China Cyber UpdateStrategic CommunicationsStrategyChina NotepadNewsletterContactRequest a sample
Monthly business briefing

China Cyber Update

The current developments in Chinese cybersecurity, analyzed from the perspective of foreign companies and without false alarm.

The China Cyber Update is a monthly briefing on Chinese cybersecurity, data regulation and AI policy. Original reports from new laws and regulations are weighed and analyzed in their political context, without which they often remain unintelligible. With an enforcement radar. Written for CIOs, CISOs, CEOs and boards. Published without interruption since August 2021, now in its sixth year.


Read a free sample

The July 2026 sample edition of the China Cyber Update.

What is in every edition

Part I. What is new this month

The current month in geopolitics, cyber and data regulation, reported and placed in context, briefly.

A section written for the subscriber

Plus a chapter written for each subscriber every month. Regulatory changes and enforcement with a direct effect on your company.

Part III. The running China Cyber Report

Every significant development since 2021, summarized briefly. Arrive mid-year and still get the whole picture.

Who reads it

Subscribers are mostly CIOs, CISOs, risk officers and general counsel at multinationals with important China operations.

Where it sits next to what you already buy

Threat intelligence vendors

Technical feeds deliver indicators of compromise. We deliver the direction of cybersecurity policy, with the analytical edge a board meeting needs.

Law firm alerts

An alert arrives once the new law or regulation is final. We give the important warnings months earlier.

Other advisory agencies

Expensive one-off studies deliver temporary snapshots. We deliver continuity.

How we research

We work from Chinese primary sources. Notices from the Cyberspace Administration of China (CAC), ministry announcements, draft and final national standards, court records and Chinese business media.

The work runs by the rules of a newsroom. Every claim is evidenced, every number checked against the original document, official Chinese claims double-checked.

Cyber security in China. The rules a foreign company needs to understand

Three national laws, one State Council regulation and a large body of technical standards. Current as of August 2026. We provide orientation, not legal advice.

Cybersecurity Law

In force since 1 June 2017. An amendment took effect on 1 January 2026. It writes state support for artificial intelligence into the law, reaches conduct outside China that endangers Chinese network security.

Data Security Law

In force since 1 September 2021. It grades data by importance to the state and raises obligations with the grade. The category of important data comes from here.

Personal Information Protection Law

In force since 1 November 2021. China’s counterpart to the European GDPR, governing consent, processing and the export of personal information.

Network Data Security Management Regulations

In force since 1 January 2025. The first State Council regulation implementing all three laws together.

Multi-Level Protection Scheme, MLPS 2.0

The Ministry of Public Security grades systems one to five. Obligations tighten sharply from level three. The standards behind MLPS 2.0 apply since 1 December 2019 and reach cloud platforms, industrial control systems and the internet of things.

Cross-border data transfer

Three routes. A security assessment by the Cyberspace Administration of China, since 1 September 2022. A standard contract, since 1 June 2023. Certification, since 1 January 2026. Provisions of 22 March 2024 exempted non-sensitive data on fewer than 100,000 people a year, and transfers needed for trade, cross-border HR and contract performance.

Generative artificial intelligence

The Interim Measures for the Management of Generative AI Services apply since 15 August 2023. Labelling of AI-generated content, visibly and in file metadata, since 1 September 2025.

Who enforces it

Cyberspace Administration of China

The central internet regulator. It leads rulemaking and enforcement under all three laws, runs cybersecurity reviews and approves cross-border data transfers.

Ministry of Public Security

Administers the Multi-Level Protection Scheme and carries the police powers behind cybersecurity enforcement.

TC260

The national technical committee for cybersecurity standards. Its GB/T standards are formally voluntary and supply the detail regulators judge compliance by, so foreign companies treat them as binding.

What matters to a board is the sequence. A standard is drafted, a consultation opens, a rule follows, enforcement arrives later. Read the first step and you have time. Wait for the alert and you do not.

Questions about the China Cyber Update

What does the China Cyber Update cost?

Prices on request, tiered by the degree of customization for each company. Single and enterprise licenses are available.

Can I see it before subscribing?

Yes. The sample is a real edition with client-specific detail and the cumulative report removed, so the reporting, the sourcing and the judgment stay visible.

How is it different from a threat intelligence feed?

A threat feed reports indicators of compromise. We report which direction Chinese policy is taking and what it means for a foreign company.

In what language is it published?

Usually in English, and in other languages on request.