Cybersecurity Policy Report, Network Risk Assessment Recommendations Published for Comment in China, (Dec 8, 2025)
By Tony Foley
The Cyberspace Administration of China (CAC) has released draft measures for comment that are designed to establish administrative rules related to network data security risk assessments.
CAC said the measures marked a crucial step in the construction of a network data security risk assessment system. The development of the measures was stipulated in the country’s Data Security Law, as well as the Regulations on the Administration of Network Data Security. They establish a risk assessment mechanism that integrates national coordination, industry supervision, local coordination, and the primary responsibilities of network data processors, requiring such processors to effectively fulfill their primary responsibilities and guiding relevant departments in carrying out network data security governance and supervision.
Included in the measures are assessment report templates that require network processors to conduct risk assessments on schedule, prepare and submit reports as required, and have provincial-level or higher cyberspace administration departments and other relevant departments conduct random checks on the authenticity and accuracy of the reports.
According to a notice accompanying the measures, the CAC is soliciting comments on the measures through Jan. 5, 2026. Interested parties can submit comments, via the CAC website, by e-mail or by regular mail as specified in the notice.
News: InternationalLegislation DataSecurity