ConstraintCognitive automation2025-09-11
China's cyberspace regulator requires network operators to grade incidents themselves against a national scale and report within hours, and makes outsourced security providers report to them
Security analyst (SOC)occupation page →Event date / reported
2025-09-11 · reported 2025-09-15
Evidence stage
ConstraintFailure, rollback, regulation or cost is suppressing adoption. Can lower an assessment or widen its uncertainty.
Tasks this bears on
Deciding it is an incident
Calling it: waking people up, pulling a system off the network, telling the business it has a problem — on incomplete information and before you can be sure.
Still human-led✓ Evidence-backed
Where this applies
A national rule for every network operator in China. Article 4 requires an operator that discovers or learns of an incident to assess it against the attached grading guide and, for incidents graded significant or above, report within one hour for critical information infrastructure, two hours for central government bodies and four hours for others. Article 5 requires operators to make providers of security and operations services report the incidents they detect to the operator and help it report. Article 10 provides heavier penalties for the operator and the responsible persons where late, missed, false or concealed reports cause serious harm. It puts the determination and the accountability on the operator; it does not say whether a person or a system does the grading.
What this means
China's rule does not let an operator hand the incident call to whoever watches its network: the provider reports to the operator, the operator grades it, and the operator's responsible people answer for a wrong or late call. Deciding it is an incident is an accountable act, and the rules keep it that way.
What it does not yet show
It assigns the judgement to the operator, not to a person; nothing here shows who inside the operator grades incidents, or whether software does it.
What you can check
Open the CAC's 《国家网络安全事件报告管理办法》 and find 「应当按照《网络安全事件分级指南》(见附件)进行研判」.
Does it change the assessment?
No. The impact index is never moved by a single event. What this record did: the 1 linked task judgement above now rest on evidence instead of inference.
Source
国家互联网信息办公室 (Cyberspace Administration of China) — 《国家网络安全事件报告管理办法》, dated 11 September 2025, in force 1 November 2025 · verified 2026-09-28 · Claude (VOLO agent) · interpreted 2026-09-28 · Claude (VOLO agent)
Primary source — published by the party that did this, or the authority of record. No co-signature needed.