Delivering from CDN nodes inside mainland China is a separate product and compliance decision, not just a checkbox on a global network map. Confirm current requirements with qualified local counsel and the selected service provider before launch; this page is technical guidance, not legal advice.

Start with the delivery region

Decide whether the requirement is:

  1. edge delivery from nodes inside mainland China;
  2. delivery from nearby locations outside the mainland, such as Hong Kong, Japan, or Singapore; or
  3. one global configuration that includes the mainland.

These designs have different onboarding, performance, feature, contract, and regulatory consequences. For example, Alibaba Cloud’s current CDN documentation distinguishes mainland-only, global, and global-excluding-mainland acceleration regions. It requires an ICP filing for the first two and not for the third. See Alibaba Cloud’s acceleration-region documentation.

ICP filing is an architecture prerequisite

Alibaba Cloud’s ICP filing overview states that domain names resolving to servers in mainland China require the appropriate filing before service. Its CDN-specific guidance says a domain accelerated in mainland China or a global region must have an ICP filing.

Requirements vary by service type, entity, province, content, and provider. Treat the filing, licence, content review, domain ownership, and access-provider relationship as launch dependencies. Do not promise a filing timeline until the provider has reviewed the actual entity and service.

Understand the operating model

Some international CDN brands provide mainland delivery through a licensed local partner. Cloudflare, for example, states that its China Network is a separate Enterprise subscription operated with JD Cloud, requires a valid ICP filing or licence and content vetting, and does not expose every global-network feature. See Cloudflare’s onboarding guide and China Network FAQ.

For every candidate, document:

  • the contracting entity and licensed network operator;
  • domains and content approved for onboarding;
  • which edge, security, logging, certificate, and compute features differ from the global service;
  • where configuration, logs, and personal data are stored or processed;
  • support ownership across the international vendor and local partner;
  • the procedure for changing or removing a domain.

Design the origin path

An in-mainland edge does not guarantee a fast application if cache misses travel to a distant origin. Measure both cache hits and origin fetches. Consider a compliant regional origin, origin shielding, controlled replication, or a deliberately cache-heavy static architecture where appropriate.

Keep cache keys and TTLs consistent across mainland and global configurations unless a documented requirement differs. Review cache-key design, cache control, and Multi-CDN cache consistency before splitting traffic.

Measure before committing

Run tests from several mainland cities, access networks, device types, and times of day. Record DNS time, connection and TLS time, time to first byte, download throughput, cache status, origin-fetch time, error rate, and route changes. Compare the same object and protocol against nearby offshore delivery.

Do not rely on a provider’s global point-of-presence count or a single synthetic probe. Validate the exact domain, product, local-partner configuration, and traffic mix that will be purchased.

Launch checklist

  1. Define mainland and offshore user journeys separately.
  2. Confirm filing, licensing, content-review, and domain prerequisites with the provider and counsel.
  3. Inventory feature differences and data-handling implications.
  4. Test cache-hit and cache-miss paths from multiple networks.
  5. Validate certificates, DNS, IPv6, logging, WAF rules, and purge behavior.
  6. Establish an offshore fallback and decide when it is acceptable to use it.
  7. Record the source URLs and review date for every compliance and product claim.
  8. Recheck requirements before material domain, entity, origin, or provider changes.

Profiles for Alibaba Cloud CDN, ChinaNetCenter, ChinaCache, and other providers are starting points for research, not proof that a particular account or domain is eligible.