On 27 April 2020, the Cyberspace Administration of China (“CAC”) together with 12 other bureaus, including the National Development and Reform Commission, jointly issued the Measures for Cyber Security Review (the “2020 Measures”), replacing the Measures for Security Review of Network Products and Services (for Trial Implementation) (the “2017 Measures”) issued by CAC in 2017, and will be officially implemented on 1 June, 2020. As early as 24 May 2019, CAC issued the Measures for Cybersecurity Review (Consultation Draft) (the “2019 Consultation Draft”), putting forward the core idea of taking Critical Information Infrastructure Operators (“CIIO”) as the starting point for reviewing, which reflects the trend of China’s cybersecurity review and supervision.
Focus 1National security is more focused to ensure the safety of CII supply chain
The legal basis of cybersecurity review system comes from Article 59 of the National Security Law, “the state shall establish the rules and mechanisms for national security review and supervision, and conduct national security review of network information technology products and services that affect or may affect national security”, and Article 35 of the Cyber Security Law, “where Critical Information Infrastructure Operators purchase network products and services, which may affect state security, they shall pass the state security review organized by the national cyberspace administration in conjunction with relevant departments of the State Council.”
Therefore, the legislative goal of the cybersecurity review system is protecting national security. Compared with Article 1 of the 2017 Measures, which states “for the purposes of improving the security control level of network products and services, preventing cybersecurity risks, and protecting national security”, Article 1 of the 2020 Measures focused more on the legislative intent of protecting national security and the safety of CII supply chain. Compared to the 2017 Measures, the 2020 Measures additionally emphasize the review principle and review direction in its Article 3, “… shall adhere to the combination of preventing network security risks and promoting the application of advanced technology, the combination of fair and transparent procedures and the protection of intellectual property rights, the combination of prior review and continuous supervision, the combination of corporate commitment and social supervision, to review from the aspects including the safety of products and services and the possible national security risks.”
Focus 2Take CIIO as an important starting point for cybersecurity review and implement the cybersecurity review reporting system
In the 2017 Measures, the scope of cybersecurity review was “important network products and services concerning national security, which are purchased in the network and information system”, focusing on the network products and relevant providers. Nevertheless, the 2020 Measures take CIIO as the important starting point for cybersecurity review, which is in line with the 2019 Consultation Draft. CIIO should organize and urge the network product and service providers to cooperate with cybersecurity review, signing contracts and fulfilling commitments for cybersecurity commitments.[1]According to Article 19 of the 2020 Measures, CIIO who violate these Measures shall be punished under Article 65 of the Cybersecurity Law.[2]
In terms of the initiation and prediction of the review, compared to Article 8 of the 2017 Measures, which stipulates that the review targets are determined “in accordance with the relevant requirements of the state, the recommendations of the national trade associations and users' responses”, the 2020 Measures implement the cybersecurity review reporting system through Article 5, requiring CIIO to predict the national security risks that the product and services may bring, and proactively report to the cybersecurity review office. The change from passive determination to active declaration reduces the burden of the government and leads to a more precise and flexible identification of review targets. Relevant industrial standards can be made by CII protection department to serve as an important guidance for enterprises in the next stage of cybersecurity review. With respect to reviewing products and services, in comparison with the 2017 Measures, the 2020 Measures further clarify the relevant scope. Not all network products and services procured by CIIO need cybersecurity review. The scope of application of cybersecurity review is limited to the procurement of network products and services that have an important impact on the security of CII.
Additionally, with relevant to the legislative principle of fair and transport procedures and protecting intellectual property, compared to the 2017 Measures’ relatively simple confidentiality regulations, Article 16 of the 2020 Measures emphasizes the specific targets of confidentiality obligations are trade secrets and intellectual property, which not only includes the undisclosed information of operators, but also product and service providers, strengthening the protection of intellectual property right of enterprises. Article 17 of the 2020 Measures also adds a complaint clause for situations that are objectively unfair or in breach of the confidentiality obligations, which echoes its legislative principle of fair and transport procedures to protect relevant parties.
Focus 3The content of the security review emphasizes the influence of products and services on CII, and adheres to the opening-up policy
The change of legislative purposes leads to the change of the reviewed contents. The 2017 Measures focused on reviewing the security and controllability of network products and services, while the 2020 Measures emphasize the possible national security risks that network products and services may bring, which is mainly reflected in Article 9:
Article 9 The cybersecurity review shall focus on national security risks that procurement of network products and services may bring, mainly including:
The risks of illegal control, interference or damage to the Critical Information Infrastructure caused by the use of the products and services, and the theft, leakage and damage to the important data;
The damage to business continuity of Critical Information Infrastructure caused by the disruption of the supply of products and services;
The security, openness, transparency, source diversity of products and services, the reliability of supply channels and the risks of supply disruption due to political, diplomatic and trade factors, etc.
