EN 1090 vs MLPS 2.0 (Multi-Level Protection Scheme)
EN 1090
European standard for steel/aluminium structural execution
MLPS 2.0 (Multi-Level Protection Scheme)
China's mandatory graded protection scheme for network security
Quick Verdict
EN 1090 ensures safe steel/aluminium fabrication with CE marking for EU construction, while MLPS 2.0 mandates graded cybersecurity for Chinese networks. Companies adopt EN 1090 for market access; MLPS 2.0 to avoid fines and ensure compliance.
EN 1090
EN 1090 Execution of steel and aluminium structures
Key Features
- Factory Production Control (FPC) certification required
- Risk-based Execution Classes (EXC1-EXC4)
- Mandates CE marking under CPR
- Technical execution rules for steel/aluminium
- Welding quality aligned with ISO 3834
MLPS 2.0 (Multi-Level Protection Scheme)
Multi-Level Protection Scheme 2.0
Key Features
- Five-level classification based on societal impact
- Mandatory audits and PSB approval for Level 2+
- Technical controls for cloud, IoT, big data, ICS
- Governance with role separation and personnel vetting
- Enforced by Public Security Bureaus inspections
Detailed Analysis
A comprehensive look at the specific requirements, scope, and impact of each standard.
EN 1090 Details
What It Is
EN 1090 is a harmonized European standard series for execution and conformity assessment of structural steel and aluminium components. It implements CPR requirements, enabling CE marking. Primary scope covers fabrication, assembly, and market placement of load-bearing components. Key approach is risk-based via Execution Classes (EXC1-EXC4), scaling controls by consequence, service, and production categories.
Key Components
- **EN 1090-1Conformity assessment, FPC certification, DoP.
- **EN 1090-2/-3Technical rules for steel/aluminium (materials, welding, tolerances, corrosion, NDT).
- Core: Traceability, welding per ISO 3834, inspection regimes.
- AVCP systems with Notified Body oversight.
Why Organizations Use It
Mandated for EU market access; reduces liability, ensures safety. Drives capability in welding, traceability; enhances competitiveness via certification. Builds stakeholder trust through verified performance.
Implementation Overview
Phased: gap analysis, FPC build, personnel training, NB certification, surveillance. Targets fabricators; 6-12 months typical. Requires welding coordinators, digital records.
MLPS 2.0 (Multi-Level Protection Scheme) Details
What It Is
MLPS 2.0 (Multi-Level Protection Scheme 2.0) is China's mandatory cybersecurity regulation, operationalizing Article 21 of the Cybersecurity Law. It classifies information systems into five protection levels based on potential impact to national security, social order, and public interests, requiring graded technical, management, and governance controls.
Key Components
- Core domains: physical security, network protection, data security, access control, monitoring, governance.
- Baseline controls for all levels plus extended requirements for cloud, IoT, big data, ICS.
- Built on national standards like GB/T 22239-2019.
- Compliance via self-classification, third-party audits (Level 2+), PSB approval.
Why Organizations Use It
- Legal obligation for all network operators in China; non-compliance risks fines, suspensions.
- Enhances risk management, resilience; supports market access, procurement.
- Builds regulator trust, avoids enforcement by Public Security Bureaus.
Implementation Overview
- Phased: scoping, classification, gap analysis, remediation, audits, ongoing monitoring.
- Applies to all sizes, industries in mainland China; higher costs/audits for Level 3+. (178 words)
Key Differences
| Aspect | EN 1090 | MLPS 2.0 (Multi-Level Protection Scheme) |
|---|---|---|
| Scope | Execution of steel/aluminium structures, CE marking | Graded cybersecurity for all networks/systems |
| Industry | Construction, fabrication (EU/EEA) | All sectors operating networks (China) |
| Nature | Harmonized technical standard, FPC certification | Mandatory cybersecurity regulation, PSB enforcement |
| Testing | FPC audits, ITT/ITC by notified bodies | Third-party evaluations, PSB inspections (Level 2+) |
| Penalties | Market exclusion, no CE marking | Fines, operations suspension, inspections |
Scope
Industry
Nature
Testing
Penalties
Frequently Asked Questions
Common questions about EN 1090 and MLPS 2.0 (Multi-Level Protection Scheme)
EN 1090 FAQ
MLPS 2.0 (Multi-Level Protection Scheme) FAQ
You Might also be Interested in These Articles...

Evidential Readiness Blueprint: Mapping Multi-Cloud Access Controls to Cyber Essentials Audit Requirements
Step-by-step blueprint for IT managers to document and verify access control plus patch management evidence across Microsoft 365, AWS, and Azure for first-time

The NIS2 "FTE Trap": Why 5 Analysts for 24/7 Security is Actually 8 (and Why the Board Needs to Know)
Exposed: NIS2 FTE Trap math shows 5 analysts fail 24/7 coverage due to sickness, training, leave & 2026 churn. Line-by-line breakdown for compliance. Alert your

Decoding Tomorrow's Regulations: How Advanced Compliance Tools Predict and Prepare for Future Shifts
Advanced compliance tools use AI, analytics & real-time monitoring to predict regulatory shifts, cut non-compliance costs 3x, and ensure audit readiness. Stay p
Run Maturity Assessments with GRADUM
Transform your compliance journey with our AI-powered assessment platform
Assess your organization's maturity across multiple standards and regulations including ISO 27001, DORA, NIS2, NIST, GDPR, and hundreds more. Get actionable insights and track your progress with collaborative, AI-powered evaluations.
Explore More Comparisons
See how EN 1090 and MLPS 2.0 (Multi-Level Protection Scheme) compare against other standards