In March 2023, China opened its first-ever cybersecurity review into a foreign company’s products. The target was Micron, the Idaho-based memory chipmaker, CNBC reported, and the case ended seven weeks later with a ban on the sale of its products to Chinese state infrastructure operators.
That precedent matters, now that Beijing has trained the same regulatory tool on Palo Alto Networks (PANW), headquartered in Santa Clara, Calif.
The Cyberspace Administration of China said Thursday, Aug. 6, that it has launched a formal security review of products Palo Alto sells in the country, citing the need to protect critical information infrastructure under national security and cybersecurity law.
Beijing did not publicly specify which software or hardware lines are under review, which is standard protocol for CAC security audits.
Palo Alto operates offices in Beijing, Shenzhen, Shanghai, and Guangzhou, and its shares fell as much as 4.2% in premarket trading before turning slightly green, according to a Seeking Alpha report.
That muted reaction contrasts with how markets treated the Micron review in 2023, when the stock slid for days on fears of a full China exit.
Why investors shrugged this time says as much about Palo Alto’s business as it does about Beijing’s intentions.
Palo Alto isn’t Beijing’s first cybersecurity review of a U.S. tech company
The Cybersecurity Review Office used nearly identical language, citing the same national security and cybersecurity laws, when it opened its Micron probe in 2023, according to the South China Morning Post.
That review concluded weeks later with a determination that Micron’s products posed security risks, and Chinese operators of critical infrastructure were barred from buying them, according to the Center for Strategic and International Studies. Micron’s China revenue never fully recovered to prior levels.
Palo Alto’s exposure looks different on paper. The Asia Pacific region, where China sits alongside Japan, Australia and other markets, made up roughly 12% of Palo Alto’s total revenue in fiscal 2025, according to the company’s annual report filed with the SEC.
China itself is a sliver of that regional total, since Beijing has spent years pushing domestic alternatives into critical infrastructure contracts, limiting how much a full exit would actually cost Palo Alto’s bottom line.
The market’s calm reaction says more
Palo Alto (PANW) shares have climbed roughly 88% over the past three months, fueled by a blowout fiscal third quarter and CEO Nikesh Arora’s insistence that AI has not disrupted the cybersecurity budget cycle the way some feared, according to CNBC.
The stock touched fresh highs this week, and options traders had already priced in an unusually strong August seasonal pattern.
Related: IBM just answered a $5 billion cybersecurity question
Palo Alto reports fiscal fourth-quarter results on Sept. 1, giving investors a nearer-term catalyst than a Chinese regulatory review in a market that generates a small fraction of its revenue.
That calculus already played out once. When Reuters first reported in January that China had ordered domestic firms to drop cybersecurity software from Palo Alto and more than a dozen other U.S. and Israeli vendors, Palo Alto’s share price stayed virtually flat, while Broadcom fell more than 4%.
Investors had already concluded that China represented upside optionality, not a core pillar of the growth story.
3 strikes from Chinese government in 7 months
The pattern predates the Aug. 6 announcement. A Chinese government directive reviewed by Bloomberg News in January accused Palo Alto of having a “U.S. Western intelligence background,” without offering evidence, and ordered Chinese firms to phase out its products by mid-2026.
The following month, Reuters reported that Palo Alto’s own Unit 42 researchers softened a hacking report that had privately linked a major espionage campaign to Beijing, out of concern that naming China could invite retaliation against its offices or clients there.
More Tech:
- ServiceNow’s quiet $1B cybersecurity boom
- A European rival to SpaceX is chasing a $2B valuation
- SK Hynix denies Intel Ohio fab deal, but the market didn’t care
That decision briefly became its own story. It suggested Beijing’s pressure was already shaping how a major American cybersecurity firm talks about Chinese state hacking, even before any formal review existed, raising questions about how much other Western vendors self-censor under similar pressure.
The Aug. 6 formal probe marks the third strike in this sequence, turning informal pressure into an official state procedure.
The review is a lever, not a verdict
What separates this episode from Micron is intent. Beijing needed no additional leverage over Micron beyond its stated security concerns.
With Palo Alto, the review arrives layered on top of an unproven spy accusation, a software phase-out order, and reporting that the company had already tempered its own threat research.
That sequence looks less like a routine security audit and more like sustained pressure on a company Beijing has chosen to make an example of in its broader standoff with Washington.
Investors are betting the stakes stay contained to a market that barely moves Palo Alto’s revenue. The bigger question is whether Beijing extends this playbook to vendors with far more to lose in China, since a regulatory tool built to police data leaving the country is proving just as effective at squeezing the companies trying to sell into it.
Related: BofA downplays China’s threat to Micron’s AI business

