The CAC Security Assessment is mandatory for high-volume data processors and CIIOs, while Standard Contractual Clauses (SCCs) are available for organizations processing personal information of fewer than 1 million individuals annually that do not qualify as CIIOs — but the two routes differ in cost, duration, legal certainty, and ongoing compliance burden by approximately 300% across all metrics. A CAC Security Assessment costs an average of RMB 400,000-1,200,000 in preparation costs, takes 6-9 months from initiation to approval, and is valid for 2 years. Standard Contractual Clauses cost an average of RMB 100,000-300,000 to prepare and file, take 2-4 months to implement, and require refiling only on material changes. Choosing the wrong route — or failing to identify which route applies — exposes foreign companies to fines of up to RMB 50 million or 5% of annual revenue under PIPL Article 66. Understanding the precise eligibility criteria, process differences, and strategic considerations for each route is essential for any foreign company transferring personal information from China to overseas affiliates, headquarters, or service providers.
Who Must Use the CAC Security Assessment Route
The CAC Security Assessment (安全评估, ānquán pínggū) is the strictest of the three approved cross-border data transfer routes under PIPL Article 38. It is governed by the Measures for Security Assessment of Cross-Border Data Transfers (数据出境安全评估办法, shùjù chūjìng ānquán pínggū bànfǎ, effective September 2022, updated March 2026). Under these Measures, a CAC Security Assessment is mandatory for: Critical Information Infrastructure Operators (CIIOs) formally designated under the Cybersecurity Law (CSL, 网络安全法, wǎngluò ānquán fǎ); organizations that process the personal information of more than 1 million individuals annually and plan to transfer personal information abroad; organizations transferring important data (重要数据, zhòngyào shùjù) as defined in industry-specific catalogues under the Data Security Law (DSL, 数据安全法, shùjù ānquán fǎ); and organizations that have transferred the sensitive personal information of more than 10,000 individuals abroad in the preceding 12 months, even if their total processed personal information is below the 1 million threshold.
Foreign companies should carefully assess whether any of these criteria apply, as the consequences of incorrectly using the SCC route when the Security Assessment route is mandatory include invalidation of the transfer authorization and exposure to full PIPL penalties. The CAC’s 2025 enforcement actions included at least 4 cases where companies had inappropriately used SCCs for transfers requiring a Security Assessment, with fines averaging RMB 4.5 million per case. A 2025 survey by the China Data Security Association found that approximately 22% of FIEs initially self-assessed their data volume incorrectly, leading to the wrong route choice.
Who Can Use the SCC Route
Standard Contractual Clauses (SCCs, 标准合同条款, biāozhǔn hétong tiáokuǎn) under the Measures on Standard Contracts for Cross-Border Transfer of Personal Information (个人信息出境标准合同办法, gèrén xìnxī chūjìng biāozhǔn hétong bànfǎ, effective June 2023) are available for organizations that meet ALL of the following conditions: not formally designated as a CIIO; processes personal information of fewer than 1 million individuals annually; transfers personal information of fewer than 100,000 individuals abroad since January 1 of the prior year; transfers sensitive personal information of fewer than 10,000 individuals abroad; and does not involve the transfer of important data under any industry-specific catalogue.
The practical impact for foreign companies: a typical mid-size WFOE (外商独资企业, wàishāng dúzī qǐyè) with 200-500 employees and a relatively small customer base can usually use the SCC route, provided it does not process data for more than 1 million individuals and does not hold important data. For larger FIEs with significant customer-facing operations — especially in e-commerce, fintech, or social media — the Security Assessment route is more likely to be required. Companies should reassess their eligibility annually as data volumes grow, particularly during periods of business expansion or customer base growth.
Comparative Analysis: 10 Key Differences
| Dimension | CAC Security Assessment | Standard Contractual Clauses | Practical Impact |
|---|---|---|---|
| Eligibility threshold | CIIO, >1M individuals, important data, or >10K sensitive PI | Non-CIIO, <1M individuals, no important data | Security Assessment required for larger/higher-risk profiles |
| Approval model | Affirmative CAC approval before transfer | File-and-effect after 15-day CAC review | SCCs are faster, lower rejection risk |
| Processing time | 45-90 working days (official); 6-9 months real-world | 15 working days (CAC review); 2-4 months total | SCCs are 3-4x faster |
| Validity period | 2 years from approval date | Duration of contract (review at 3 years) | Security Assessment requires formal renewal every 2 years |
| Preparation cost | RMB 400,000-1,200,000 | RMB 100,000-300,000 | Security Assessment 3-4x more expensive |
| Renewal cost (annualized) | RMB 200,000-600,000/year | RMB 33,000-100,000/year | Security Assessment 6x more expensive |
| CAC revocation risk | CAC may revoke at any time | CAC may require modification | Both carry regulatory risk |
| Documentation burden | Full DPIA + data flow map + security assessment + legal opinions | Signed SCC + DPIA + filing form | Security Assessment 3-4x more documentation |
| Third-party beneficiary rights | Not explicitly provided | Data subjects have third-party rights | SCCs provide stronger individual protection |
| Public disclosure risk | Non-compliance publicly named | Filing status not public | Comparable — both carry naming risk |
The CAC Security Assessment Process: Step by Step
- Determine applicability — Assess whether any of the four mandatory assessment criteria apply to your company. This requires a data classification audit and volume assessment under PIPL thresholds, typically taking 4-8 weeks for a mid-size FIE.
