Does Tenable Work in China? Data Residency, Localization & PIPL Cross-Border
Tenable Vulnerability Management (formerly Tenable.io) is a cloud console hosted in regional sites — US, EU, APAC and more — with no mainland-China region, so your asset inventory, vulnerability findings and scan data rest offshore: a PIPL cross-border transfer. Self-managed Nessus and Tenable Security Center run in-country (the lawful lever). A compliance-first look at where your security data is allowed to rest.
Does Tenable work in China?
On the compliance axis the answer turns on where your security data rests, not on reachability: the Tenable Vulnerability Management cloud (formerly Tenable.io) has no mainland-China region, so your asset inventory, vulnerability findings and scan data come to rest offshore.
Tenable concentrates a precise, ranked map of your estate's exploitable weaknesses, the scan evidence behind each finding, and the credentials used for authenticated scans — among the most sensitive operational data a security team holds. Where the assets and users are in China that is personal information, and where the scanned systems carry financial, health or government-ID data it reaches Article 28 sensitive personal information, so reporting it to an offshore console is a PIPL cross-border transfer (Articles 38–40). For a critical information infrastructure operator or high-volume handler, the Cybersecurity Law in-country storage duty applies (Article 39, formerly Article 37) and an offshore cloud cannot meet it. The lawful lever: Nessus and Tenable Security Center (formerly Tenable.sc) are self-managed — run them on mainland-China infrastructure and the data stays in-country.
A risk map, not a ruling — confirm the specifics with counsel. Our China team can map your exposure →
What Tenable's own documentation says about China
| Fact | Primary source |
|---|---|
| Tenable's cloud hosts your data in a regional "site," and none is in mainland China. Tenable's documentation defines a site as "a specific instance or deployment region where your exposure management data is hosted," then maps every site to a US, EU (Frankfurt), UK (London), Canada, Japan, Singapore, Sydney, Mumbai, São Paulo or Abu Dhabi AWS region — with no mainland-China site to select, so for a China-based estate the asset inventory and findings leave the country to reach the console. | Tenable Docs, "Tenable Site to Region Mapping" (docs.tenable.com), retrieved 2026-10-10 |
| Nessus and Tenable Security Center are self-managed, so the data can stay in-country. Tenable markets Nessus under "Deploy on Any Platform" and says you "can deploy Nessus on a variety of platforms," and it calls Tenable Security Center "the leading on-premises solution for vulnerability management," with "flexible on-premises or hybrid deployment options" so that "your data remains on-premises." Run on mainland-China infrastructure, they keep the asset inventory, weakness catalog and scan data on mainland soil. | Tenable product pages, "Nessus" and "Tenable Security Center" (tenable.com), retrieved 2026-10-10 |
| China asset, vulnerability and scan data sent to an offshore console is a PIPL cross-border transfer. Where that data carries the personal information of people in China, exporting it to a Tenable site abroad triggers PIPL Articles 38–40: notice, a separate consent where sensitive personal information is involved, and one transfer mechanism — a CAC security assessment, the CAC standard contract, or certification. The handler on the hook is the operator, not Tenable. | Personal Information Protection Law of the PRC, Articles 38–40 (cac.gov.cn), retrieved 2026-10-10 |
| CIIOs and high-volume handlers owe an in-country storage duty an offshore cloud cannot meet. Personal information and important data collected in the mainland must be stored in the mainland, with a security assessment before any export — Cybersecurity Law Article 39 (formerly Article 37) and PIPL Article 40. The 2025 Cybersecurity Law amendment, in force January 1, 2026, renumbered the data-localization article from 37 to 39, substance unchanged. | Cybersecurity Law of the PRC, Article 39 (2025 amendment, in force 2026-01-01); PIPL Article 40 (cac.gov.cn), retrieved 2026-10-10 |
Sources verified by the 21YunBox compliance team on 2026-10-10.
