Assessment is a CAC review of the export — not a notary stamp on your SCC.
PIPL and CAC measures require a security assessment through CAC (via provincial cyberspace authorities) when statutory triggers are met: CII operators exporting PI, export of important data, and PI export above current volume or sensitive-volume triggers. The file typically includes a self-assessment, contracts, and security materials. Timelines are measured in months, not days. Passing assessment is not a permanent private licence — watch validity and change-of-circumstance rules. This page will not print a volume number that CAC can amend.
4 questions before you choose the route.
This page identifies the right question and evidence. It does not determine the legal outcome on a reader’s facts.
Is a trigger met?
CII, important data, current volume/SPI bands.
TriggerWho files?
The PRC exporter / handler, not the overseas parent alone.
FilerWhat is in the pack?
Self-assessment, contracts, security.
PackWhat if you are under the trigger?
SCC or certification sibling.
ElseWorking rule: Map the regulated role before marketing or launch in China.
The signal ledger.
These facts move the question beyond a label and into a product, money-flow and control analysis.
Bring a compact evidence docket—not a pitch deck.
Give a compliance team or counsel the operating facts that reveal the perimeter.
Questions people ask before they build.
Short answers for orientation. The right result can change with the service model and current rules.
How long does it take?
Plan in months. Do not book a go-live on a wiki guess.
Can we export while it is pending?
Generally no for the triggered export. Seek counsel on transitional facts.
Primary authorities
Reviewed sources support orientation, not a fact-specific assessment.
