AWS China partition — what works vs global accounts
AWS China is a separate partition (Beijing / Ningxia), not a global region toggle. Product teams need a China account rail, catalog gap checks, and ICP adjacency before public go-live.
AWS China is a separate cloud partition inside Mainland China — not a region you add to a global AWS account. Beijing (cn-north-1, Sinnet) and Ningxia (cn-northwest-1, NWCD) run under China operators with their own accounts, endpoints, and support channels. Your product team must clear entity / account rails, catalog gap checks, and ICP adjacency before public workloads are real.

What AWS China is for product teams
Hard names your stack decision will use:
- AWS China partition — Amazon Web Services in China is operated in Beijing by Beijing Sinnet Technology and in Ningxia by Ningxia Western Cloud Data Technology (NWCD). Official China FAQs and the China overview describe these as China Regions — not global AZ extensions.
- Separate account credentials — Customers must sign up for credentials unique to AWS China. Existing AWS Inc. credentials cannot access China resources, and China credentials cannot access global regions (same FAQ set).
- Two regions only —
cn-north-1(Beijing / Sinnet) andcn-northwest-1(Ningxia / NWCD). Multi-region and DR plans must fit this pair — not the global region matrix. - Catalog is not a mirror — As of 2026-02-28, the official services-by-region table lists 120 service rows. Core IaaS/PaaS is relatively complete; GenAI, several app platforms, and customer-engagement SaaS are the usual holes.
- PRC business license for self-service — Registration expects a valid Chinese business license plus contact validation. Individual global-style accounts are not the China path.
- ICP adjacency for public content — Hosting public content on AWS China typically requires ICP filing; without it, accounts may remain Internal Access. Buying China cloud does not skip the filing gate.
- Endpoints and console — Day-to-day work uses the amazonaws.cn partition and China-specific documentation — not
aws.amazon.comalone.
Vocabulary first. Next: what must be true before console work, then the catalog and gap evidence your architecture review needs.
Catalog snapshot (2026-02-28)
We parsed the official AWS China services by region page, last updated 2026-02-28. The table lists 120 service rows.
| Coverage | Count |
|---|---|
| Available in Beijing and Ningxia | 102 |
| Beijing only | 9 |
| Ningxia only | 9 |
Row counts understate SKU and feature differences within a service. For sign-off, cross-check each required service against the official table and China-specific documentation — not the global AWS product page alone.
Regions
AWS China has two regions: Beijing (cn-north-1, Sinnet) and Ningxia (cn-northwest-1, NWCD). AWS Global currently advertises 39 geographic regions and 123 Availability Zones — a different scale and operator model entirely. Confirm current global infrastructure counts on the AWS Global Infrastructure page when you cite scale in a board pack.
What must be true before AWS China console work
Missing any of these stops your product team before a stable China reference architecture — often before the first usable China payer account.
| Precondition | Why your process stalls |
|---|---|
| Separate China account decision — not “add China to the global Org” | Global credentials cannot open China resources; IAM, billing, and Organizations do not span the partition |
| PRC entity or landing-partner path | Self-service registration expects a Chinese business license; teams without a PRC company cannot finish the payer path alone |
| Account admin + finance contacts that China operators can validate | Registration follow-up, fapiao setup, and support channels need reachable China-side contacts |
| Service bill of materials checked against the China regional table | Global Bedrock / App Runner / SES-style designs fail at architecture review when rows are missing |
| Region strategy for Beijing vs Ningxia | Nine services are single-region only (e.g. CloudFront / Route 53 in Ningxia; Cognito in Beijing) |
| ICP / public-publish plan for customer-facing endpoints | Without filing, public content stays blocked or limited to Internal Access |
| IaC and CI/CD scoped to the China partition | Global Terraform modules, OIDC trust, and artifact feeds often assume endpoints that do not exist in China |
Chinese-language consoles, operator support (Sinnet / NWCD), and filing rails are part of this floor. Product teams usually cannot finish AWS China onboarding from an overseas laptop alone.
From global AWS assumption to China-ready stack
| Stage | Decision / outcome |
|---|---|
| 1. Partition verdict | Confirm the workload must run in Mainland China (residency / regulator / domestic integration) — not “reach China users from global AWS” alone |
| 2. Account rail | Open a China payer account (PRC license path or landing partner); do not expect global Org inheritance |
| 3. Region plan | Choose Beijing, Ningxia, or both; map single-region-only services before DR diagrams |
| 4. Catalog trim | Diff required services vs the official China table; replace or relocate GenAI / engagement / edge gaps |
| 5. Deploy baseline | Redeploy IAM, networking, data stores, and pipelines on China endpoints |
| 6. Filing adjacency | Align domain, DNS, and public publish with ICP / PSB before cutover |
| 7. Operate | Support via China operators; keep Global and China stacks explicitly separate |
Why account, catalog, and ICP failures cascade
No China account → no resources to architect. Global credentials never see Beijing or Ningxia. Architecture reviews that assume “flip a region” waste cycles until the payer rail exists.
Account without entity path → registration never closes. Self-service expects a Chinese business license. Teams outside Mainland China ops norms stall at the first registration form unless a local company or China landing partner supplies the rail.
Catalog assumed = Global → mid-build redesign. Bedrock, App Runner, Amplify Hosting, Connect, Pinpoint, and SES-style dependencies are common Global defaults that do not appear in the China table. Discovering that after sprint commitments is an expensive cascade.
