检索整个资料库

搜索法律、法规、标准与实务指南

猜你想搜

当前重点

2026-07-03互联网信息服务管理办法修订草案公开征求意见2026-06-18网络数据安全风险评估:草案与最终办法

What changed

重要变化概览

重点比较报告期限、附件和评估程序从征求意见稿到正式办法的变化。

  • The final reporting deadline is 20 working days after the annual assessment, rather than 10 working days in the draft.
  • The draft's prescribed report-template annex is not included in the final measures.
  • The final text uses a coordinated inter-agency mechanism and less prescriptive wording on named standards and certified assessors.
added

Effective date

此前规则

The draft left the effective date blank.

当前规则

The final measures take effect on 20 August 2026.

实际影响:Creates a fixed implementation date.

Final Article 25.

clarified

Assessment cadence

此前规则

Annual assessment for important-data processors; general-data processors encouraged at least every three years.

当前规则

The final measures retain both frequencies.

实际影响:The main cadence was retained from the draft.

Draft Article 6; final Article 5.

modified

Assessment methodology

此前规则

The draft expressly named GB/T 45577 and other relevant national standards.

当前规则

The final text requires compliance with law and regulation and reference to relevant national standards without naming GB/T 45577 in the article.

实际影响:The final wording is less tied to a named standard in the operative rule.

Draft Article 7; final Article 6.

modified

Report format

此前规则

The draft required the attached report template unless a competent authority prescribed otherwise.

当前规则

The final text defers to competent-authority requirements and permits reference to national standards where no requirement exists.

实际影响:Organizations should monitor sector-specific report requirements rather than rely on the draft annex.

Draft Article 13; final Article 15.

modified

Report submission

此前规则

Submission within 10 working days after completing the annual assessment.

当前规则

Submission within 20 working days after completing the annual assessment.

实际影响:The final rule doubles the stated submission period.

Draft Article 14; final Article 16.

modified

Certified assessor trigger

此前规则

The draft used mandatory language for specified cases and prioritized certified assessors for voluntary engagement.

当前规则

The final measures use a defined authority power to require a certified assessor in specified risk or incident cases and encourage certification generally.

实际影响:The final text changes the trigger structure and should replace draft-based workflow assumptions.

Draft Articles 8–9 and 15; final Articles 8–9 and 17.

deleted

Draft annex

此前规则

The consultation package included a network data security risk assessment report template.

当前规则

The final measures do not include that annex.

实际影响:The consultation template should not be presented as a mandatory final form.

Compare the official consultation and final publication pages.

官方来源