Industrial Internet & IoV · 工业互联网与车联网.
12 entries. The MIIT-led layer for industry and connected vehicles — the three-tier industrial-data classification, risk-assessment and incident-response rules, the automotive data-security and data-export regime, internet data centers, and live-streaming commerce — stacked on top of the general regime.
Reference Handbooks .
权威实务手册 · institutional handbooks and joint guides
- § 01 · CESI Industrial DSRA Service Certification Rules
Certification Rules for Data Security Risk Assessment Services in the Industry and Information Technology Sector (V1.2, CESI-SC-OD15)
工业和信息化领域数据安全风险评估服务认证规则(V1.2,CESI-SC-OD15)
Issued by Beijing CESI Certification Co., Ltd. — the certification arm of the China Electronics Standardization Institute — as rule CESI-SC-OD15, first in April 2023 and re-issued as V1.2 on May 18, 2026 to meet CNCA's 2025–2026 rules on certification-rule management and service certification, this document sets out how third-party assessors become certified to conduct data security risk assessments for MIIT-regulated enterprises. It is a service-certification scheme in CNCA field SC12, assessed against CESI/TS SC003-2023 (the technical specification for industrial and IT-sector risk-assessment services) and the two MIIT industry standards for risk assessment, YD/T 6415-2025 (industrial) and YD/T 3956-2024 (telecommunications). Certification combines three modes — inspection of past service records (mode F), confirmation or verification of service capability by observing a live assessment at a client site (mode G), and a service-management audit (mode I) — with a sample size equal to the square root of the assessor's client sites in the previous year, one-fifth of which are observed on site. Initial certification requires at least six on-site and twelve total auditor-days; annual surveillance at least three and four; certificates run three years, and no auditor may audit the same assessor for five consecutive years. The rules detail application conditions, the site-audit process with opening and closing meetings, grounds for termination, a ten-working-day certification decision, surveillance triggers (regulatory findings, security incidents attributed to the assessor, client complaints), change, expansion and reduction of scope, suspension for three months and revocation, complaints and appeals, mark usage, and fees (RMB 2,000 registration, RMB 2,000 annual, RMB 5,000 per auditor-day). For enterprises choosing an assessor under MIIT's mandatory risk-assessment rules, the CESI certificate is one of the few public quality signals.
Departmental Rules .
部门规章 · CAC, MIIT, MPS and others
- § 01 · ICS Cybersecurity Protection Guide
Guide to Cybersecurity Protection for Industrial Control Systems
工业控制系统网络安全防护指南
Issued by the Ministry of Industry and Information Technology on January 19, 2024 as 工信部网安〔2024〕14号 (Gong Xin Bu Wang An [2024] No. 14), this Guide is the successor to MIIT's 2016 Guide to Information Security Protection for Industrial Control Systems and the baseline that every enterprise using or operating PLC, DCS, SCADA and similar systems in China is expected to meet. Its 33 numbered items are grouped into security management (asset lists, configuration baselines, supplier contracts, certified critical network equipment, training), technical protection (host hardening, zoned network architecture, restricted remote access, cloud migration, application testing, and a system-data-security section that imports the important-data and core-data classification together with the domestic-storage and export-assessment rules), security operations (monitoring, honeypots, operations centers, incident plans, six-month log retention, annual protection-capability assessments, vulnerability management) and responsibility. It is a guide rather than a rule carrying its own penalties, but MIIT inspections, the critical information infrastructure regime and the 2022 Industrial Data Security Measures treat it as the reference standard. Overseas counsel advising manufacturers, OT vendors or cloud providers in China will find here the concrete controls behind ICS security (工控安全) obligations.
