- China's Cyberspace Administration launched a cybersecurity review into Palo Alto Networks products, citing national security and cybersecurity laws.
- Chinese organisations were told to identify and replace any designated cybersecurity products with domestic technologies by the first half of 2026.
- The move came just a day after China's Ministry of Commerce (MOFCOM) announced countermeasures in response to US escalation of unilateral protectionist moves, stating that the US seriously violates the important consensus reached by the two heads of state and severely damages China's legitimate rights and interests.
- Beijing has stepped up scrutiny of foreign technology suppliers while promoting domestic alternatives, saying imported products used in sensitive networks could expose data or critical infrastructure to overseas risks.
- The move comes amid growing trade and technology tensions between Beijing and Washington that have threatened an uneasy truce achieved at recent high-level bilateral summits.
- China's commerce ministry announced on Wednesday a on U.S. companies and U.S.-bound drone exports, describing them as countermeasures to Washington's recent curbs on Chinese companies' access to the U.S. market. The CAC did not say whether the Palo Alto review was linked to the commerce ministry's measures.
- Experts said the review is a necessary measure to safeguard national security, not merely a countermeasure amid bilateral frictions, and that it carries added significance given Washington's history of cyber penetration.
- Given Palo Alto Networks' wide product coverage across networking, cloud, security operations, and AI, its extensive presence raises the likelihood of systemic security risks, while the review also alerts current customers to examine any present or future technical vulnerabilities and security shortcomings, Zhou said.
- The regulator's latest action echoes its 2023 review of U.S. memory-chip maker Micron Technology. The CAC later said Micron's products had failed the review and told operators of China's critical information infrastructure to stop buying them, citing national security risks.
- Micron has since stopped supplying server chips to data centres in China after the business from the ban, Reuters reported in October. It continues to sell to some Chinese customers, including in the automotive and mobile-phone sectors.
China has launched a cybersecurity review of products sold by Palo Alto Networks, citing risks to critical information infrastructure and national security. The review, initiated by the Cyberspace Administration of China (CAC), is part of a broader strategy to enhance domestic cybersecurity measures amid rising tensions with the U.S.1
The CAC stated that the review is necessary to protect critical infrastructure and prevent cybersecurity vulnerabilities, referencing national security laws. Chinese organizations are required to replace any products from designated foreign companies with domestic alternatives by the first half of 2026. This move follows accusations against Palo Alto Networks and other foreign firms of having links to intelligence services, although no evidence has been provided.2

Shares of Palo Alto Networks fell as much as 4.2% following the announcement, reflecting investor concerns over the implications of the review. “If any foreign firm operating in China endangers critical network infrastructure or presents a genuine risk, it is both lawful and justifiable for regulators to conduct the necessary inquiries,” said Zhou, a cybersecurity analyst.
The review aligns with China's ongoing efforts to scrutinize foreign technology suppliers while promoting domestic alternatives, as the government believes that imported products could expose sensitive data to overseas risks. “Conducting a cybersecurity review of Palo Alto Networks is a necessary measure to safeguard national security,” said Qin An, a director at Tianjin University.
This action echoes previous reviews, such as that of Micron Technology, which faced similar scrutiny and was subsequently banned from supplying certain products to China.12
“The review, initiated under China's national security and cybersecurity laws, did not identify specific products or alleged vulnerabilities. It echoes the 2023 Micron Technology review, which led to a ban on its products, and comes a day after MOFCOM announced countermeasures against US companies.”