CHINA
Since January 1996
Since June 2001
Since August 2003
Since June 2001
Since August 2003
Pillar Technical standards applied to ICT goods and online services |
Indicator Self-certification for product safety
State Radio Regulation of China (SRRC) (无线电设备型号核)
Network Access License (NAL) (进网许可证)
China Compulsory Certification (CCC) Requirement (中国强制认证(CCC)要求)
Network Access License (NAL) (进网许可证)
China Compulsory Certification (CCC) Requirement (中国强制认证(CCC)要求)
China’s current certification requirements for telecommunications equipment are reported to conflict with its WTO obligations of limiting imported products to no more than one conformity assessment scheme and requiring the same mark for all products (Article 13.4.a of China’s WTO Accession).
China has three different licensing regimes: the State Radio Regulation of China (SRRC), the Network Access License (NAL) and the China Compulsory Certification (CCC). The CCC is required for a list of products that includes many types of IT products, such as video and audio equipment. The NAL is required for all telecommunications equipment in China. The NAL license requires extensive testing and support and may include network trials and review of the product by a local panel of experts, in addition to labouratory testing against China's national standards. Radio communication equipment intended to be marketed in China requires radio-type approval granted by the Ministry of Industry and Information Technology of the People’s Republic of China (MIIT)’s ‘State Radio Regulation Committee (SRRC). Specified equipment samples are tested in designated labouratories according to local Chinese standards.
Therefore, for a given piece of equipment, it can cost between USD 30,000-35,000 to test for all three licenses (SRRC, NAL, and CCC). The CCC mark is used for both Chinese and foreign products. Moreover, all testing for the CCC mark must be conducted in China, and US exporters are often required to submit their products to Chinese labouratories for additional tests.
The CCC certificate and permission to print the CCC mark must be renewed annually as part of a follow-up certification. Part of the follow-up certification is also a one-day factory audit.
China is also reported as having limitations on foreign -invested conformity assessment bodies in the country.
China has three different licensing regimes: the State Radio Regulation of China (SRRC), the Network Access License (NAL) and the China Compulsory Certification (CCC). The CCC is required for a list of products that includes many types of IT products, such as video and audio equipment. The NAL is required for all telecommunications equipment in China. The NAL license requires extensive testing and support and may include network trials and review of the product by a local panel of experts, in addition to labouratory testing against China's national standards. Radio communication equipment intended to be marketed in China requires radio-type approval granted by the Ministry of Industry and Information Technology of the People’s Republic of China (MIIT)’s ‘State Radio Regulation Committee (SRRC). Specified equipment samples are tested in designated labouratories according to local Chinese standards.
Therefore, for a given piece of equipment, it can cost between USD 30,000-35,000 to test for all three licenses (SRRC, NAL, and CCC). The CCC mark is used for both Chinese and foreign products. Moreover, all testing for the CCC mark must be conducted in China, and US exporters are often required to submit their products to Chinese labouratories for additional tests.
The CCC certificate and permission to print the CCC mark must be renewed annually as part of a follow-up certification. Part of the follow-up certification is also a one-day factory audit.
China is also reported as having limitations on foreign -invested conformity assessment bodies in the country.
Coverage Electrical and ICT goods
Sources
- https://web.archive.org/web/20170610214814/http://www.tiaonline.org/gov_affairs/fcc_filings/documents/P%20Telecommunications%20Industry%20Association%201377%20Report.pdf
- https://web.archive.org/web/20170826034140/http://www.china-certification.com/en/network-access-license-nal-for-telecommunication-equipment
- https://web.archive.org/web/20230929193647/http://www.china-certification.com/en/list-of-ccc-mandatory-products/
- https://web.archive.org/web/20200805072748/http://www.cnca.gov.cn:80/cnca/cncatest/20040420/column/227.htm
- https://web.archive.org/web/20230324181523/https://www.typeapproval.com/china/#telecommunications-equipment
- https://web.archive.org/web/20241202144202/https://www.tuv.com/market-access-services/en/certification-filter/srrc-approval.html
- https://web.archive.org/web/20220304051816/http://www.gov.cn/flfg/2009-07/21/content_1369826.htm
- http://www.lcs-rf.com/readnews.asp?id=158
- https://web.archive.org/web/20230302164952/http://www.tinglitu.com/html/200305/law_97539.html
- https://www.appluslaboratories.com/global/es/what-we-do/service-sheet/china-radio-type-approval-
- Show more...
