China CAC — map the gates that hit your product
The Cyberspace Administration of China (CAC) is Mainland China’s top internet regulator. Product teams map CAC touchpoints — filings, apps, content, data, AIGC — as gates, not as statute reading.
The Cyberspace Administration of China (CAC) is Mainland China’s top cyberspace regulator — not one product license you buy. Your team maps which product surfaces trigger CAC-led or CAC-adjacent gates: content and platforms, personal data and cross-border transfer, algorithms, generative AI, and enforcement risk on apps or sites. Those gates sit beside ICP, store, and hosting tracks.

What the CAC is for product teams
Hard names your program will use:
- CAC — Cyberspace Administration of China; also the office side of the Central Cyberspace Affairs Commission. Portal: cac.gov.cn.
- Regulator umbrella, not a single form — CAC sets and enforces internet governance across cybersecurity, personal information, online content, algorithms, and generative AI. Product work hits named tracks (filing, assessment, registration, rectification), not one CAC checkbox.
- Legal backbone — Cybersecurity Law (CAC text), Personal Information Protection Law (PIPL), and Data Security Law (DSL). CAC leads or coordinates; sector bodies still own their consoles.
- Cross-border data — Outbound transfer security assessment (CAC Measures) matters when China-sourced personal or important data leaves Mainland China.
- Algorithms and AIGC — Algorithm filing via beian.cac.gov.cn. Generative AI under CAC interim measures (CAC text); see China’s AIGC filing.
- Coordination — MIIT (ICP), public security, and market regulators often share one incident. A CAC content or data order can freeze growth even when ICP is done.
- Common myth — “ICP done, so CAC does not apply.” ICP is a hosting gate. CAC still governs data, algorithms, AIGC, and platform content once users in Mainland China are in scope.
Vocabulary first. Next: what must exist before CAC-facing work is executable.
What must exist before CAC-facing work starts
Missing any of these stops your product team before a real CAC review, filing, or assessment path — not after you finish reading the statutes.
| Precondition | Why your process stalls |
|---|---|
| Clear China product surfaces — site, app, Mini Program, generative feature, recommendation, China user data | You cannot pick a CAC track without knowing what is public and what data moves |
| Mainland China entity or agency organizing path | Provincial CAC, MIIT, and assessment channels expect a China applicant / responsible party |
| Chinese-language ops and legal-person verification | Portals, notices, and rectification letters are not English self-serve packs |
| Data and architecture diagram — where personal / important data is stored and whether it crosses the border | Cross-border assessment and PIPL answers fail without a shared diagram |
| Content and algorithm ownership — who can change ranking, generation, and moderation | Reviewers and enforcement ask for live controls, not slideware |
| Timeline for parallel tracks — ICP, app filing, AIGC, store review | CAC work rarely waits for a “compliance week” after launch marketing |
Product teams without Mainland China ops rails usually cannot open provincial CAC or algorithm portals without Mainland China ops.
Map CAC touchpoints to your product surfaces
Use this as a surface → gate map. Stages are decisions, not console click-paths.
| Stage | Decision / outcome |
|---|---|
| 1. Inventory China-facing surfaces | Which URLs, apps, Mini Programs, APIs, and generative features users in Mainland China actually hit |
| 2. Separate hosting gates from CAC gates | ICP / hosting readiness (ICP filing, ICP licence) vs content, data, algorithm, AIGC |
| 3. Classify data movement | In-country only vs cross-border transfer that may need CAC security assessment |
| 4. Classify AI / ranking | Recommendation or generative public services → algorithm and/or AIGC filing tracks |
| 5. Align app and channel packs | Mobile app filing and store review (mobile app filing) must match the same privacy and content story CAC would test |
| 6. Plan enforcement readiness | Who receives rectification orders, who can take features offline, who owns evidence |
Sibling context when the surface is a system you operate in-country: China MLPS is a post-launch graded security program — related cybersecurity posture, different clock from CAC content or AIGC filing.
Why one CAC gate blocks the next
Unclear surface inventory → wrong track. Teams that “file for CAC” without separating website ICP, app filing, algorithm filing, and AIGC registration burn months on the wrong provincial queue.
