May 21, 2023 — China's Cybersecurity Review of Micron Technology
On May 21, 2023, China's Cybersecurity Review Office (CRO) announced that US chipmaker Micron Technology's products failed the cybersecurity review.
The review found that Micron products pose serious cybersecurity risks to China's critical information infrastructure (CII) supply chain, affecting national security.
Operators of CII — government agencies, large data centers, and telecom operators — were instructed to stop purchasing Micron products.
China revenue share declined from 58% peak to just 7.1% — a structural shift accelerated by the CAC decision
Sources: Micron SEC Filings (FY2018–FY2025), Digitimes Research, Company Annual Reports
Same legal playbook, opposite direction — but with key differences in scope, basis, and transparency
| Dimension | China → Micron (2023) | US → Huawei / ZTE | Verdict |
|---|---|---|---|
| Legal Form | Cybersecurity Review (CAC) | FCC orders, Entity List (BIS) | Same Security framing |
| Effect | Excludes Micron from CII procurement | Excludes Huawei/ZTE from US market | Same Foreign vendor exclusion |
| Scope | CII operators only — not general consumers | Broad — prohibits imports and sales entirely | Different Narrow vs. broad |
| Legal Basis | Product-based — specific technical findings in Micron products | Company-based — the firm itself is listed as a threat | Different Product vs. entity |
| Transparency | Limited — general statement of "serious risks" | Limited — national security rationale | Same Both are opaque |
What would a government need to publish for us to tell genuine security from market protection?
Not just "it's risky" — what exactly is the risk? Which component, which vulnerability, which threat vector? Without specifics, the decision is unverifiable.
Which law? How was the review conducted? What evidence was examined? Due process matters — security claims without procedural transparency are indistinguishable from protectionism.
Who must comply? What exactly is prohibited? Is there a path to remediation? A black-box decision gives us reason to doubt whether it is genuinely about security.
Sources: TrendForce, DRAMeXchange, CFM Flash Market
The Micron decision and US vendor bans are the same play run in opposite directions.
Both use security exceptions to restrict foreign vendors. The difference lies in scope, basis, and transparency.
The ultimate test is not what the measure calls itself —
but whether it can be justified with evidence.
Thank you.