CHINA
Since June 2007
Since December 2019
Since December 2019
Since December 2019
Since December 2019
Since December 2019
Since December 2019
Pillar Technical standards applied to ICT goods and online services |
Indicator Self-certification for product safety
Administrative Measures for the Multi-level Protection of Information Security
Information Security Technology - Baseline for Cybersecurity Classification Protection (GB/T 22239-2019)
Information Security Technology - Technical Requirements of Security Design for Cybersecurity Classification Protection (GB/T 25070-2019)
Information Security Technology - Evaluation Requirements for Cybersecurity Classification Protection (GB/T 28448-2019).
Information Security Technology - Baseline for Cybersecurity Classification Protection (GB/T 22239-2019)
Information Security Technology - Technical Requirements of Security Design for Cybersecurity Classification Protection (GB/T 25070-2019)
Information Security Technology - Evaluation Requirements for Cybersecurity Classification Protection (GB/T 28448-2019).
The Administrative Measures for the Multi-level Protection of Information Security (MLPS) require all IT systems in China to be classified into different levels of security, from one to five (with the most sensitive systems designated as level 5). In 2019, the MLPS 2.0 (composed by GB/T 22239-2019, GB/T 25070-2019, and GB/T 28448-2019) has expanded the definition of 'information systems' to broader systems, including network infrastructure, cloud computing systems, mobile application platforms, connected devices and industrial control systems.
The MLPS 2.0 requires networks of level 3 and above to adopt network products and services appropriate to their security protection levels. Under the MLPS 2.0, companies must self-assess their security management and compliance, and such assessment results must be evaluated and endorsed by the MLPS regulatory body.
The MLPS 2.0 requires companies in China to set up their cloud infrastructure, including servers, virtualised networks, software, and information systems. Such cloud infrastructures are subject to testing and evaluation by the Chinese government. Overseas operation and maintenance of Chinese cloud computing platforms must also follow Chinese laws and regulations. The national standards also state that customers' data and users' personal information processed by cloud service providers should be stored inside China, which is an additional requirement. It is currently uncertain how these national standards would be enforced, and there have not yet been reports of enforcement.
The MLPS 2.0 requires networks of level 3 and above to adopt network products and services appropriate to their security protection levels. Under the MLPS 2.0, companies must self-assess their security management and compliance, and such assessment results must be evaluated and endorsed by the MLPS regulatory body.
The MLPS 2.0 requires companies in China to set up their cloud infrastructure, including servers, virtualised networks, software, and information systems. Such cloud infrastructures are subject to testing and evaluation by the Chinese government. Overseas operation and maintenance of Chinese cloud computing platforms must also follow Chinese laws and regulations. The national standards also state that customers' data and users' personal information processed by cloud service providers should be stored inside China, which is an additional requirement. It is currently uncertain how these national standards would be enforced, and there have not yet been reports of enforcement.
Coverage Information systems including network infrastructure, cloud computing systems, mobile application platforms, connected devices and industrial control systems
Sources
- https://web.archive.org/web/20231129222542/http://www.ustr.gov/sites/default/files/2014%20TBT%20Report.pdf
- https://web.archive.org/web/20240328031234/https://www.dataguidance.com/opinion/china-mlps-20-baseline-requirements-and-practical
- https://web.archive.org/web/20241202145636/https://www.amcham-shanghai.org/en/article/mlps-20-set-take-effect-december-1
- https://web.archive.org/web/20211125185807/https://assets.kpmg/content/dam/kpmg/cn/pdf/en/2019/05/mlps-insights-strategies.pdf
- https://web.archive.org/web/20230306020809/https://www.csis.org/analysis/how-chinese-cybersecurity-standards-impact-doing-business-china
- https://web.archive.org/web/20220706053414/https://www.tanovo.com/upload/sitearticle_file/208/%E3%80%90%E7%AD%89%E4%BF%9D2.0-%E6%AD%A3%E5%BC%8F%E5%8F%91%E5%B8%83%E7%89%88%E3%80%91GBT25070-2019%E4%BF%A...