- Conduct a DPIA — Prepare a comprehensive Personal Information Protection Impact Assessment (PIPIA, 个人信息保护影响评估, gèrén xìnxī bǎohù yǐngxiǎng pínggū) covering the purpose, scope, necessity, and security measures of the proposed cross-border data transfer. The DPIA must address the legality and legitimacy of the data transfer, the potential impact on individual rights, and the effectiveness of security measures at the overseas data recipient. The DPIA must be retained for at least 3 years under PIPL Article 55-56.
- Engage PRC legal counsel — Work with a PRC-licensed law firm to prepare the assessment application, including basic information about the data exporter and importer, a detailed description of the data being transferred, the DPIA report, the data processing agreement with the overseas recipient, and relevant business licenses and certifications.
- Submit through provincial CAC — File the application with the provincial-level CAC office where your company is registered. The provincial CAC conducts an initial review (typically 7-15 working days) before forwarding to the national CAC.
- National CAC assessment — The national CAC conducts the formal security assessment, reviewing all materials, consulting with relevant industry regulators, and potentially requesting supplementary information. The CAC must issue a decision within 45 working days, extendable by up to 45 working days for complex cases.
- Receive and implement decision — If approved, the company receives a formal approval notice valid for 2 years, possibly with conditions. If denied, the company must cease cross-border transfers and may receive guidance on how to modify the application for resubmission.
The SCC Filing Process: Step by Step
- Confirm eligibility — Verify all five conditions for SCC use. Incorrect self-assessment can lead to enforcement actions. Reassess eligibility annually.
- Execute the standard contract — Use the CAC’s standard form including the names and contact information of both parties, the purpose and legal basis for the transfer, data categories and sensitivity, retention period, security measures, data subject rights, liability provisions, and dispute resolution terms.
- Conduct a DPIA — Prepare a PIPIA specific to the SCC-filed transfer. While less detailed than the Security Assessment DPIA, it must still cover legality, necessity, and security implications. Retain for at least 3 years.
- File with provincial CAC — Submit the executed SCC, DPIA, and filing form within 30 working days of contract execution. The CAC has 15 working days to review. If no objections raised, the SCC becomes effective and the company may proceed with transfers.
Strategic Decision Framework
- Your company is a CIIO or processes >1M individuals: Security Assessment is mandatory. Begin 9 months before intended transfer start. Budget RMB 600,000-1,200,000 for initial compliance. Engage specialized PRC data compliance counsel with CAC assessment experience.
- Your company processes 100,000-1M individuals and is not a CIIO: Evaluate both routes. SCC is preferred for cost and speed. If data volume is expected to exceed 1M within 2 years, starting with Security Assessment may be strategic to avoid a mid-cycle route change.
- Your company processes fewer than 100,000 individuals: SCC is the appropriate choice unless you handle important data. Budget RMB 100,000-300,000. Prepare for volume growth that may trigger Security Assessment eligibility.
- Your company transfers sensitive healthcare or financial data: Consider Security Assessment even below volume thresholds. Industry regulators (NHC for healthcare, PBOC for finance) may require Security Assessment-level review regardless of PIPL thresholds. Sector-specific important data catalogues are broader than general PIPL categories.
- Your company operates in an FTZ with pilot exemptions: Check whether your FTZ management authority has issued exemptions from cross-border data transfer requirements. Shanghai FTZ, Lingang, Hainan FTP, and Shenzhen Qianhai have pilot programs that may exempt certain non-personal business data from both routes, requiring formal documentation and advance registration.
Recent Regulatory Changes (2025-2026)
The March 2026 update to the Measures for Security Assessment of Cross-Border Data Transfers introduced a tiered assessment model with streamlined renewal for low-risk transfers, reducing documentation burden by approximately 40% for qualifying companies. The updated measures clarified the data volume calculation methodology: the 1 million individual threshold is now calculated based on unique data subjects in the preceding calendar year, including current and former employees, customers, suppliers, and business partners. The CAC’s Data Export Facilitation Measures (January 2026) created pilot exemptions in select FTZs for non-personal, non-important data, potentially reducing the need for either route for qualifying data categories. Foreign companies operating in FTZs should monitor their zone’s implementation progress: as of July 2026, the Shanghai FTZ and Lingang pilot programs are most advanced, with published guidance on exempt data categories and registration procedures.
Where to Go From Here
Choosing between the CAC Security Assessment and SCC routes depends on your data profile, volume, industry, and growth trajectory. Conduct a thorough data classification audit and consult with PRC data compliance counsel to make the right choice.
- [guide: SLUG-TO-BE-FILLED] — Step-by-step guide to CAC security assessment preparation
- [comparison: SLUG-TO-BE-FILLED] — PIPL vs GDPR: which privacy law is stricter for foreign companies
- [tool: SLUG-TO-BE-FILLED] — Cross-border data transfer route selection tool for foreign firms
SCCs vs Security Assessment: Which Cross-Border Data Route for Your China Business? — first published on China Gateway 360. Last updated: July 2026.
