China Cybersecurity Law (CSL)
The Cybersecurity Law of the People's Republic of China (effective June 2017) is China's foundational cybersecurity legislation. It establishes requirements for network operators and critical information infrastructure (CII) operators including multi-level protection scheme (MLPS), personal information protection, CII security, data localization, and security review mechanisms. Enforced by the Cyberspace Administration of China (CAC).
Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.
Framework Domains (5)
Chapter II — Network Security Support and Promotion
National cybersecurity strategy, standards, and technology promotion
| Code | Title |
|---|---|
| CSL-II-01 | National Cybersecurity Strategy |
| CSL-II-02 | Cybersecurity Standards System |
| CSL-II-03 | Cybersecurity Education and Training |
| CSL-II-04 | Network Product and Service Security |
Chapter III — Network Operation Security
General obligations for network operators and multi-level protection scheme
| Code | Title |
|---|---|
| CSL-III-01 | Multi-Level Protection Scheme (MLPS) |
| CSL-III-02 | Network Security Management System |
| CSL-III-03 | Technical Security Measures |
| CSL-III-04 | Network Log Retention |
| CSL-III-05 | Real-Name Verification |
| CSL-III-06 | Security Incident Response Plan |
Chapter IV — Network Information Security
Personal information protection and content regulation
| Code | Title |
|---|---|
| CSL-IV-01 | Personal Information Collection Consent |
| CSL-IV-02 | Personal Information Protection Obligations |
| CSL-IV-03 | Data Breach Notification |
| CSL-IV-04 | Individual Rights |
Chapter V-VII — Monitoring, Response and Penalties
Government monitoring, emergency response, and legal liability
| Code | Title |
|---|---|
| CSL-V-01 | Government Cybersecurity Monitoring |
| CSL-V-02 | Cybersecurity Emergency Response |
| CSL-VII-01 | Penalties for Network Operators |
| CSL-VII-02 | Penalties for CII Operators |
Critical Information Infrastructure (CII)
Additional security requirements for CII operators
| Code | Title |
|---|---|
| CSL-CII-01 | CII Identification and Protection |
| CSL-CII-02 | CII Security Assessment |
| CSL-CII-03 | Data Localization for CII |
| CSL-CII-04 | CII Procurement Security Review |
| CSL-CII-05 | CII Personnel Security |
Maps to 601 other frameworks
Frequently Asked Questions
What is China Cybersecurity Law (CSL)?
China Cybersecurity Law (CSL) is a compliance framework from China with 5 domains and 23 controls. The Cybersecurity Law of the People's Republic of China (effective June 2017) is China's foundational cybersecurity legislation. It establishes requirements for network operators and critical information infrastructure (CII) operators including multi-level protection scheme (MLPS), personal information protection, CII security, data localization, and security review mechanisms. Enforced by the Cyberspace Administration of China (CAC). It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.
How many controls does China Cybersecurity Law (CSL) have?
China Cybersecurity Law (CSL) has 23 controls organised across 5 domains. The largest domains are Chapter III — Network Operation Security (6 controls), Critical Information Infrastructure (CII) (5 controls), Chapter II — Network Security Support and Promotion (4 controls). Each control defines specific requirements that organisations must implement to achieve compliance.
What frameworks does China Cybersecurity Law (CSL) map to?
China Cybersecurity Law (CSL) maps to 601 other compliance frameworks. The top mapping partners are UK Telecommunications (Security) Act 2021 (35% coverage), TISAX — Trusted Information Security Assessment Exchange (35% coverage), PAS 1192-5:2015 — Security-Minded Approach to BIM and Digital Built Environments (35% coverage). Use our comparison tool to explore control-level mappings between frameworks.
How do I get started with China Cybersecurity Law (CSL) compliance?
Start your China Cybersecurity Law (CSL) compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about China Cybersecurity Law (CSL) requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 23 controls and track your progress.
Start Your Compliance Journey
Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 692 frameworks.
Get Started Free →Free forever — no credit card required