Chapter III Network Operation Security

Article 40

Permalink

Translation Notice

This is an unofficial English translation prepared for general informational purposes only. It does not constitute legal advice. In case of any discrepancy, the official Chinese text published by the competent authority shall prevail.

本文为非官方英文翻译,仅供一般信息参考,不构成法律意见。如与主管机关发布的中文正式文本不一致,以中文正式文本为准。

Chinese Original

第四十条 关键信息基础设施的运营者应当自行或者委托网络安全服务机构对其网络的安全性和可能存在的风险每年至少进行一次检测评估,并将检测评估情况和改进措施报送相关负责关键信息基础设施安全保护工作的部门。

Translation Status

Site reference translation is in editorial review for this article. The Chinese original above is the controlling official text; do not treat this status note as a translation.

Plain English Note

Site explanation only. Not part of the translation.

Article 40 is part of the CSL critical information infrastructure framework and should be read with CII protection, security review, and annual assessment requirements.

  • cybersecurity
  • critical information infrastructure

Related rules: Critical Information Infrastructure Security Protection Regulation

Related standards: GB/T 22239; GB/T 28448

Source reference: CSL Article 40. Source authority: Cyberspace Administration of China publication; source text from the Standing Committee of the National People's Congress. Effective version: 2026-01-01 amended effective version. Amendment status: amended by 2025-10-28 amendment decision; current official text uses article-number gaps. Last verified: 2026-05-20. Last updated: 2026-05-20. Official source.