Follow us on

Current location:

Home > ChinaCompliance
China Proposes Seven Mandatory Standards for Data and Cybersecurity Case Handling – AUG, 2026

2026.08.28 11:56

Author:admin

Tags: by ED04 #Data Security #Cybersecurity

Share to--:

From July 21 to August 20, 2026, the National Standardization Administration of China (SAC) opened a Call for Comment period on seven mandatory national standards projects concerning data security and cybersecurity cases, as well as the prevention of data-related illegal and criminal activities, to enhance national security. The Ministry of Public Security (MPS) proposed these standards projects. None of the seven projects involve a specific product category list, indicating that the standards will be applicable across all sectors.

The seven projects are organized into two parallel three-part case-management standards and one standalone prevention standard.

  • The Data Security Case standard comprises three parts covering requirements for the discovery and verification of clues, specifications for assistance in determining the nature, and requirements for investigation and forensics.

  • The Cybersecurity Case standard follows an identical three-part structure, addressing the same three stages of case handling.

  • Finally, the standalone project establishes a separate framework of technical and managerial countermeasures aimed at disrupting data crime chains.

Cybersecurity incidents in China have risen sharply. According to the Supreme People's Court, concluded cases endangering cybersecurity surged 158.5% over the past five years compared with the previous five-year period.

The Call for Comment notes that the lack of unified national standards has led to inconsistent case-determination thresholds, procedural gaps, and uneven legal outcomes, including cases that go unfilled or unpunished. This undermines judicial integrity.

These standards are intended to close that gap. They codify clear obligations and procedures for clue discovery, verification, and reporting; nature-determination assistance; and investigation and forensics cooperation. They also ensure seamless handover between criminal and administrative proceedings.

Data processors and network operators are the primary obligated parties. Product and service providers must report supply-chain clues. The case-management standards do not impose new daily security or technical obligations. Instead, they clarify how obligated parties must cooperate with public security and regulators when a case arises, reducing legal uncertainty. The standalone prevention standard gives enterprises systematic countermeasures against data crimes. Together, the standards support closed-loop incident response that improves both preparedness and remediation.

The standards projects have not officially commenced. So the final framework and requirements remain uncertain. Foreign stakeholders with a stake in these rules should monitor the development process.

 

If any further information is needed, or any question you may have, please contact us at: assistant@bestao-consulting.com


Related News