Why 21YunBox Pricing Contact Log in
Talk to an expert Test your site in China

Does Crafter CMS Work in China? Open-Source Self-Hosting, ICP & PIPL

Crafter CMS is open-source, self-managed software — so you can run it on servers inside mainland China and keep content and data in-country. What self-hosting does not grant: the ICP filing a public mainland site needs, or PIPL cover once data leaves the mainland. A compliance-first look at self-host vs the vendor-managed cloud.

Does Crafter CMS work in China?

Yes — because CrafterCMS is open-source software you deploy yourself, you can run it on servers inside mainland China and keep content and user data in-country. But self-hosting hands you the hardware, not the paperwork: the public site still needs its own ICP filing, and the moment personal data leaves the mainland, PIPL governs it.

CrafterCMS describes Crafter Community as "a fully open-source, community-supported version of CrafterCMS," "Distributed under the GPL v3 open-source license," that you can operate "on any public cloud provider (AWS, GCP, Azure) or your own private infrastructure." That self-managed nature is exactly why the China answer is not a flat no — you can place the deployment, and the data it holds, inside the mainland. What the software cannot do for you: a public mainland site needs an ICP filing under State Council Order No. 292 and MIIT Order No. 33, tied to your in-country hosting and a Chinese entity; and any personal data from Chinese users that leaves the mainland is a cross-border transfer under PIPL. Take CrafterCMS's vendor-managed cloud instead of self-hosting, and that offshore path reopens both. The table below pairs CrafterCMS's own wording with the rule each choice triggers.

This is a risk map, not a verdict — whether you need an ICP filing, in-country storage, or both turns on what you serve, how much personal data you hold, and who your users are. Our China team can map your exposure with you →

What Crafter CMS's own documentation says about China

FactPrimary source
CrafterCMS is open-source software you run yourself — so it can live inside mainland China. CrafterCMS calls Crafter Community "a fully open-source, community-supported version of CrafterCMS," "Distributed under the GPL v3 open-source license," built on "a Git-based content repository." Because you download and operate it — CrafterCMS says you can run it "on any public cloud provider (AWS, GCP, Azure) or your own private infrastructure" — nothing in the software stops you deploying on mainland servers and keeping content and user data in-country, the way a self-hosted database sits wherever you install it. CrafterCMS — Crafter Community (craftercms.com), retrieved 2026-10-07
It is a decoupled, Git-based CMS — the content repository is one you control. CrafterCMS's documentation states its "authoring system is built on Git" and calls it a "hybrid-headless, API-first" CMS, while on GitHub the project describes itself as "a decoupled CMS" whose build produces ".tar.gz files ready to be deployed to any system." A Git-backed, deploy-anywhere architecture is what makes an in-country, self-managed deployment practical rather than theoretical. CrafterCMS Documentation (craftercms.com/docs) & craftercms/craftercms on GitHub, retrieved 2026-10-07
Self-hosting in China does not hand you an ICP filing — hosting in-country is the moment that duty attaches to you. A public-facing website served to mainland visitors needs an ICP filing (ICP 备案) bound to in-country hosting and a Chinese legal entity, under State Council Order No. 292 and MIIT Order No. 33. Open-source software is silent on this; by running your own mainland servers you simply become the operator who owes the filing. State Council Order No. 292; MIIT Order No. 33 — China ICP filing regime (MIIT, beian.miit.gov.cn), retrieved 2026-10-07
Keep the data in-country and PIPL's cross-border rules stay dormant; move it offshore and they apply. If personal data from Chinese users stays on your mainland deployment you avoid a cross-border transfer; route it to an offshore instance — a backup, an analytics tool, or CrafterCMS's vendor-managed cloud — and it becomes a cross-border transfer under PIPL (notice, separate consent and a transfer mechanism, Articles 38–43). For a CIIO or large-volume handler, personal information collected in China must be stored in the mainland (PIPL Article 40; Cybersecurity Law Article 39 (formerly Article 37)) — a duty a self-hosted in-country deployment can meet and an offshore one cannot. PIPL Articles 38–43 & 40; Cybersecurity Law Article 39 (formerly Article 37); CrafterCMS deployment options (craftercms.com), retrieved 2026-10-07

Sources verified by the 21YunBox compliance team on 2026-10-07.

