National Financial Regulatory Administration, Measures for the Administration of Cybersecurity in the Banking and Insurance Industries (Draft for Comments)

国家金融监督管理总局银行业保险业网络安全管理办法 (征求意见稿)

Critical information infrastructure operators in the banking and insurance sectors are required to focus on commercial cryptography management / Issued: 2026-07-10

By Susan Mok

Issued: July 10, 2026





Main contents: The Measures cover the asset security management, internet perimeter protection, internal network perimeter protection, vulnerability and defect management, application software security, remote access permissions, endpoint and media control, supply chain security, new technology security, outsourced security management, cryptographic security management, data security management and personal information security management of Financial Institutions in the banking and insurance industries, as well as financial holding companies (Financial Institutions).

Exclusive Content

A Subscription is Required to Access this Content

Subscribe to China Law & Practice today for:

  • Access to 3000+ essential documents, including key PRC laws translated into English
  • Newsletters with business-critical and sector-specific updates
  • Premium mobile access with timely analysis on China’s fast-changing market

Already a Subscriber? Log In Here

Questions? Contact us at [email protected] | 1-855-808-4530 (Americas) | 44(0) 800 098 386009 (UK & Europe)