China MLPS — post-launch assessment, not a launch gate
MLPS is Mainland China’s graded cybersecurity assessment for systems you already operate in-country. After launch you inventory, grade, file Level 2+, assess, and remediate — it does not replace ICP or store launch gates.
MLPS is a graded cybersecurity assessment program for systems you operate in Mainland China — not a product-launch checkbox. After (or as) those systems are live, your product team inventories protection objects, grades them (Levels 1–5), files Level 2+ with the local public-security cybersecurity unit, implements controls, completes assessment where required, and remediates on a recurring cycle. MLPS does not block store or website launch; ICP, app filing, and channel review do that work on other tracks. Overseas ownership does not skip the MLPS obligation.

What China MLPS means
Hard names your program will use:
- MLPS / 等级保护 — Multi-Level Protection Scheme: classify Mainland China–operated networks and information systems, apply level-matched controls, and for Level 2+ typically file and assess.
- Post-launch security program — MLPS work assumes systems (or a clear China-operated scope) exist to grade. Challenges sit in the MLPS project (scoping → filing → assessment → remediation → recurrence), not in “freeze the product launch until the certificate arrives.”
- Legal backbone — The PRC Cybersecurity Law requires a cybersecurity multi-level protection system for network operators. Technical grading practice is guided by national standards such as GB/T 22240-2020 (classification guide entry).
- Protection objects — Grade systems, not “the company once.” Typical objects: Mainland-hosted apps and backends, office / enterprise systems in China, China-region cloud workloads, and in-country data platforms that meet the “independent function + clear security owner” test.
- Levels 1–5 — Impact-based grades. Level 1 is lowest; Level 2+ usually triggers PSB filing and independent assessment. Wrong grade → wrong control and assessment scope.
- Not ICP / not website PSB alone — Domain ICP and post-launch website PSB are separate launch / traffic tracks. Sequence context: ICP and PSB filing. Hosting path: China Product Hosting.
- Ongoing program — Assessments, remediation, and evidence packs recur by level. A one-time binder is not “done.”
Vocabulary first. Next: which decisions you lock for the MLPS program, and where that program stalls.
What must be true before MLPS work starts
Missing any of these stalls the MLPS project before an honest grading kickoff — not your store or ICP launch track.
| Precondition | Why your MLPS process stalls |
|---|---|
| China-operated system inventory — hosts, apps, data stores, networks in Mainland China | You cannot grade “the brand”; you grade objects that already (or will soon) run |
| Security owner per object — named Mainland China–reachable owner | Filing and assessment packages need a responsible operator |
| Entity / partner path for PSB interaction | Local public-security channels expect a China organizing path |
| Architecture baseline for the graded build — cloud region, auth, logging, data stores | Mid-assessment redesign resets evidence |
| Budget for assessment + remediation | Controls and licensed testing are not free paperwork |
| Timeline tolerance for the MLPS cycle — months for Level 2–3 programs is common | Boards that need “MLPS certificate next month” force fake grades |
Chinese-language materials, licensed assessment partners, and remediation owners are part of this floor. Product teams usually cannot clear Level 2+ from an overseas-only security questionnaire.
Grade, file, assess, operate
| Stage | Decision / outcome |
|---|---|
| 1. Inventory objects | Which Mainland China systems are distinct protection objects |
| 2. Grade | Level 1–5 via impact analysis (qualified path for Level 2+) |
| 3. File (Level 2+) | Submit grading pack to local public-security cybersecurity unit |
| 4. Implement controls | Close gaps for that level before / during assessment |
| 5. Assess | Licensed assessment evidence for the graded scope |
| 6. Operate | Recurring assessment, change control, incident evidence |
Levels (selection gate)
Wrong level chooses the wrong control baseline and assessment depth. Use this summary to frame the decision — then grade with a qualified path, not a slide guess.
| Level | Practical read | Typical next step in the MLPS program |
|---|---|---|
| 1 | Lowest impact class | Controls still required; filing usually not the PSB Level 2+ path |
| 2 | Common for many business systems | File + assessment path |
| 3 | Higher impact / important networks | Stricter controls; recurring assessment cadence |
| 4–5 | Particularly / extremely important | Rare for typical SaaS; specialist track |
Necessity: product marketing that “self-declares Level 1” to skip filing while running Mainland China personal-data backends is a common failure mode — assessors and PSB channels grade impact, not optimism.
Who usually needs an MLPS program
Plan an MLPS program when you operate in Mainland China any of:
- Web / app backends, account or payment platforms on Mainland China infrastructure
- SaaS or enterprise systems hosted in China regions for China users or staff
- China-region cloud VPCs, databases, storage supporting those products
- In-country networks (office, dedicated lines, China CDN nodes you operate as a system)
If the product stays fully overseas with no China-operated object, MLPS may not apply yet — but China Product Hosting, ICP, and app filing can still govern launch. Do not confuse “no China VM yet” with “no China compliance,” and do not confuse “launched” with “MLPS finished.”
