Cloudflare in Mainland China — Enterprise, ICP, JD Cloud
Cloudflare China Network runs on JD Cloud in Mainland China — not a global region toggle. Enterprise plus a separate subscription, ICP filing, and JD content vetting apply.
Cloudflare China Network is not a region toggle on global Cloudflare. Default global Cloudflare still serves Mainland China users from the nearest overseas edge. The China Network path runs selected Cloudflare products on JD Cloud data centers inside Mainland China — and it is gated by Enterprise + a separate China Network subscription, ICP filing per apex domain, and JD Cloud content vetting. Treat this Guide as a decision map for product teams — not a self-serve handbook that finishes China edge alone.

What Cloudflare China Network is for product teams
Hard names your stack decision will use:
- Two paths, not one toggle — Default global Cloudflare reaches Mainland China users from overseas POPs. Cloudflare China Network places a subset of performance and security products on JD Cloud data centers inside Mainland China (China Network overview).
- JD Cloud operates the in-China edge — Cloudflare (as a US company) does not hold an MIIT CDN license for Mainland China. JD Cloud holds the licenses required to operate CDN there; China Network runs on that partner footprint.
- Enterprise + separate subscription — China Network is not included in Pro or Business. You need a Cloudflare Enterprise plan, the China Network package, and agreement to the China Service Supplemental Terms — through sales, not self-serve checkout.
- ICP filing is a hard gate — Every apex domain you onboard must have a valid ICP filing or license. Footer ICP display and JD Cloud content review come before enablement.
- Product catalog is a subset — WAF, DDoS, CDN cache, Workers, and related services appear on the available products list with documented gaps (Turnstile, Pages, R2 limits, static-only cache tiers, Bot Management ML limits).
- Own-domain edge ≠ third-party compatibility — China Network improves delivery of your onboarded zone. Blocked overseas scripts, fonts, video hosts, and analytics still fail unless you replace or mirror them — China Network does not auto-rewrite those dependencies.
- Global Acceleration is a related suite — Connectivity offerings (including CDN Global Acceleration for dynamic content with offshore origins) sit beside China Network and also cover some Zero Trust paths into Mainland China.
Vocabulary first. Next: what must be true before sales and JD Cloud work, then the comparison and product evidence your architecture review needs.
What must be true before China Network onboarding
Missing any of these stops your product team before JD Cloud enables in-China POPs — often before the first usable China Network zone.
| Precondition | Why your process stalls |
|---|---|
| Cloudflare Enterprise + China Network package | Pro / Business cannot access in-China POPs; China Network is a separate paid subscription |
| China Service Supplemental Terms accepted via sales | Package and terms are not self-serve dashboard checkboxes |
| PRC organizing entity or China landing partner path | ICP filing needs a Mainland China organizing-entity rail; Cloudflare and JD Cloud do not file ICP for you |
| Valid ICP filing or license per apex domain | No ICP → no China Network onboarding; PoC also requires a valid ICP number |
| ICP number displayed in the site footer | Required before JD Cloud content vetting and for ongoing compliance |
| JD Cloud vetting pack ready | Company name, domain, ICP number, content description, signed Self Attestation — domains can be rejected |
| Product bill of materials checked against China Network availability | Global-only features (Turnstile, Pages, R2 create-in-China, Cache Reserve) fail at architecture review |
| Third-party dependency plan for Mainland China users | Google Fonts, YouTube, overseas captcha / analytics hosts still time out even when your apex is on China Network |
| DNS cutover plan (default vs In-China Authoritative DNS; full vs partial CNAME) | Wrong suffix or premature In-China DNS can raise latency for non-China users |
| PSB filing timeline where required | ICP first; PSB within 30 days of launch — see ICP and PSB guide |
Chinese-language filing consoles, entity rails, and sales-led contracting are part of this floor. Product teams usually cannot treat China Network as a handbook finished from an overseas laptop alone.
What the Cloudflare China Network is
Delivering content quickly and securely to users in Mainland China requires infrastructure within the country. Traffic routed through servers outside Mainland China faces significant latency and reliability issues at the network boundary — the problem Cloudflare’s global POPs improve but do not eliminate.