- https://web.archive.org/web/20220129105239/https://www.djbh.net/webdev/web/HomeWebAction.do?p=getGzjb&id=8a81825674296d130174bdf702c8002e
- Show more...
CHINA
Since July 2015
Pillar Technical standards applied to ICT goods and online services |
Indicator Product screening and additional testing requirements
National Security Law of the People's Republic of China (中华人民国国家安全法)
The National Security Law foresees the rollout of a “secure and controllable” internet infrastructure. Under the National Security Law, the State can establish national security review and oversight management systems and mechanisms, conduct a national security review of foreign commercial investment, special items and technologies, internet information technology produces and services, projects involving national security matters, as well as other major matters and activities, that impact or might impact national security.
Coverage Horizontal
Sources
- https://web.archive.org/web/20230202090346/http://www.xinhuanet.com//politics/2015-07/01/c_1115787097.htm
- https://web.archive.org/web/20231220170803/https://www.chinalawtranslate.com/en/2015nsl/
- https://web.archive.org/web/20231218162838/http://www.gov.cn/zhengce/2015-07/01/content_2893902.htm
- Show more...
CHINA
Since October 2019, entry into force in January 2020
Pillar Technical standards applied to ICT goods and online services |
Indicator Restrictions on encryption standards
Cryptography Law of the People’s Republic of China (中华人民共和国密码法)
Art. 26 of the Cryptography Law stipulates that commercial cryptography products relating to national security, the national economy and the people’s livelihood, or the public interest, may be sold or otherwise made available for use only after passing testing and certification conducted by duly qualified bodies. Art. 27 further requires that, where operators of critical information infrastructure procure network products or services incorporating commercial cryptography that may affect national security, such products or services must undergo a national security review conducted jointly by the national cyberspace administration, the national cryptography administration, and other relevant authorities. Art. 28 provides that the department responsible for commerce under the State Council, together with the national cryptography administration, shall impose import licensing requirements, in accordance with the law, on commercial cryptography possessing encryption functions and bearing upon national security or the public interest; however, such licensing is not to apply to commercial cryptography used in mass‑consumption products. The legislation does not, however, clarify what constitutes commercial cryptography used in mass‑consumption products, thereby generating uncertainty as to how this significant exemption will operate in practice.
More generally, it is reported that there are onerous requirements on the use of encryption, including intrusive approval processes and, in many cases, mandatory use of indigenous encryption algorithms (e.g., for Wi-Fi and 4G cellular products).
More generally, it is reported that there are onerous requirements on the use of encryption, including intrusive approval processes and, in many cases, mandatory use of indigenous encryption algorithms (e.g., for Wi-Fi and 4G cellular products).
Coverage Horizontal
Sources
- https://web.archive.org/web/20250807143252/http://www.npc.gov.cn/englishnpc/c2759/c23934/202009/t20200929_384279.html
- https://web.archive.org/web/20231208065421/https://www.insideprivacy.com/data-security/china-enacts-encryption-law/
- https://web.archive.org/web/20260428020926/https://ustr.gov/sites/default/files/files/Press/Reports/2025NTE.pdf
- https://web.archive.org/web/20260404201644/https://ustr.gov/sites/default/files/2022%20National%20Trade%20Estimate%20Report%20on%20Foreign%20Trade%20Barriers.pdf
- Show more...
CHINA
Since April 2009, entry into force in October 2009
Pillar Online sales and transactions |
Indicator Licensing scheme for e-commerce providers
Postal Law of the People's Republic of China (中华人民共和国邮政法)
According to Art. 51 of the Postal Law of the People's Republic of China, a specific license is needed for express delivery business. It is reported that the administrative licensing for express delivery services is non-transparent and burdensome, preventing competition. It is reported that as companies are required to apply to each city where there is a postal administration department, they need to go through at least 350 review and approval processes if they want to operate at the national level.
Coverage Express delivery services
Sources
- https://web.archive.org/web/20170915200941/https://www.europeanchamber.com.cn/en/publications-archive/374/Logistics_Position_Paper_2015_2016
- https://web.archive.org/web/20191203041332/http://www.asianlii.org/cn/legis/cen/laws/plotproc367/
- https://web.archive.org/web/20220320062912/http://www.gov.cn/flfg/2009-04/24/content_1295123.htm
- Show more...
