Research across the library

Search laws, regulations, standards and guides

Suggested searches

Current priorities

2026-07-03Revised Internet Information Service Measures draft2026-06-18Network data risk assessment: draft versus final

What changed

Material differences at a glance

The final measures retain annual assessment for important-data processors and the three-year encouragement for general-data processors, but change report preparation and submission mechanics, remove the draft report template, and revise institutional and enforcement language.

  • The final reporting deadline is 20 working days after the annual assessment, rather than 10 working days in the draft.
  • The draft's prescribed report-template annex is not included in the final measures.
  • The final text uses a coordinated inter-agency mechanism and less prescriptive wording on named standards and certified assessors.

Source comparison

7 reviewed change records
Article / SectionPrevious TextUpdated TextTypePractical ImpactNotes
Effective dateThe draft left the effective date blank.The final measures take effect on 20 August 2026.+ AddedCreates a fixed implementation date.Final Article 25.Effective: 2026-08-20Previous sourceCurrent source
Assessment cadenceAnnual assessment for important-data processors; general-data processors encouraged at least every three years.The final measures retain both frequencies.i ClarifiedThe main cadence was retained from the draft.Draft Article 6; final Article 5.Effective: 2026-08-20Current source
Assessment methodologyThe draft expressly named GB/T 45577 and other relevant national standards.The final text requires compliance with law and regulation and reference to relevant national standards without naming GB/T 45577 in the article.~ ModifiedThe final wording is less tied to a named standard in the operative rule.Draft Article 7; final Article 6.Effective: 2026-08-20Current source
Report formatThe draft required the attached report template unless a competent authority prescribed otherwise.The final text defers to competent-authority requirements and permits reference to national standards where no requirement exists.~ ModifiedOrganizations should monitor sector-specific report requirements rather than rely on the draft annex.Draft Article 13; final Article 15.Effective: 2026-08-20Current source
Report submissionSubmission within 10 working days after completing the annual assessment.Submission within 20 working days after completing the annual assessment.~ ModifiedThe final rule doubles the stated submission period.Draft Article 14; final Article 16.Effective: 2026-08-20Current source
Certified assessor triggerThe draft used mandatory language for specified cases and prioritized certified assessors for voluntary engagement.The final measures use a defined authority power to require a certified assessor in specified risk or incident cases and encourage certification generally.~ ModifiedThe final text changes the trigger structure and should replace draft-based workflow assumptions.Draft Articles 8–9 and 15; final Articles 8–9 and 17.Effective: 2026-08-20Current source
Draft annexThe consultation package included a network data security risk assessment report template.The final measures do not include that annex.− DeletedThe consultation template should not be presented as a mandatory final form.Compare the official consultation and final publication pages.Effective: 2026-08-20Current source

Official sources

This website is for informational and educational purposes only. It does not constitute legal advice. The Chinese text shall prevail. Users should consult qualified legal counsel for specific matters.