The Cloudflare China Network addresses this by running selected Cloudflare performance and security products on JD Cloud data centers located in Mainland China. Those data centers cover most populated regions in China. You manage configurations on the same Cloudflare dashboard you use everywhere else, with the same customer support model — including optional premium and local-language support.
Main features documented by Cloudflare include:
- A single solution for performance improvement and security services such as WAF, DDoS protection, and bot management.
- A unified dashboard for network traffic and security posture.
- In-China Authoritative DNS and in-China nameservers to reduce Time to First Byte (TTFB).
- Global Acceleration — connectivity offerings that simplify deploying global assets for Mainland China users.
Availability and prerequisites
The China Network is not included in standard Cloudflare plans. It is available as a separate subscription for customers on a Cloudflare Enterprise plan. You must sign a contract, add the China Network package to your Enterprise account, and agree to the China Service Supplemental Terms — all through your Cloudflare sales team, not as self-serve checkout.
Every apex domain you onboard must have a valid ICP filing or license. Only domains that have completed ICP filing and related compliance requirements can use the China Network. Content served inside Mainland China is monitored by local authorities and must comply with local regulations.
Cloudflare also notes that IPv6 support is mandatory for all Internet-facing services operating in Mainland China. The China Network automatically enables IPv6 on your domains to fulfill this requirement — it cannot be disabled.
Cloudflare itself, as a US company, does not hold a Ministry of Industry and Information Technology (MIIT) CDN license for Mainland China. JD Cloud holds the licenses required to operate and provide CDN services there.
Default global Cloudflare vs China Network
| Dimension | Default (no China Network) | Cloudflare China Network |
|---|---|---|
| Edge POPs for Mainland China users | Nearest global data centers (outside Mainland China) | JD Cloud data centers inside Mainland China |
| Plan requirement | Any plan (Pro, Business, Enterprise, etc.) | Enterprise + China Network package |
| ICP | Not required for overseas-only serving | Required for each apex domain |
| DNS resolution | Closest data center to the end user | Mainland China clients resolve via JD Cloud; optional In-China Authoritative DNS (see below) |
| Product scope | Full global Cloudflare catalog | Subset — see product availability below |
| Third-party blocked hosts | Still fail from Mainland China clients | Still fail unless you replace or mirror them — China Network does not auto-fix dependency compatibility |
Without the China Network, Mainland China users hit the nearest overseas edge. Latency is usually better than a single far origin but worse and less predictable than a domestic POP — and it varies by region and time of day. That path works for some marketing sites and internal tools; it is not the same as legally serving filed content from in-China infrastructure.
Product availability snapshot
Not all Cloudflare products run on the China Network. The tables below summarize what Cloudflare documents as available on the JD Cloud–operated network. For sign-off, cross-check the official page and your account team — product lists evolve.
Application services
| Product / feature | China Network notes |
|---|---|
| Authoritative DNS | In-China resolution available (see DNS section) |
| CDN / Cache | Core cache features; static cache only — no Cache Reserve or Tiered Cache |
| Image Transformations | Edge format optimization |
| DDoS Protection | Layer 7 protection (HTTP flood, WordPress Pingback, HULK, LOIC, etc.) |
| Managed rules | OWASP and Cloudflare managed rulesets |
| Custom rules | Custom WAF rules; uploaded content scanning; managed challenges |
| Rate limiting rules | Expression-based rate limits |
| Content scanning | Detect and scan uploaded files for malicious signatures |
| Client-side security (Page Shield) | Track and alert on external scripts |
| Bot Management | Available; limited ML models only |
| Argo Smart Routing | Layer 7 smart routing to origin |
| Rules | Request/response adjustments and Cloudflare settings |
| Load Balancing | Performance and availability |
Developer services
| Product / feature | China Network notes |
|---|---|
| Workers | Serverless execution on Cloudflare network |
| Workers KV, R2, Assets, Images | Available with restrictions — see gaps below |
| mTLS, Rate Limiting, Secrets, Service bindings | Supported |
| Tail Workers, Version metadata, Workers for Platforms | Supported |
Network services
| Feature | China Network notes |
|---|---|
| IPv6 | Enabled by default on all data centers |
| SSL/TLS | Customer, Dedicated, Universal, Custom, ACM certificates |
| HTTP/3 (QUIC) | Supported |
| WebSockets | Supported with Workers |
Zero Trust services
Zero Trust offerings in Mainland China are covered under Global Acceleration rather than the standard China Network product list. See the Global Acceleration section below.
