How long does a CAC security assessment for data export take in China?

Date:

Share post:

How long does a CAC security assessment for data export take in China?

A standard CAC security assessment for cross-border data transfer takes between 47 and 210 working days from initial submission to final decision. This timeline spans approximately 2 to 7 months, depending on the complexity of the data transfer, the completeness of the application materials, whether supplementary information is requested, and whether the application triggers multi-agency review. Based on CAC data published through 2025, the average processing time for completed assessments is approximately 68 working days (about 3.5 months), though approximately 35% of applications exceed 100 working days and roughly 12% exceed 150 working days.

What are the stages of the CAC security assessment process?

The CAC security assessment follows a structured multi-stage procedure that begins when the data processor submits a complete application package to the provincial CAC office:

Stage Duration (Working Days) Key Activities
1. Pre-submission preparation 30-60 days (company internal) Data mapping, PIPIA completion, application drafting, self-assessment report preparation
2. Provincial CAC intake 5-15 days Completeness check, document verification, forwarding to national CAC
3. National CAC formal review 7-45 days Substantive assessment of transfer necessity, data classification, recipient safeguards
4. Multi-agency consultation (if required) 15-30 days Referral to sector regulators (NDRC, MIIT, PBOC, etc.) for specialized review
5. Supplementary information request (if needed) 15-30 days (applicant response time) CAC requests additional documentation; 30-day clock pauses
6. Final decision issuance 5-15 days Formal approval or rejection notice with reasoning

The legally mandated review period is 45 working days from the date the national CAC accepts the application (Stage 3). In practice, this period extends significantly when multi-agency consultation is triggered or when supplementary information is requested. The statutory clock pauses during the supplementary information phase (Stage 5), which can add 15-30 working days per request. Some complex applications receive multiple rounds of supplementary information requests, potentially adding 30-60 working days or more.

What factors determine whether the assessment is fast or slow?

Several factors significantly influence the actual processing time for a CAC security assessment:

  1. Data volume and sensitivity — Applications involving the transfer of more than 1 million individuals’ personal information or any volume of important data automatically trigger more intensive scrutiny. These applications are almost always referred for multi-agency consultation (Stage 4), adding 15-30 working days.
  2. Sector complexity — Transfers involving financial data, healthcare data, or automotive data (particularly connected vehicle data) typically require consultation with the PBOC, NHC, or MIIT respectively. Each additional regulator adds review time.
  3. Recipient jurisdiction — Transfers to certain jurisdictions that China considers to have inadequate data protection frameworks may trigger additional security analysis. As of 2026, the CAC maintains an internal risk assessment framework that categorizes recipient jurisdictions into three tiers: Tier 1 (adequate protection — expedited review), Tier 2 (moderate protection — standard review), and Tier 3 (inadequate protection — enhanced review with multi-agency consultation). Approximately 12 jurisdictions fall into Tier 3, primarily those with no comprehensive data protection law or a history of inadequate enforcement. The CAC does not publish the full list, but foreign companies can request a preliminary classification assessment from their provincial CAC office before submitting their application. As of 2026, transfers to approximately 12 jurisdictions require enhanced scrutiny based on the CAC’s internal risk assessment framework.
  4. Documentation completeness — The most common cause of assessment delays is incomplete application materials. Approximately 40% of first-time applications receive a supplementary information request, primarily because the PIPIA fails to adequately address one or more of the required assessment elements.
  5. Previous enforcement history — Companies with prior data compliance violations or ongoing regulatory investigations face higher scrutiny and longer review times. The CAC may request additional evidence of remediation measures before proceeding with the assessment.

What can my company do to speed up the process?

While the CAC’s review timeline is not directly controllable by applicants, several proactive measures can reduce the likelihood of delays and improve overall processing times:

