China EditionArticle 5 · China Edition

Three-Tier Compliance System & MLPS 2.0 Integration

Three-Tier Compliance System & MLPS 2.0 Integration


Beneath the voluntary industry initiative framework lies the mandatory cybersecurity baseline required by Chinese law. Three tiers, one baseline.

Core Principle: Voluntary Framework, Mandatory Baseline

The three-tier compliance system established by this framework — "Community Committed," "Community Mutual Benefit," and "Community Exemplary" — is built atop a non-negotiable baseline:

Multi-Level Protection Scheme 2.0 (MLPS 2.0, GB/T 22239-2019) is a mandatory compliance requirement for all data centers. This framework's three-tier system does not replace, reduce, or exempt any obligations under MLPS 2.0. Data centers must first complete MLPS 2.0 compliance at their applicable level before applying for this framework's tier certification.

This design aligns with the recommendation of Qwen Max (our Chinese policy reviewer): "Any internal three-tier framework must explicitly state that it operates on top of mandatory MLPS 2.0."


Three-Tier System in Detail

Tier 1: Community Committed

ElementRequirement
Entry thresholdMLPS 2.0 filing and assessment completed at the applicable level
Framework commitmentPublicly declare adoption of this framework, publish a compliance roadmap
Baseline establishmentComplete baseline data collection for all five pillar indicators
TimelineBaseline establishment within 12 months from the date of declaration
Disclosure requirementPublic compliance roadmap + annual progress summary

Tier 1 is the "entry tier" — designed with a threshold achievable by all compliantly operating data centers. Its core value lies in the visibility of the public commitment: once declared, both the community and regulators can track its progress.


Tier 2: Community Mutual Benefit

ElementRequirement
EntryMLPS 2.0 completed + Tier 1 maintained for 12 months
Core indicatorsAll five pillar core indicators met
AuditAnnual independent third-party audit — full audit report publicly disclosed
EnergyPUE compliant (non-hub nodes ≤ 1.30, hub nodes ≤ 1.25 or lower)
WaterWUE ≤ 1.0 L/kWh · Water stress assessment completed
Community benefitCommunity benefit sharing agreement signed and implemented
DisclosureAnnual community impact report published · Real-time dashboard (non-CII) or periodic regulatory reports (CII)

Tier 2 is the baseline compliance tier of this framework — representing "what data centers ought to achieve."

CII Special Note: Data centers involving Critical Information Infrastructure (CII) should evaluate whether an upgrade to MLPS Level 4 is required (Article 14 of the Regulations on the Security Protection of Critical Information Infrastructure). The additional requirements of MLPS Level 4 do not affect the structure of this framework's three-tier system, but may affect specific compliance timelines for Tiers 2 and 3.

Tier 3: Community Exemplary

ElementRequirement
EntryMLPS 2.0 completed + Tier 2 maintained for 24 months
Leading indicatorsAchieve industry-leading performance in at least two pillar areas
Innovative practiceAt least one community benefit innovation practice with publicly documented case records
Industry contributionPublicly share operational data (desensitized) to advance industry benchmarking
Community verificationIndependent community satisfaction survey — positive rating ≥ 80%

Tier 3 represents "what data centers can become" — not the ceiling of compliance, but the exemplar of community relations.


Relationship Between the Three-Tier System and MLPS 2.0

``

┌──────────────────────┐

│ Tier 3: Community │ ← Aspirational

│ Exemplary │

├──────────────────────┤

│ Tier 2: Community │ ← Baseline Compliance

│ Mutual Benefit │

├──────────────────────┤

│ Tier 1: Community │ ← Entry Commitment

│ Committed │

├══════════════════════┤

│ MLPS 2.0 Mandatory │ ← Legal Baseline (Non-Negotiable)

│ GB/T 22239-2019 │

└──────────────────────┘

``
⚠️ Note: Some CII scenarios legally require MLPS Level 4. "MLPS 2.0" in this diagram is a general reference; the specific level must be determined in accordance with the Regulations on the Security Protection of Critical Information Infrastructure and the Cybersecurity Law.

Compliance Disclosure Requirements Summary

TierPublic DisclosureRegulatory ReportingCommunity Notification
Tier 1Roadmap + Annual summaryPer MLPS requirementsAnnual
Tier 2Audit report + Impact report + Real-time dashboard*Per MLPS + CII requirementsQuarterly
Tier 3All Tier 2 content + Industry shared dataSame as aboveMonthly
CII data centers replace public real-time dashboards with periodic regulatory reports.

Eternal Harmony is an AI research and development company. This is part of our public-interest research on technology infrastructure and community impact.

This framework is an independent initiative, not approved or endorsed by any government agency.