| New Article 3 | No equivalent standalone provision. | Adds an express national cybersecurity policy provision. | + Added | Places the law within the current national cybersecurity policy framework. | Added by item 1 of the amendment decision.Effective: 2026-01-01Current source |
| Former Article 18 / new Article 20 | Former Article 18 included a second paragraph that was removed. | Adds support for AI research, infrastructure, ethics, risk monitoring, security supervision, and AI-enabled cybersecurity management. | ~ Modified | Expressly brings AI development and safety into the Cybersecurity Law framework. | Items 2 and 3 of the amendment decision.Effective: 2026-01-01Current source |
| Former Article 40 / new Article 42 | The article addressed protection of user information collected by network operators. | Adds an express requirement to comply with the Cybersecurity Law, Civil Code, PIPL, and other laws and administrative regulations when processing personal information. | i Clarified | Clarifies coordination with the later personal-information legal framework. | Item 4 of the amendment decision.Effective: 2026-01-01Current source |
| New Article 61 | Former Article 59 contained the earlier penalty structure for specified security-protection failures. | Introduces differentiated penalties and higher bands where failures cause serious or particularly serious cybersecurity consequences. | ~ Modified | Raises consequence-based exposure for network operators and critical information infrastructure operators, including responsible personnel. | Item 5 of the amendment decision; consult the official text for exact penalty ranges.Effective: 2026-01-01Current source |
| New Article 63 | No equivalent standalone liability article for selling or providing specified uncertified or non-compliant products. | Adds liability for selling or providing network critical equipment and specialized cybersecurity products that do not meet certification or testing requirements. | + Added | Creates a dedicated enforcement basis for this product-control requirement. | Item 7 of the amendment decision.Effective: 2026-01-01Current source |
| New Articles 64–69 | Former liability articles used the earlier numbering and penalty structure. | Reorders and revises liability for prohibited activities, review obligations, CII procurement, and prohibited-information handling. | ~ Modified | Requires compliance mappings and citations to use the amended numbering and penalty provisions. | Items 8–11 of the amendment decision.Effective: 2026-01-01Current source |
| New Article 71 | Personal-information and cross-border liabilities were distributed across former Articles 64, 66, and 70. | Consolidates coordination with other laws and administrative regulations for prohibited content, personal-information rights, and CII cross-border storage or transfer conduct. | ↔ Procedural | Directs readers to the relevant specialized legal regime for handling and penalties. | Item 12 of the amendment decision.Effective: 2026-01-01Current source |
| New Article 73 | No equivalent express cross-reference in the law. | Adds an express cross-reference to lighter, mitigated, or no punishment under the Administrative Penalty Law. | + Added | Makes general administrative-penalty mitigation principles explicit within the law. | Item 13 of the amendment decision.Effective: 2026-01-01Current source |
| Former Article 75 / new Article 77 | The earlier extraterritorial provision addressed attacks, intrusion, interference, destruction, or other activities causing serious consequences. | Uses broader language covering activities by overseas institutions, organizations, or individuals that endanger PRC cybersecurity and retains possible sanctions for serious consequences. | ~ Modified | Broadens the wording of the extraterritorial conduct provision. | Item 14 of the amendment decision.Effective: 2026-01-01Current source |