China's Cyberspace Administration Launches Security Review of Palo Alto Networks
Miles Bennett
China's Cyberspace Administration launched a security review of Palo Alto Networks' products sold in the country, citing national-security risks. The move mirrors the playbook used against Micron in 2023 — and a 'fail' verdict could amount to a de facto ban.
What exactly is being reviewed?
The review targets Palo Alto Networks' products sold in China, citing risks to "national security and critical infrastructure."
The CAC named no specific products, disclosed no vulnerability details, and announced no immediate penalties.
This means → the review is a signal move for now; real impact hinges on whether a "failed" verdict follows.
Why now?
The announcement came one day after China unveiled a package of trade countermeasures against the United States.
Those measures include restricting Chinese firms from doing business with several U.S. entities, banning cooperation with U.S. compliance and certification bodies, and imposing export controls on drone components shipped to the U.S., per CNBC.
In plain terms = the timing is not coincidental — the security review is one card in a broader retaliation deck.
How deep is Palo Alto's China footprint?
The company operates offices in Beijing, Shanghai, Guangzhou, and Shenzhen.
In January, Chinese authorities already ordered domestic firms to stop using products from more than a dozen U.S. and Israeli companies, Palo Alto included, per Reuters.
This means → the review is not a cold start; Palo Alto has been on China's regulatory radar for months, and earlier restrictions are already in effect.
The precedent — what happened to Micron?
In 2023, the CAC ruled that Micron's products failed its security review, then barred China's critical-infrastructure operators from purchasing Micron chips.
Micron exited the Chinese data-center market, retaining only a slice of mobile and automotive customers.
This reflects the real power of the review: it is not the investigation itself that bites — it is the verdict. A "fail" is a de facto ban.
A delicate backdrop: Palo Alto's own actions
Its threat-intelligence unit, Unit 42, has repeatedly published reports attributing cyberattacks to Chinese state actors, including a March disclosure on an operation targeting Southeast Asian military bodies and a late-July identification of "an AI-powered autonomous hacking campaign by a Mandarin-speaking threat actor."
Yet in February, the company refused to attribute a global cyber-espionage campaign to the Chinese government, with executives fearing retaliation, per Reuters.
In plain terms = Palo Alto has been naming China in global reports while treading carefully inside the Chinese market — that balancing act is becoming untenable.
What to watch next?
The single question that matters: whether the review replicates the Micron playbook and culminates in a ban order.
A "fail" verdict would likely mean the same outcome — critical-infrastructure clients zeroed out.
This means → for Palo Alto, the risk in China has escalated from "regulatory friction" to an existential-level event for its local business.
Content is for reference only, not financial advice.