For a security team serving mainland China, the question about Tenable was never whether the scanner installs or whether an agent reaches the console — Nessus installs anywhere you put it, and the cloud is reachable across the border. Tenable is a vulnerability-management platform: it builds a full asset inventory, a running catalog of each asset’s exploitable weaknesses, the scan data behind every finding, and, for authenticated scans, the credentials used to log in and look deeper. Taken together, that is a precise map of where your estate is soft. So the real question is a residency one: where is that map allowed to come to rest? Tenable Vulnerability Management (formerly Tenable.io) is a cloud console whose data is hosted in a regional “site,” and none of those sites is in mainland China, so the inventory and findings rest offshore. Nessus and Tenable Security Center (formerly Tenable.sc) are self-managed — you run them on your own infrastructure, including mainland soil, which is the lawful lever. The irony a security buyer feels first: the tool bought to protect the estate is itself an offshore cross-border path for a catalog of its weak points.
Tenable in China at a glance
| What decides it | In Tenable's own terms — and China's law |
|---|---|
| Where the security data physically rests | Tenable Vulnerability Management (formerly Tenable.io) has no region of its own; your site does. Tenable's documentation defines a site as "a specific instance or deployment region where your exposure management data is hosted," then maps every site to a US, EU (Frankfurt), UK (London), Canada, Japan, Singapore, Sydney, Mumbai, São Paulo or Abu Dhabi AWS region — none in mainland China. Nessus and Tenable Security Center are self-managed, so they rest wherever you deploy them, mainland soil included. |
| What it ingests, and why residency bites | The platform concentrates a full asset inventory, a catalog of each asset's exploitable weaknesses, the scan data behind every finding, and the credentials used for authenticated scans. Where those assets and users are in China, device names, user accounts and network addresses are personal information under PIPL; and where the scanned systems hold Article 28 sensitive data — financial, health or government-ID — the findings and scan artifacts can expose it. A ranked map of your weak points paired with live credentials is, on its own, among the most sensitive operational data you keep. |
| Your mainland data in the cloud | Asset, vulnerability and scan data generated in China and held in an offshore Tenable site is a cross-border transfer PIPL governs: notice, a separate consent where sensitive personal information is involved, and one transfer mechanism (PIPL Articles 38–40). The handler on the hook is you, the operator — not Tenable. |
| In-country storage duty | A critical information infrastructure operator or high-volume handler owes an in-country storage duty an offshore service cannot meet: personal information and important data collected in the mainland must stay in the mainland (PIPL Article 40; Cybersecurity Law Article 39 (formerly Article 37)) — the 2025 Cybersecurity Law amendment, in force January 1, 2026, renumbered the data-localization article from 37 to 39, substance unchanged. |
| Is it reachable? | Treat reachability as the delivery half, not the question — the scanners run fine in-country and the cloud is reachable across the border. The lawful lever is to run the collection and console in-country: Nessus and on-premises Tenable Security Center on mainland infrastructure, or a licensed sovereign equivalent. Any China-facing surface in front of them — the admin console, a reporting portal — needs an ICP filing tied to a mainland hosting resource (State Council Order No. 292; MIIT Order No. 33). |
Where the data actually rests
Tenable Vulnerability Management does not have a region of its own; the site your environment is provisioned into does. Tenable’s own documentation is explicit about what a site is — “A Tenable “Site” is a specific instance or deployment region where your exposure management data is hosted” — and then maps each site to an AWS region: the US sites to us-east-1, us-west-2 and us-east-2; fra to Frankfurt (eu-central-1); uk-lon-1 to London (eu-west-2); ca01 to Canada (ca-central-1); jp01 to Tokyo; sing to Singapore; ap-syd-1 to Sydney; in01 to Mumbai; br01 to São Paulo; with Abu Dhabi (me-central-1) added in 2024. There is no mainland-China site on that list and none to select; Tenable’s service-description guide likewise places the platform only across “AMER, APAC, and EMEA.” Point your organization’s vulnerability data at any of those and the inventory, findings and scan results come to rest abroad; under the Personal Information Protection Law, moving the China personal information inside them out of the country is a cross-border transfer, and the handler responsible is you.
Nessus and Tenable Security Center are the other shape. Nessus is the scanner you install and operate yourself — Tenable markets it under the heading “Deploy on Any Platform,” noting you “can deploy Nessus on a variety of platforms,” and its results live on the host you run it on. Tenable Security Center (formerly Tenable.sc) is the console that aggregates and reports on that data, and Tenable calls it “the leading on-premises solution for vulnerability management,” with “flexible on-premises or hybrid deployment options” so that “your data remains on-premises.” Run both on mainland-China infrastructure and the asset inventory, the weakness catalog and the scan data never leave the mainland. That is the lawful lever, and it is a genuine one here: unlike vendors that have retired self-hosting, Tenable still sells and supports an on-premises console.
