Current-law scope and cautions
- The Joint Provisions require network product providers to report relevant vulnerability information to the MIIT vulnerability platform within 2 days.
- The rule says “2 days”; this tool does not relabel the period as 2 working days.
- Public disclosure, malicious exploitation guidance, and provision of vulnerability information to overseas actors can trigger separate restrictions.
Use: This is a screening/estimation tool, not a legal opinion. Confirm the latest primary authority, regulator practice, local rules and transaction documents before acting.
