You can refer to this document when releasing apps in the Chinese mainland.
HUAWEI AppGallery has provided the following FAQs and guidance related to the security assessment report, to strengthen security management of Internet information services and corresponding new technologies and apps that destabilize public opinions, and implement the policies stipulated in: Cybersecurity Law of the People's Republic of China, Regulation on Internet Information Service of the People's Republic of China, Measures for the Administration of Security Protection of Computer Information Networks with International Interconnections, Administrative Regulations on Assessing the Security of New Technologies and Applications for Internet News Information Service, Provisions on the Security Assessment for Internet Information Services with Public Opinion Attributes or Social Mobilization Capabilities, Provisions on the Administration of Deep Synthesis Internet Information Services, and Provisional Measures for Management of Generative AI Services. This helps ensure that you are better able to assess security risks, and work closely with AppGallery to maintain a secure network environment.
1. Why do I need to submit the security assessment report, and for which apps is the report required?
- The Provisions on the Security Assessment for Internet Information Services with Public Opinion Attributes or Social Mobilization Capabilities ("the Provisions" for short) stipulate that Internet information service providers who are able to destabilize public opinions shall perform security assessments on their own, or via a third party, based on the legality of their information services, new technologies, and new apps, and the effectiveness of implementing security measures and preventing and controlling security risks. For apps that have passed the security assessment and comply with laws, administrative regulations, departmental rules, and standards, a security assessment report shall be developed and submitted to the cyberspace administration and the public security organs on the National Internet Security Management Service Platform.
According to Article 3 of the Provisions, Internet information service providers that fall under any of the following circumstances shall conduct a security assessment on their own in accordance with the Provisions and shall be responsible for the assessment results:
(1) Launching information services with public opinion attributes or social mobilization capabilities, or adding related functions to existing services.
(2) Using new technologies or apps that cause significant changes to the functional attributes, technical implementation methods, or underlying resource configurations of the information service, resulting in substantial changes to its public opinion attributes or social mobilization capabilities.
(3) Significant increase in the user scale, leading to substantial changes in the public opinion attributes or social mobilization capabilities of the information service.
(4) Occurrence of dissemination or spread of illegal or harmful information, indicating that existing security measures are insufficient to effectively prevent cybersecurity risks.
(5) Other circumstances where cybersecurity authorities at or above the municipal level, or public security authorities, issue a written notice requiring a security assessment.
The term "Internet information services with public opinion attributes or social mobilization capabilities" as referenced in the Provisions includes the following circumstances:
(1) Operating information services such as forums, blogs, microblogs, chat rooms, communication groups, public accounts, short-video platforms, live-streaming services, information-sharing services, mini programs, or providing corresponding functions.
(2) Operating other Internet information services that provide channels for public opinion expression or have the capability to mobilize the public to engage in specific activities. - According to the Provisions on the Administration of Deep Synthesis Internet Information Services and Provisional Measures for Management of Generative AI Services, the deep synthesis or generative AI service providers and technical support parties that provide tools, including models and templates, with any of the following functions, shall perform a security assessment by themselves or by entrusting a professional institute to do so:
(1) Function that generates or edits biometric information such as facial and voice information
(2) Function that generates or edits non-biometric information about special objects or scenarios that may involve national security and public interests.
The following are representative examples of such apps:


2. How do I submit the security assessment report to relevant departments for review?
Sign in to the National Internet Security Management Service Platform. For details about the process, please refer to the security assessment guidelines on the platform.

3. How do I upload the security assessment report to AppGallery?
When releasing a relevant app to AppGallery, you will also need to upload the security assessment report and screenshots of the result from your submission to the National Internet Security Management Service Platform.
How to upload: Sign in to AppGallery Connect, click Apps and atomic services, and find your app. Click Version information, and upload the report to Proof of copyright under Copyright information.

Example of a security assessment report:

Notes:
The service name in the security assessment report must match the name of the uploaded app, and the organization name must match the developer name.
Examples of submission result screenshots:
Example 1:

Example 2:

Notes:
(1) Provide a screenshot of the submission result of the security assessment report on the National Internet Security Management Service Platform, with an onsite inspection result of "Passed" or a review status of "Approved".
(2) The service name or name in the screenshots must match the name of the uploaded app.
(3) The entity name on the screenshots must match the developer name.
4. Does the service name in the security assessment report need to be consistent with the app name?
Yes. Please make sure that the service name and company name in the report are consistent with those of the app released on AppGallery.
5. Can the assessment execution party in the security assessment report be the company to which the app belongs?
Yes. According to the Provisions, Internet information service providers can perform a security assessment on their own or via a third party. If the self-assessment mode is selected, the assessment execution party shall be the company to which the app belongs, and the person in charge of the assessment shall come from the same company. If the third-party assessment mode is selected, the assessment execution party shall be a third party, and the person in charge of the assessment shall come from the third party.
6. Can I authorize others to use the security assessment report?
No. Internet information service providers shall perform the security assessment in accordance with the Provisions, comprehensively assess the legality of their information services, new technologies, and new apps, and the effectiveness of implementing security measures specified in applicable laws, administrative regulations, department regulations, and standards, and effectiveness of preventing and controlling security risks, as well as be responsible for assessment results, and rectify security risks in a timely manner.
7. How do I obtain the review progress of the submitted security assessment report?
For details about other security assessment–related issues and on-site check progress, please contact the local cyberspace administration and public security organs.
These FAQs will be updated in accordance with latest policy requirements.
If you have any further questions, you can contact us in the interaction center of AppGallery Connect. Thank you for your support.
Related policies:
Provisional Measures for Management of Generative AI Services
Provisions on the Administration of Deep Synthesis Internet Information Services
Cyberspace Administration of China and Ministry of Public Security Strengthen the Security Assessment on New Internet Technologies and Applications Such as Voice-based Social Applications and Deep Fake Technologies
Provisions on the Security Assessment for Internet Information Services with Public Opinion Attributes or Social Mobilization Capabilities
AppGallery - Interpretation of App Qualification Review Standards: Security Assessment Report