- § 02 · Industrial Data Classification and Grading Guide
Guide to the Classification and Grading of Industrial Data (Trial)
工业数据分类分级指南(试行)
Issued by the General Office of the Ministry of Industry and Information Technology on February 27, 2020 as 工信厅信发〔2020〕6号 (Gong Xin Ting Xin Fa [2020] No. 6), this trial Guide was the first MIIT instrument to tell industrial enterprises and Industrial Internet platform enterprises how to sort their data into categories and grade it by consequence. It defines industrial data as lifecycle data from research and development, production, operations and maintenance, management and platform operation, and grades it into three levels (一级/二级/三级) according to the potential impact of tampering, destruction, leakage or illegal use on production safety, economic loss, cascading effects and recovery cost, with Level 3 data subject to the strictest protection, sharing and reporting duties. This impact-based three-tier scheme is the origin of the industrial-data grading that MIIT carried into the 2022 Administrative Measures for Data Security in the Field of Industry and Information Technology, where the three levels were re-labelled general, important and core data and anchored to the Data Security Law; the Level 1 criteria here reappear almost verbatim as the general-data criteria in the Measures. For overseas counsel, the Guide explains the pedigree of the classification lists that MIIT-regulated suppliers and joint ventures still maintain.
- § 03 · Industrial Data Security Capability Plan
Implementation Plan for Enhancing Data Security Capabilities in the Industrial Sector (2024–2026)
工业领域数据安全能力提升实施方案(2024-2026年)
Issued by the Ministry of Industry and Information Technology in February 2024 (工信部网安〔2024〕18号), this three-year action plan is the roadmap for how MIIT operationalizes the 2022 Industrial and Information Technology Data Security Measures across manufacturing. It sets five numeric targets for end-2026: full coverage of data-security requirements for above-scale industrial enterprises; more than 45,000 enterprises conducting classified and graded protection, including at least the top-10% by revenue in each province; at least 100 standards initiated; at least 200 typical cases across 10 or more industries; and 30,000 training places with 5,000 trained industrial data-security specialists. Eleven tasks are grouped under three capabilities. For enterprises: awareness and accountability of legal representatives, important-data and core-data cataloguing and filing with annual risk assessments, a rolling roster of key enterprises subject to intensified supervision, and scenario-specific protection for aggregation, sharing, export and outsourced processing. For regulators: a '1+N' industrial classification-and-grading standard system with sector-specific important-data identification rules, sector data-export security guidelines, an MIIT data-security management platform covering 20 provincial and 500 enterprise nodes, the 'Data Security Escort' inspection campaign and 'Data Security Shield' drills, and a stronger enforcement corps. For industry: encryption, privacy-computing and anti-ransomware products, pilots, and a talent pipeline. For foreign manufacturers in China, the Plan explains why MIIT provincial bureaus are now asking for important-data catalogues and annual assessment reports, and signals the sector-by-sector data-export guidelines — the automotive one was the first — that follow from it.
- § 04 · Industrial Data Security Measures
Administrative Measures for Data Security in the Field of Industry and Information Technology (Trial)
工业和信息化领域数据安全管理办法(试行)
These Measures are the principal sector-specific framework implementing the Data Security Law within the industry, telecommunications and radio-spectrum fields administered by MIIT. They establish a three-tier data classification (general / important / core data), filing of important- and core-data catalogues, full-lifecycle security obligations, cross-border transfer controls, monitoring and incident-response duties, and a testing/certification/assessment regime. Issued as MIIT Cyber Security [2022] No. 166 and effective January 1, 2023.
- § 05
Implementing Rules for Data Security Risk Assessment in the Field of Industry and Information Technology (Trial)
工业和信息化领域数据安全风险评估实施细则(试行)
These Implementing Rules operationalize the annual risk-assessment obligation imposed on processors of important data and core data by the MIIT Industrial Data Security Measures. They prescribe the assessment scope, the eight mandatory assessment focus areas, the once-a-year cadence and one-year validity of results, triggering events for re-assessment, requirements for in-house or third-party assessment teams, reporting timelines to local regulators, and the duties and capability-certification regime for third-party assessment institutions. Issued as MIIT Cyber Security [2024] No. 82 and effective June 1, 2024.
