China Cybersecurity Incident Reporting and the Four-Hour Deadline
China's incident reporting rules give most companies four hours from discovery to file. What a report must contain and how to be ready to meet the deadline.
August 13, 2026 · 14 min read

China now runs one of the strictest cybersecurity incident reporting regimes in the world, and the clock is measured in hours.
The Cyberspace Administration of China (CAC) issued the Administrative Measures for National Cybersecurity Incident Reporting on 11 September 2025, together with a Cybersecurity Incident Grading Guide. They took effect on 1 November 2025, and a dedicated online platform is available for submitting reports.
The Measures do not create an entirely new obligation. Reporting duties already existed under the Cybersecurity Law, the Data Security Law, the Personal Information Protection Law and the critical information infrastructure rules. What the Measures do is make the procedure concrete: who reports, to whom, within how long, and with what content. For most foreign-invested companies operating networks or providing online services in China, that means a four-hour deadline they are not currently built to meet.
Who the rules apply to
The Measures apply to network operators that build, operate or provide services through networks within the territory of China. That phrase is broader than it sounds.
It is not limited to technology companies. A manufacturer running an ERP system and a customer database, a retailer operating a WeChat mini-programme and a membership scheme, a services firm holding employee and client personal information, all fall within scope. Domestic and foreign companies are treated alike.
There is also a supply chain dimension. The Measures require network operators to contractually oblige third parties providing cybersecurity, system operation and maintenance or similar services to report incidents they detect promptly to the operator, and to assist the operator in meeting its own reporting duties. If your IT operations are outsourced, your contracts need this clause.
Four tiers of severity
Incidents are graded into four tiers based on their impact on national security, social order, economic activity and the public interest: general, relatively severe, severe and particularly severe. Grading follows the national standard referenced in the accompanying guide.
The stringent timelines attach to incidents graded relatively severe and above. An incident may be relatively severe where it involves the loss, theft, tampering or falsification of important data, or of a large volume of personal information, in a way that poses a serious threat to national security and social stability.
Whether general incidents must be reported is not stated explicitly, and that ambiguity has not been fully resolved. The prudent working assumption is to grade every incident, document the reasoning, and report where the assessment reaches relatively severe or is genuinely borderline.
The reporting deadlines
The deadline depends on what kind of operator you are.
Operators of critical information infrastructure report to their protection authority and to the public security authorities within one hour. Where the incident is severe or particularly severe, the receiving authority escalates immediately and no later than thirty minutes.
Network operators that are central or state organs or their directly subordinate units report to the relevant agency's cyberspace body within two hours.
All other network operators, which covers the great majority of foreign-invested companies, report to the provincial-level cyberspace administration department where they are located promptly and no later than four hours. For severe and particularly severe incidents, that provincial department escalates to the CAC immediately and within one hour, notifying relevant departments at the same level.
Four hours is the number that matters for most readers. It runs from discovery, not from the completion of your internal investigation, and it does not pause for time zones, weekends or a group approval chain routed through European or North American headquarters.
What the report must contain
The Measures specify the content of an initial report, and the list is the single most useful preparation tool available. Most of it can be drafted as a template before anything happens.
1. The affected entity or facility. The name of the organisation, the systems or networks affected and basic identifying information.
2. When the incident was discovered and when it occurred. Both, where known. The discovery time is the one that starts your clock, and it should be recorded precisely at the moment it happens.
3. The type of incident. Whether it involves malware, a network attack, unauthorised access, data loss or leakage, a service interruption, or equipment or facility failure.
4. The impact and harm caused. Systems affected, services degraded or unavailable, and the categories and approximate volumes of data involved.
5. The grade assigned and the basis for it. Your assessment against the four tiers, with the reasoning.
6. The measures taken and their effect. Containment steps already implemented and whether they have worked.
7. Preliminary cause analysis. What you currently believe happened. This is explicitly preliminary, and a candid statement of uncertainty is better than speculation presented as fact.
8. Assistance required and further intended action. Any support sought from the authorities and your next steps, including whether law enforcement has been engaged.
Two points on drafting. Say what you know and label what you do not, because an initial report is understood to be incomplete and overstating certainty creates problems when the facts change. And keep the Chinese-language version primary, prepared by someone who can write it under pressure rather than translated in the moment.
