Key practical points:
• Operators of critical infrastructure have heightened security duties beyond the general cybersecurity requirements.
• A security officer must be appointed, periodic risk assessments conducted, and incident response plans maintained.
• Procurement of network products and services may be subject to a national security review.
• Storing certain data in China and reviewing its cross-border transfer may be required.
• Major security incidents must be reported promptly to the competent authorities.
• Companies operating in these sectors, including foreign ones, must comply.
💬 General consulting
Regulations on Protecting Critical Information Infrastructure Security · Yalla China
关键信息基础设施安全保护条例 / Regulations on Protecting the Security of Critical Information Infrastructure
Enacted: 2021-07-30 ✅ Effective: 2021-09-01
📝 Overview
These regulations govern protection of critical information infrastructure in sectors such as energy, finance, telecommunications, and transport, whose disruption affects national security and the public interest. Issued by the State Council, effective from 2021.
This is general information only, not legal advice. For your specific case, consult a licensed lawyer.
📜 The law text / key provisions
💬 Practical reading
💬 This is a general reading/opinion for orientation — not the official legal text nor legal advice.
If your company operates in a critical sector (energy, finance, telecom, etc.), it may be classed as a critical infrastructure operator with extra security duties. Consult a cybersecurity compliance specialist to determine your status. This is general orientation, not legal advice.
📎 Official source
State Council / gov.cn
🕒 Updated: 16 March 2026