CHINA
Since August 2018, entry into force in January 2019
Pillar Online sales and transactions |
Indicator Licensing scheme for e-commerce providers
E-Commerce Law of the People’s Republic of China (中华人民国电子商务法)
China's first comprehensive legislation regulating e-commerce came into effect in January 2019. According to Art. 9, the law applies to all "e-commerce operators," including all individuals and legal entities selling goods and/or providing services on the Internet or other information networks. This includes operators of e-commerce platforms, sellers of goods and services on the e-commerce platforms of others, and those who operate their own websites or through other network services. The law is reported to extend to non-traditional shopping channels, including social media and messaging services, such as WeChat, and streaming sites, such as Douyin. According to Arts. 10-14, all e-commerce operators are obliged to obtain business licenses, register with the tax authorities, and ensure that information on their business and administrative licenses related to their business services is displayed online in a readable form at all times.
Coverage E-commerce sector
Sources
- https://web.archive.org/web/20210917141914/https://www.deacons.com/news-and-insights/publications/china-passes-new-e-commerce-law-a-safe-harbour-with-chinese-characteristics.html
- https://web.archive.org/web/20220313050215/https://ipkey.eu/sites/default/files/documents/resources/PRC_E-Commerce_Law.pdf
CHINA
Since August 2017
Pillar Intermediary liability |
Indicator User identity requirement
Administrative Measures on Internet Forum Community Service (互联网论坛社区服务管理规定)
According to the Administrative Measures on Internet Forum Community Service, providers of Internet forum community services are required to obtain and verify the identity information of users and enter into service agreements with them.
Coverage Internet forum community services
CHINA
Since December 2015, entry into force in January 2016, last amended in April 2018
Pillar Intermediary liability |
Indicator Monitoring requirement
Counterterrorism Law of the People's Republic of China (中华人民共和国反恐怖主义法)
According to Art. 19 of the Counter-Terrorism Law issued in 2016, telecom operators and Internet service providers shall establish content monitoring and network security programs. Likewise, companies are required to adopt precautionary security measures to prevent the dissemination of information on extremism, report terrorism information to the authorities in a timely manner, keep original records, and promptly delete such messages to prevent further circulation. The law introduces both pecuniary fines and detentions up to 15 days for telecommunications operators and ISPs personnel who fail to “stop transmission” of terrorist or extremist content, “shut down related services,” or implement “network security” measures to prevent the transmission of such content.
Coverage Telecommunications sector and Internet Service Providers (ISPs)
Sources
- https://web.archive.org/web/20211208055946/http://www.natlawreview.com/article/china-enacts-new-counter-terrorism-law#sthash.bNpN0ZCP.dpuf
- https://web.archive.org/web/20231206210106/https://www.globalpolicywatch.com/2016/01/china-enacts-broad-counter-terrorism-law/
- https://web.archive.org/web/20220330120526/http://www.npc.gov.cn/zgrdw/npc/xinwen/2018-06/12/content_2055871.htm
- Show more...
CHINA
Since June 2016, entry into force in August 2016
Pillar Intermediary liability |
Indicator Monitoring requirement
Administrative Provisions on Information Services of Mobile Internet Application Programs (移动互联网应用程序的信息服务管理规定)
According to Art. 7 of the Administrative Provisions on Information Services of Mobile Internet Application Programs, app providers are required to monitor online content and report violations to government authorities. App providers and app stores must not use apps to endanger national security, disrupt the public order, or produce, reproduce, publish, or disseminate content banned by laws and regulations, according to the Provisions. In addition, app providers must monitor banned content and take action against users that publish banned content by issuing warnings, restricting functions, stopping updates, or terminating accounts. They must also keep a record of the violations and report the matters to relevant government authorities. In addition, according to Art. 8, app stores are required to verify the legitimacy of app providers and ensure app providers protect user information and publish lawful content. App stores are required to take action against offending app providers by issuing warnings, suspending their publications, or removing the aberrant apps from the stores. App stores are also required to keep records of the violations and report them to the relevant government authorities.
