China Cybersecurity Law Update - Critical Network Equipment and Dedicated Cybersecurity Products Catalogue issued

Written By

john shi module
John Shi

Partner
China

I am a partner in Bird & Bird's Corporate team and the chief representative of the Beijing office. I have extensive experience in transactional and commercial work across various sectors.

svenmichael werner module
Sven-Michael Werner

Partner
China

I am a partner in the international Corporate Group based in Shanghai and have been living and working in China since 1999, and based in Shanghai since 2003. I have close to 20 years' experience practising law in China.

michelle chan module
Michelle Chan

Of Counsel
UK

I'm a technology, telecoms and media lawyer, providing strategic, corporate and commercial advice to major players in the Asia Pacific region. I am based in London and I am Of Counsel in our Corporate & Commercial team.

As reported previously, the China Cybersecurity Law came into effect on 1 June 2017.

Article 23 of the China Cybersecurity Law contemplates that certain "critical network equipment" (CNE) and "dedicated cybersecurity products" (DCSP) are required to either (1) obtain security certification from accredited certification bodies or (2) pass security inspection before they can be put on sale or supplied in China. The Article further specifies that catalogues will be issued in due course on the equipment and products which will be subject to such requirement.

The Catalogue

On 1 June 2017, the Cyberspace Administration of China (CAC), the Ministry of Industry and Information Technology (MIIT), the Public Security Bureau (PSB) and the Certification and Accreditation Administration of China (CAA) jointly issued the first catalogue, which provides for the following:

Critical network equipment

The following types of CNEs meeting the prescribed specifications set out in the catalogue will be subject to the accreditation or inspection requirements:

  • Routers
  • Switches
  • Servers (rack-mounted)
  • Programmable logic controllers

Dedicated cybersecurity products

The following types of DCSPs meeting the prescribed specifications set out in the catalogue will also be subject to the accreditation or inspection requirements:

  • Integrated data backup
  • Firewall (hardware)
  • Web application firewall
  • Intrusion detection system
  • Intrusion defence system
  • Security isolation and information exchange products (gatekeeper)
  • Anti-spam mail products
  • Network synthetical audit system
  • Network vulnerability scanning product
  • Security data system
  • Website recovery products (hardware)

Accredited bodies

The catalogue itself provides that the CAC, MIIT, PSB and CAA will jointly promulgate further measures on how a body may become an accredited body and to provide the accreditation and certification contemplated in the catalogue.

Publication of approved products

As is the practice of the PRC government on products which require accreditation or approval, products which have been duly accredited or have passed relevant inspection will be announced publicly on a regular basis.

More implementation rules to come

On the eve of the coming into force of the China Cybersecurity Law, the CAC issued a set of Q&As clarifying that there will be no moratorium of the coming into effect of the law. Relevant ministries and authorities are expected to promulgate regulations and implementation measures within a period of one year such that the law could begin to be properly implemented. Quite apart from this catalogue, we are expecting more implementation and administrative measures to be issued shortly.

Latest insights

More Insights
featured image

Coimisiún na Meán Publishes Its Strategy Statement 2025–2027

3 minutes Apr 25 2025

Read More
Curiosity line blue background

UK/EU data protection in financial services round-up – 2025 so far….

5 minutes Apr 23 2025

Read More
Curiosity line pink background

China Cybersecurity and Data Protection: Monthly Update - April 2025 Issue

Apr 23 2025

Read More