- § 06
Emergency Response Plan for Data Security Incidents in the Field of Industry and Information Technology (Trial)
工业和信息化领域数据安全事件应急预案(试行)
This Emergency Response Plan, issued as MIIT Cyber Security [2024] No. 214, establishes the incident-response framework for data security incidents in the industry, telecommunications and radio fields. It grades incidents into four levels (especially significant, significant, relatively significant, and general), sets out the organizational structure, monitoring and early-warning, reporting timelines, graded response measures and post-incident handling, and defines how MIIT and local industry regulators coordinate with data processors. The page below translates the issuing notice in full; the annexed plan text was distributed as a separate attachment and is summarized rather than reproduced article-by-article.
- § 07
Notice of the Ministry of Industry and Information Technology on Strengthening the Cybersecurity and Data Security of the Internet of Vehicles
工业和信息化部关于加强车联网网络安全和数据安全工作的通知
This Notice sets out MIIT's consolidated cybersecurity and data security requirements for the Internet of Vehicles (IoV) ecosystem, covering intelligent connected vehicle manufacturers, IoV service-platform operators and related parties. It addresses vehicle network security, vulnerability management, IoV network and communications security, monitoring and emergency response, MLPS grading and filing, platform security, OTA upgrade security, data classification and grading, data security technical safeguards, and cross-border data transfer. Issued as MIIT Cyber Security [2021] No. 134 and effective September 15, 2021.
- § 08 · Automotive Data Provisions
Several Provisions on Automotive Data Security Management (Trial)
汽车数据安全管理若干规定(试行)
These Provisions are the foundational rule governing the processing of automotive data — both personal information and important data arising in the design, production, sale, use and maintenance of vehicles. They define automotive data, personal/sensitive personal information and important data (including a list of important-data categories), set out processing principles (in-vehicle processing, default no-collection, precision-range applicability, anonymization), notice-and-consent requirements, important-data risk assessment and annual reporting, and domestic storage with security assessment for cross-border transfer. Jointly issued by the CAC, NDRC, MIIT, MPS and MOT as Order No. 7 and effective October 1, 2021.
- § 09
Administrative Measures for the Supervision of Live-Streaming E-Commerce
直播电商监督管理办法
These Measures establish the supervisory framework for live-streaming e-commerce in China, allocating obligations among platform operators, live-streaming-room operators, live-streaming marketing personnel and their service agencies. They impose real-identity verification and registration, periodic reporting of identity information to market-regulation authorities, graded and classified management, transaction-information retention of at least three years, prohibitions on false or misleading commercial publicity (including via AI), AI-generated-persona labeling, and consumer-rights and credit-supervision mechanisms. Jointly issued by the State Administration for Market Regulation and the Cyberspace Administration of China as Order No. 117 and effective February 1, 2026.
National Standards .
国家标准 · GB/T, TC260
- § 01
Guidelines for the Security of Automotive Data Export (2026 Edition)
汽车数据出境安全指引(2026版)
These Guidelines give automotive data processors a practical, scenario-based roadmap for lawfully exporting automotive data under the Data Security Law, PIPL and the Network Data Security Management Regulation. They define what counts as a data-export act, set out the quantitative thresholds that trigger a security assessment, standard contract or certification (and the exemptions), provide a detailed important-data determination catalogue across six business scenarios, describe the end-to-end export procedure, and impose management, technical-protection, logging and emergency-response requirements. The important-data determination tables are rendered below as structured prose by scenario rather than reproduced cell-by-cell.
- § 02
Implementing Guidelines for the Protection of Customer Data Security in Internet Data Centers
互联网数据中心客户数据安全保护实施指引
Issued as MIIT General Office Cyber Security [2025] No. 5, this instrument comprises a notice and an annexed implementing guideline directing Internet Data Center (IDC) operators to strengthen the security of customer data they host. It follows the principle of consistent rights and responsibilities, classified strategy, combined management-and-technology, and ensured security, and sets out general safeguard capabilities (responsibility boundaries, access/operation/destruction/isolation controls, incident response, and security-service provision) plus scenario-specific requirements for server-hosting and for data-storage-and-computing (including AI training-data and computing-power-scheduling security). Both the notice and the annexed guideline are translated in full below.