Business Support

Technical Support

About Guangxun

About Ainopol

Order No.176 Replaces Order No.151: How Hotels and Enterprises Achieve Cybersecurity Compliance? How to Select AINOPOL Products?
2026-09-11 15:11:29 5

On August 6, 2026, the Ministry of Public Security issued the Measures for Public Security Organs' Supervision and Inspection of Cyberspace Security (Order No. 176 of the Ministry of Public Security), which will officially take effect on October 1, 2026. Meanwhile, the Provisions for Public Security Organs' Supervision and Inspection of Internet Security (Order No. 151 of the Ministry of Public Security) issued in 2018 shall be repealed simultaneously.


This is more than just a replacement of old regulations with new ones; the scope of supervision has expanded from the "Internet" to the entire "cyberspace".

In other words, whether you run a hotel or a physical enterprise, as long as you use networks, process data, or handle user information, you may be subject to regular inspections.

What hotels and enterprises truly need to consider is how to build a network infrastructure that can continuously meet regulatory requirements.

I. What exactly has changed under Order No.176?

The new Order No.176 officially replaces Order No.151, bringing an all-round upgrade to cybersecurity supervision. Corporate internal networks, data and personal information are all brought under supervision, substantially increasing compliance pressure on all business entities.

  1. Broader supervision scope: upgraded from "Internet access security" to "cyberspace security"
    The old Order No.151 was limited to Internet security. Article 2 of the newly issued Order No.176 clearly defines cyberspace security as the combination of network security, data security and information security, greatly expanding the boundary of supervision.

The Data Security Law and Personal Information Protection Law serve directly as the legal basis for supervision and inspection, rather than being restricted merely to Internet-layer security.

Even non-public business systems, internal data warehouses and employee information databases fall within the scope of public security inspections as long as they involve data and information security.

  1. More entities under supervision: inspections may apply even without Internet connectivity


Previously, inspected subjects were limited to two categories of Internet service providers and internet-connected entities. Now, any entity engaged in network operation, data processing, personal information processing and other related activities may become an inspection target.

This means the supervision covers not only Internet companies, but also cash register systems of offline merchants, property management companies’ surveillance platforms, and any other systems that process data.

Many organizations used to believe that "no external exposure means no security obligations". This mindset is no longer valid. Security responsibilities must also be implemented for internal network assets and data assets.

  1. Smarter inspection methods: less disruption, yet no escape from oversight


The former Order No.151 mainly relied on on-site inspections. The new Order No.176 explicitly grants the legal authority for remote technical detection, forming a combined model of preliminary online remote screening plus on-site verification, alongside the implementation of a flexible law enforcement mechanism.

Changes in inspection methods: Previously, inspections were mostly carried out on-site. Now priority is given to online patrols and remote testing. Issues that can be resolved remotely will be handled remotely first to minimize on-site visits.
Inspection frequency defined: For Level 3 and above (high-grade) systems, only one on-site inspection will be conducted per year. Clear criteria are in place to avoid arbitrary and frequent inspections.
Mutual recognition of inspection results: If inspections have already been completed by other authorities (such as MIIT and the Cyberspace Administration) within the year, public security organs will directly adopt those results and will not repeat on-site inspections for the same matter.

II. What will be inspected? What are the consequences upon non-compliance?

Article 7 of Order No.176 specifies 11 key routine inspection items, fully covering the three dimensions of network security, data security and information security.

Among them, filing administration, log retention and anti-virus protection are mandatory routine inspection items. Supervision over the whole process control of cybersecurity grading protection, protection of critical information infrastructure, and closed-loop rectification of vulnerabilities has been significantly strengthened. Algorithm security as well as data and personal information protection are newly added verification points in this regulation.

Against the inspection checklist of the new rules, enterprises generally exhibit five prominent problems:

  • Unclear inventory of data assets: No clarity on where sensitive data is stored, its types or how data flows, with a lack of data asset inventories and classification and grading.
  • No audit traceability for operational activities: Absence of audit records for operations on databases, business systems and API interfaces. Logs are fragmented with unsynchronized timestamps, making traceability and location identification impossible when security incidents occur.
  • Unprotected transmission of sensitive data: Sensitive data is transmitted in plaintext in high-risk scenarios including test environments, outsourced delivery and report export, bringing potential leakage risks.
  • Ineffective operation and maintenance access control: Insufficient access management for high-privilege accounts such as DBAs and third-party maintenance personnel, which may lead to unauthorized operations.
  • No closed-loop risk self-inspection: Vulnerability rectification is perfunctory without re-inspection records; documents for each phase of graded protection are incomplete; compliance ledgers and rectification records are inadequate and fail to provide verifiable evidence.

