ProductsIntelligencePricingMethodologyContact
Cresthaven AnalyticsIntelligence Brief

China CAC Cyberspace & Data Governance Brief

August 20, 2026·Cyberspace Administration of China (CAC)·APAC

China's Cyberspace Administration issues implementation guidance for network data security risk assessment regulations effective August 20, 2026

China's Cyberspace Administration issued a question-and-answer guidance document on August 20, 2026, addressing implementation of the Network Data Security Risk Assessment Measures, which entered into force on the same date. The guidance clarifies certification pathways for assessment institutions and reporting obligations for processors of important data.

The Network Data Security Risk Assessment Measures are in force as of August 20, 2026. Important data processors operating in China hold a binding obligation to submit annual risk assessment reports within 20 working days of assessment completion, with a designated fallback channel to provincial or national cyberspace administrations where supervisory authority is ambiguous. Assessment institutions have three named certification bodies available for service certification, though certification remains voluntary under the current framework.

  • Certification Pathway Now Operational: Assessment institutions seeking to provide network data security risk assessment services may apply for certification through three named bodies: the CAC Data and Technology Support Center, the Ministry of Public Security Third Research Institute, and the Taier Certification Center. Each has filed its Data Security Risk Assessment Service Certification Rules with the national certification and accreditation authority, and will conduct certifications under those rules and applicable standards.
  • Important Data Processors Face a 20-Working-Day Reporting Window: Processors of important data must submit their annual risk assessment report to the competent authority within 20 working days of completing the assessment. This deadline is binding under the Measures and is not subject to extension by the processor's own scheduling.
  • Fallback Reporting Channel Designated: Where the competent supervisory authority is not clearly identified, important data processors must route their risk assessment reports to either the provincial-level cyberspace administration or the national CAC. Contact information for both national and provincial cyberspace administrations has been published alongside the guidance to facilitate this routing.
  • Certification Is Encouraged, Not Mandated: The Measures encourage assessment institutions to obtain certification but do not make certification a legal prerequisite for conducting assessments. Institutions operating without certification remain permissible under the current framework, though certified status signals regulatory alignment.

- The Network Data Security Risk Assessment Measures are the first binding subordinate regulation in China to operationalize the important-data risk assessment obligations established under the 2021 Data Security Law, converting those obligations from statutory principle into enforceable procedural requirements.

- The 20-working-day post-assessment reporting deadline and the three-institution certification registry are new structural elements. Neither has a direct precedent in prior CAC data security guidance.

- The Ministry of Public Security's Third Research Institute appears as a named certification body, signaling coordinated engagement between the CAC and the public security apparatus on the infrastructure for data security assessments.

HIGH — A binding regulation with an August 20, 2026 effective date imposes sector-wide procedural obligations on all processors of important data operating under Chinese jurisdiction, requiring immediate assessment of reporting timelines and supervisory authority identification.

effective — 2026-08-20

Monitor the Cyberspace Administration of China for further implementing rules, technical standards referenced in the certification rules, and any sector-specific guidance from industry regulators designating competent supervisory authorities for important data processors in their respective domains.

《网络数据安全风险评估办法》(Network Data Security Risk Assessment Measures), effective 2026-08-20; 《中华人民共和国认证认可条例》(Regulations of the People's Republic of China on Certification and Accreditation); 《数据安全法》(Data Security Law of the People's Republic of China), 2021

www.cac.gov.cn — Source ↗

This is a sample intelligence brief from Cresthaven Analytics. Live subscribers receive briefs like this on a daily or weekly cadence depending on tier.