Documented gaps and footnotes
These limitations matter during architecture review:
- Turnstile is not available within Mainland China. China Network zones and global zones with Mainland China visitors may experience Turnstile issues.
- Pages is not available in Mainland China because the
pages.devcertificate does not reside within Mainland China. Global Pages may potentially be extended into Mainland China through Global Acceleration. - R2 buckets cannot be created within Mainland China, and custom domains are not supported within Mainland China. R2 can be extended into Mainland China through Global Acceleration.
- Origin Rules require China Network enabled on both the original zone and the target zone. Otherwise visitors receive error 1016 with HTTP 530.
- Bot Management supports only certain machine-learning models compared with global.
From Enterprise contract to China Network live
Cloudflare documents onboarding in Get started. The sequence is sales-led and compliance-heavy.
| Step | Official requirement | Practical notes |
|---|---|---|
| 1. Contract required services | Hold a Cloudflare Enterprise plan; add the China Network package; agree to China Service Supplemental Terms | Contact your Cloudflare sales team — not self-serve in the dashboard |
| 2. Obtain ICP and vet domain content | ICP filing or license for all apex domains; present valid ICP for zones being onboarded; display ICP number in page footer; submit vetting information to JD Cloud | JD Cloud must review and approve domain content before China Network is enabled |
| 3. Onboard domains | Add domains after content vetting completes | First-time zone enablement takes approximately 24–48 hours; subsequent enable/disable is available in the dashboard |
| Stage | Decision / outcome |
|---|---|
| 1. Path verdict | Confirm you need in-China edge (filed content / domestic POP performance) — not only overseas Cloudflare reachability |
| 2. Contract rail | Enterprise + China Network package + Supplemental Terms via sales |
| 3. Entity + ICP | PRC organizing path; ICP per apex; footer display |
| 4. JD Cloud vetting | Submit pack; accept approve / reject risk before enablement |
| 5. Product trim | Diff required features vs available-products list; plan Global Acceleration if origins stay offshore |
| 6. DNS cutover | Default closest-POP DNS vs In-China Authoritative DNS; full NS or partial CNAME suffixes |
| 7. Dependency hardening | Replace or mirror blocked third-party hosts for Mainland China clients |
| 8. Operate | Monitor ICP status; align PSB; keep global and China paths explicitly understood |
Step 2 — what JD Cloud vetting requires
Before JD Cloud enables China Network for your domains, you typically provide:
- Customer and company name
- Domain name
- ICP license or filing number
- A general description of each domain’s content (for example, marketing website)
- A signed Self Attestation letter (provided by your sales team)
JD Cloud reviews content to ensure compliance with Mainland China Internet regulations and JD Cloud service terms. They can approve or reject any domain based on content nature. A proof-of-concept (PoC) also requires a valid ICP number and JD Cloud content vetting approval before Cloudflare will provision China Network access.
Important: Neither Cloudflare nor JD Cloud is responsible for processing ICP applications on your behalf. Cloudflare can provide referrals to ICP partners; the filing itself is your organizing entity’s obligation. See our ICP and PSB filing guide for the full sequence product teams follow.
Why contract, ICP, and dependency failures cascade
No Enterprise China Network package → no in-China POPs. Pro and Business never see JD Cloud China Network edges. Architecture reviews that assume “enable China in the dashboard” waste cycles until sales contracting exists.
Enterprise without ICP → vetting never starts. Every apex needs a valid filing or license. Cloudflare and JD Cloud do not process ICP applications. Teams without a PRC entity rail stall at the filing gate unless a China landing partner supplies the organizing path.
ICP without footer / attestation pack → JD Cloud rejects or delays. Content description, Self Attestation, and footer display are part of the enablement floor — not optional polish.
China Network live, third-party hosts ignored → “slow China” still looks broken. Your HTML may cache on JD Cloud while Google Fonts, YouTube, overseas captcha, and analytics scripts still time out for Mainland China users. Edge success on the apex does not equal page success.