Follow-up and closure
The initial report is not the end. As the investigation develops, material new findings need to be reported, and after the incident is resolved a closure report is expected covering the confirmed cause, the full extent of impact, the remediation completed, accountability within the organisation and the measures adopted to prevent recurrence.
This matters for how you handle the first four hours. A defensible initial report followed by disciplined updates is the expected pattern. Withholding the initial report to produce something comprehensive inverts the design of the regime.
The first four hours
Compressed against a real clock, four hours is workable but only with decisions made in advance. A realistic sequence, starting from the moment of discovery.
Minute zero to fifteen. Record the discovery time and the identity of the person who discovered it. Notify the designated China incident lead by a channel that works at any hour, meaning a phone call rather than an email or a ticket. Open an incident log, which becomes the evidentiary record.
Fifteen to forty-five minutes. Establish the basic facts: which systems, what data categories, whether the activity is ongoing, whether personal information is involved and in roughly what volume. Take immediate containment steps that do not destroy evidence. Notify the group security function in parallel, as information rather than as a request for permission.
Forty-five to ninety minutes. Make a provisional grading decision against the four tiers and document the reasoning. Confirm your reporting authority, which for most companies is the provincial cyberspace administration department where the entity is located. If there is any prospect of critical information infrastructure status, escalate on the one-hour assumption instead.
Ninety minutes to two and a half hours. Draft the report in Chinese from the prepared template, populating the eight elements. Have it reviewed by local legal counsel, ideally on a pre-agreed retainer so that the first hour is not spent finding someone. Determine in parallel whether the incident also triggers PIPL notification to affected individuals or reporting under sector-specific rules.
Two and a half to three and a half hours. Obtain the internal sign-off, which should be a single named person and not a committee. File through the reporting platform and retain the confirmation. Log the filing time.
Three and a half to four hours. Buffer. Something will have gone wrong, most often that the person with filing authority is unreachable or that a platform credential has expired. Build the buffer in and test the credentials quarterly.
The sequence rewards preparation over speed. Nearly everything on that timeline other than the facts themselves can be prepared in advance: the template, the counsel relationship, the platform access, the grading criteria and the named decision maker.
Grading in practice
Grading is the judgement that determines whether the clock is running, so it helps to work through the tiers against recognisable situations.
Likely general
A single employee laptop infected with commodity malware, contained by endpoint protection, with no evidence of data exfiltration or lateral movement. A brief outage of an internal tool with no external service impact and no data loss. These are handled internally with the assessment documented, on the working assumption that the escalated timelines are not engaged.
Likely relatively severe or above
Unauthorised access to a customer database containing personal information at meaningful scale. A ransomware event encrypting production systems and interrupting service to customers. Exfiltration of important data as defined under the data security framework. Compromise of an administrative account with broad access to systems holding personal information. Any incident where you cannot rule out large-scale personal information loss within the reporting window.
The borderline case
The genuinely difficult scenario is the one where the facts are unclear at hour two. A suspicious outbound data transfer has been detected, the volume is unknown and the investigation will take days. The instinct is to wait for clarity.
The better approach is to report on the basis of the reasonable worst case that the available evidence supports, state the uncertainty explicitly, and correct it through follow-up reporting. A report that overstated severity and was subsequently revised down is a far better position than a late report justified by an incomplete investigation.
The overlap with PIPL notification
Reporting to the cyberspace administration is not the only obligation a data breach triggers, and the two are frequently confused.
Under the Personal Information Protection Law, where personal information is or may be leaked, tampered with or lost, the handler must take remedial measures and notify both the relevant authority and the affected individuals. The notification to individuals must cover the categories of information involved, the causes and potential harm, the remedial measures taken, steps individuals can take to reduce harm, and contact details. There is a limited carve-out where effective measures mean harm can be avoided, though the authority may still require notification.
The practical consequence is that a single incident can generate three separate communications: the four-hour report to the provincial cyberspace department, an authority notification under PIPL, and notification to affected individuals. They serve different purposes and are written differently. The regulatory report is technical and factual; the notification to individuals is plain-language and actionable. Drafting both from the same text serves neither well.
Sector rules add further layers. Financial services, healthcare, automotive and telecommunications operators may have additional reporting lines to their industry regulator, on their own timetables.
Vendor contract language that works
The requirement to bind service providers is easy to satisfy in new contracts and routinely neglected in existing ones. Four provisions do the work.
