China Implements Strict Requirements for Cybersecurity Incident Reporting
With a rising number of data breaches and cybersecurity incidents in recent years, China has rolled out stringent new rules that set clear requirements on incident reporting items, time limits and procedures for all network operators. This article provides an overview to navigate the incident reporting obligations.

Data incident reporting obligations are frequently referenced in PRC data protection regulations. On September 15, 2025, the Cyberspace Administration of China (the “CAC”) formally released the Measures for Administration of National Cybersecurity Incident Reporting (the “Measures”), which has taken effect on November 1, 2025, to implement these reporting obligations under PRC law.
The Measures apply to network operators involved in the construction, operation, or provision of services within China, and provide a standardized framework for reporting cybersecurity incidents, clarifying the supervisory authorities and establishing detailed reporting procedures and timelines.
What is a “cybersecurity incident” subject to the Measures?
Under the Measures, a “cybersecurity incident” refers to an event that causes harm to networks, information systems, or the data and business applications within them, which may arise from human factors, cyberattacks, network vulnerabilities, software/hardware defects or failures, or force majeure and which result in negative impacts on the nation, society, and economy.
The Measures classify cybersecurity incidents into four categories, based on severity: “particularly significant incidents,” “significant incidents,” “major incidents,” and “general incidents.” The classification criteria include, but are not limited to:
- Disruption of critical network systems or services
- Quantity of individuals affected in the case of a data breach involving personal information
- Scale of important data impacted
- Economic losses incurred
- Threats to national security or public interests
The Measures provide non-exhaustive thresholds for classifying cybersecurity incidents, which serve as reference points for assessing their severity and determining the corresponding reporting obligations. For example, based on the number of affected individuals in a data breach, cybersecurity incidents can be classified as follows:
- 100 million or more — Classification: Particularly significant incident
- 10 million or more — Classification: Significant incident
- 1 million or more — Classification: Major incidents
- Less than 1 million — Classification: General incidents
How should a cybersecurity incident be reported?
The Measures sets out the reporting requirements for particularly significant, significant, and major incidents as below, which are the same across all three categories.
- General operators — Receiving authority: Local CAC; Reporting deadline: Within 4 hours of discovery
- Operators under central and state organs, or one of their directly affiliated units — Receiving authority: Internal cybersecurity office; Reporting deadline: Within 2 hours of discovery
- Critical information infrastructure (“CII”) operators — Receiving authority: CII protection departments and public security bureaus (“PSBs”); Reporting deadline: Within 1 hour of discovery
Reports may be submitted through the following channels: the 12387-incident reporting hotline, the website, the WeChat mini program and public account, or the email address or fax number set up or designated by the CAC.
In addition to the above, operators must also comply with any sector-specific incident reporting requirements that may apply. Furthermore, if a cybersecurity incident involves suspected cybercrime, a separate report should be submitted to the local PSB in a timely manner.
Notably, the Measures do not explicitly require the reporting of general incidents. However, in practice, we have seen authorities proactively investigated or inquired about certain incidents, especially those that attract public or media attention. Therefore, operators are advised to closely monitor evolving enforcement trends, assess their overall data compliance posture, and consider whether voluntary reporting is appropriate for a general incident on a case-by-case basis.
What information must be reported?
According to the Measures, the initial report of a cybersecurity incident should include the following key information:
- Basic information about the reporting entity and the systems involved
- Basic incident details, e.g., time, location, type, severity level of the incident along with its impact and harm, the measures taken and their effectiveness
- Observed development trends and potential further impacts
- Preliminary analysis of the cause of the incident
- Clues or evidence that may assist in identifying the source or attribution
- Proposed further response measures and any requests for assistance
- Status of evidence preservation at the incident site
If the full details, such as the cause or development trend, cannot be determined within the prescribed reporting timeframe, operators are permitted to submit the first two items first (i.e., operator and system information, and basic incident details) and follow up with additional information as soon as it becomes available. In addition, in case further significant developments arise during the investigation, operators will need to promptly report any relevant updates.
Once the incident has been resolved, the network operator must conduct a comprehensive post-incident review and submit a summary within 30 days. This summary should include the causes of the incident, the emergency response measures taken, the resulting harm, accountability, the corrective actions taken and the lessons learned.
What liabilities may arise from violations?
Failure to comply with the Measures may result in administrative liabilities under applicable data protection laws, including but not limited to, rectification orders, warnings, confiscation of illegal gains, and monetary penalty. In particular, the Measures emphasize that delayed reporting, failure to report, false reporting, or concealment of cybersecurity incidents—especially where such conduct leads to significant harm—may trigger enhanced penalties for both operators and directly responsible individuals, within the scope prescribed by law.
Notably, the Measures encourage third parties to report cybersecurity incidents to the authorities. Such reports may trigger regulatory investigations or inspections, which could lead to more severe enforcement actions against operators who have not fulfilled their incident reporting obligations.
Observations and Recommendations
In recent years, the rapid advancement of emerging technologies, such as artificial intelligence, has led to a significant increase in cybersecurity incidents. These incidents have not only disrupted business operations but also even triggered regulatory scrutiny and proactive investigations into operators’ broader data compliance practices.
To better prevent and respond to the unexpected data security incidents under the new regulatory environment, we recommend operators consider the following proactive measures.
- Regularly review and strengthen cybersecurity and data protection measures to identify and address potential vulnerabilities, thereby reducing the likelihood of incidents.
- Establish internal detection and reporting mechanisms, tailored to meet the strict and differentiated timelines set forth in the Measures.
- Develop clear internal guidelines for classifying incidents, update incident response plans to reflect the new reporting obligations and pre-prepare templates to ensure timely and accurate reporting.
- Update agreements with third-party partners, requiring IT vendors, service providers, and affiliates to provide immediate notification of any incidents and offer necessary assistance when required.
- Coordinate cross-functional stakeholders (e.g., legal, compliance, PR and IT teams) in the event of an incident and involve external security experts and legal counsel as needed to ensure appropriate handling and messaging.
Notably, the Measures provide that operators who have implemented reasonable and necessary protective measures, followed incident response plans, mitigated harm, and reported promptly may be subject to reduced or even waived penalties, depending on the circumstances.
With the implementation of the Measures, it is expected that Chinese authorities would place increased focus on how operators manage cybersecurity incidents, likely leading to heightened oversight and more frequent investigations in this area.
Article provided by INPLP member: David Tang (Beijing Han Kun Law Offices Shanghai Branch, China)