Product and service providers’ compliance with Chinese laws, administrative regulations and departmental regulations;
Other factors that may jeopardize the security of Critical Information Infrastructure and national security.
Compared to the Article 4 of the 2017 Measures[3], the new provisions have the following characteristics:
The 2020 Measures reorganize the review elements of the 2017 Measures, and exclude the part of personal information. The new provision no longer uses the expression of user-related information, while highlighting the risks regarding important data, showing the government’s dual-track approach to regulating important data and personal information.
In comparison with the 2017 Measures, the 2020 Measures highlight the risks to CII after the use of products and services, rather than starting from its own security risks, which clarifies the connection between the protection of CII and the use of products and services, focusing more on the legislative goal of protecting supply chains.
The 2020 Measures also specify the requirement of protecting supply chains, as it emphasizes the risk of supply chain disruption, requiring to ensure the diversity of sources of products and services as well as the reliability of supply channels. Moreover, the 2020 Measures delete the stipulation regarding foreign funding and controlling from 2019 Consultation Draft. As the spokesperson of CAC once said, “the Measure clearly stipulates the content to be reviewed, from which we can see the goal of cybersecurity review is to protect national security, not to restrict or discriminate against foreign products and services. Opening-up is our fundamental national policy. Our policy of welcoming foreign products and services into Chinese markets has not changed.” The above-mentioned amendments have reflected this idea.
Focus 4The review procedures become more transparent
In terms of review procedures, the 2020 Measures basically maintain the frame work of the 2019 Consultation Draft, which has significantly revised the relevant provisions in the 2017 Measures, as CIIO have to declare proactively, and a special procedure for reporting to Office of the Central Cyberspace Affairs Commissions is established.
Compared to the 2017 Measures, the 2020 Measures further improve the review procedure and clearly define the starting point and time limit of each review stage, avoiding unnecessary burden to enterprises and time delay caused by unclear regulations.
Conclusion
The 2020 Measures reflect the legislative intent of protecting national security and the security of CII supply chain and changes the review system from passive determination to active declaration, reducing the burden of the government and leading to a more precise and flexible identification of review targets. Relevant industrial standards can be made by CII protection department to serve as important guidance for enterprises in the next stage of cybersecurity review. The review contents now focus more on the aim of protecting national security and exclude the provisions related to personal information, which reflects the government’s dual-track approach to regulating important data and personal information. The provisions on the reporting and review procedures are more transparent, improving the efficiency of cybersecurity review and also ensuring the operators’ right to know. The enterprises’ legal rights and interests are better protected, as operators and product and service providers gain the right to complain in situations that are objectively unfair or in breach of the confidentiality obligations.
With the aim of further reducing cybersecurity risks, we recommend relevant enterprises to carry out overall cybersecurity compliance work, including but not limited to, establishing network product and service procurement system, multi-level protection scheme, and data classification system relating to important data.
[Notes]
[1]Article 6 and 18 of the Measures for Cybersecurity Review.
[2]Article 65 of Cybersecurity Law: “Where a critical information infrastructure operator, in violation of the provision of Article 35 of this Law, uses any network product or service that has not undergone security review or has failed to pass security review, the competent department shall order it to cease the use thereof, and impose a fine of not less than one time but not more than ten times the purchase amount on it, and impose a fine of not less than 10,000 yuan but not more than 100,000 yuan on its directly responsible person in charge and other directly liable persons.”
[3]Article 4: Cybersecurity review shall focus on the security and controllability of network products and services, mainly including:
(1) The security risk of products and services themselves, and the risk of unlawful control, interference and interruption;
(2) The supply chain security risk in the production, testing, delivery and technical support of products and key components;
(3) The risk that the product and service providers take advantage of their convenience in providing products and services to unlawfully collect, store, handle and use user-related information;
(4) The risk that product and service providers take advantage of users' dependence on the products and services to damage cybersecurity and the interests of users;
(5) Other risks that may endanger national security.
Zhong Lun Commentary on the Measures for Cyber Security Review
作者:JihongCHEN JiaweiWU YangLIU来源:中伦律师事务所

On 27 April 2020, the Cyberspace Administration of China (“CAC”) together with 12 other bureaus, inc