institutions or meet the requirements of security detection before being sold or provided. The national
cyberspace administration authority shall, in concert with the relevant departments under the State Council,
formulate and release the catalog of critical network equipment and specialized cybersecurity products, and
promote the mutual recognition of security certification and security detection results, so as to avoid
repeated certifications and detections.
Article 24 When network operators handle network access and domain registration services for users, handle
network access formalities for fixed-line or mobile phone users, or provide users with information
publication services, instant messaging services and other services, they shall require users to provide real
identity information at the time of signing agreements with users or confirming the provision of services.
Where users do not provide real identify information, network operators shall not provide them with
relevant services.
The State implements the strategy of trusted identities in cyberspace, supports the research and
development of secure and convenient technologies for electronic identity authentication, and promotes the
mutual recognition among different electronic identification authentications.
Article 25 Network operators shall formulate contingency plans for cybersecurity incidents, and promptly
deal with system bugs, computer viruses, network attacks and intrusions and other security risks; when any
incident endangering cybersecurity occurs, network operators shall immediately initiate contingency plans,
take corresponding remedial measures, and report the same to the relevant competent departments in
accordance with the provisions.
Article 26 Carrying out such activities as cybersecurity authentication, detection and risk evaluation, and
releasing cybersecurity information like system bugs, computer viruses, network attacks and intrusions to
society shall comply with the relevant regulations of the State.
Article 27 Any individual or organization shall neither engage in activities endangering cybersecurity,
including illegally invading others' networks, interfering with the normal functions of others' networks and
stealing cyber data, nor provide programs or tools specifically used for activities endangering cybersecurity,
such as network intrusions, interference with the normal functions and protective measures of the network,
and theft of cyber data; if such individual or organization knows that a person engages in activities
jeopardizing cybersecurity, it shall not provide technical support, advertising promotion, payment and
settlement services or other types of assistance to such person or organization.
Article 28 Network operators shall provide technical support and assistance to the public security organs and
state security organs in lawfully safeguarding national security and investigating crimes.
Article 29 The State supports the cooperation among network operators in areas such as collection, analysis,
and reporting of cybersecurity information and emergency disposal, so as to improve the ability of network
operators to safeguard the security.
Relevant industrial organizations shall establish and perfect cybersecurity protection regulations and
coordination mechanisms for their own industry, strengthen the analysis and evaluation of cybersecurity
risks, regularly give risk warnings to their members, and support and assist members in handling
cybersecurity risks.
Article 30 The information acquired by cyberspace administration authorities and relevant departments in
the course of their fulfillment of responsibilities for protecting cybersecurity shall be used exclusively for the
need of cybersecurity protection rather than for any other purpose.
Section 2 Operation Security of Critical Information Infrastructure
5