On August 6, 2026, the Ministry of Public Security issued the Measures for Public Security Organs' Supervision and Inspection of Cyberspace Security (Order No. 176 of the Ministry of Public Security), which will officially take effect on October 1, 2026. Meanwhile, the Provisions for Public Security Organs' Supervision and Inspection of Internet Security (Order No. 151 of the Ministry of Public Security) issued in 2018 shall be repealed simultaneously.

This is more than just a replacement of old regulations with new ones; the scope of supervision has expanded from the "Internet" to the entire "cyberspace".
In other words, whether you run a hotel or a physical enterprise, as long as you use networks, process data, or handle user information, you may be subject to regular inspections.
What hotels and enterprises truly need to consider is how to build a network infrastructure that can continuously meet regulatory requirements.
The new Order No.176 officially replaces Order No.151, bringing an all-round upgrade to cybersecurity supervision. Corporate internal networks, data and personal information are all brought under supervision, substantially increasing compliance pressure on all business entities.
The Data Security Law and Personal Information Protection Law serve directly as the legal basis for supervision and inspection, rather than being restricted merely to Internet-layer security.
Even non-public business systems, internal data warehouses and employee information databases fall within the scope of public security inspections as long as they involve data and information security.

Previously, inspected subjects were limited to two categories of Internet service providers and internet-connected entities. Now, any entity engaged in network operation, data processing, personal information processing and other related activities may become an inspection target.
This means the supervision covers not only Internet companies, but also cash register systems of offline merchants, property management companies’ surveillance platforms, and any other systems that process data.
Many organizations used to believe that "no external exposure means no security obligations". This mindset is no longer valid. Security responsibilities must also be implemented for internal network assets and data assets.

The former Order No.151 mainly relied on on-site inspections. The new Order No.176 explicitly grants the legal authority for remote technical detection, forming a combined model of preliminary online remote screening plus on-site verification, alongside the implementation of a flexible law enforcement mechanism.
Changes in inspection methods: Previously, inspections were mostly carried out on-site. Now priority is given to online patrols and remote testing. Issues that can be resolved remotely will be handled remotely first to minimize on-site visits.
Inspection frequency defined: For Level 3 and above (high-grade) systems, only one on-site inspection will be conducted per year. Clear criteria are in place to avoid arbitrary and frequent inspections.
Mutual recognition of inspection results: If inspections have already been completed by other authorities (such as MIIT and the Cyberspace Administration) within the year, public security organs will directly adopt those results and will not repeat on-site inspections for the same matter.

Article 7 of Order No.176 specifies 11 key routine inspection items, fully covering the three dimensions of network security, data security and information security.
Among them, filing administration, log retention and anti-virus protection are mandatory routine inspection items. Supervision over the whole process control of cybersecurity grading protection, protection of critical information infrastructure, and closed-loop rectification of vulnerabilities has been significantly strengthened. Algorithm security as well as data and personal information protection are newly added verification points in this regulation.
Against the inspection checklist of the new rules, enterprises generally exhibit five prominent problems:
What happens if non-compliance is identified?
Order No.176 itself does not impose fines directly. Instead, it acts as a "measuring ruler". Once risks are identified, penalties will be imposed in accordance with higher-level laws such as the Data Security Law. Consequences fall into tiered levels:
Tier 1 (Problems identified, rectification ordered)
Public security authorities will supervise rectification, issue public security notice letters, release circulars for disposal, or interview persons-in-charge.
Tier 2 (Failure to perform data security protection obligations)
Pursuant to Article 45 of the Data Security Law, fines ranging from 50,000 RMB to 500,000 RMB may be imposed on the entity; persons directly responsible may face fines from 10,000 RMB to 100,000 RMB.
Tier 3 (Refusal to rectify or occurrence of serious consequences)
Where massive data leakage and other severe outcomes occur, fines will rise to between 500,000 RMB and 2 million RMB. Authorities may order suspension of relevant business, business shutdown for rectification, or even revocation of relevant business permits or business licenses. Fines for directly responsible persons will also increase to 50,000 RMB to 200,000 RMB.
As network supervision continues to tighten, hotels and enterprises, as network operators, must guarantee network user experience while strictly meeting the mandatory requirements of network security and compliance:

The Mengxiang-series Secure Optical Gateway serves as the core of the complete solution. It natively integrates real-name authentication, log auditing, perimeter security protection and data access control within a single hardware appliance. There is no need to stack third-party devices from multiple vendors, which avoids compatibility failures caused by multi-device interaction.
Furthermore, the Mengxiang Gateway supports three deployment modes: routing, bridge and bypass. For new projects, the routing mode can directly replace egress devices. For existing hotels and enterprises unwilling to modify their current networks, transparent bridge inline connection or bypass mirror access is available. Large-scale reconstruction of existing networks is unnecessary. Compliance upgrades can be completed quickly without service interruption, suiting projects with different budgets and renovation conditions.
The implementation of Ministry of Public Security Order No.176 marks a new phase of cyberspace security supervision in China featuring broader coverage and refined law enforcement.
For network operators of public venues such as hotels, shopping malls and industrial parks, proactively understanding policy changes, sorting out compliance gaps and selecting implementable technical solutions is a rational choice to reduce risks and guarantee business continuity.
Compliance is never a one-time project, but an ongoing operational task requiring continuous investment. When real-name authentication becomes frictionless, log retention runs automatically, and security inspections have verifiable evidence, enterprises can truly turn compliance pressure into service competitiveness.
If you want to learn more about deploying authentication and auditing capabilities complying with Order No.176 within your existing network environment, please contact our technical team for targeted scenario assessment recommendations.