National Cybersecurity Incident Reporting Measures effective 1 Nov 2025 (CAC)
Analysis
By UA Ledger staff — 2 min read

CAC’s National Cybersecurity Incident Reporting Measures (issued 11 September 2025) take effect 1 November 2025. Ordinary network operators must report larger-or-above incidents to provincial CAC within four hours; CII timelines are tighter.
CAC published the full text of the 国家网络安全事件报告管理办法 on 15 September 2025 (document dated 11 September 2025). Article 14 states the measures take effect on 1 November 2025. The page we opened on 20 September 2026 includes the operative articles and the annexed 网络安全事件分级指南.
Reporting clocks (Article 4)
When an operator discovers or learns of a cybersecurity incident affecting its systems and grades it 较大以上 (larger or above) under the guide:
- Critical information infrastructure: report to the protection department and public security immediately, no later than 1 hour. For 重大 / 特别重大 incidents, the protection department must escalate to national CAC and the Ministry of Public Security within 30 minutes.
- Central/state organs and direct units: report to the department’s cyberspace office within 2 hours; major/particularly major escalate to national CAC within 1 hour.
- Other network operators: report to the provincial cyberspace department within 4 hours; major/particularly major escalate from provincial to national CAC within 1 hour.
Article 7 lists required report fields (entity, time/place/type/level, impact, measures, cause hypothesis, forensics clues, requested support, site protection). Article 8 requires a disposition summary within 30 days after handling ends. Article 9 establishes the 12387 reporting channels.
What this is not
This is a statutory reporting procedure, not a breach notification template for every PIPL individual notice, and not evidence that any named game or MMP already filed under the new clocks. The commission shorthand “tiered 1–4 hour timelines” matches the 1-hour (CII), 2-hour (central organs) and 4-hour (other operators) outer bounds for larger-or-above incidents—not a single uniform four-hour rule for every entity.
Operator action
| Field | Evidence |
|---|---|
| Issued | 2025-09-11 |
| CAC page date | 2025-09-15 |
| Effective | 2025-11-01 |
| Other operators (较大以上) | ≤4 hours to provincial CAC |
| CII | ≤1 hour to protection dept + PSB |
| Hotline | 12387 |
| UA implication | China player / ad-account incidents that meet the grade thresholds need pre-built escalation runbooks; do not invent an incident that was not reported |
Download the measures card. Preserve November 2025 as the effective date when citing this rule later.
Research checked 20 September 2026. Local draft; human editorial review pending.
Featured
Related posts
measurement
platforms
·1 min read
When to turn rewarded ads off for payers (and how to measure the loss)
measurement
platforms
·1 min read
When custom product pages need their own MMP campaign mapping
measurement
platforms
·1 min read
Season pass refund rate versus standard IAP refund rate
measurement
platforms
·1 min read
Pre-reg cohort quality vs post-launch paid cohort quality
More from the Measurement desk
measurement
platforms
·2 min read
AppLovin Ad Review drops user-level journeys for aggregate-only reporting
measurement
platforms
·2 min read
Apple adds an EU alternative ATT prompt from iOS 27.2 — mandatory in five markets
measurement
platforms
·1 min read
Pity-adjusted expected value versus player-facing banner claims
measurement
platforms
·1 min read