Explaining Major Amendments to China's "Cybersecurity Law": How Should Companies Respond to Tougher Penalties and Broader Extraterritorial Application?

The “Cybersecurity Law of the People’s Republic of China” (Cybersecurity Law, Chinese original: 中华人民共和国网络安全法), which serves as one of the cornerstones of China’s cybersecurity regulations, has reached a historic turning point. On October 28, 2025, the Standing Committee of the National People’s Congress announced significant amendments to this law, which will take effect on January 1, 2026. Read more.
This is the first major revision since its implementation in 2017. It significantly expands liabilities, addresses emerging technologies such as artificial intelligence (AI), and increases the extraterritorial application. Understanding these changes is crucial for Japanese companies operating in China to ensure legal compliance.
This article will outline the background of this major revision to the Cybersecurity Law, explain amendments in detail, and present changes Japanese companies must adopt.
Background of Major Revision to the “Network Security Law” (Cybersecurity Law) in China

Along with the Data Security Law and the Personal Information Protection Law, the Cybersecurity Law of China serves as one of the country’s ‘Three Data Laws.’ The law aims to establish regulatory frameworks.
https://monolith.law/corporate/china-cyber-security-law
One factor behind the recent amendment is the need to address new risks caused by the rapid development of the digital economy.
The rapid adoption of artificial intelligence technologies, including generative AI, has created various issues including the safety of algorithms, the legality of training data, and AI ethical standards. Existing laws were not designed to address these new challenges, so the Chinese government had to establish a new legal framework to deal with those emerging issues.
Furthermore, new threats have emerged, including network breaches, cyberattacks, and the spread of illegal information. To deal with these threats effectively, Chinese authorities felt a need to have effective and up-to-date regulations.
The other factor is related to China’s national strategy. Based on China’s initiatives to build a “cyber power” and the “Comprehensive National Security Outlook,” the Chinese administration has been developing legal systems to protect sovereignty and security in cyberspace.
Moreover, the previous law had relatively mild punishments, and differences in punishment standards between the law and the subsequently enacted Data Security Law and Personal Information Protection Law were also a major issue. The recent revision aims to enhance the coordination of these “Three Data Laws” and secure uniform and integral law enforcement.
In addition, given the current international situation, the scope of extraterritorial application of the law has been clearly defined and expanded to address attacks from abroad and actions threatening national security. This change allows Chinese authorities to impose sanctions on foreign organizations and individuals.
Key Points of the Revised “Network Security Law”
The newly revised law not only inherits substantial obligations from the previous law but also includes several significant new provisions and amendments.
Establishment of Basic Policies and AI-Related Provisions
The new law explicitly mentions the Communist Party’s leadership in cybersecurity operations and the implementation of the “Comprehensive National Security Outlook.”
Furthermore, for the first time, the revised law systematically codifies AI policies in the main body of the cybersecurity law. While the government supports research and development of basic AI theories and algorithms, it also strengthens risk monitoring and safety supervision, and establishes ethical norms for the sake of cybersecurity.
Safety Protection Obligations and Coordination with Personal Information Protection Law
Network operators are obligated to ensure network safety by implementing the Multi-Level Protection Scheme (MLPS), which includes the establishment of internal management systems, clarification of the person in charge, and implementation of technical measures.
The new law explicitly states that when handling personal information, businesses must follow not only the Network Security Law but also the Civil Code and the Personal Information Protection Law.
This clarification enhances the consistency of related legal systems and requires integrated compliance responses.
Safety of Network Products and Services
The law highlights the importance of the safety of supply chains for critical equipment and dedicated products. It is strictly prohibited to provide and sell critical network equipment that has failed or not undergone safety certification and inspection.
Violations may result in sales suspension, confiscation of illegal income, and substantial fines.
Tougher Penalties
One of the most significant aspects of this revision is the introduction of a tiered penalty system based on the severity of harm and the overall increase in fine levels.
Fines for Network Operators
Previously, Chinese authorities sometimes issued corrective recommendations alone. However, under the new law, they can directly impose fines alongside corrective orders for violations of safety protection obligations. Fines for refusing correction or causing harm range from 50,000 yuan to 500,000 yuan (a significant increase from the previous law’s maximum of 100,000 yuan).
Moreover, based on the aggravated punishment provision, businesses can be fined between 500,000 yuan and 2 million yuan for causing significant harm such as massive data leaks or partial functional loss of critical information infrastructure. For causing special hazards, such as the loss of major functions of critical information infrastructure, fines range from 2 million yuan to 10 million yuan.
Fines for Individuals
The responsibility of individuals in charge within companies has also been expanded. Based on the level of harm, fines range from 50,000 yuan to 200,000 yuan for significant harm, and from 200,000 yuan to 1 million yuan for especially significant harm. In addition to the traditional “person in charge,” “other persons directly responsible” are also explicitly included as subjects of punishment.
Other Sanctions
In addition to fines, severe administrative penalties such as temporary suspension of business, business suspension and rectification, closure of websites or applications, and revocation of business licenses may be imposed depending on the circumstances. In cases of special hazards, these punishments will be mandatorily applied.
Expansion of Extraterritorial Application
Previously, extraterritorial application was limited to activities threatening China’s critical information infrastructure (CII). However, the new law also targets foreign institutions, organizations, and individuals engaged in activities threatening China’s overall network security. In cases of serious incidents, Chinese authorities may impose sanctions such as asset freezes.
Corporate Compliance with the new “Network Security Law”