Whether Crafter CMS “works” in mainland China is a compliance question before it is a performance one — and because CrafterCMS is open-source software you deploy yourself, it has a more forgiving answer than a hosted SaaS does. You can run it on your own servers inside the mainland, which means content and user data can stay in-country from the start. What that does not buy you is the paperwork: a public mainland site still needs its own ICP filing, and any personal data that leaves the mainland is governed by China’s PIPL. Self-hosting settles where the data lives; it does not settle whether you are cleared to operate.

CrafterCMS Crafter Community product page describing Crafter Community as a fully open-source, community-supported edition distributed under the GPL v3 open-source license
CrafterCMS's own Community page: Crafter Community is "a fully open-source, community-supported version of CrafterCMS," "Distributed under the GPL v3 open-source license" — software you download and run yourself, including on servers inside mainland China. Source: craftercms.com/products/crafter-community

Crafter CMS in China at a glance

What decides it In CrafterCMS's own terms
What it is "A decoupled CMS" and a "hybrid-headless, API-first" platform whose "authoring system is built on Git" — open-source software, "Distributed under the GPL v3 open-source license," that you download and run yourself.
Where it can run Because it is self-managed, you operate it "on any public cloud provider (AWS, GCP, Azure) or your own private infrastructure" — including servers inside mainland China, so the origin need not sit offshore.
Serving the public A public mainland site still needs an ICP filing tied to in-country hosting and a Chinese entity. The software does not provide one; self-hosting in-country simply makes the filing your duty.
Your users' data Self-host in the mainland and content and personal data can stay in-country. Route it offshore — or take the vendor-managed cloud — and it becomes a cross-border transfer PIPL governs.
Self-host vs managed cloud CrafterCMS offers a vendor-managed cloud and a "Self-hosted/Self-managed with enterprise support" Enterprise edition. A vendor-managed, offshore instance reopens the ICP and PIPL questions a mainland deployment answers.

Open source, self-managed — so it can run where you put it

CrafterCMS is not a hosted service you rent; it is software you run. CrafterCMS calls Crafter Community “a fully open-source, community-supported version of CrafterCMS,” “Distributed under the GPL v3 open-source license,” built on “a Git-based content repository,” and says you can operate it “on any public cloud provider (AWS, GCP, Azure) or your own private infrastructure.” On GitHub the project describes itself as “a decoupled CMS” whose build produces “.tar.gz files ready to be deployed to any system.” That self-managed shape is why the China answer is not a flat no: the same way a self-hosted database sits wherever you install it, a CrafterCMS deployment can sit on servers inside mainland China, with content and user data staying in-country. The reachability worry that dogs an offshore SaaS barely arises once the origin is already in the mainland.

Self-hosting places the servers — not the ICP filing

Putting CrafterCMS on mainland hardware settles data residency, but it is also the moment the licensing duty lands on you. A public-facing website served to mainland visitors turns on an ICP filing (ICP 备案) under State Council Order No. 292 and MIIT Order No. 33, bound to in-country hosting and a Chinese legal entity. Open-source software does nothing to grant that filing; by hosting in-country you simply become the operator who owes it. “We self-host, so we’re covered” is the trap here — self-hosting answers where the data lives, not whether you are cleared to publish.

Keep the data in-country and PIPL stays quiet — move it and it doesn’t

Self-hosting in the mainland is the one configuration that keeps personal data from Chinese users on Chinese soil, which is what China’s data rules prefer. The exposure appears the moment that data crosses the border — a backup to an offshore bucket, a third-party analytics beacon, or CrafterCMS’s own vendor-managed cloud. Under China’s Personal Information Protection Law that export is a cross-border transfer: you must give notice, obtain separate consent, and clear one transfer mechanism (a CAC security assessment, the CAC standard contract, or certification), per Articles 38–43. And if you are a critical information infrastructure operator or a large-volume handler, personal information collected in China must be stored in the mainland (PIPL Article 40; Cybersecurity Law Article 39 (formerly Article 37)) — a duty an in-country CrafterCMS deployment can satisfy and an offshore one cannot.

