APIS Consulting

← Blog

MLPS 2.0 grading, explained without the jargon

Five ascending security levels illustrating China's MLPS 2.0 grading system

Almost every information system operated in China falls under the Multi-Level Protection Scheme — 等级保护, usually shortened to MLPS or "dengbao". It assigns your system a protection grade from 1 to 5, and that grade dictates the controls you must implement and whether an accredited assessment is mandatory.

What the grade actually measures

The grade is not about how sensitive you think your data is. It is set by the harm that would result to citizens, organisations, or the state if the system were breached or disrupted. Most commercial systems land at Grade 2 or Grade 3 — and the jump between those two is where cost and obligation rise sharply.

Why self-assessing carelessly hurts

Two failure modes are common:

  • Under-grading to avoid the assessment burden — which becomes a compliance finding

the moment a regulator or partner looks closely.

  • Over-grading out of caution — which saddles a modest system with Grade 3

obligations it never needed.

The grade is a deliberate judgement, best made with someone who has argued the classification before.

The short version

Establish the grade honestly, document the reasoning, implement the matching controls, and — at Grade 3 and above — plan for the accredited assessment. Done in that order, it is manageable. Discovered late, it is not.

Official reference

The baseline referred to in this article is China’s current national standard, GB/T 22239-2019: Information security technology, Baseline for classified protection of cybersecurity. The standard page records its status and the most recent review information.

← All articles