What happens if non-compliance is identified?

Order No.176 itself does not impose fines directly. Instead, it acts as a "measuring ruler". Once risks are identified, penalties will be imposed in accordance with higher-level laws such as the Data Security Law. Consequences fall into tiered levels:

Tier 1 (Problems identified, rectification ordered)
Public security authorities will supervise rectification, issue public security notice letters, release circulars for disposal, or interview persons-in-charge.

Tier 2 (Failure to perform data security protection obligations)
Pursuant to Article 45 of the Data Security Law, fines ranging from 50,000 RMB to 500,000 RMB may be imposed on the entity; persons directly responsible may face fines from 10,000 RMB to 100,000 RMB.

Tier 3 (Refusal to rectify or occurrence of serious consequences)
Where massive data leakage and other severe outcomes occur, fines will rise to between 500,000 RMB and 2 million RMB. Authorities may order suspension of relevant business, business shutdown for rectification, or even revocation of relevant business permits or business licenses. Fines for directly responsible persons will also increase to 50,000 RMB to 200,000 RMB.

III. How Enterprises and Hotels Achieve Compliance

As network supervision continues to tighten, hotels and enterprises, as network operators, must guarantee network user experience while strictly meeting the mandatory requirements of network security and compliance:

  • Real-name authentication: Guests accessing WiFi must complete real identity registration (supporting ID cards, passports and other documents). It shall be traceable who is using the network.
  • Log retention for over 6 months: Identity logs, internet access logs and system operation logs shall be stored locally for more than six months and retrievable for presentation during public security inspections.
  • Data and personal information protection: How guest/employee information is stored, who can access it, and whether encryption is deployed. This is a new focus under Order No.176 and also the weakest link for most hotels in the past.
  • Basic security protection: Anti-virus, intrusion prevention, data backup and other safeguards.
  • Policies and responsible personnel: Appoint cybersecurity responsible persons and establish management systems and emergency response procedures. Inspections assess not only hardware, but also personnel.

IV. AINOPOL: Compliance Solution for the Era of Order No.176


The Mengxiang-series Secure Optical Gateway serves as the core of the complete solution. It natively integrates real-name authentication, log auditing, perimeter security protection and data access control within a single hardware appliance. There is no need to stack third-party devices from multiple vendors, which avoids compatibility failures caused by multi-device interaction.

  1. Diverse authentication methods: It supports 18 authentication modes including PMS integration via room numbers, WeChat Portal, SMS verification, and ID document recognition. It meets the real-name internet access requirements for hotel guests, visitors and staff, satisfying the mandatory identity verification requirements for online access stipulated in Order No.176.
  2. 180-day internet access log retention: The gateway locally encrypts and stores complete 5-tuple internet access records, identity information and operation logs for 180 days with tamper-proof protection. It also supports one-click retrieval and export of compliance reports to readily handle online inspections and on-site audits. This addresses common pain points faced by many organizations, such as log gaps, missing fields and difficult log retrieval.
  3. Native security protection capabilities: Equipped with a 2nd-generation firewall, it integrates IPS intrusion prevention, AV antivirus scanning and WAF web protection to block external network attacks. It also blocks unauthorized private connections of illegal terminals and segregates network segments for visitors, office services and IoT services, mitigating risks of lateral movement within the internal network and data leakage.

Furthermore, the Mengxiang Gateway supports three deployment modes: routing, bridge and bypass. For new projects, the routing mode can directly replace egress devices. For existing hotels and enterprises unwilling to modify their current networks, transparent bridge inline connection or bypass mirror access is available. Large-scale reconstruction of existing networks is unnecessary. Compliance upgrades can be completed quickly without service interruption, suiting projects with different budgets and renovation conditions.

The implementation of Ministry of Public Security Order No.176 marks a new phase of cyberspace security supervision in China featuring broader coverage and refined law enforcement.

For network operators of public venues such as hotels, shopping malls and industrial parks, proactively understanding policy changes, sorting out compliance gaps and selecting implementable technical solutions is a rational choice to reduce risks and guarantee business continuity.

Compliance is never a one-time project, but an ongoing operational task requiring continuous investment. When real-name authentication becomes frictionless, log retention runs automatically, and security inspections have verifiable evidence, enterprises can truly turn compliance pressure into service competitiveness.

If you want to learn more about deploying authentication and auditing capabilities complying with Order No.176 within your existing network environment, please contact our technical team for targeted scenario assessment recommendations.