Why MLPS programs stall (before, during, after assessment)
No object inventory → endless scope fights. Assessment firms and PSB packs need named systems, boundaries, and owners.
Guessed level → failed assessment or rework. Under-grading to avoid filing is how programs restart after the first findings letter.
ICP done, MLPS ignored → false “fully compliant” story. Website filing does not certify system security grades — and finishing ICP still does not mean MLPS is optional once you operate China systems.
Cloud vendor “compliant region” ≠ your MLPS done. Provider infrastructure grades do not replace your application / tenant object obligations.
No remediation owner → assessment theater. Findings without budget and engineers never close — this is a mid/late MLPS-phase failure, not a launch freeze.
PIPL / data programs in parallel without a shared diagram → contradictory answers. Data localization and MLPS evidence must describe the same architecture across the MLPS lifecycle.
What blocks product teams on MLPS
- Treating MLPS as a launch gate — launch uses ICP, channel, and product readiness; MLPS is the post-operation graded assessment track.
- Treating MLPS as a certificate purchase — it is controls + evidence + recurrence across pre-assessment, assessment, and remediation.
- Fragmented China stacks — every unmanaged SaaS and shadow VPC becomes another object.
- Overseas-only logging and admin paths — assessors ask for Mainland China–operable evidence.
- Opaque brokers promising “guaranteed Level 2 in weeks” — diligence entity, assessor license, and rejection handling.
- Ignoring MLPS after a successful launch — paid growth into an ungraded China stack creates audit and enforcement exposure later.
- No link to hosting and filing — MLPS sits beside ICP/PSB and app filing on a different clock; sequence deliberately without blocking go-live on MLPS completion.
When you need a China landing partner for MLPS
Most product teams exploring Mainland China entry need a China landing partner (and licensed assessment relationships) to inventory objects, grade honestly, file Level 2+, remediate, and keep the recurring program alive Your team still owns architecture and data decisions; the partner path makes PSB and assessment rails executable when they are not already in-house.
What we can offer?
MLPS is a post-launch graded assessment program for China-operated systems — inventory, level, file, assess, remediate. Chinaready helps your product team see whether MLPS is in scope and run that program without confusing it with launch gates:
- China Readiness Assessment — Map which Mainland China systems look like MLPS objects, whether Level 2+ is plausible, and which MLPS-phase risk (scope, grade, remediation) the board should fund — separate from the launch date.
- China Access Acceleration — Keep admin, auth, and critical deps reachable so assessment evidence and operator access match the graded architecture.
- China Product Hosting — Place China-critical workloads where ICP/PSB and later MLPS evidence can describe a coherent Mainland China stack.
- Mobile App Distribution — Ship channel launches on their own gates, then align the live system boundaries your MLPS pack will grade — so distribution and security assessment stay consistent without blocking each other.
Contact us when you need an MLPS scope read for systems you operate (or will operate) in Mainland China — without treating MLPS as a launch freeze.
Frequently asked questions
What is MLPS in China?
MLPS (Multi-Level Protection Scheme / 等级保护) is the graded cybersecurity framework for networks and information systems operated in Mainland China. Operators classify each protection object (Levels 1–5), implement matching controls, and for Level 2 and above typically file with the local public-security cybersecurity unit and complete assessments.
Does MLPS block product launch?
No. Store listings, ICP/website filings, and go-live decisions are separate tracks. MLPS is a post-launch (post-operation) security grading and assessment program for China-operated systems. It has its own pre-assessment, assessment, and remediation phases — those challenges do not mean “no launch until MLPS finishes.”
Do foreign companies need MLPS?
Ownership does not exempt you. If your Mainland China entity (or in-country stack) operates networks, information systems, or data-processing objects in Mainland China, MLPS grading applies to those objects. Overseas-only SaaS with no China-operated system is a different analysis.
Is MLPS the same as ICP or PSB website filing?
No. ICP / PSB website filings are traffic and site registration gates often tied to going live. MLPS is a cybersecurity grading and assessment program for systems you operate. Different clocks — see the ICP/PSB sequence Guide.
What MLPS level do most product teams hit?
Levels are assigned per object by impact analysis, not by “foreign vs local.” Consumer-facing apps, personal-data backends, and core business systems hosted in Mainland China commonly land at Level 2 or 3 in practice — but guessing wrong is expensive. Use a qualified grading / assessment path.
Can we finish MLPS without Mainland China ops?
Usually no. Level 2+ work needs Chinese-entity ownership of the object, local PSB filing channels, licensed assessment partners, and remediation owners.