Product parity assumed = Global → mid-build redesign. Turnstile, Pages, R2 create-in-China, Cache Reserve / Tiered Cache, and Origin Rules cross-zone constraints are common Global defaults that fail on China Network.
In-China Authoritative DNS enabled for mixed traffic → latency spike outside Mainland China. After enablement, all DNS — including non-China clients — routes to JD Cloud China. Cloudflare recommends confirming >90% Mainland China traffic first.
Offshore origin without Global Acceleration plan → dynamic paths stay brittle. Static cache on China Network helps HTML/assets; API and personalized responses with origins outside Mainland China often need CDN Global Acceleration (Enterprise + China Network prerequisites).
Landing partner — Chinaready
Companies without a Mainland China organizing entity typically need a PRC subsidiary, qualifying branch, representative office where permitted, or a landing partner arrangement — to obtain ICP filing and coordinate with Cloudflare sales and JD Cloud vetting. The three official onboarding steps assume you already have, or are building, that China-side structure.
A China landing partner is not a workaround for filing. It is an operating model for product teams that need a Mainland China organizing-entity path aligned with hosting choice, provider-console filing managed with correct scope and documents, domain and DNS that match what MIIT approved, and a single coordination point between the product team and compliance steps. That is the role Chinaready is built for.
| Official step | How Chinaready supports product teams |
|---|---|
| 1. Contract | Align the PRC entity with Cloudflare Enterprise and China Network contracting; coordinate with your sales conversations — Chinaready is not a Cloudflare or JD Cloud reseller |
| 2. ICP + vetting | Parallel-track ICP filing for apex domains; prepare JD Cloud vetting materials (company name, domain, ICP number, content description, attestation support); ensure ICP number display in site footer before review |
| 3. Onboard | Coordinate domain and DNS cutover after JD Cloud approval; align partial-setup CNAME patterns if your architecture splits global and in-China resolution |
Teams that lack a clear PRC entity path, or need filing and onboarding coordinated on a defined timeline, can start with a China Readiness Assessment. PSB filing within 30 days of launch still applies where required — see the ICP and PSB guide.
China Authoritative DNS
By default, the Cloudflare China Network resolves each DNS request at the data center closest to the client. For clients outside Mainland China, the closest global Cloudflare data center handles the request. For clients inside Mainland China, a JD Cloud data center handles the request.
This default behavior does not require In-China Authoritative DNS — it is how China Network routing works once your domain is onboarded with valid ICP.
In-China Authoritative DNS (In-China nameserver)
Cloudflare can deploy DNS service inside Mainland China to improve TTFB. With this option enabled, DNS queries resolve at JD Cloud data centers in Mainland China instead of at global DNS servers.
When to use: Cloudflare recommends confirming that the majority (over 90%) of your traffic comes from Mainland China before enabling In-China Authoritative DNS.
Warning: After you enable In-China Authoritative DNS, all DNS requests — including those from users outside Mainland China — route to JD Cloud data centers in Mainland China instead of the nearest global data center. This can increase latency for users outside Mainland China.
| DNS option | Behavior |
|---|---|
| Default | Uses the DNS server closest to the end user (global POPs outside Mainland China; JD Cloud POPs inside Mainland China) |
| In-China DNS | Uses only DNS in Mainland China, operated by JD Cloud |
ICP gate: In-China Authoritative DNS applies to domains that have completed ICP filing and China Network onboarding. Domains without ICP cannot use the in-China DNS path on the China Network.
Setup: After China Network is enabled, contact your Cloudflare sales team to enable In-China Authoritative DNS — it is not currently self-serve in the dashboard. Update your domain registrar with assigned in-China nameservers (full setup) or create CNAME records (partial setup):
- In-China DNS: CNAME to
.cdn.cloudflarecn.net(for example,www.example.cn.cdn.cloudflarecn.net) - Global default DNS: CNAME to
.cdn.cloudflareanycast.net(for example,www.example.com.cdn.cloudflareanycast.net)
Test resolution after changes. For partial setups mixing global and in-China zones, each record points to the appropriate suffix for that zone’s requirement.
