China's Cyberspace Administration of China (CAC) announced on August 6, 2026 that its Cybersecurity Review Office has opened a formal cybersecurity review of products sold in China by Palo Alto Networks (派拓公司), the US-headquartered network-security vendor. The review is conducted under the Cybersecurity Review Measures, the National Security Law and the Cybersecurity Law, and is aimed at safeguarding the stable operation of critical information infrastructure (CII), preventing cybersecurity risks, and maintaining national security. The probe converts earlier, informal procurement guidance steering Chinese buyers away from US and Israeli cybersecurity suppliers into an official, named investigation of a single vendor.
The one-paragraph CAC notice is procedural, but its legal bases are the operative point. A review under the Cybersecurity Review Measures can conclude that a product endangers national security and trigger procurement restrictions, and it sits on top of a Cybersecurity Law amended on October 28, 2025 and in force since January 1, 2026 that substantially raised the penalty ceiling for non-compliant network operators and product suppliers.
Who is exposed to the review, and how immediately?
The direct subjects are Palo Alto Networks' China sales arm and any of its firewall, cloud-security and endpoint products already deployed in mainland China. The more time-sensitive exposure falls on the buy side: CII operators in finance, telecoms, energy, government and large enterprise customers running Palo Alto Networks gear in their network perimeters. For these operators, a formal review creates the live possibility that new procurement, renewal or patch paths are restricted before a conclusion is published, and the Cybersecurity Review Measures let the office require additional undertakings from buyers while a review is pending.
Multinational IT and security teams whose China subsidiaries or joint ventures use Palo Alto Networks products face the same inventory problem: they must now map where the vendor's products sit in regulated Chinese networks and prepare for a scenario in which replacement becomes necessary.
What outcomes can a Cybersecurity Review Office probe produce?
Under the Cybersecurity Review Measures (last revised in 2022), the Cybersecurity Review Office reviews products and services that CII operators procure, or that platform operators handling large volumes of data use, where they may affect national security. The review can result in a clearance with conditions, an order to adjust procurement, or a determination that the product or supplier may not be purchased by CII operators. The measures also authorise the office to ask the operator and the supplier for source code, data-handling and supply-chain information during the review.
The legal-consequence track runs through the Cybersecurity Law: operating CII with products that fail a security review, or breaching procurement-review obligations, exposes the operator and the supplier to administrative penalties, which the January 1, 2026 amendment sharpened with higher fines and stronger personal liability for responsible managers.
How does this fit the January 2026 vendor-replacement guidance?
The August 6 probe is the formal escalation of a January 2026 steer, reported by Bloomberg and carried by TipRanks, in which Chinese authorities quietly guided state-backed and CII buyers away from US and Israeli cybersecurity vendors, Palo Alto Networks among them. That guidance was informal and procurement-directed; this announcement is the first named, statute-based review of the company under the Cybersecurity Review Measures.
| Dimension | January 2026 guidance | August 6, 2026 review |
|---|---|---|
| Legal character | Informal procurement steer | Formal review under Cybersecurity Review Measures |
| Named target | US and Israeli vendors, category-wide | Palo Alto Networks, named |
| Stated basis | Not statute-cited | National Security Law, Cybersecurity Law, Cybersecurity Review Measures |
| Buyer consequence | Discretionary substitution | Possible procurement restriction or CII purchase ban |
What should security and procurement teams do now?
Three actions are immediately defensible. First, inventory every Palo Alto Networks product deployed in mainland China networks, separating CII-adjacent from general enterprise use, since CII operators carry the primary review obligation. Second, review current support, renewal and patch contracts for clauses that assume uninterrupted supplier engagement, and map a fallback vendor shortlist that has already cleared Chinese security assessment. Third, brief legal and compliance leadership on the amended Cybersecurity Law's higher penalty exposure so that continued deployment is a documented decision, not a default.
Continuous, per-jurisdiction regulatory monitoring surfaces a step like this the moment the CAC publishes, before it reaches the trade press.
Take advantage of this real-time watch
For compliance counsel: confirm whether your organisation qualifies as a CII operator under Chinese law, track the Cybersecurity Review Office's conclusion, and prepare a replacement timeline keyed to the review's outcome rather than to a vendor's commercial calendar.