Coverage Internet app providers and mobile Internet app stores
Sources
- https://web.archive.org/web/20230207032431/https://www.loc.gov/item/global-legal-monitor/2016-07-26/china-cyberspace-administration-releases-new-rules-on-mobile-apps/
- https://web.archive.org/web/20221115212611/https://www.lexology.com/library/detail.aspx?g=6f52a281-b5b7-4f9f-940d-1951a905c4e1
- https://web.archive.org/web/20210117001232/https://www.internationallawoffice.com/Newsletters/Tech-Data-Telecoms-Media/China/AnJie-Law-Firm/Draft-rules-on-collection-of-personal-data-by-apps-revised#1
- https://web.archive.org/web/20200215210816/http://www.cac.gov.cn/2016-06/28/c_1119122192.htm
- Show more...
CHINA
Since December 2019, entry into force in March 2020
Pillar Intermediary liability |
Indicator Monitoring requirement
Provisions on the Governance of the Online Information Content Ecosystem (网络信息内容生态治理规定)
Under Chapter III of the Provisions on the Governance of the Online Information Content Ecosystem, content service platforms are obligated to establish and implement a governance framework aimed at fostering a "network information content ecology" in accordance with the Provisions. The platforms are also encouraged to promote permissible information and prohibit forbidden content, while being required to prevent the dissemination of information deemed necessary to suppress. Art. 34 further mandates that platforms adopt appropriate measures against individuals or entities responsible for producing, copying, or disseminating prohibited information. These measures may include issuing warnings, requiring corrections or other forms of rectification, imposing functional restrictions, suspending updates, and closing accounts, in accordance with relevant laws and contractual obligations. Additionally, under Art. 10, platforms are required to promptly remove illegal content, maintain records of such activities, and report these matters to the relevant authorities. Furthermore, Arts. 13, 14 and 15 stipulate that platforms must, among other obligations, develop and provide online products and services suitable for minors, enhance the monitoring and regulation of displayed advertisements, and establish a credit management system for user accounts, along with providing corresponding services as necessary.
Art. 41 of the Provisions specifies that the content service platforms mentioned in these Provisions refer to network information service providers that offer services for the dissemination of network information content.
Art. 41 of the Provisions specifies that the content service platforms mentioned in these Provisions refer to network information service providers that offer services for the dissemination of network information content.
Coverage Network information content service platforms
Sources
- https://web.archive.org/web/20240807074200/https://www.cac.gov.cn/2019-12/20/c_1578375159509309.htm
- https://web.archive.org/web/20240120065130/https://wilmap.stanford.edu/entries/provisions-governance-online-information-content-ecosystem
- https://web.archive.org/web/20221007125543/http://en.shanghaiinvest.com/information-center/newsletters/item/333-provisions-on-governance-of-the-network-information-content
- https://web.archive.org/web/20241202203024/https://www.huntonak.com/privacy-and-information-security-law/provisions-on-the-governance-of-network-information-content-ecology-goes-into-effect-in-china
- Show more...
CHINA
Since August 2017
Since August 2017
Since August 2017
Pillar Intermediary liability |
Indicator Monitoring requirement
Administrative Measures on Internet Forum Community Service (互联网论坛社区服务管理规定)
Administrative Measures on Internet Comment (关于互联网评论的行政措施)
Administrative Measures on Internet Comment (关于互联网评论的行政措施)
According to the Administrative Measures on Internet Forum Community Service and the Administrative Measures on Internet Comment, providers of Internet forum community services and providers of comment functions (together known as 'Speech Function Providers') are required to monitor the posts and comments, take action and report to the Cyberspace Administration of China if prohibited information has been published or discovered. In such situations, Speech Function Providers are required to cease transmission of the content, delete content or comments, restrict the comment function, close user accounts or sub-forums and revoke administrator powers (in the case of a forum). For news-related comment functions, the comments must be censored before being published. Speech Function Providers are also required to set up a complaints procedure in relation to posts and comments.
Coverage Internet Forum Community Services and Providers of Comment Functions
CHINA
Reported in 2012, last reported in 2026
Pillar Content access |
Indicator Blocking or filtering of commercial web content
Reported blockings of international digital platforms
It is reported that China operates one of the world’s most sophisticated systems of internet censorship, commonly referred to as the Great Firewall, which restricts access to more than 200,000 websites and severely limits the availability of numerous international platforms and news sources. Most major global social media and messaging services, including Facebook, WhatsApp, Twitter, Instagram, Signal, Clubhouse, YouTube, Telegram, Snapchat, Line, Pinterest, and Grindr are blocked, as are many international news organisations and their Chinese‑language editions, such as The New York Times, Reuters, The Wall Street Journal, the Australian Broadcasting Corporation (ABC) and the British Broadcasting Corporation (BBC). Google’s search engine has been inaccessible in China since 2012, and Yahoo’s search function was similarly blocked in 2018.
