What Happened?

May 21, 2023 — China's Cybersecurity Review of Micron Technology

● The Event

On May 21, 2023, China's Cybersecurity Review Office (CRO) announced that US chipmaker Micron Technology's products failed the cybersecurity review.

The review found that Micron products pose serious cybersecurity risks to China's critical information infrastructure (CII) supply chain, affecting national security.

Operators of CII — government agencies, large data centers, and telecom operators — were instructed to stop purchasing Micron products.

● The Scope
● Target
CII operators only — government agencies, large data centers, telecom operators
● Not Banned
Ordinary consumers and the general public — the ban was targeted, not blanket
● Key Distinction
Targeted restriction on sensitive buyers, not a wholesale market prohibition

Impact on Micron's China Business

China revenue share declined from 58% peak to just 7.1% — a structural shift accelerated by the CAC decision

China Revenue as % of Micron's Total Revenue

58%
Peak China revenue share (FY2018)
~$100B+ from China market
11%
Pre-ban share (FY2022)
$3.31B of $30.76B total revenue
7.1%
Latest share (FY2025)
Sharp decline after CAC decision

Sources: Micron SEC Filings (FY2018–FY2025), Digitimes Research, Company Annual Reports

China's Micron Ban vs US Huawei / ZTE Bans

Same legal playbook, opposite direction — but with key differences in scope, basis, and transparency

DimensionChina → Micron (2023)US → Huawei / ZTEVerdict
Legal FormCybersecurity Review (CAC)FCC orders, Entity List (BIS)Same Security framing
EffectExcludes Micron from CII procurementExcludes Huawei/ZTE from US marketSame Foreign vendor exclusion
ScopeCII operators only — not general consumersBroad — prohibits imports and sales entirelyDifferent Narrow vs. broad
Legal BasisProduct-based — specific technical findings in Micron productsCompany-based — the firm itself is listed as a threatDifferent Product vs. entity
TransparencyLimited — general statement of "serious risks"Limited — national security rationaleSame Both are opaque

The Big Question

What would a government need to publish for us to tell genuine security from market protection?

🔎

Specific Technical Finding

Not just "it's risky" — what exactly is the risk? Which component, which vulnerability, which threat vector? Without specifics, the decision is unverifiable.

Legal Basis & Procedure

Which law? How was the review conducted? What evidence was examined? Due process matters — security claims without procedural transparency are indistinguishable from protectionism.

🎯

Clear Scope

Who must comply? What exactly is prohibited? Is there a path to remediation? A black-box decision gives us reason to doubt whether it is genuinely about security.

Global DRAM Market Share (2023–2024)

Global NAND Market Share (Q2 2024)

Sources: TrendForce, DRAMeXchange, CFM Flash Market

Conclusion

The Micron decision and US vendor bans are the same play run in opposite directions.

Both use security exceptions to restrict foreign vendors. The difference lies in scope, basis, and transparency.

The ultimate test is not what the measure calls itself —
but whether it can be justified with evidence.

Thank you.