Applicability
The law applies to all \"network operators\" � any entity operating or providing network services in China, including websites, mobile apps, cloud services, and internal corporate networks.
Multi-Level Protection Scheme (MLPS 2.0)
Information systems are classified into five security levels based on the impact of a breach. Level 2 and above require filing with the public security bureau and passing a security assessment by a qualified third party. Level 3 and above require annual audits.
Data Localization
Critical information infrastructure (CII) operators must store personal information and?? data within China. Data exported must undergo a security assessment. CII sectors include finance, energy, transportation, healthcare, and telecommunications.