ICP complete, data story unfinished → false green light. A filed domain does not authorize unrestricted outbound personal-data export or unfiled generative features for the public in Mainland China.
Overseas model / overseas admin path → AIGC and algorithm stalls. Registration and live testing expect China-reachable controls and, for simplified generative paths, a China-filed model story — see AIGC filing.
App privacy text ≠ live collection → removal risk. CAC and coordinated enforcement have pulled apps and Mini Programs when collection exceeds disclosed purpose. Store approval does not immunize a later data or content order.
No cross-border diagram → assessment and partner diligence fail together. Cloud “global region” language is not a CAC outbound-data answer. Hosting choices must match the assessment path — China Product Hosting.
Content ops without a China owner → rectification without an executor. Warnings and suspension orders need someone who can change production the same day.
Where CAC programs stall product teams
- Treating CAC as background reading — the decision is which gates your surfaces trigger, not whether you can recite CSL / DSL / PIPL names.
- One-license thinking — there is no single “CAC licence” that replaces ICP, app filing, algorithm filing, and AIGC tracks.
- Launch marketing ahead of generative or ranking features — public AIGC and recommendation surfaces need filing logic before paid acquisition.
- Fragmented privacy copy — English global policy, Chinese in-app copy, and actual SDKs disagree under review.
- Broker promises of “CAC done in weeks” — diligence who applies, which provincial office, and what happens on reject or restart.
- Ignoring coordination — MIIT, PSB, and CAC can all touch the same incident; fixing only one console leaves the product exposed.
When you need a China landing partner for CAC gates
Most product teams exploring Mainland China entry need a China landing partner to turn CAC touchpoints into an executable sequence — entity path, Chinese portals, data and AIGC packages, and parallel ICP / app / store rails — not another longer statute reading list. Your team still owns product scope and architecture choices; the partner path makes provincial CAC, assessment, and rectification rails workable when they are not already in-house.
What we can offer?
CAC work is a gate map across filings, apps, content, data, and AIGC — not one form. Chinaready helps your product team see which surfaces are in scope and run the Mainland China path beside hosting and distribution:
- China Readiness Assessment — Inventory China-facing surfaces, flag CAC-adjacent gates (data, algorithms, AIGC, content risk), and separate them from ICP / launch blockers the board can fund in order.
- China Access Acceleration — Keep admin, auth, and review test paths reachable from Mainland China so live CAC or store testing matches the architecture you claim.
- China Product Hosting — Place China-critical workloads where ICP, data residency, and later assessment evidence describe one coherent stack.
- Mobile App Distribution — Align app filing, store packs, and privacy / content disclosures with the same story CAC-coordinated enforcement would test after launch.
Contact us when you need a CAC gate map for the product you plan to run for users in Mainland China —.
Frequently asked questions
What is the Cyberspace Administration of China (CAC)?
The CAC (国家互联网信息办公室 / 中央网络安全和信息化委员会办公室) is Mainland China’s central internet and cyberspace regulator. It leads policy and enforcement across cybersecurity, personal-information protection, online content, algorithms, and generative AI services — often coordinating with MIIT, public security, and market regulators.
Does every product need a direct CAC filing?
No. Many products hit CAC rules through adjacent gates — ICP and hosting readiness, mobile app filing, content ops, cross-border data assessment, algorithm filing, or AIGC filing/registration. Map your surfaces first; do not assume one universal “CAC license.”
Is CAC the same as ICP or MLPS?
No. ICP is mainly an MIIT / telecom hosting gate for websites and apps that publish online. MLPS is a graded cybersecurity assessment for systems you operate in Mainland China. CAC is the cyberspace regulator whose rules and reviews often sit beside — or trigger after — those tracks.
Do overseas-only products ignore CAC?
Not always. If you collect or process personal information of individuals in Mainland China, run China-facing recommendation or generative services, or transfer China-sourced data abroad, CAC-led rules can still apply. Overseas hosting alone is not a free pass.
Can we finish CAC-related work without Mainland China ops?
Usually no. Entity path, Chinese-language portals, local verification, provincial or central review, and parallel MIIT / store / PSB tracks require Mainland China ops rails.