What it ingests is personal information
Tenable earns this scrutiny because of what it concentrates. A vulnerability-management platform does not hold a slice of your data; it holds a structured description of your whole estate — every asset it has discovered, the operating systems and software on them, the specific weaknesses it found, and the scan evidence behind each one. For authenticated scans it also holds, or brokers, the credentials used to log in. Taken together that is a precise, ranked map of where an attacker would succeed, paired with some of the keys to get there. Concentrating that offshore is a security and trade-secret concern before it is anything else.
It becomes a data-protection one the moment the estate is in China. Asset records name hosts, user accounts, email addresses and network locations — personal information under PIPL once they describe identifiable people — and where the scanned systems carry Article 28 sensitive personal information, such as financial, health or government-ID data, the findings and artifacts can expose it. That is the irony a security team feels sharply: the platform you bought to protect the estate becomes, if it reports to an offshore cloud, an outbound cross-border path for a catalog of that estate’s weak points.
That is why residency here is not merely good practice. For a critical information infrastructure operator, and for a handler whose volumes cross the regulators’ thresholds, personal information and important data collected in the mainland must be stored in the mainland (PIPL Article 40; Cybersecurity Law Article 39 (formerly Article 37)). An offshore vulnerability-management cloud structurally cannot satisfy that duty — the data is, by definition, in the wrong country. And where an export is permitted at all, crossing a volume or sensitivity threshold can trigger a CAC-led data-export security assessment before any of it lawfully leaves.
Running it on a no-China-region cloud doesn’t meet the residency duty — and what does
The honest summary is narrow and important: nothing about Tenable is “blocked.” Nessus scans, Security Center reports, and the cloud console is reachable from the mainland. The exposure is not the software; it is a managed deployment that parks the mainland’s asset inventory, findings and scan data outside the mainland. Fix where the data rests and the exposure closes.
The lawful lever is to run the collection and the console in-country. Nessus on mainland infrastructure gathers the scan data locally; Tenable Security Center, deployed on-premises in-country — or a licensed in-country or sovereign-cloud equivalent — aggregates and reports on it without the inventory or findings leaving the mainland. Pointing a mainland scanner back at an offshore Tenable site is not localization and does not meet the storage duty; standing up the data layer in-country is. Where a subset of data may lawfully cross the border, you keep that transfer minimized, consented and backed by a transfer mechanism, while any China-facing surface in front of the platform earns its own ICP filing.
This is a risk map, not a verdict. Whether you owe in-country storage, a transfer mechanism, a separate consent, an ICP filing, or some combination turns on your entity, your data volumes, how much of the scanned estate holds personal or sensitive data, and who your users are — settle the specifics with counsel before you decide where a single scan result lives.
The lawful path — map, localize, deliver
You do not have to drop Tenable to run it lawfully for mainland China. 21YunBox is a compliant overlay, not a migration — and, for a platform you already run, a partner that sits alongside your stack, not a competitor to it. There are three moves, and they fit together.
Map. Our China compliance team reads your PIPL cross-border, data-residency and data-localization (CII) obligations against your actual entity, your data volumes, and whose personal information your scans touch — the asset records, the findings, the scan artifacts and the credentials — so the exposure is written down before anything moves.
Localize. Because the risk is where the data rests, we run the vulnerability-management data layer in-country — Nessus and an on-premises Tenable Security Center on mainland infrastructure, or a licensed in-country or sovereign-cloud equivalent — so the inventory, findings and scan data China requires to stay on mainland soil do. Localize means a lawful in-country deployment, never a tunnel back to an offshore site; only the minimized, lawfully transferable subset ever crosses.
Deliver. For any China-facing surface in front of the platform — the admin console, the reporting portal, the self-service page your mainland operators hit — the 21YunBox Optimizer provides ICP-filed, in-country delivery, in front of the stack you already run. No rebuild, no second codebase. 21YunBox never uses or suggests circumvention of any kind; the entire point is a lawful, filed, in-country path.
The goal is plain: your Tenable deployment runs legally and compliantly for your users in China.
Related reading:
- How to get an ICP filing for China
- Cross-border data transfers under PIPL
- China’s Cybersecurity Law and data localization
- China’s data-export security assessment measures
