On October 1, 2026, the Ministry of Public Security's Measures for Public Security Organs' Supervision and Inspection of Cyberspace Security (Order No. 176) took effect. They replace the 2018 Provisions on Internet Security Supervision and Inspection (Order No. 151). The text is dated August 6, 2026, and the ministry released it on August 7. The new rules are short, 23 articles, but they change what police may do to a company's systems.
The strongest case for the rules
The case for them deserves a fair hearing. China's security regime now rests on the Cybersecurity Law, the Data Security Law, the Personal Information Protection Law and the Critical Information Infrastructure (CII) Protection Regulation. The 2018 provisions predate most of it. Hunton Andrews Kurth describes the new measures as consolidating police inspection authority to match that stack. A single instrument is easier to follow than scattered practice. Many governments also test operators' defences, and unpatched systems do get breached, so a regulator that can find vulnerabilities before criminals do is not inherently illegitimate.
The measures also contain real procedural limits. According to the text as published by provincial public security bodies, on-site inspections need at least two officers with credentials and a supervision notice from a county-level or higher organ. Authorities are told to "避免重复检查、交叉检查" (avoid duplicate and cross inspections) to limit the burden on companies. Routine on-site visits for MLPS Level 3-and-above networks and CII operators are capped at one a year, and inspected entities pay no fees (Hunton).
What actually changed
The headline power is remote testing. Article 4 lets prefecture-level and higher public security organs conduct "漏洞探测、渗透性测试" (vulnerability probing and penetration testing) against networks and information systems in their jurisdiction. It applies to those other than CII, and the target gets three working days' notice of timing and scope (Ankang Public Security Bureau text; Guizhou provincial text). Online monitoring, network patrols and capability testing sit alongside it. CII operators are handled under separate CII regulations.
That is a notable shift in kind. Penetration testing is normally something a company commissions, scopes and controls. Here it is something the police do to an ordinary operator, with a notice period but no stated requirement of consent, warrant or independent review. The notice protects against surprise outages. It does not protect against the test itself.
Article 7 sets the scope of review at 11 areas. Several are routine security hygiene: security management systems, vulnerability remediation, malware defences, graded-protection duties. Others are not. The list includes user registration and activity logging, "prohibited content" filtering mechanisms, algorithm recommendation management responsibility, and technical cooperation with law enforcement for national security (Ankang text). In other words, a cybersecurity inspection also audits whether a platform's speech controls and data retention satisfy the police.
Why the design worries us
Three problems stand out, each tied to the text.
First, mixing security and content. A vulnerability scan answers a technical question. Whether a platform filters enough "prohibited content" is a political judgement. Putting both in one inspection regime gives the same officers leverage over technical operations and expression. For a pro-speech, pro-innovation publication, that bundling is the core concern. Operators have every incentive to over-block and over-retain user data to pass an inspection.
Second, security risk from the inspection itself. The measures allow police to delegate work to third-party technical firms. Contractors must pledge confidentiality over trade secrets and personal information they learn, and Article 20 bars staff from disclosing, selling or unlawfully providing such material. Hunton adds that contractors face background vetting and that misconduct can bring disciplinary or criminal liability. Those are sensible provisions, but they are promises, not independent oversight. Every outside party with access to a company's vulnerability data is a possible leak, and the findings of a penetration test are among the most sensitive data a company holds.
Third, repeat-offender targeting. Entities with prior incidents or uncorrected administrative penalties get priority inspection. That is defensible as risk-based enforcement, but it also means the firms that disclose incidents are the ones that attract the most scrutiny, which discourages disclosure.
Commentators also read the measures as extending reach toward corporate data processing, personal information management and cross-border transfers, which matters for foreign firms with China operations (ChinaPulse). We could not confirm that reading from the operative text alone. What is clear is that the 11-area list covers data and personal information protection.
A proportionate alternative
Nothing here requires abandoning inspection. A proportionate version would separate security testing from content review. It would put remote penetration testing behind written, scoped authorisation that the operator can contest, and publish aggregate inspection statistics. It would also require that vulnerability findings be held by the agency and not by commercial contractors, and give operators a route to challenge priority-inspection designations. Several of those safeguards are partly present, such as notice, credentials and contractor confidentiality. The gap is independent review.
The measures are best read as a real improvement in procedure sitting on top of a real expansion in reach. Businesses operating in China should expect notices, plan for three-day response windows, and treat vulnerability data as something that will be shared with the state. Whether the safeguards hold depends on enforcement in practice, which this text cannot show.