Self-host or managed cloud — the choice is itself a compliance choice

CrafterCMS gives you both shapes: the self-managed editions you run yourself, and a vendor-managed cloud — CrafterCMS lists its Enterprise edition as “Self-hosted/Self-managed with enterprise support.” For a China audience that choice is not merely operational. Run it yourself in the mainland and you hold the levers: in-country storage, and an ICP filing you can anchor to your own hosting. Hand delivery and storage to a vendor-managed instance hosted outside the mainland and you are back to an offshore site — data crossing the border under PIPL, on infrastructure that cannot carry a mainland ICP filing. Same software, opposite compliance posture.

This is a risk map, not a verdict — whether self-hosting in the mainland, an ICP filing, in-country storage, or all three apply to you depends on what your site does and whose data it holds, and it is worth settling with counsel before you ship.

Where 21YunBox fits — a compliant overlay, not a migration

You do not migrate off CrafterCMS, and you do not stand up a parallel codebase to reach China. Whether your CrafterCMS origin runs on mainland servers or offshore, 21YunBox adds the layer the software leaves to the operator: compliant, ICP-filed delivery from inside the mainland, placed in front of the origin you already run — no rebuild, no second codebase. Our China compliance team works out which obligations actually bind you — ICP filing, PIPL cross-border, data residency — for your entity, your data volumes and your users, then stands up the in-country delivery and storage a lawful China presence needs, while your Git-based authoring stays exactly where your developers already work.

Get a compliance assessment →


Related reading:

Frequently Asked Questions

Can we run Crafter CMS on our own servers inside mainland China?
Yes — that is the point of its open-source, self-managed model. CrafterCMS describes Crafter Community as "a fully open-source" edition "Distributed under the GPL v3 open-source license," and says you can operate it "on any public cloud provider (AWS, GCP, Azure) or your own private infrastructure." Nothing in the software prevents a mainland deployment, and self-hosting in-country is exactly what lets you keep content and personal data on the mainland. What self-hosting does not do is grant an ICP filing or satisfy PIPL on its own — those remain the operator's duties.
If we self-host Crafter CMS in China, are we automatically compliant?
No — treat it as a risk to work through with counsel, not a box the software ticks. Hosting your own servers in the mainland is the moment an ICP filing obligation attaches to the public site (State Council Order No. 292; MIIT Order No. 33), and whether a data-localization duty applies turns on your role (e.g. a CIIO) and your data volumes (PIPL Article 40; Cybersecurity Law Article 39 (formerly Article 37)). If any personal data from Chinese users leaves the mainland — to a backup, an analytics tool, or CrafterCMS's vendor-managed cloud — that is a cross-border transfer PIPL governs. Self-hosting settles where the data lives; it does not settle the paperwork.
Can 21YunBox help us run Crafter CMS compliantly in China?
Yes. You keep your CrafterCMS deployment as it is; our China team maps which obligations actually bind you — ICP filing, PIPL cross-border and data-residency — for your entity, data volumes and users, and stands up the ICP-filed, in-country delivery a compliant China presence needs in front of your existing origin. Whether you self-host in the mainland or serve China from an offshore CrafterCMS instance, get in touch and we'll work through your specific case.

ARTICLES RELATED TO CRAFTER CMS

CATEGORIES

CMS

Make Your Site Work inside the Great Firewall of China

Enter your information, and our staff will assist you in getting a 21YunBox account for China.

Make Your Site Work Within the Great Firewall of China
Make Your Site Work Within the Great Firewall of China

By clicking 'Get Started', I also agree to 21YunBox's Terms of Service and Privacy Policy.