China Justice Observer

中司观察

EnglishArabicChinese (Simplified)DutchFrenchGermanHindiItalianJapaneseKoreanPortugueseRussianSpanishSwedishHebrewIndonesianVietnameseThaiTurkishMalay

China Issues Security Protection Regulations on Critical Information Infrastructure

Wed, 15 Sep 2021
Categories: China Legal Trends

On 17 Aug. 2021, the State Council promulgated the “Security Protection Regulations on Critical Information Infrastructure (hereinafter “the Regulations”,关键信息基础设施安全保护条例), which entered into force on 1 Sept. 2021.

There are 51 articles in six chapters. The Regulations provides for the identification of critical information infrastructure, the responsibilities and obligations of the critical information infrastructure operators, the guarantee and promotion of the critical information infrastructure, and the relevant legal liabilities.

Critical information infrastructure in the Regulations refers to the important network facilities and information systems in important industries and fields such as public communication and information services, energy, transportation, water conservancy, finance, public services, e-government services, and science and technology industry of national defense, as well as other important network facilities and information systems that may seriously endanger national security, national economy, people's livelihoods or public interests in the event of damage, malfunction or data leakage.

Pursuant to the Regulations, an operator shall establish and improve the cybersecurity protection and accountability system, and ensure the input of human, financial and material resources. The operator’s person chiefly in charge shall take overall responsibility for the security protection of critical information infrastructure, lead the security protection of critical information infrastructure and the disposal of major cybersecurity events, and organize the study on the resolution of major cybersecurity issues. Besides, an operator shall conduct cybersecurity detection and risk assessment on the critical information infrastructure by itself or an entrusted cybersecurity service provider at least once a year, promptly rectify security problems discovered, and report relevant information as required by the protection authorities. An operator who violates the Regulations may be ordered to make corrections, given a warning, imposed a fine or other administrative penalties, or may even be prosecuted for criminal liability if the act constitutes a crime.

 

 

Cover Photo by Stephen Tafra (https://unsplash.com/@stafra) on Unsplash

Contributors: CJO Staff Contributors Team

Save as PDF

Related laws on China Laws Portal

You might also like

Beyond the Memorandum: Shanghai Court Enforces Singapore Judgment by Confirming “Reciprocal Consensus” Under China’s New Framework

On January 8, 2025, the Shanghai International Commercial Court recognized and enforced a Singapore High Court monetary judgment in Zhao v Ye (2023) Hu 01 Xie Wai Ren No. 28. It marks the first judicial confirmation of “reciprocal consensus” between China and Singapore under the 2022 reciprocity criteria, based on the China-Singapore Memorandum of Guidance (MOG).

SPC Issues New Rules for Government Information Disclosure Cases

In May 2025, China's Supreme People's Court (SPC) issued a new judicial interpretation, replacing its 2011 predecessor to standardize adjudication of government information disclosure cases and safeguard citizens' right to know by clarifying trial standards, defendant identification, burden of proof, and preventive relief.

China's Top Court Releases Minor Protection Cases

China's Supreme People's Court (SPC) released five typical cases to strengthen holistic judicial protection for minors, exemplifying the "best interests of the child" principle through integrated criminal, civil, and administrative proceedings.

China Enacts Landmark Private Economy Promotion Law

China enacted its landmark first Private Economy Promotion Law, effective May 20, 2025, to guarantee fair competition, streamline market access via a unified negative list, and bolster private enterprises through financing, innovation, and service support.