EN 1090
European standard for steel/aluminium structural execution
MLPS 2.0 (Multi-Level Protection Scheme)
China's mandatory graded protection scheme for network security
Quick Verdict
EN 1090 ensures safe steel/aluminium fabrication with CE marking for EU construction, while MLPS 2.0 mandates graded cybersecurity for Chinese networks. Companies adopt EN 1090 for market access; MLPS 2.0 to avoid fines and ensure compliance.
EN 1090
EN 1090 Execution of steel and aluminium structures
Key Features
- Factory Production Control (FPC) certification required
- Risk-based Execution Classes (EXC1-EXC4)
- Mandates CE marking under CPR
- Technical execution rules for steel/aluminium
- Welding quality aligned with ISO 3834
MLPS 2.0 (Multi-Level Protection Scheme)
Multi-Level Protection Scheme 2.0
Key Features
- Five-level classification based on societal impact
- Mandatory audits and PSB approval for Level 2+
- Technical controls for cloud, IoT, big data, ICS
- Governance with role separation and personnel vetting
- Enforced by Public Security Bureaus inspections
Detailed Analysis
A comprehensive look at the specific requirements, scope, and impact of each standard.
EN 1090 Details
What It Is
EN 1090 is a harmonized European standard series for execution and conformity assessment of structural steel and aluminium components. It implements CPR requirements, enabling CE marking. Primary scope covers fabrication, assembly, and market placement of load-bearing components. Key approach is risk-based via Execution Classes (EXC1-EXC4), scaling controls by consequence, service, and production categories.
Key Components
- **EN 1090-1Conformity assessment, FPC certification, DoP.
- **EN 1090-2/-3Technical rules for steel/aluminium (materials, welding, tolerances, corrosion, NDT).
- Core: Traceability, welding per ISO 3834, inspection regimes.
- AVCP systems with Notified Body oversight.
Why Organizations Use It
Mandated for EU market access; reduces liability, ensures safety. Drives capability in welding, traceability; enhances competitiveness via certification. Builds stakeholder trust through verified performance.
Implementation Overview
Phased: gap analysis, FPC build, personnel training, NB certification, surveillance. Targets fabricators; 6-12 months typical. Requires welding coordinators, digital records.
MLPS 2.0 (Multi-Level Protection Scheme) Details
What It Is
MLPS 2.0 (Multi-Level Protection Scheme 2.0) is China's mandatory cybersecurity regulation, operationalizing Article 21 of the Cybersecurity Law. It classifies information systems into five protection levels based on potential impact to national security, social order, and public interests, requiring graded technical, management, and governance controls.
Key Components
- Core domains: physical security, network protection, data security, access control, monitoring, governance.
- Baseline controls for all levels plus extended requirements for cloud, IoT, big data, ICS.
- Built on national standards like GB/T 22239-2020.
- Compliance via self-classification, third-party audits (Level 2+), PSB approval.
Why Organizations Use It
- Legal obligation for all network operators in China; non-compliance risks fines, suspensions.
- Enhances risk management, resilience; supports market access, procurement.
- Builds regulator trust, avoids enforcement by Public Security Bureaus.
Implementation Overview
- Phased: scoping, classification, gap analysis, remediation, audits, ongoing monitoring.
- Applies to all sizes, industries in mainland China; higher costs/audits for Level 3+. (178 words)
Key Differences
| Aspect | EN 1090 | MLPS 2.0 (Multi-Level Protection Scheme) |
|---|---|---|
| Scope | Execution of steel/aluminium structures, CE marking | Graded cybersecurity for all networks/systems |
| Industry | Construction, fabrication (EU/EEA) | All sectors operating networks (China) |
| Nature | Harmonized technical standard, FPC certification | Mandatory cybersecurity regulation, PSB enforcement |
| Testing | FPC audits, ITT/ITC by notified bodies | Third-party evaluations, PSB inspections (Level 2+) |
| Penalties | Market exclusion, no CE marking | Fines, operations suspension, inspections |
Scope
Industry
Nature
Testing
Penalties
Frequently Asked Questions
Common questions about EN 1090 and MLPS 2.0 (Multi-Level Protection Scheme)
EN 1090 FAQ
MLPS 2.0 (Multi-Level Protection Scheme) FAQ
You Might also be Interested in These Articles...

CMMC Level 3 Implementation Guide: Integrating NIST SP 800-172 Enhanced Controls for APT Defense
Step-by-step CMMC Level 3 guide for DIB contractors. Implement 24 NIST SP 800-172 controls on Level 2. Prep for DIBCAC, C3PAO scoping & 180-day POA&Ms. Boost cy

CIS Controls v8.1 for Cloud & Kubernetes: A Practical Implementation Playbook (AWS/Azure/GCP + IaC)
Translate CIS Controls v8.1 to cloud-native: Kubernetes patterns for IAM, logging, vuln mgmt, hardening on AWS, Azure, GCP + IaC. Practical playbook for teams.

CIS Controls v8.1 for Cloud & SaaS: A Practical Safeguard Playbook for AWS/Azure/GCP and Microsoft 365
Turn CIS Controls v8.1 into a cloud-first playbook for AWS, Azure, GCP & Microsoft 365. Get actionable IaaS/PaaS/SaaS safeguards, automation patterns, evidence
Run Maturity Assessments with GRADUM
Transform your compliance journey with our AI-powered assessment platform
Assess your organization's maturity across multiple standards and regulations including ISO 27001, DORA, NIS2, NIST, GDPR, and hundreds more. Get actionable insights and track your progress with collaborative, AI-powered evaluations.
Check out these other Gradum.io Standards Comparison Pages
GLBA vs MAS TRM
Discover GLBA vs MAS TRM: Compare US financial privacy/safeguards rules with Singapore's tech risk guidelines. Key insights for global compliance, security strategies.
CMMC vs MLPS 2.0 (Multi-Level Protection Scheme)
Discover CMMC vs MLPS 2.0: Compare DoD's tiered cybersecurity model with China's graded protection scheme. Key insights for DIB firms mastering global compliance challenges.
COBIT vs ISO 27701
COBIT vs ISO 27701: IT governance powerhouse meets privacy PIMS standard. Compare domains, design factors & controls for compliance, risk. Choose your fit now!