Description

Closed consultation on Measures for the Management of Cybersecurity Incident Reporting

On 7 January 2024, the Cyberspace Administration of China closed its consultation on the Measures for the Management of Cybersecurity Incident Reporting, as foreseen in the Cybersecurity Law of the People's Republic of China. The Measures apply to network operators and service providers operating in China, and they establish reporting timelines ranging from 1 hour to 24 hours depending on the severity of the incident and the nature and target of the incident. Furthermore, the Measures include disclosure content requirements for three types of incidents, namely relatively large, major, or particularly major, with an attached document detailing the thresholds for each kind of incident.

Original source

Scope

Policy Area
Data governance
Policy Instrument
Cybersecurity regulation
Regulated Economic Activity
cross-cutting
Implementation Level
national
Government Branch
executive
Government Body
other regulatory body

Complete timeline of this policy change

Hide details
2023-12-08
in consultation

On 8 December 2023, the Cyberspace Administration of China published and opened a consultation unti…

2024-01-07
processing consultation

On 7 January 2024, the Cyberspace Administration of China closed its consultation on the Measures f…

2025-09-11
adopted

On 11 September 2025, the Cyberspace Administration of China adopted the National Cybersecurity Inc…

2025-11-01
in force

On 1 November 2025, the National Cybersecurity Incident Reporting Management Measures, formulated b…