China Cybersecurity Law (CSL)
The Cybersecurity Law of the People's Republic of China (effective June 2017) is China's foundational cybersecurity legislation. It establishes requirements for network operators and critical information infrastructure (CII) operators including multi-level protection scheme (MLPS), personal information protection, CII security, data localization, and security review mechanisms. Enforced by the Cyberspace Administration of China (CAC).
Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.
Framework Domains (11)
Chapter II — Network Security Support and Promotion
National cybersecurity strategy, standards, and technology promotion
| Code | Title |
|---|---|
| CSL-II-01 | National Cybersecurity Strategy |
| CSL-II-02 | Cybersecurity Standards System |
| CSL-II-03 | Cybersecurity Education and Training |
| CSL-II-04 | Network Product and Service Security |
Chapter III — Network Operation Security
General obligations for network operators and multi-level protection scheme
| Code | Title |
|---|---|
| CSL-III-01 | Multi-Level Protection Scheme (MLPS) |
| CSL-III-02 | Network Security Management System |
| CSL-III-03 | Technical Security Measures |
| CSL-III-04 | Network Log Retention |
| CSL-III-05 | Real-Name Verification |
| CSL-III-06 | Security Incident Response Plan |
Chapter IV — Network Information Security
Personal information protection and content regulation
| Code | Title |
|---|---|
| CSL-IV-01 | Personal Information Collection Consent |
| CSL-IV-02 | Personal Information Protection Obligations |
| CSL-IV-03 | Data Breach Notification |
| CSL-IV-04 | Individual Rights |
Chapter V-VII — Monitoring, Response and Penalties
Government monitoring, emergency response, and legal liability
| Code | Title |
|---|---|
| CSL-V-01 | Government Cybersecurity Monitoring |
| CSL-V-02 | Cybersecurity Emergency Response |
| CSL-VII-01 | Penalties for Network Operators |
| CSL-VII-02 | Penalties for CII Operators |
Critical Information Infrastructure (CII)
Additional security requirements for CII operators
| Code | Title |
|---|---|
| CSL-CII-01 | CII Identification and Protection |
| CSL-CII-02 | CII Security Assessment |
| CSL-CII-03 | Data Localization for CII |
| CSL-CII-04 | CII Procurement Security Review |
| CSL-CII-05 | CII Personnel Security |
Data Protection
| Code | Title |
|---|---|
| CN-CSL-V2-CII-LOCALIZATION | CII Data Localization |
| CN-CSL-V2-INFOSEC-PII | Personal Information Security (Chapter IV) |
Governance
| Code | Title |
|---|---|
| CN-CSL-V2-CH1-DEF | Definitions and Scope (Chapter I) |
| CN-CSL-V2-CH2-SUPPORT | Cybersecurity Support and Promotion (Chapter II) |
| CN-CSL-V2-CII-DESIGNATION | CII Designation and Identification |
| CN-CSL-V2-CII-PERSONNEL | CII Specialized Security Body and Personnel |
| CN-CSL-V2-CREDIT-RECORDS | Cybersecurity Credit Records |
| CN-CSL-V2-LIABILITY | Legal Liability (Chapter VI) |
Legal
| Code | Title |
|---|---|
| CN-CSL-V2-CROSSBORDER-INV | Cross-Border Investigation Cooperation |
Operational
| Code | Title |
|---|---|
| CN-CSL-V2-CII-DRILLS | CII Annual Assessment and Drills |
| CN-CSL-V2-INCIDENT | Incident Response Plan |
| CN-CSL-V2-MONITORING | Monitoring, Early Warning, and Emergency Response (Chapter V) |
| CN-CSL-V2-PROHIBITED-CONTENT | Prohibited Information Handling |
| CN-CSL-V2-REALNAME | Real-Name Registration |
Supply Chain
| Code | Title |
|---|---|
| CN-CSL-V2-CII-PROCUREMENT | CII Procurement Security Review |
| CN-CSL-V2-PROCUREMENT | Network Product and Service Procurement |
Technical
| Code | Title |
|---|---|
| CN-CSL-V2-MLPS | Multi-Level Protection Scheme (MLPS 2.0) |
| CN-CSL-V2-NETOPS | Network Operations Security (Chapter III, Section 1) |
| CN-CSL-V2-VULN-DISCLOSURE | Vulnerability Discovery and Disclosure |
Your Compliance Coverage
If you comply with China Cybersecurity Law (CSL), you already cover:
UK Telecommunications (Security) Act 2021
19%
8 controls mapped
Compare →TISAX — Trusted Information Security Assessment Exchange
19%
8 controls mapped
Compare →PAS 1192-5:2015 — Security-Minded Approach to BIM and Digital Built Environments
19%
8 controls mapped
Compare →+ 622 more: Canada ITSG-33 — IT Security Risk Management (19%), New Zealand Information Security Manual (NZISM) (19%)
See all 625 mapped frameworks ↓Maps to 625 other frameworks
Frequently Asked Questions
What is China Cybersecurity Law (CSL)?
China Cybersecurity Law (CSL) is a compliance framework from China with 11 domains and 42 controls. The Cybersecurity Law of the People's Republic of China (effective June 2017) is China's foundational cybersecurity legislation. It establishes requirements for network operators and critical information infrastructure (CII) operators including multi-level protection scheme (MLPS), personal information protection, CII security, data localization, and security review mechanisms. Enforced by the Cyberspace Administration of China (CAC). It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.
How many controls does China Cybersecurity Law (CSL) have?
China Cybersecurity Law (CSL) has 42 controls organised across 11 domains. The largest domains are Chapter III — Network Operation Security (6 controls), Governance (6 controls), Critical Information Infrastructure (CII) (5 controls). Each control defines specific requirements that organisations must implement to achieve compliance.
What frameworks does China Cybersecurity Law (CSL) map to?
China Cybersecurity Law (CSL) maps to 625 other compliance frameworks. The top mapping partners are UK Telecommunications (Security) Act 2021 (19% coverage), TISAX — Trusted Information Security Assessment Exchange (19% coverage), PAS 1192-5:2015 — Security-Minded Approach to BIM and Digital Built Environments (19% coverage). Use our comparison tool to explore control-level mappings between frameworks.
How do I get started with China Cybersecurity Law (CSL) compliance?
Start your China Cybersecurity Law (CSL) compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about China Cybersecurity Law (CSL) requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 42 controls and track your progress.
Start Your Compliance Journey
Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 704 frameworks.
Get Started Free →Free forever — no credit card required