Three-Tier Compliance System & MLPS 2.0 Integration
Beneath the voluntary industry initiative framework lies the mandatory cybersecurity baseline required by Chinese law. Three tiers, one baseline.
Core Principle: Voluntary Framework, Mandatory Baseline
The three-tier compliance system established by this framework — "Community Committed," "Community Mutual Benefit," and "Community Exemplary" — is built atop a non-negotiable baseline:
Multi-Level Protection Scheme 2.0 (MLPS 2.0, GB/T 22239-2019) is a mandatory compliance requirement for all data centers. This framework's three-tier system does not replace, reduce, or exempt any obligations under MLPS 2.0. Data centers must first complete MLPS 2.0 compliance at their applicable level before applying for this framework's tier certification.
This design aligns with the recommendation of Qwen Max (our Chinese policy reviewer): "Any internal three-tier framework must explicitly state that it operates on top of mandatory MLPS 2.0."
Three-Tier System in Detail
Tier 1: Community Committed
| Element | Requirement |
| Entry threshold | MLPS 2.0 filing and assessment completed at the applicable level |
| Framework commitment | Publicly declare adoption of this framework, publish a compliance roadmap |
| Baseline establishment | Complete baseline data collection for all five pillar indicators |
| Timeline | Baseline establishment within 12 months from the date of declaration |
| Disclosure requirement | Public compliance roadmap + annual progress summary |
Tier 1 is the "entry tier" — designed with a threshold achievable by all compliantly operating data centers. Its core value lies in the visibility of the public commitment: once declared, both the community and regulators can track its progress.
Tier 2: Community Mutual Benefit
| Element | Requirement |
| Entry | MLPS 2.0 completed + Tier 1 maintained for 12 months |
| Core indicators | All five pillar core indicators met |
| Audit | Annual independent third-party audit — full audit report publicly disclosed |
| Energy | PUE compliant (non-hub nodes ≤ 1.30, hub nodes ≤ 1.25 or lower) |
| Water | WUE ≤ 1.0 L/kWh · Water stress assessment completed |
| Community benefit | Community benefit sharing agreement signed and implemented |
| Disclosure | Annual community impact report published · Real-time dashboard (non-CII) or periodic regulatory reports (CII) |
Tier 2 is the baseline compliance tier of this framework — representing "what data centers ought to achieve."
CII Special Note: Data centers involving Critical Information Infrastructure (CII) should evaluate whether an upgrade to MLPS Level 4 is required (Article 14 of the Regulations on the Security Protection of Critical Information Infrastructure). The additional requirements of MLPS Level 4 do not affect the structure of this framework's three-tier system, but may affect specific compliance timelines for Tiers 2 and 3.
Tier 3: Community Exemplary
| Element | Requirement |
| Entry | MLPS 2.0 completed + Tier 2 maintained for 24 months |
| Leading indicators | Achieve industry-leading performance in at least two pillar areas |
| Innovative practice | At least one community benefit innovation practice with publicly documented case records |
| Industry contribution | Publicly share operational data (desensitized) to advance industry benchmarking |
| Community verification | Independent community satisfaction survey — positive rating ≥ 80% |
Tier 3 represents "what data centers can become" — not the ceiling of compliance, but the exemplar of community relations.
Relationship Between the Three-Tier System and MLPS 2.0
``
┌──────────────────────┐
│ Tier 3: Community │ ← Aspirational
│ Exemplary │
├──────────────────────┤
│ Tier 2: Community │ ← Baseline Compliance
│ Mutual Benefit │
├──────────────────────┤
│ Tier 1: Community │ ← Entry Commitment
│ Committed │
├══════════════════════┤
│ MLPS 2.0 Mandatory │ ← Legal Baseline (Non-Negotiable)
│ GB/T 22239-2019 │
└──────────────────────┘
``⚠️ Note: Some CII scenarios legally require MLPS Level 4. "MLPS 2.0" in this diagram is a general reference; the specific level must be determined in accordance with the Regulations on the Security Protection of Critical Information Infrastructure and the Cybersecurity Law.
Compliance Disclosure Requirements Summary
| Tier | Public Disclosure | Regulatory Reporting | Community Notification |
| Tier 1 | Roadmap + Annual summary | Per MLPS requirements | Annual |
| Tier 2 | Audit report + Impact report + Real-time dashboard* | Per MLPS + CII requirements | Quarterly |
| Tier 3 | All Tier 2 content + Industry shared data | Same as above | Monthly |
CII data centers replace public real-time dashboards with periodic regulatory reports.
Eternal Harmony is an AI research and development company. This is part of our public-interest research on technology infrastructure and community impact.
This framework is an independent initiative, not approved or endorsed by any government agency.