Global Acceleration
Organizations that serve content or connect employees in Mainland China face connectivity challenges from network infrastructure and regulatory requirements at the border. Global Acceleration is a suite of connectivity and performance offerings that address these challenges through optimized network paths into and out of Mainland China. Services are provided by Cloudflare partners including China Mobile International (CMI), CBC Tech, and JD Cloud.
Global Acceleration can be an add-on to China Network and also extends Zero Trust services into Mainland China.

CDN Global Acceleration
CDN Global Acceleration provides stable, reliable connections for dynamic content — API responses, personalized pages, and other non-static payloads — entering and exiting Mainland China on the China Network CDN. This matters when your origin must stay outside Mainland China but you still need acceptable performance for Mainland China users.
Prerequisites for CDN Global Acceleration:
- Cloudflare Enterprise plan
- China Network enabled on the zone
The general process documented by Cloudflare:
- Validate prerequisites — Enterprise and China Network (for CDN GA); separate entitlements for Cloudflare One Client or Cloudflare WAN acceleration.
- Sign contract — your Cloudflare account team assists with contracting directly or through local China partners, depending on the service.
- Deploy — local China partners assist with Global Acceleration deployment.
Other Global Acceleration offerings (brief)
Cloudflare documents additional Global Acceleration services on the same page:
| Service | Scenario |
|---|---|
| Cloudflare One Client Global Acceleration | Cloudflare One Client used in Mainland China |
| Cloudflare WAN Global Acceleration | Cloudflare WAN used in Mainland China |
| ICP services | Partner-assisted ICP filing or license acquisition (distinct from Cloudflare filing ICP directly) |
| MLPS services | Multi-Level Protection Scheme Level 3 certification support |
| Travel SIM | Temporary Cloudflare One Client access for employees traveling to Mainland China |
For architecture sign-off, treat CDN Global Acceleration as the path for offshore origins behind a filed China Network front door — not as a substitute for ICP when serving from in-China infrastructure.
Key considerations
Before committing to the China Network, review this checklist against your stack and compliance plan:
- Enterprise + China Network package — both are required; Pro or Business plans cannot access in-China POPs.
- ICP filing or license per apex domain — filing is your organizing entity’s responsibility; Cloudflare and JD Cloud do not process applications.
- ICP displayed in footer — required before JD Cloud content vetting and ongoing compliance.
- JD Cloud content vetting — domains can be rejected; plan content descriptions and attestation early.
- ICP revocation — local authorities manage revocation; JD Cloud may suspend or terminate China Service; Cloudflare reroutes affected domains to nearest data centers outside Mainland China.
- Product parity — not all global Cloudflare features run in Mainland China; review Turnstile, Pages, R2, cache tier, and Origin Rules constraints.
- Third-party dependencies — China Network does not auto-mirror blocked fonts, video, captcha, or analytics hosts.
- IPv6 — automatically enabled on China Network; cannot be disabled.
- In-China DNS tradeoff — routes all DNS globally to JD Cloud China when enabled; only for >90% Mainland China traffic.
- Data residency — account identification (email, password hashes, billing) is not stored on China Network; zone configuration and Developer Suite bindings are stored on the China Network operated by partners when China Service is enabled for a zone.
- PSB filing — ICP filing first; PSB filing within 30 days of launch where applicable — see ICP and PSB guide.
What blocks product teams on Cloudflare China Network
- Treating China as a global Cloudflare region toggle — overseas POPs and China Network are different products with different contracts.
- Pro / Business expectations — in-China POPs never appear without Enterprise + China Network.
- No PRC entity rail for ICP — filing stalls before JD Cloud vetting; Cloudflare and JD Cloud do not file for you.
- JD Cloud content rejection — domains can be refused based on content nature even after contracting.
- Catalog optimism — Turnstile, Pages, R2, and cache-tier gaps force redesign after sprint commitments.
- Ignoring third-party host failures — apex on China Network while fonts/scripts/video still time out looks like “CDN did nothing.”
- In-China DNS for global audiences — all DNS shifts to JD Cloud China; non-China latency rises.
- Confusing reachability with in-China filing — speeding access for Mainland China users to a global Cloudflare footprint is a different problem than serving ICP-filed content from JD Cloud China Network POPs.
