Skip to content
Menu ▾
Patent pending

Regulayer  /  The 146 laws  /  Security standards

China · Cybersecurity Law (CSL)

Network logging & incident reporting.

Applies to: Network operators in China. Built · amended 28 Oct 2025 · amended law in force 1 Jan 2026

What the signed record shows

Network-log records (>=6-month retention), response signals, and incident detail; real-identity records.

The proof is a signed, tamper-evident record. Anyone can check it, free, without an account, and nothing has to leave the building to make it. Evidence, not a promise.

Current status. The NPC Standing Committee adopted a decision amending the Cybersecurity Law on 28 October 2025, and the amended law is in force from 1 January 2026. The amendment adds AI provisions: state support for AI foundational research, algorithm development, training data and computing infrastructure, AI ethics norms, risk monitoring and assessment, and safety oversight. The duties this page describes, network logging, real-identity records and incident reporting, carry forward from the 2017 text into the amended law.

Primary source: Cybersecurity Administration of China, the Cybersecurity Law as amended, incorporating the 28 October 2025 NPC amendment. Checked 17 August 2026.

Citation: CSL (2016, as amended 2025), logging and incident duties; article numbers cited to the 2017 text pending re-check against the amended text

In the same family

What to do about it

Seven days free, then $349 a month.

A signed record of which AI you used and what you checked, sealed to the exact file you deliver, made on your own machine and checkable free by anyone you send it to.

Start the free weekOr verify a real record, free →

Part of the Regulayer proof catalogue: 146 laws and standards, one sealed engine. This page is a product description, not legal advice.

What the statute requires, section by section

Cybersecurity Law of the People's Republic of China (CSL); adopted 7 November 2016, in force 1 June 2017, amended by NPC Standing Committee decision of 28 October 2025 with the amended law in force 1 January 2026. DISTINCT from PIPL (2021) and the Data Security Law (2021). Provisions addressed:

Art. 21
Multi-Level Protection Scheme (MLPS): internal security management; technical measures; monitor and record network operational status and cybersecurity incidents, and RETAIN NETWORK LOGS FOR AT LEAST 6 MONTHS; data classification, backup and encryption.
Art. 25
Cybersecurity contingency plan; on an incident, initiate the plan, adopt remedial measures, and report to competent departments.
Art. 42
Personal-information security; on leakage/destruction/loss, take immediate remedial measures and promptly notify users and report to competent departments.
Art. 24
Real-identity information; Art. 34, critical-information- infrastructure (CII) operator obligations. Note: the authoritative text is Chinese; English is reference.

Taken from the Regulayer entry for this instrument, which is built against the primary text.