you, the handler, not on Craft: Articles 13 and 23 require notice and a basis to collect the data, and Articles 38–40 require a transfer mechanism for sending it abroad — a CAC security assessment, the CAC standard contract, or certification — plus cookie and tracking consent. And for a critical information infrastructure operator or a high-volume handler, the Cybersecurity Law’s Article 39 (formerly Article 37 — the 2025 Cybersecurity Law amendment, in force January 1, 2026, renumbered the data-localization article from 37 to 39, with its substance unchanged) requires personal information generated in China to be stored in the mainland, which an offshore deployment cannot satisfy. Unless your Craft site genuinely collects sensitive personal information, the heightened sensitive-data duties do not attach by default — which of these bite turns on what your fields actually hold.
Loading isn’t the question — a compliant, ICP-filed in-country site is
The fix is not to make an offshore Craft site reachable from the mainland — reachability was never the question. It is to put the site and its visitor data where the law needs them: on an in-country path. Host the self-hosted Craft on China-resident infrastructure, file the ICP against that mainland resource, and keep the content and the visitor personal information — the form submissions, accounts, comments and analytics — inside the mainland, with data minimization so only what may lawfully leave the country crosses the border. In-country means keeping the data on an in-country path — never a tunnel that ships it offshore anyway. None of this is a verdict that Craft CMS is “blocked” or “illegal” in China; it is self-hostable software, and much of the exposure dissolves the moment you choose an in-country deployment. It is a risk-and-residency map, and which duties bite your case turns on your entity, what your fields collect, your role under Chinese law, and who your visitors are — worth settling the specifics with counsel before your China presence depends on it.
The lawful path — map, localize, deliver
There is a compliant way to run Craft CMS for a mainland-China audience, and because the CMS is self-hostable, its middle step is unusually clean — one that sits in front of the Craft install you already run, with no rebuild and no migration.
First, map: our China team inventories what your Craft site collects from mainland visitors — contact-form submissions, registered-user accounts, comments, and the analytics, cookies and tracking behind the page — establishes where Craft is hosted today (often an offshore PaaS or VM), the ICP status of the China-facing domain, and the consent and residency basis each flow relies on. We build the technical picture; the legal conclusions are settled with counsel.
Then localize: this is where Craft’s self-hostable design pays off directly. We help you deploy Craft on a China-resident path, keep the content and the visitor personal information in the mainland, obtain the Article 13/23 notice-and-consent and the cookie consent, and handle any CIIO or high-volume storage duty. Localize means keeping the data and the site on an in-country path — never a route that ships it offshore anyway.
Then deliver: the public China-facing site is an internet information service, so it carries an ICP filing duty bound to a mainland hosting resource and needs compliant, in-country delivery. 21YunBox delivers it in-country — the 21YunBox Optimizer — in front of the Craft you already run, so it runs legally and compliantly for your users in China. 21YunBox never uses or suggests circumvention of any kind — we keep in-country what the law says must stay, deliver the rest compliantly from inside the mainland, and never move personal information across the border by stealth. 21YunBox is a compliance overlay and partner to the CMS you already run, not a competitor to it.
Related reading:
- How to get an ICP filing for China
- Cross-border data transfers under PIPL
- China’s Personal Information Protection Law (PIPL)
- China’s Cybersecurity Law
