Beijing's internet regulator is reviewing US cybersecurity vendor Palo Alto Networks' products in China under the framework that grounded Micron in 2023, with no products named.
Beijing's internet regulator opened a formal cybersecurity review of Palo Alto Networks on August 6, invoking the statutory framework that grounded Micron's memory-chip sales in China in 2023. The Cyberspace Administration of China announced the review through its Cybersecurity Review Office, the body that led the Micron action, and disclosed no list of which Palo Alto Networks products are under scrutiny, no alleged vulnerabilities, and no timeline. The agency's public notice, carried by Xinhua and China Daily in Chinese and English, restates standard CAC language: the review aims "to ensure the secure and stable operation of critical information infrastructure, prevent cybersecurity risks, and safeguard national security" (CAC notice; Xinhua English; China Daily USA).
The Cybersecurity Review Office is the operational arm of Beijing's cyber regulator, created under the 2017 Cybersecurity Law and the National Security Law, and empowered to investigate whether foreign products pose national security risks to China's critical information infrastructure. The office can compel documentation, audit source code, and recommend restrictions on sales or procurement.
The 2023 Micron action is the closest precedent, trade-press analysis suggests. TechTimes and Geopolitechs treat the Palo Alto Networks review as a procedural parallel to the 2023 action that grounded Micron's memory-chip sales in China, applying the same statutory hooks and the same opacity (TechTimes; Geopolitechs). The CAC's Cybersecurity Review Office — the body behind both the Micron action and the current Palo Alto Networks review — has not published the specific 2023 Micron finding, its statutory basis, or the precise scope of the restriction in an English-language primary source in the current source bundle.
Palo Alto Networks is a structurally different target. The Santa Clara-based company is one of the largest US-headquartered cybersecurity vendors, with deep deployment inside Chinese enterprise and government networks. Its firewalls, intrusion-prevention systems, and Prisma Cloud platform sit in the same critical information infrastructure that the CAC review statute is designed to protect, but from the other side of the wire. A finding of "cybersecurity risk" against a network-security vendor, even one limited to sensitive sectors, carries a different procurement signal than the Micron outcome, because security buyers already self-screen on vendor trust.
The opacity of the announcement is itself the operative fact. The Register's "mysterious probe" characterization captures it: no products are named, no findings disclosed, no timeline given (The Register). The review period, not any public allegation, is the pressure on the vendor and its Chinese customers. A vendor under CAC review sits in regulatory limbo inside its largest addressable state-customer segment in Asia, because state-owned enterprises and critical infrastructure operators tend to de-risk away from products under active review before any finding lands.
What to watch next: a formal CAC conclusion, in the shape of the 2023 Micron finding, would give the first hard read on whether the review targets specific Palo Alto Networks product lines or the vendor's presence in critical infrastructure more broadly. The announcement is silent on overlap with US-China export controls and on procurement guidelines for state-owned enterprises, leaving both threads open. Reciprocal moves by the US government, including any Commerce Department or CISA posture toward Chinese security vendors operating in the US, would also mark the story's next phase. The 2023 Micron file shows what that posture produces: an effective exclusion from critical infrastructure buyers, not a public indictment.