When did the Measures for Network Data Security Risk Assessment enter into force?
The Measures entered into force on August 20, 2026, the same day the CAC published its implementation Q&A.
Who must file a network data security risk assessment report, and within what deadline?
Important-data handlers must complete an annual network data security risk assessment and submit the report to their competent department within 20 working days of completion, under Article 16 of the Measures.
Where should an important-data handler file the report if its competent department is unclear?
It should file with the provincial cyberspace administration or the national CAC; the Q&A provides a contact table of national and provincial cyberspace departments.
How can a risk-assessment institution obtain service certification under the Measures?
Under Article 8, assessment institutions are encouraged to obtain certification from one of three bodies that have filed the Data Security Risk Assessment Service Certification Rules with CNCA: the CAC Data and Technology Assurance Center, the MPS Third Research Institute, or TAIR Certification Center.