Information date: 2 September 2026 — China’s Network Data Security Risk Assessment Measures took effect on 20 August 2026. They turn risk assessment into an evidence-governance process: an organisation must define the assessed object, preserve truthful materials, manage any commissioned assessor and respond to remediation requirements. A spreadsheet can coordinate the work, but it cannot replace technical testing or a competent legal assessment.
Start with the verified fact
The CAC measures sit alongside the Network Data Security Management Regulations. The measures require an entrusted assessment agreement to define rights and obligations. An assessment report is signed by the responsible person of the institution and the assessment leader and carries the institution’s seal. The rules prohibit requesting a false or improper report.
Where a competent authority requires remediation, the measures state that the organisation reports the remediation status within 15 working days after completing it. This is not a universal 15-day deadline to finish every correction. The trigger, competent authority and exact requirement must be read from the applicable notice and current rules.
How the mechanism reaches an operating decision
Scope errors undermine the whole exercise. If the asset list excludes a production database, vendor connection or mobile application, later testing cannot support an enterprise-wide conclusion. If every system is included without prioritisation, the project can become too broad to finish. The tool should connect business process, data category, system, interface, processor, location, control, evidence and unresolved risk.
Commissioning an external institution does not transfer the company’s accountability for truthful input or remediation. Contracts need confidentiality, data minimisation, permitted access, workpapers, incident handling and independence. The business owner must still decide whether a high-risk process can continue while a control gap remains.
Choose whether to proceed, redesign or pause
Assess first the systems that process important, sensitive or high-volume personal information, support critical operations, expose external interfaces or have undergone a material change. Use a targeted update when only one integration changes and prior evidence remains valid. Use a broader assessment when architecture, data purpose, controller responsibility or the threat model has changed substantially.
Proceed with operation when residual risk is accepted by the authorised owner and required remediation is complete or properly controlled. Restrict or pause an activity when evidence is missing for a high-impact path, a required control has failed, or a regulator’s direction has not been satisfied.
Turn the decision into an evidence file
- Create a scope register with business process, system owner, data type, volume, location, interfaces and applicable regulatory trigger.
- Link each control to a named test, sample, date, tester and retained evidence; do not mark a policy as proof of technical operation.
- For an external assessment, define access, confidentiality, independence, workpapers, report ownership and correction handling in the agreement.
- Record every finding with impact, root cause, corrective owner, due date, validation method and operational restriction.
- If remediation reporting is required, retain completion and validation evidence and calculate the authority-facing deadline from the actual completion date.
- Approve the final report through the required responsible persons and update only affected rows after a contained system change.
Run one proportionate review
For China network-data risk assessment tool, review the items that could change the commercial conclusion: the current primary source, the applicable entity and date, the owner of each open task, and the evidence required before money or customer commitments become irreversible. A wording preference is not a control failure. Correct a draft only when a factual error, unsupported claim, missing source, unsuitable taxonomy or unusable action would mislead the reader.
For China network-data risk assessment tool, keep a compact record of the source URL, access date, assumptions, responsible person and next review trigger. When a rule, product or market figure changes, update the affected row and decision instead of rebuilding evidence that remains valid. This preserves traceability while keeping the process economical.
Boundary of the conclusion
This tool does not decide whether a particular company must conduct or submit a risk assessment, nor does it classify data. Those conclusions require the current Chinese rules, regulator directions and system facts. Sector and cross-border-data requirements may add separate assessments or filings.
Security assessment is not a guarantee that an incident will not occur. Continuous monitoring, access control, vulnerability management, vendor governance and incident response remain necessary after the report is signed.