With the implementation of the new law, companies operating in China must rigorously review their current system and establish stricter governance structures.
Review and Improvement of Internal Security Management Systems
Companies must ensure that their networks are protected appropriately based on the Cybersecurity Grading Protection System.
Clarification of Responsibilities
It is essential to clearly designate a network security officer and incorporate their authority and duties into internal regulations. The new law significantly increases fines for individuals, making it crucial for companies to educate and support their personnel in fulfilling their duties to reduce legal risks.
Implementation of Technical Measures
Companies must implement technical measures to prevent computer viruses and cyberattacks, and retain logs for more than six months. Additionally, they must make sure that data classification, backup of critical data, and encryption measures meet the latest technical standards.
Supply Chain Compliance
It is necessary to strictly confirm whether the critical network equipment and dedicated products used or sold by the company have passed the safety certification and inspection recognized by Chinese authorities.
Verification During Procurement
Companies identified as CII operators must pass a national security review when obtaining network products or services that may impact national security.
Non-Disclosure Agreement
It is mandatory to enter into agreements with providers regarding safety and confidentiality and clearly define the scope of responsibilities.
Establishment of Incident Response and Reporting Systems
Companies must develop emergency response plans (manuals) for security incidents and conduct regular training. In the event of an incident, they must take remedial measures immediately. Companies must also establish a process for promptly reporting to authorities.
Safety Evaluation for the Introduction of New Technologies (AI)
When introducing AI into operations, companies must assess the safety of algorithms and their compliance with ethical standards. The law promotes the healthy development of AI while outlining plans to enhance risk monitoring. Businesses operating in China should take proactive measures in anticipation of future supervisory regulations.
Management of Cross-Border Data Transfers
When transferring critical data and personal information overseas, companies must appropriately conduct procedures such as safety evaluations, certifications, and the conclusion of standard contracts in accordance with the Data Security Law and the Personal Information Protection Law. The law emphasizes coordination with these other laws, making the establishment of a unified data management system an urgent task.
Conclusion: Consult with a Lawyer for Compliance with China’s Network Security Law
The recent amendment to China’s Network Security Law symbolizes a shift in Chinese digital governance, moving from “guidance through corrective recommendations” to “strict law enforcement accompanied by substantial fines.”
The fine, which can reach up to 10 million yuan, can greatly impact a company’s operations. Companies must now have a more precise understanding of the law and engage more carefully in their management decisions.
Furthermore, it is essential to review compliance with related subordinate regulations, such as the “Network Data Security Management Regulations” enacted in January 2025, and to establish a multilayered compliance system to safely continue business operations in the Chinese market.
To deal with these legal amendments, it is crucial to consult with lawyers who have expertise not only in law but also in IT business.
Guidance on Measures by Our Firm
Monolith Law Office is a legal firm with extensive experience in both IT and law. In recent years, global business has been expanding increasingly, and the need for legal reviews by experts is growing. Our firm provides solutions related to international legal affairs.




















