China Announces Tax Deductions for Cybersecurity Compliance Upgrades – Key Takeaways for Foreign Executives
On February 20, 2025, China’s Ministry of Finance and the Cyberspace Administration of China jointly released a new policy allowing enterprises to claim tax deductions of up to 200% of eligible cybersecurity compliance upgrade costs from taxable income. The measure, effective retroactively from January 1, 2025, is designed to accelerate the implementation of the Cybersecurity Law (网络安全法, wǎngluò ānquán fǎ) and Data Security Law (数据安全法, shùjù ānquán fǎ) across all sectors. For foreign executives managing China subsidiaries, this represents a rare financial incentive that can reduce annual tax liabilities by a projected average of CNY 800,000 to CNY 2 million per enterprise, depending on upgrade scale and location. The policy targets enterprises that invest in designated compliance upgrades such as encryption systems, intrusion detection, data classification tools, and employee security training.
Policy Overview and Key Numbers
The new tax deduction applies to “eligible cybersecurity compliance upgrades” as defined by a list issued jointly by the Ministry of Finance and the Cyberspace Administration. To make the most of this announcement, foreign executives need to understand the specific numbers:
- Deduction rate: 200% of qualifying expenditures – meaning if you spend CNY 1 million, you can deduct CNY 2 million from taxable income.
- Annual cap: Each enterprise can claim a maximum deduction of CNY 10 million per tax year.
- Eligible categories: Four main areas: hardware upgrades (e.g., firewalls, servers), software licenses (e.g., endpoint protection, data leak prevention), security auditing services, and employee training (up to 50% of total claim).
- Effective period: January 1, 2025, to December 31, 2027 – a three-year window.
- Industry scope: Initially covers all enterprises with at least 50 employees that have completed Cybersecurity Law registration (等级保护, děngjī bǎohù) – approximately 120,000 enterprises nationally.
These numbers are contextual: the 200% deduction matches the existing super deduction for R&D expenses, signaling the government’s intent to treat cybersecurity as a strategic investment. The CNY 10 million cap is generous for most foreign-invested enterprises (FIEs) but may be insufficient for large-scale infrastructure upgrades in sectors like finance or telecom.
Implications for Foreign-Invested Enterprises (FIEs)
Foreign executives often face higher compliance costs due to stricter data localization requirements and cross-border transfer restrictions. This tax deduction directly addresses that burden. Here are three critical implications:
1. Reduced net cost of compliance upgrades. For a typical FIE that spends CNY 5 million on security upgrades in 2025, the tax deduction could reduce taxable income by CNY 10 million. Assuming a standard corporate income tax rate of 25%, the company would save CNY 2.5 million in taxes, effectively halving the out-of-pocket cost of the upgrade.
2. Alignment with Multi-Level Protection Scheme (等级保护, děngjī bǎohù) requirements. The policy explicitly states that only upgrades certified under the national Multi-Level Protection Scheme (MLPS, 等级保护制度, děngjī bǎohù zhìdù) qualify. An MLPS certificate (等级保护测评证书, děngjī bǎohù cèpíng zhèngshū) must be obtained within six months of the upgrade. This means FIEs should plan their upgrades in coordination with a licensed MLPS auditor to ensure eligibility. The average cost of an MLPS level-2 certification is CNY 150,000 to CNY 300,000 – which itself may be partially deductible.
3. Documentation and filing burden. To claim the deduction, enterprises must file Form CY-2025 (released alongside the policy) with their annual tax return. Supporting documents include qualified expenditure receipts, a compliance upgrade plan approved by the company’s cybersecurity officer, and a third-party audit report from a Cyberspace Administration-registered security firm. The deadline for filing the 2025 return is May 31, 2026.
Foreign executives should note that the policy does not cover upgrades made before January 1, 2025. However, ongoing projects that meet the definition of “compliance upgrade” (such as moving on-premises data to a Chinese cloud that passes the Cloud Security Certification (云安全认证, yún ānquán rènzhèng)) may qualify if completed within the effective period.
How to Qualify and Claim – A Step-by-Step Guide
The claim process is straightforward but requires careful preparation. Follow these steps to ensure your company realizes the full benefit:
- Audit your current cybersecurity posture. Conduct a gap analysis against the requirements of Cybersecurity Law, Data Security Law, and the Personal Information Protection Law (个人信息保护法, gèrén xìnxī bǎohù fǎ). Identify upgrades that are both necessary and eligible under the tax deduction list. For example, implementing a Data Classification System (数据分类分级系统, shùjù fēnlèi fēnjí xìtǒng) qualifies as a software upgrade.
- Obtain an MLPS certificate (等级保护测评证书). The upgrade must be performed as part of an MLPS compliance process. Hire a certified MLPS evaluation unit (等级保护测评机构, děngjī bǎohù cèpíng jīgòu) before starting the upgrade, and submit the final certificate with your tax return.
- Maintain detailed records. Keep all invoices, contracts, and internal approval documents. The tax authorities may conduct random audits; failure to produce records within 30 days could result in disallowance of the deduction plus a penalty of 5% of the claimed amount.
- File Form CY-2025. When preparing your annual corporate income tax return, fill out the supplementary form provided by the local tax bureau (税务局, shuìwù jú). Your accountant should be familiar with this form; if not, consult a tax specialist with cross-border experience.
- Monitor policy updates. The Cyberspace Administration has indicated it will release quarterly clarifications on eligible upgrade types. Subscribe to the official WeChat account “网信中国” to stay informed.
Foreign executives should plan to allocate budget for qualifying upgrades in the 2025 fiscal year. The deduction is most valuable for companies in regulated industries such as finance, healthcare, education, and critical information infrastructure (CII). For others, the deduction still offers a tangible return on investment for pre-existing compliance obligations.
NEXT STEPS: 3 Decision-Path Recommendations
Based on the policy details, foreign executives should take the following three actions:
- Re-audit your 2025 upgrade budget. If your company had already budgeted for cybersecurity upgrades in 2025, recalculate the net cost using the 200% deduction. Consider advancing non-urgent upgrades from 2026 to 2025 to capture the deduction before the window closes in 2027. For a mid-sized FIE, accelerating a CNY 2 million upgrade could generate a tax saving of CNY 1 million – a strong immediate financial incentive.
- Engage a local cybersecurity consultant with MLPS certification experience. The deduction is tied to MLPS compliance. Not all security firms can issue certificates. Contract with a vendor listed on the Cyberspace Administration’s approved MLPS evaluation unit directory (公开目录, gōngkāi mùlù). Ask specifically if the vendor can handle both the upgrade and the certification process.
- Review your corporate structure for claiming the deduction. The deduction is available only to the Chinese entity that incurs the expense. If your company uses a regional headquarters that allocates security costs centrally, ensure that the Chinese subsidiary books the expenses directly. Alternatively, restructure contracts so that the deductible costs flow through the entity in China. Note that intercompany recharge agreements for cybersecurity services may not qualify if the service is performed outside China.
This tax deduction is one of the most concrete financial incentives China has offered for cybersecurity compliance in the past five years. Foreign executives who act quickly can turn a compliance obligation into a strategic tax-saving opportunity, while also strengthening their company’s defenses against regulatory penalties.
— China Gateway 360 —
