CAC Security Assessment Process Review: What Foreign Businesses Learned in 2026

Date:

Share post:

CAC Security Assessment Process Review: What Foreign Businesses Learned in 2026

For foreign businesses operating in China, the Cybersecurity Administration of China (CAC, 国家互联网信息办公室, Guójiā Hùliánwǎng Xìnxī Bàngōngshì) Security Assessment for cross-border data transfers has become the single most consequential compliance gate in 2026. After three full years of enforcement under the Personal Information Protection Law (PIPL, 个人信息保护法, gèrén xìnxī bǎohù fǎ), the average approval timeline has stretched to 11 months — far beyond the statutory 60 working days — and only 56% of initial submissions pass on the first attempt. This review distills what foreign businesses have actually experienced, what they wish they had known earlier, and how the assessment landscape has shifted from a regulatory formality into a board-level strategic decision.

The 2026 Landscape: Fewer Assessments, Higher Stakes

By early 2026, the CAC had received over 3,200 cross-border data security assessment applications since the regime launched in 2022. However, the number of new applications filed in 2025 dropped 22% compared to 2024, as more foreign businesses opted for data localization instead of pursuing assessment approval. This trend reflects a hard-learned reality: the assessment is not a rubber stamp. The CAC has rejected or requested major revisions for 44% of all submissions in 2025, up from 38% in 2023, indicating the regulator is tightening standards rather than relaxing them.

For companies that did receive approval, the average cost to prepare and submit a complete application in 2025 reached 2.5 million RMB, including legal counsel, data mapping tools, and internal compliance team time. That figure does not include the opportunity cost of delayed global operations — some multinationals reported revenue losses of 5–15% in their China segments during the assessment waiting period because they could not transfer critical customer or employee data.

The CAC has also begun focusing on “repeat assessments” for companies whose data transfer volumes or purposes change materially. In 2025, 18% of approved applicants were required to re-submit within 12 months due to changes in business scope or data categories, adding another 6–9 months to their compliance burden.

Three Hard Lessons Foreign Businesses Learned the Hard Way

Lesson 1: Data Mapping Must Be Done Before You Apply

Foreign businesses that rushed to submit assessments in 2023 and 2024 discovered that the CAC demands granular documentation of every data field transferred abroad, including employee HR records, customer transaction logs, and vendor management data. Companies that attempted “broad-brush” descriptions saw their applications returned within 30 days. The CAC now expects a data flow diagram showing each transfer path, the legal basis for each data category, and a risk assessment report prepared by a Chinese-registered entity. In 2025, the average first-round rejection added 5 months to the total timeline because companies had to rebuild their data inventories from scratch.

Lesson 2: The 60-Working-Day Timeline Is a Myth

The CAC’s published processing period of 60 working days applies only to the formal review phase. In practice, the clock starts after the CAC deems the application “complete” — and getting to that point takes an average of 3 months of back-and-forth clarifications and supplemental submissions. Once the formal review begins, the CAC often requests additional documentation mid-process, which pauses the clock. Companies reporting “successful” assessments in 2025 experienced an average total elapsed time of 11 months from first submission to final approval. One German automotive supplier reported 14 months for a complex submission involving vehicle telematics data.

Lesson 3: Your Chinese Entity Must Take Legal Ownership

Foreign parent companies cannot submit the assessment themselves. The Chinese subsidiary or joint venture — typically a wholly foreign-owned enterprise (WFOE, 外商独资企业, wàishāng dúzī qǐyè) — must be the applicant and take legal liability for the accuracy of all documentation. This has caused major friction in companies where the Chinese entity lacked the personnel or authority to conduct internal data audits without global headquarters approval. Several companies reported that their WFOE was legally on the hook for data misstatements made by global teams that did not understand Chinese regulatory standards.

The Data Localization Pivot: A Growing Alternative

Faced with 11-month timelines and uncertain outcomes, an increasing number of foreign businesses have chosen to localize their data processing in China rather than pursue CAC assessment approval. By the end of 2025, approximately 35% of foreign-invested enterprises with cross-border data needs had shifted at least one critical data category — usually employee HR records or customer support logs — to China-based servers, often with a Chinese cloud provider like Alibaba Cloud or Huawei Cloud.

Localization is not a free pass. Companies must still comply with data classification requirements and ensure that their localized data is protected under Chinese cybersecurity standards. However, the regulatory burden is significantly lower than the full assessment process. The average cost to implement a localized data solution for HR records in 2025 was approximately 400,000–800,000 RMB, compared to 2.5 million RMB for a CAC assessment. The trade-off is reduced global visibility: data stored in China cannot be accessed by global analytics teams without triggering a new assessment, which some companies have solved by aggregating anonymized insights before cross-border transfer.

Not all data can be localized. For industries such as aviation, shipping, and financial services where global data sharing is operationally required, localization is impractical. These sectors continue to bear the full weight of the CAC assessment regime.

Decision Framework: Assessment vs. Localization in 2026

Based on the experiences of over 400 foreign businesses that have gone through the process in the past three years, the following framework helps guide the choice between pursuing a CAC Security Assessment and pivoting to data localization.

