RoHS
EU directive restricting hazardous substances in EEE
MLPS 2.0 (Multi-Level Protection Scheme)
China's mandatory graded cybersecurity protection framework
Quick Verdict
RoHS restricts hazardous substances in EEE for EU market access, ensuring safe recycling. MLPS 2.0 mandates graded cybersecurity for Chinese networks, protecting national security. Companies adopt RoHS for global trade compliance; MLPS for China operations.
RoHS
Directive 2011/65/EU (RoHS 2)
Key Features
- Homogeneous material limits: 0.1% most substances, 0.01% cadmium
- Open scope: all EEE unless explicitly excluded
- Time-limited exemptions via delegated acts (Annex III/IV)
- Requires technical documentation and EU Declaration of Conformity
- Tiered verification: XRF screening to IEC 62321 lab testing
MLPS 2.0 (Multi-Level Protection Scheme)
Multi-Level Protection Scheme 2.0
Key Features
- Five-level impact-based system classification
- Mandatory registration and PSB approval (Level 2+)
- Graded technical controls for cloud, IoT, ICS
- Third-party audits with 75/100 pass score
- Law enforcement oversight and periodic re-evaluations
Detailed Analysis
A comprehensive look at the specific requirements, scope, and impact of each standard.
RoHS Details
What It Is
Directive 2011/65/EU (RoHS 2) is an EU regulation restricting hazardous substances in electrical and electronic equipment (EEE). It aims to protect health and environment by limiting substances during waste management, complementing WEEE Directive. Scope covers all EEE unless excluded, with restrictions at homogeneous material level using maximum concentration values (MCVs): 0.1% for most, 0.01% for cadmium.
Key Components
- Ten restricted substances (Pb, Cd, Hg, Cr(VI), PBB, PBDE, four phthalates).
- **Annexes III/IVTime-limited exemptions for specific uses.
- Compliance via technical documentation, EU Declaration of Conformity (DoC), and CE marking.
- IEC 63000 for documentation; IEC 62321 for testing.
Why Organizations Use It
Mandated for EU market access; prevents fines, recalls. Drives supply chain governance, substitution innovation, recyclability. Enhances ESG reputation, level playing field.
Implementation Overview
Risk-based: scope analysis, BoM review, supplier declarations, tiered testing (XRF/ICP-MS), exemption tracking. Applies to manufacturers/importers of EEE globally selling to EU; 6-18 months typical, no central certification but audit-ready files retained 10 years.
MLPS 2.0 (Multi-Level Protection Scheme) Details
What It Is
MLPS 2.0 (Multi-Level Protection Scheme) is China's legally mandated regulatory framework for graded cybersecurity protection of information systems and networks. Enforced under the 2017 Cybersecurity Law (Article 21), it requires operators to classify systems into five levels based on potential harm to national security, social order, and public interests, implementing commensurate technical, governance, and organizational controls.
Key Components
- Core domains: physical security, network protection, data security, access control, monitoring, and governance.
- Standards like GB/T 22239-2019, GB/T 25070-2019 define baselines, extended for cloud, IoT, big data, ICS.
- Built on impact-based classification; Levels 2+ require third-party audits (75/100 score minimum) and PSB approval.
Why Organizations Use It
- Mandatory for all mainland China network operators, including foreign firms; non-compliance risks fines, suspensions.
- Enhances resilience, supports market access, aligns with data laws; builds regulator trust.
Implementation Overview
- Phased: scoping, classification, gap analysis, remediation, audits, ongoing re-evaluations.
- Applies universally; higher costs/audits for Levels 3+; suits all sizes in China operations.
Key Differences
| Aspect | RoHS | MLPS 2.0 (Multi-Level Protection Scheme) |
|---|---|---|
| Scope | Hazardous substances in EEE materials | Graded cybersecurity for all networks |
| Industry | EEE manufacturers globally, EU-focused | All network operators in China |
| Nature | EU product restriction directive, mandatory | Chinese cybersecurity regulation, mandatory |
| Testing | XRF screening, IEC 62321 lab tests | Third-party audits, PSB inspections |
| Penalties | Fines, recalls by Member States | Fines, suspensions by PSBs |
Scope
Industry
Nature
Testing
Penalties
Frequently Asked Questions
Common questions about RoHS and MLPS 2.0 (Multi-Level Protection Scheme)
RoHS FAQ
MLPS 2.0 (Multi-Level Protection Scheme) FAQ
You Might also be Interested in These Articles...

DORA Third-Party Risk Management: A Consultant’s Guide to Mapping Critical ICT Service Providers in 2026
Navigate DORA's complex third-party risk pillar. Step-by-step consultant guide to identify critical ICT providers, remediate Article 30 contracts, and build the

SOC 2 Audit Survival Guide: First 5 Steps to Ace Your Type 2 Audit with Infographic
Ace your SOC 2 Type 2 audit with the first 5 essential steps: evidence collection, auditor tips, red flags from SignWell's experience. Get checklists & infograp

Thailand PDPA Implementation Guide: Subordinate Regulations for 72-Hour Breach Reporting and Cross-Border Transfers (2022-2024 Rules)
Step-by-step Thailand PDPA guide: 72-hour breach notifications, cross-border transfers (2022-2024 rules). Risk checklists, GDPR templates avoid THB 5M fines. Mu
Run Maturity Assessments with GRADUM
Transform your compliance journey with our AI-powered assessment platform
Assess your organization's maturity across multiple standards and regulations including ISO 27001, DORA, NIS2, NIST, GDPR, and hundreds more. Get actionable insights and track your progress with collaborative, AI-powered evaluations.
Check out these other Gradum.io Standards Comparison Pages
CE Marking vs ISO 27001
Discover CE Marking vs ISO 27001: EU product safety marking or global ISMS standard? Key differences, requirements, strategies for compliance & market success. Read now!
NIS2 vs Australian Privacy Act
Unlock NIS2 vs Australian Privacy Act: EU cyber resilience meets Aussie data safeguards. Compare scopes, reporting, fines & strategies for global compliance success!
CAA vs Basel III
CAA vs Basel III: Compare Clean Air Act air quality standards with Basel III banking capital/liquidity rules. Unlock compliance strategies, pitfalls, and executive guides for resilient operations.