MLPS is classify → (file) → test → remediate — not a sticker you buy.
Under CSL and the classified-protection regime, network operators grade systems (typically levels 1–5) by harm if the system is damaged. Class 3 and above generally means filing with public security, periodic testing by a qualified house, and a remediation loop. Class 2 is still a real grade with security baselines; it is not ‘do nothing’. Cloud tenants and landlords split responsibilities — both can have MLPS facts. The live CSL page stays the statute related guide; this page is the MLPS how-to. Testing vendor lists and fee schedules are not published here.
4 questions before you choose the route.
This page identifies the right question and evidence. It does not determine the legal outcome on a reader’s facts.
What is the system boundary?
App, network, cloud account, plant OT.
BoundaryWhat class is justified?
Harm to citizens, social order, national security.
ClassIs filing required?
Typical class 3+ filing with MPS.
FileWho tests and how often?
Qualified test house; cadence by class.
TestWorking rule: Map the regulated role before marketing or launch in China.
The signal ledger.
These facts move the question beyond a label and into a product, money-flow and control analysis.
Bring a compact evidence docket—not a pitch deck.
Give a compliance team or counsel the operating facts that reveal the perimeter.
Questions people ask before they build.
Short answers for orientation. The right result can change with the service model and current rules.
Do foreign-invested companies need MLPS?
If they operate networks in China, yes they are in the operator set. Class still depends on the system.
Is class 3 mandatory for SaaS?
No. Many SaaS systems are class 2 or 3 depending on users and harm. Do not self-serve a class 3 promise on a wiki.
Primary authorities
Reviewed sources support orientation, not a fact-specific assessment.
