China CAC — map the gates that hit your product

The Cyberspace Administration of China (CAC) is Mainland China’s top internet regulator. Product teams map CAC touchpoints — filings, apps, content, data, AIGC — as gates, not as statute reading.

Compliance 6 min read cac, cyberspace, compliance, data, aigc, China

Frequently asked questions

What is the Cyberspace Administration of China (CAC)?

The CAC (国家互联网信息办公室 / 中央网络安全和信息化委员会办公室) is Mainland China’s central internet and cyberspace regulator. It leads policy and enforcement across cybersecurity, personal-information protection, online content, algorithms, and generative AI services — often coordinating with MIIT, public security, and market regulators.

Does every product need a direct CAC filing?

No. Many products hit CAC rules through adjacent gates — ICP and hosting readiness, mobile app filing, content ops, cross-border data assessment, algorithm filing, or AIGC filing/registration. Map your surfaces first; do not assume one universal “CAC license.”

Is CAC the same as ICP or MLPS?

No. ICP is mainly an MIIT / telecom hosting gate for websites and apps that publish online. MLPS is a graded cybersecurity assessment for systems you operate in Mainland China. CAC is the cyberspace regulator whose rules and reviews often sit beside — or trigger after — those tracks.

Do overseas-only products ignore CAC?

Not always. If you collect or process personal information of individuals in Mainland China, run China-facing recommendation or generative services, or transfer China-sourced data abroad, CAC-led rules can still apply. Overseas hosting alone is not a free pass.

Can we finish CAC-related work without Mainland China ops?

Usually no. Entity path, Chinese-language portals, local verification, provincial or central review, and parallel MIIT / store / PSB tracks require Mainland China ops rails.

Tell us where you are stuck in China.

Share your product, stack, and timeline — we will point you to the next concrete step.