When Cloudflare China Network fits
Choose the Cloudflare China Network when you are already on Cloudflare Enterprise, need in-China edge performance and security for ICP-filed domains, and can complete JD Cloud content vetting — including maintaining footer ICP display and compliance with local content rules.
It is usually the wrong first answer when the problem is simply reachability of a global Cloudflare site to Mainland China users on a non-Enterprise plan. Latency from overseas POPs, third-party dependency failures, and filing obligations are different classes of work. Teams on Pro or Business evaluating China reachability should measure first — see Netlify and China and Vercel and China for the reachability framing — and consider hybrid routes, dependency stripping, or a domestic front door before committing to Enterprise China Network contracting.
Minimum diligence before sign-off: confirm every required product in the available products list; parallel-track Enterprise contracting, PRC entity work, and ICP filing; plan DNS cutover (default vs In-China Authoritative DNS); scope Global Acceleration if origins stay offshore; harden third-party dependencies; align PSB filing with launch.
For a route recommendation tailored to your stack, start a China Readiness Assessment.
When you need a China landing partner for Cloudflare China
Most product teams exploring Mainland China entry need a China landing partner to clear the PRC entity / ICP rail, prepare JD Cloud vetting, and coordinate DNS cutover with Cloudflare sales — not a longer dashboard tutorial. Your team still owns product and architecture decisions; the partner path makes entity, filing, and onboarding rails executable when they are not already in-house.
What we can offer?
Cloudflare China Network is an Enterprise + ICP + JD Cloud path — not a global region toggle. Chinaready helps your product team decide whether China Network fits and what must be true before in-China POPs are real:
- China Readiness Assessment — Map whether you need China Network vs overseas Cloudflare reachability, which entity/ICP rail you can execute, and which product gaps block the reference architecture.
- China Access Acceleration — Keep admin paths, hybrid links, and Mainland China user experience workable while global Cloudflare and China Network stay explicitly separate.
- China Product Hosting — Place China-critical fronts on a Mainland China–operable stack where ICP/PSB, DNS, and Cloudflare/JD Cloud enablement describe one coherent publish path.
- Mobile App Distribution — Ship channel launches on their own gates while web edge and China Network choices stay consistent with the live product boundary.
Contact us when you need a Cloudflare China Network vs global decision — Enterprise contracting adjacency, ICP, JD Cloud vetting, and dependency hardening — without treating China as a region checkbox.
References
- Cloudflare China Network — overview — last checked 2026-08-08
- Cloudflare China Network — Get started — last checked 2026-08-08
- Cloudflare China Network — China Authoritative DNS — last checked 2026-08-08
- Cloudflare China Network — Global Acceleration — last checked 2026-08-08
- Cloudflare China Network — Available products and features — last checked 2026-08-08
- Cloudflare China Network — FAQ — last checked 2026-08-08
- Cloudflare China Network — Internet Content Provider (ICP) — last checked 2026-08-08
- China Service Supplemental Terms — last checked 2026-08-08
- JD Cloud — China Network partner operator overview
- China ICP and PSB filing for foreign companies — Chinaready guide
Frequently asked questions
Is the Cloudflare China Network included in standard Cloudflare plans?
No. China Network is a separate subscription for Cloudflare Enterprise customers, contracted through Cloudflare sales — not self-serve checkout on Pro or Business.
Does Cloudflare China Network require ICP filing?
Yes. Every apex domain onboarded to China Network must have a valid ICP filing or license before JD Cloud content vetting and enablement.
Who operates Cloudflare’s Mainland China data centers?
Selected Cloudflare products run on JD Cloud data centers inside Mainland China under Cloudflare’s official partner arrangement.
Is In-China Authoritative DNS required for China Network?
No. Default China Network routing does not require In-China Authoritative DNS; that DNS path is optional for domains that complete ICP filing and China Network onboarding.
Can teams on Pro or Business use China Network POPs?
No. In-China POPs require both an Enterprise plan and the China Network package; Pro and Business cannot access those POPs.
Does China Network fix blocked third-party scripts and fonts?
No. China Network accelerates and secures your onboarded domain on JD Cloud POPs — it does not automatically mirror or rewrite blocked third-party hosts (for example Google Fonts, YouTube embeds, or overseas analytics).


