TODAY'S MARKET INTELLIGENCE
Implementation of Network Data Security Risk Assessment Measures: Three Paths - Security Service Providers, Data Governance Parties, and Compliance Auditors
English summary
### Implementation of Network Data Security Risk Assessment Measures: Three Paths - Security Service Providers, Data Governance Parties, and Compliance Auditors Time: 2026-07-31 14:43:39 Content: 1. A 'mandatory order' that shakes the industry: On June 18, the Cyberspace Administration of China (CAC), the Ministry of Industry and Information Technology (MIIT), and the Ministry of Public Security (MPS) jointly issued the 'Measures for Network Data Security Risk Assessment', effective from August 20. This is not a recommended guideline, but a mandatory order. Hard-core policy clauses: Important data processors must conduct a comprehensive risk assessment once a year, report to competent authorities, and accept random inspections and verifications; when there is a major change in data security status, a special supplementary assessment must be conducted in a timely manner. General data processors are encouraged to conduct at least once every 3 years. Assessment agencies: cannot sub-contract; the same agency cannot conduct annual assessments for the same processor more than 3 consecutive times—this means service providers need to rotate, and the market will not be dominated by one player. To summarize the impact in one sentence: it turns data security risk assessment from an 'optional value-added service' into a 'statutory rigid expenditure'. ...
The English text is machine translated and may require verification against the Chinese version.
Browse today's intelligence