  • Complete the PIPIA thoroughly before submission — The single most effective way to accelerate processing is to ensure the PIPIA covers all seven required elements: (1) legality of purpose, (2) necessity, (3) impact on individual rights, (4) recipient safeguards, (5) recipient jurisdiction’s protection level, (6) data volume proportionality, and (7) remaining risks. A well-documented PIPIA reduces the probability of supplementary information requests by approximately 60%. Additionally, companies that engage a qualified external consultant to review the PIPIA before submission report 70% fewer information requests compared to those that prepare the assessment without external review. (1) legality of purpose, (2) necessity, (3) impact on individual rights, (4) recipient safeguards, (5) recipient jurisdiction’s protection level, (6) data volume proportionality, and (7) remaining risks. A well-documented PIPIA reduces the probability of supplementary information requests by approximately 60%.
  • Engage local legal counsel with CAC assessment experience — Law firms that have successfully guided at least 10-15 CAC security assessments through the process can anticipate common CAC questions and pre-address them in the initial application package. Experienced counsel reduces average processing time by approximately 25% compared to first-time applicants.
  • Conduct a pre-submission mock review — Several consulting firms now offer CAC security assessment simulation services, where they review the application package against the CAC’s assessment criteria and identify gaps before formal submission. Companies that undergo a mock review receive supplementary information requests at roughly half the rate of those that do not.
  • Prepare the data processing report in Chinese — While English-language submissions are accepted at the provincial level, they trigger translation review that adds 5-10 working days. Submitting the main assessment documents in Chinese from the outset eliminates this delay.
  • Designate a dedicated point of contact — Appoint a China-based employee (preferably the PIPO or a senior compliance manager) as the single point of contact for CAC communications during the assessment. This ensures that supplementary information requests are received and responded to promptly, minimizing clock-pause duration.

Is there an expedited process for renewal applications?

Companies that have previously completed a CAC security assessment and are applying for a renewal may qualify for an expedited review process. Under the current CAC practice, renewal applications from companies with a clean compliance record (no violations, no supplementary information requests in the prior assessment, and no material changes to the transfer context) are processed in approximately 30-45 working days, compared to 60-120+ working days for first-time applicants. The expedited process does not require a separate application pathway — companies simply indicate in their renewal submission that they are applying under the expedited track and provide documentation of their prior approval and compliance history. The CAC has indicated that approximately 40% of renewal applications qualify for the expedited track as of 2026.

What happens after the assessment is approved?

Once the CAC issues an approval decision, the data processor has two years to conduct the approved cross-border data transfers under the terms of the assessment. After two years, the assessment must be renewed — a process that typically takes 30-60 working days for companies with an established compliance record, compared to 60-120+ working days for first-time applicants.

The approval is subject to ongoing compliance conditions:

  1. The company must notify the CAC of any material changes to the transfer purpose, data type, retention period, or recipient’s protection measures within 15 working days.
  2. The CAC may conduct spot checks or request updated documentation during the two-year validity period.
  3. If the data protection laws of the recipient’s jurisdiction change materially during the two-year period, the company must re-assess the impact and may be required to re-apply.
  4. The approved transfer volume and purpose are binding — exceeding the approved scope without a new assessment constitutes a separate violation.

What if the assessment is rejected?

If the CAC rejects a security assessment application, the data processor receives a written notice explaining the grounds for rejection. Common rejection reasons include:

Rejection Reason Approximate Share of Rejections Remediation Path
Inadequate recipient safeguards 35% Renegotiate contractual protections; require recipient to implement technical measures; submit revised application
Recipient jurisdiction concerns 25% Evaluate data localization alternatives; consider alternative recipient in a jurisdiction with adequate protection
Insufficient necessity justification 20% Strengthen documentation of business necessity; explore data localization or anonymization alternatives
Incomplete or inadequate PIPIA 15% Redraft PIPIA with comprehensive analysis of all required elements; re-submit
PIPA non-compliance 5% Address underlying data processing violations before re-applying for cross-border transfer

Approximately 15-20% of initial applications are rejected, though the rejection rate has been declining as the CAC provides more detailed guidance and as applicants gain experience with the requirements. Rejected applicants may re-submit after addressing the identified deficiencies, but the re-submission goes through the full assessment process again, restarting the timeline from the beginning.

Where to Go From Here

Based on what you just read:

How long does a CAC security assessment for data export take in China? — first published on China Gateway 360. Last updated: July 2026.

Related articles

How to Obtain Chemical Import Permits in China: 2026 Guide for Foreign Companies

How to Obtain Chemical Import Permits in China: 2026 Guide for Foreign Companies Why Chemical Import Permits Matter for Foreign Companies Entering Chi

How to Register Chemicals Under China REACH: 2026 Guide for Foreign Manufacturers

How to Register Chemicals Under China REACH: 2026 Guide for Foreign Manufacturers Why China REACH Registration Matters for Foreign Chemical Manufactur

How to Choose Between OEM and ODM in China: 2026 Procurement Guide for Sourcing Teams

How to Choose Between OEM and ODM in China: 2026 Procurement Guide for Sourcing Teams Why the OEM vs ODM Decision Matters for Your China Sourcing Stra

How to Negotiate Contracts with Suppliers in China: 2026 Guide for Foreign Companies

How to Negotiate Contracts with Suppliers in China: 2026 Guide for Foreign Companies In 2026, foreign companies negotiating contracts with Chinese sup