BEIJING, 9 AUG 2026 — China's Cybersecurity Review Office opened a formal review on 6 August into Palo Alto Networks products sold in China. Chinese organisations were already told to stop using them in January, with a transition deadline that has now passed.
The sequence is unusual. A review normally decides whether a product may be used. This one arrives after the using largely stopped, which means it is doing something other than deciding.
What was announced
The review is being conducted under the National Security Law, the Cybersecurity Law and the Measures for Cybersecurity Review. The stated purpose is to safeguard the security and stable operation of critical information infrastructure, prevent cybersecurity risks and protect national security — the standard formula, naming no specific defect and setting out no allegation.
No finding has been published, no timetable given, and no particular product version identified. What exists so far is the opening of a process.
The order it comes in
-
The directive
Chinese authorities tell domestic organisations to stop using cybersecurity software from more than a dozen US and Israeli firms, Palo Alto Networks among them. Transition deadline set for the first half of 2026.
-
The Unit 42 report
Reuters reports that Palo Alto executives ordered researchers to soften a threat report, removing a direct attribution of an espionage campaign to Beijing. The researchers stood behind the attribution.
-
Deadline passes
The transition period given to domestic organisations expires.
-
Formal review opens
The Cybersecurity Review Office announces a review of Palo Alto products sold in China, citing three statutes and no specific defect.
Read down that column and the review is not the first move against this vendor. It is the fourth.
What a formal review adds that a directive does not
Three things, and none of them is access.
A published finding creates a durable legal basis. A directive is an instruction that can be revised quietly; a review that concludes a product presents risks to critical information infrastructure produces a document, and documents outlive the officials who issue them and travel into procurement rules that reference them.
It also converts a commercial exclusion into a security judgement, which is the form that carries weight outside China. Other governments and enterprises weighing the same vendor are not obliged to accept the conclusion, but they will still be asked to account for it.
And it is leverage that can be released. A review that concludes without adverse findings is an instrument available if a broader trade position shifts. Opening one costs little and preserves both outcomes.
Commentators have drawn the Micron parallel, and the shape is similar: a review of a named US supplier, concluded with a finding that then justified exclusion from critical infrastructure. The precedent is worth holding loosely — Micron sells memory and Palo Alto sells the security controls themselves, which is a different kind of dependency and a different argument about risk.
This is a mirror, and it is worth saying so
Reporting this as an isolated Chinese action would be a poor description of the decade it sits in.
Western governments have spent that decade excluding Chinese vendors from sensitive infrastructure on national-security grounds — telecoms equipment most prominently, later cameras, drones and applications — generally on the same reasoning now being applied in reverse: that a supplier subject to another state's legal compulsion is a risk in a position of trust, whatever the product does.
That argument is either sound or it is not, and it does not become unsound when a different capital makes it. A firewall vendor sits deeper in a network than almost any other supplier, sees the traffic, and ships signed updates to the device enforcing policy. If jurisdiction over a supplier is a legitimate reason to exclude one, it is legitimate symmetrically.
This is the real issue for organisations to plan for. The security market is fragmenting along the same lines the telecoms market already did: not because anyone proved a product malicious, but because buyers on both sides concluded that supplier jurisdiction is part of the threat model. There is no version of the coming decade in which a global enterprise runs one security stack everywhere without asking that question first.
The uncomfortable context
Reuters reported in February that Palo Alto executives had ordered Unit 42 researchers to soften a threat report by removing a direct attribution of a global espionage campaign to Beijing, after January's ban. The company's own researchers stood behind the China attribution on the forensic evidence.
Whatever was decided in that room, the episode is now the context for this review. A security vendor accused of trimming its published attribution of Chinese activity is being formally reviewed by the Chinese state — and there is no reading of that pair which flatters anybody.
It also illustrates a structural problem for every threat-intelligence vendor selling into markets it also reports on. The research is the product's credibility, and market access is the business, and those two things pull in opposite directions the moment the research names a state. The tension is structural, regardless of what happened in this specific case.
What this means if you buy security software
The practical question is not whether China's finding will be correct. It is that security tooling has become subject to the same national-sourcing pressure that already reshaped telecoms equipment, and the direction of travel is toward more of it rather than less.
For a multinational with operations in China, the near-term issue is concrete: a security stack that cannot legally be deployed in one jurisdiction becomes two security stacks, with two sets of detections, two consoles and two sets of people who understand them. Split estates are where gaps live, and the gap is rarely in the product — it is in the seam between the teams.
For everyone else, the useful exercise is to ask which of your controls would be difficult to replace if the vendor became unavailable for non-technical reasons. Firewalls, endpoint agents and the consoles that manage them are the deepest such dependencies most organisations have, and they are chosen on features rather than on jurisdictional risk.
What to watch
Whether the review publishes a finding at all, and whether it names a technical defect or rests on the statutory formula. Whether other vendors named in the January directive receive their own reviews, which would indicate a programme rather than a case. And whether any government outside China cites a Chinese finding in its own procurement guidance, which is the point at which a domestic security judgement becomes an export.