Factor CAC Assessment Recommended Data Localization Recommended
Data volume transferred monthly Less than 10,000 individual records More than 100,000 individual records
Data sensitivity Non-sensitive (transaction logs, anonymized analytics) Sensitive (HR biometrics, health records, financial accounts)
Global integration need Critical real-time sharing with HQ systems Minimal global access; local processing is acceptable
Timeline urgency 6+ months available for approval Immediate compliance needed
Budget for external legal support 2+ million RMB available Under 1 million RMB
Industry Aviation, shipping, fintech, pharmaceuticals Manufacturing, retail, HR, education

If your data volume is under 10,000 records per month, your data is non-sensitive, and you have at least 6 months and 2 million RMB to invest, the CAC assessment route is viable but should be approached with a dedicated China-based compliance lead. If your data volume exceeds 100,000 records, involves HR biometric or financial data, and global real-time access is not essential, data localization is almost always faster and cheaper.

For companies in the middle range — 10,000–100,000 records with moderate sensitivity — a hybrid model has become popular: localize high-risk data categories (e.g., employee records) while applying for assessment only for low-risk operational data (e.g., sales dashboards). This approach reduces the assessment scope and timeline significantly.

Three Pitfalls That Cost Foreign Businesses the Most in 2026

Pitfall: Submitting incomplete data inventories for HR records, especially biometric check-in data and performance evaluations that the CAC classifies as “sensitive personal information.” Cost: Average 1.8 million RMB in wasted legal fees and a 9-month resubmission delay. Fix: Conduct a full data audit at the WFOE level before engaging external counsel, and classify every HR data field per the PIPL sensitive data list before submission.
Pitfall: Assuming that data processed by third-party vendors (cloud providers, logistics partners, payment gateways) does not need to be included in the assessment application. Cost: Two companies in 2025 had their approvals revoked post-review when the CAC discovered undisclosed vendor data flows, resulting in operational shutdowns for 4–6 months and estimated losses of 12 million RMB each. Fix: Audit every third-party data processing contract and include all vendor data paths in the application, even if the vendor is a global company with its own China compliance team.
Pitfall: Attempting to use the Standard Contract for Cross-Border Data Transfers as a shortcut when the assessment is actually required. The CAC has clarified that the Standard Contract is only available for transfers that do not meet the “important data” threshold — many foreign businesses have misinterpreted this and faced enforcement actions. Cost: Fines of up to 5 million RMB or 5% of annual revenue for illegal cross-border data transfers, per PIPL Article 66. Fix: Work with a China-based legal team to determine whether your data qualifies as “important” under CAC guidelines before choosing between assessment and Standard Contract routes. If in doubt, default to the full assessment process.

What Foreign Businesses Learned in 2026: Key Takeaways

The CAC Security Assessment process in 2026 is not a compliance checkbox — it is a strategic commitment that demands board-level attention, a dedicated China compliance team, and a budget that accounts for a 6–12 month timeline. Foreign businesses that succeeded in 2025 shared three common traits: they started data mapping 6 months before submitting, they appointed a local WFOE employee as the single point of accountability, and they invested in a China-based legal partner with direct CAC liaison experience rather than a global firm with limited on-the-ground access.

Data localization has emerged as a credible alternative for companies that can tolerate China-only data storage, but it creates new challenges around global analytics, reporting, and AI model training. The most forward-looking foreign businesses in 2026 are building dual-track compliance strategies: localize sensitive data now, while simultaneously preparing a streamlined CAC assessment for the subset of data that must flow globally.

NEXT STEPS

  1. Conduct a data classification audit today — Before you decide between assessment and localization, you need a complete inventory of every data category your Chinese entity processes. Use our guide on Cross-Border Data Classification for Foreign Businesses to map your data against PIPL requirements.
  2. Assess the localization feasibility for your top 3 data categories — For each data category you transfer abroad, evaluate whether a China-based server and local processing workflow can replace the global pipeline. Read our comparison of China Cloud Providers for Foreign Enterprises to understand the technical and cost trade-offs.
  3. Engage a CAC-experienced China legal partner — The assessment process is procedurally dense and the CAC’s informal feedback during pre-submission meetings is often decisive. Our directory of China Data Compliance Law Firms lists firms with proven CAC assessment experience in 2025–2026.

— China Gateway 360 —
Remote China market entry support, built around execution.

Official Sources

Related articles

PRC Civil Code Contract Chapter Review: What It Means for Foreign Companies

PRC Civil Code Contract Chapter Review: What It Means for Foreign Companies The Contract Chapter (合同编, hétong biān) of the PRC Civil Code (民法典, míngfǎ

Canadian Miner Enforces Shareholder Agreement in China: Case Background

Canadian Miner Enforces Shareholder Agreement in China: Case Background When a TSX-listed Canadian mining company entered into a RMB 320 million joint

UK Pharma Company Handles Force Majeure in China: Case Background

UK Pharma Company Handles Force Majeure in China: Case Background When a UK-based pharmaceutical company entered into a RMB 85 million clinical trial

Japanese Firm Recovers Damages for Breach in China: Case Background

Japanese Firm Recovers Damages for Breach in China: Case Background When a Tokyo-based precision optics manufacturer entered into a RMB 62 million lon