Coverage Websites, online news, search engines, and social media and messaging services
Sources
- https://web.archive.org/web/20260318155638/https://www.gov.uk/government/publications/china-country-policy-and-information-notes/country-policy-and-information-note-opposition-to-the-state-china-janua...
- https://web.archive.org/web/20260306172428/https://freedomhouse.org/country/china/freedom-net/2024
- https://web.archive.org/web/20260619183547/https://pulse.internetsociety.org/en/shutdowns/multiple-internet-services-blocked-in-china/
- https://www.accessnow.org/keepiton-data-dashboard/
- Show more...
CHINA
Reported in 2026
Pillar Content access |
Indicator Presence of Internet shutdowns
Presence of Internet shutdowns
The indicator "7.2.4 - Government Internet shut down in practice" of the V-Dem Dataset, which measures whether the government has the technical capacity to actively make internet service cease, thus interrupting domestic access to the internet or whether the government has decided to do so, has a score of 3 in China for the year 2025. This corresponds to "Rarely but there have been a few occasions throughout the year when the government shut down domestic access to Internet."
Coverage Horizontal
CHINA
Since February 2016
Pillar Content access |
Indicator Licensing schemes for digital services and applications
Online Publishing Service Management Rules (网络出版服务管理规定)
According to Art. 10 of the Administrative Regulations for Online Publishing Services, Chinese-foreign equity joint ventures, Chinese-foreign cooperative ventures, and foreign-funded entities are prohibited from engaging in online publishing services. Moreover, according to Art. 8, any publisher of online content, including texts, pictures, maps, games, animations, audio, and videos, must store its necessary technical equipment, related servers, and storage devices in China. Furthermore, any online publication service unit needs to get prior approval from the State Administration of Radio, Film, and Television (SARFT) if they want to cooperate on a project with any foreign company, joint venture, or individual.
Coverage Online publishing services
CHINA
Since June 2017
Since June 2017
Since June 2017
Pillar Content access |
Indicator Licensing schemes for digital services and applications
Internet News Information Service Management Regulations (互联网新闻信息服务管理规定)
Provisions on Administrative Law Enforcement Procedures for Internet Information Content Management (互联网信息内容管理行政执法程序规定)
Provisions on Administrative Law Enforcement Procedures for Internet Information Content Management (互联网信息内容管理行政执法程序规定)
According to Art. 5 of the Provisions on the Administration of Internet News Information Services, Internet news providers are required to obtain a permit to provide Internet news information services to the social public through Internet websites, application software, forums, blogs, microblogs, public account, instant messaging tools, online live streaming and other such methods. In addition, pursuant to Art. 6 of the Provisions, the applicant’s person-in-charge or chief editor must be a Chinese citizen, and the applicant shall have a legal person legally established within the territory of the People's Republic of China. Furthermore, the applicant must separately obtain an Internet Content Provider (ICP) license or an ICP filing from telecom industry regulators. According to Art. 16 of the law, without an ICP number, a website can be shut down by the hosting provider with no notice.
Furthermore, all privately operated news services are obligated to have their operations overseen by personnel endorsed by the ruling party. Editorial staff working on these platforms need approval from national or local government internet and information offices, and their employees are required to undergo training and obtain reporting credentials from the central government. The Provisions on Administrative Law Enforcement Procedures for Internet Information Content Management set out the procedural and administrative processes for the Cyberspace Administration of China to enforce the laws and regulations relating to Internet content.
Furthermore, all privately operated news services are obligated to have their operations overseen by personnel endorsed by the ruling party. Editorial staff working on these platforms need approval from national or local government internet and information offices, and their employees are required to undergo training and obtain reporting credentials from the central government. The Provisions on Administrative Law Enforcement Procedures for Internet Information Content Management set out the procedural and administrative processes for the Cyberspace Administration of China to enforce the laws and regulations relating to Internet content.
Coverage Online news providers
