The Multi-Level Protection Scheme (MLPS), commonly referred to as "Dengbao," serves as the cornerstone of China's cybersecurity regulatory framework. On December 1, 2019, the "Information Security Technology—Baseline for Cybersecurity Classification Protection" (GB/T 22239-2019) officially came into effect, marking the comprehensive transition of the MLPS from the 1.0 era to the 2.0 era. MLPS 2.0 represents not only an upgrade in technical standards but also a paradigm shift in regulatory philosophy—moving from passive defense to proactive defense, and from static compliance to dynamic security. For enterprise security leaders, gaining an in-depth understanding of the requirements of MLPS 2.0 and effectively driving compliance implementation is a fundamental aspect of their responsibilities. This article will systematically outline the core requirements and practical implementation points of MLPS 2.0.
The Five-Level Classification System of Cybersecurity Classified Protection 2.0
- ›Level 1 (User Self-Protection Level): When an information system is compromised, it causes harm to the legitimate rights and interests of citizens, legal entities, and other organizations, but does not endanger national security, social order, or public interests. Generally applicable to small internal systems. ---ITEM--- Level 2 (System Audit Protection Level): When an information system is compromised, it causes serious harm to the legitimate rights and interests of citizens, legal entities, and other organizations, or harms social order and public interests. Requires filing with the local municipal public security authority. ---ITEM--- Level 3 (Security Label Protection Level): When an information system is compromised, it causes serious harm to social order and public interests, or endangers national security. Requires filing with the local municipal public security authority and undergoing at least one annual security protection assessment. ---ITEM--- Level 4 (Structured Protection Level): When an information system is compromised, it causes particularly serious harm to social order and public interests, or causes serious harm to national security. Requires undergoing at least one security protection assessment every six months. ---ITEM--- Level 5 (Access Verification Protection Level): When an information system is compromised, it causes particularly serious harm to national security. Applicable to a very small number of national-level core systems.
Basic Requirements for Filing and Assessment
According to the "Cybersecurity Level Protection Regulations," operators of Level 2 and above information systems must complete the filing procedures with the cybersecurity protection department of the public security bureau at the municipal level or above within 30 days after the system goes live. During the filing process, the "Information System Security Level Protection Filing Form" and relevant supporting documents for the system's security protection facilities must be submitted. For Level 3 and above systems, a system security level assessment report is also required. The assessment must be conducted by a nationally certified level protection assessment service provider, and self-assessment by enterprises is not permitted. The list of assessment agencies is published by the cybersecurity protection departments of provincial-level public security bureaus. The cost of the assessment varies depending on the scale and level of the system, with a single assessment for a Level 3 system typically ranging from 150,000 to 300,000 yuan.
Expanded Coverage Areas of Multi-Level Protection Scheme 2.0
One of the most significant changes in Classified Protection 2.0 compared to 1.0 is the expansion of its protection scope from traditional information systems to five emerging domains. The cloud computing security extension requirements define the respective security responsibility boundaries for cloud service customers and cloud service providers. The Internet of Things (IoT) security extension requirements propose layered security control measures for the perception layer, network transmission layer, and processing application layer. The mobile internet security extension requirements cover mobile terminal management, mobile application security, and wireless network security. The industrial control system security extension requirements focus on the security of industrial control protocols, SCADA system protection, and industrial control network isolation. The big data security extension requirements emphasize data collection security, data storage security, data processing security, and data exchange security. These five extended domains enable Classified Protection 2.0 to meet the security protection needs of the digital transformation era.
Personnel Requirements for Level 3 and Above Systems
- ›A dedicated security management organization (such as an Information Security Department or Cybersecurity Center) should be established, operating independently from the Information Technology department. ---ITEM--- Dedicated security management personnel should be assigned, with a recommendation of at least 2-3 full-time security personnel for Level 3 systems. ---ITEM--- The person in charge of security management should possess a professional background in information security or hold certifications such as the Classified Protection Evaluation Engineer or CISP. ---ITEM--- Key personnel (security administrators, security auditors, system administrators) should undergo security background checks. ---ITEM--- A security personnel training system should be established to ensure that security management and technical personnel receive no less than 20 hours of security training annually.
Industry Differences and Special Requirements
Different industries have varying minimum requirements for the classification of cybersecurity protection levels. The financial sector is one of the most stringent in terms of cybersecurity protection requirements. According to regulations issued by the People's Bank of China and the China Banking and Insurance Regulatory Commission, the core business systems of banks are generally required to meet at least Level 3, while payment and clearing systems typically require Level 4. In the telecommunications industry, foundational network infrastructure and core business support systems are classified as critical information infrastructure. These systems must comply with Level 3 or higher cybersecurity protection standards and additionally meet the specific requirements for the protection of critical information infrastructure. In the healthcare sector, core business systems (such as HIS and EMR systems) in tertiary-level or higher medical institutions are generally required to meet at least Level 3. In the education industry, university information systems and online education platforms, which handle large amounts of student personal information, are typically required to meet Level 2 or higher. In the energy sector, industrial control systems such as power monitoring systems and oil and gas SCADA systems are generally required to meet Level 3 or higher, with additional compliance requirements for industrial control security extensions.
Security Officer's Practical Checklist for Multi-Level Protection Scheme (MLPS) Compliance
- ›Step 1: Asset Inventory and Classification – Conduct a comprehensive inventory of the enterprise's information system assets. Perform preliminary classification based on the importance of the business functions supported and the sensitivity of the data handled. Prepare the "Information System Security Classification Protection Classification Report." ---ITEM--- Step 2: Filing and Registration – Submit the classification report and relevant materials to the local municipal public security bureau's cybersecurity department to complete the filing process and obtain the filing certificate. ---ITEM--- Step 3: Gap Analysis – Conduct a comprehensive gap analysis of existing security protection measures by comparing them against the basic requirements of the Classified Protection 2.0 standards. ---ITEM--- Step 4: Security Construction and Remediation – Develop and implement a remediation plan to address non-compliance issues identified during the gap analysis. ---ITEM--- Step 5: Level Assessment – Engage a qualified assessment agency to conduct a Classified Protection assessment and obtain the assessment report. ---ITEM--- Step 6: Continuous Monitoring and Improvement – Establish a security operation and continuous improvement mechanism to ensure ongoing compliance with security protection standards.
Common Compliance Misconceptions and Key Considerations
In the practice of Multi-Level Protection Scheme (MLPS) compliance, common misconceptions among enterprises include: treating MLPS compliance as a one-time project rather than an ongoing effort; underestimating the classification level of systems to reduce compliance costs, which, if discovered by public security authorities, may lead to orders for rectification and penalties; neglecting MLPS requirements for cloud environments and mobile applications, leaving some systems in compliance blind spots; over-reliance on stacking security products while overlooking the development of management systems, as MLPS 2.0 emphasizes both management and technical measures equally; equating MLPS assessment with security assurance, when assessments only reflect the security status at a specific point in time and cannot replace daily security operations. Security leaders should clearly recognize that MLPS compliance is the baseline requirement for enterprise cybersecurity construction, not the ceiling. Achieving compliance does not equate to absolute security; continuous security investment and operations are fundamental to safeguarding enterprise cybersecurity.