Notification with a deadline shorter than yours. A vendor obligation to notify you "promptly" is inadequate when you have four hours. Specify a period measured in hours, and require notification by telephone to a named contact in addition to written confirmation.
An obligation to assist. Express cooperation in your assessment, grading and reporting, including providing logs, technical detail and personnel availability on demand.
Preservation of evidence. A duty to preserve logs and forensic artefacts rather than remediating in a way that destroys them, which well-intentioned providers do surprisingly often.
No unilateral external communication. A restriction on the vendor notifying regulators, customers or the public about an incident affecting your systems without your agreement, subject to its own legal obligations.
Where a vendor also hosts or processes personal information, these clauses sit alongside the processing terms PIPL requires, and the two sets should be reviewed together.
Testing it before you need it
A playbook that has never been exercised is a document, not a capability. A useful tabletop exercise for a China entity runs for about two hours and follows an uncomfortable scenario.
Set it at 11pm on a Friday. The China IT manager receives an alert suggesting unusual access to the customer database. The group security lead is on a flight. The provincial reporting platform credentials were set up by someone who has since left. Then work through it in real time, tracking the clock on a whiteboard.
The failure points are remarkably consistent across companies. Nobody can say what time discovery formally occurred. The named reporting authority is uncertain because the entity has offices in more than one province. The person with filing authority is asleep and has no delegate. The report template does not exist, so drafting starts from nothing in a second language. Local counsel has no retainer and cannot be engaged at that hour. The hosting provider's emergency contact routes to a ticketing queue. And the group process requires a legal sign-off that structurally cannot happen in four hours.
Each of those is fixable in advance and expensive to fix live. Running the exercise annually, and after any material change to systems or personnel, is the cheapest compliance investment available in this area.
Why this hit companies harder than expected
The Measures were finalised days after a foreign company was sanctioned for non-compliance with China's cross-border data transfer requirements, following its disclosure of a breach that exposed customer data in China. The sequencing was not lost on the market. Enforcement in this area is active, and a breach can produce two separate compliance failures: the incident itself, and the reporting or transfer handling around it.
The structural problem for multinationals is that incident response is usually designed globally. A regional IT team detects something, escalates to a global security function, which triages, engages legal and communications, and then decides on notifications. That process typically takes a day or more before any regulator is contacted. In China, four hours has already passed.
What to put in place
1. Confirm your operator category. Establish whether any part of your China operation could be treated as critical information infrastructure, because that changes your deadline from four hours to one.
2. Build grading capability locally. Someone in China must be able to grade an incident against the four tiers quickly. Grading cannot wait for a global assessment, because the grade determines whether the clock is running.
3. Give a named local person authority to report. Designate a China-based individual with standing authority to file with the provincial cyberspace department, plus a deputy. Requiring headquarters sign-off before a regulatory filing in China is incompatible with a four-hour deadline.
4. Write a China-specific playbook. One page, in Chinese and English, covering the grading criteria, the reporting channel and platform, the eight content elements a report must contain, who files, who is notified internally, and how the filing is recorded.
5. Monitor around the clock. A four-hour deadline from discovery presumes you discover things promptly. Monitoring coverage outside local business hours is part of the obligation in substance if not in wording.
6. Fix your vendor contracts. Add the required obligations for cybersecurity, hosting and IT maintenance providers to notify you promptly and assist with reporting. Do this in existing contracts as well as new ones.
7. Rehearse it. Run a tabletop exercise with a scenario that starts at 11pm local time on a Friday. Most companies discover their escalation path fails on the first phone call.
The consequences of getting it wrong
Failing to report, reporting late, or submitting false or incomplete information can draw administrative penalties. The wider exposure is reputational and operational. An incident that becomes public before it was reported, or that reveals weak internal controls, invites scrutiny of your broader data handling, including cross-border transfers, retention and localisation.
Companies that handle a breach well in China tend to share one characteristic. They decided in advance, in writing, who reports and on what basis, and they did not leave the decision to be improvised at speed by people in another time zone.
Acadia Advisory helps foreign-invested companies assess reporting obligations, prepare China-specific incident playbooks and escalation authority, review vendor contract terms, and align incident handling with the wider data compliance framework. If your China entity has no locally documented reporting path, that is the first gap to close.
Related services
- China Due Diligence Services
Corporate & financial due diligence services.
- China Company Secretarial Services
Keep your entity in good standing with reliable governance, filings, and statutory record maintenance.