Wrong region for a single-region service → broken edge or identity. CloudFront and Route 53 appear Ningxia-only in the China table; Cognito appears Beijing-only. DR and CDN designs that ignore those splits fail at implementation.
Cloud ready, ICP ignored → Internal Access only. Public content still needs filing. Buying AWS China capacity does not authorize public DNS cutover — see ICP filing and domain/DNS and ICP licence questions.
Global CI/CD pointed at China endpoints → deploy theater. Pipelines, artifact mirrors, and OIDC trusts built for Global break silently or refuse China endpoints until rebuilt for the partition.
Control plane and account model
| Dimension | AWS Global | AWS China |
|---|---|---|
| Operators | AWS / Amazon Web Services | Sinnet (Beijing), NWCD (Ningxia) |
| Account | Global AWS account | Separate China account — Global cannot access China resources and vice versa |
| Regions | Global region set | Beijing + Ningxia only |
| Public content | Standard domains / CDN / public publish | Public-facing content typically requires ICP filing; without filing, accounts may remain Internal Access |
| Service catalog | Broadest AWS portfolio | 120 rows in the official regional table; features and SKUs need per-service verification |
| Console / endpoints | aws.amazon.com, global partitions | amazonaws.cn partition and China-specific endpoints |
Migration means a new account, new IAM baseline, redeployed stacks, and re-wired integrations — not adding a China region to an existing Global payer.
Obtaining a China account (PRC entity)
AWS China offers self-service online registration for PRC-registered companies only — individual accounts are not supported.
The standard flow:
- Register a China payer account on the AWS China site with a valid business license (营业执照).
- Provide account administrator contact details; AWS China validates them in real time.
- On approval, the account is provisioned immediately.
- Complete initial setup: finance and security contacts; fapiao (invoice) information pending confirmation by the China operating company’s back office.
- After verification, an AWS China account manager typically contacts you and may grant CNY 200 in credits for testing.
Teams without a PRC entity cannot use this self-service path directly. They need a local operating company or a landing partner arrangement before a payer account can be opened. Start an assessment if you need a predictable onboarding path alongside filing and architecture work.
Customer-facing workloads still require ICP filing before public go-live and PSB filing where applicable — see our ICP and PSB guide.
Strong coverage by service domain
Source: AWS China services by region, parsed 2026-02-28.
| Service domain | Representative China services | Assessment |
|---|---|---|
| Compute | EC2, EBS, Auto Scaling, Batch, Elastic Beanstalk, Lambda, Fargate | Core compute largely available |
| Containers | ECS, EKS, ECR, App Mesh | Container mainline available |
| Storage | S3, Glacier, EFS, FSx family, Storage Gateway, Backup, DataSync | Strong coverage |
| Databases | RDS, Aurora MySQL/PostgreSQL, DynamoDB, DocumentDB, ElastiCache, MemoryDB, Neptune, Keyspaces, Timestream | Mainstream databases well covered |
| Analytics | Athena, EMR, Redshift, Glue, Lake Formation, MSK, MWAA, OpenSearch, Kinesis, Firehose | Analytics and streaming reasonably complete |
| Network | VPC, ELB, PrivateLink, Direct Connect, Transit Gateway, Network Firewall, WAF | Core networking available |
| Security / governance | IAM, IAM Identity Center, KMS, ACM, Private CA, Secrets Manager, GuardDuty, Inspector, Security Hub, Config, CloudTrail | Security baseline available |
| DevOps / delivery | CodeBuild, CodeCommit, CodeDeploy, CodePipeline, CloudFormation, Cloud Control API | Foundational CI/CD available |
Beijing vs Ningxia — regional splits
Nine services appear in only one China region. Plan multi-region architecture and DR accordingly — this is a hard selection gate, not a nice-to-know footnote.
| Beijing only | Ningxia only |
|---|---|
| Amazon Cognito | Amazon CloudFront |
| Amazon Kinesis Video Streams | Amazon Route 53 |
| Amazon Deep Learning AMIs | Amazon WorkSpaces |
| Amazon IoT Events | Amazon Budgets |
| Amazon IoT SiteWise | Amazon Cost Explorer |
| Amazon IoT TwinMaker | Cost and Usage Report |
| Amazon IoT Greengrass | AWS Elemental MediaConvert |
| Amazon Personalize | AWS Marketplace |
| Amazon QuickSight | Amazon Polly |
Notable gaps vs AWS Global
The following Global services are common in architecture references but do not appear in the AWS China regional table as of 2026-02-28. Treat them as unavailable in China unless a newer table row proves otherwise. Wrong assumption here is a hard pass/fail for GenAI and engagement designs.
| Category | Representative gaps |
|---|---|
| Generative AI | Amazon Bedrock, Amazon Q, Amazon Q Developer, Amazon Q Business |
| AI / ML managed APIs | Rekognition, Comprehend, Textract, Translate, Lex (not listed in China table) |
| Application platforms | AWS App Runner, AWS Amplify Hosting, AWS Proton |
| Customer engagement | Amazon Connect, Pinpoint, SES |
| Edge / hybrid | Local Zones, Outposts, Wavelength |
| Data / business SaaS | Clean Rooms, DataZone, FinSpace, Entity Resolution |
| Advanced security | Macie, Detective, Verified Access, Shield Advanced |
| Observability (newer) | Managed Grafana, Managed Prometheus, Application Signals |
ACM and TLS certificates
Unlike Azure China App Service — which does not document a free managed certificate — AWS China lists Amazon Certificate Manager (ACM) and AWS Private CA in both Beijing and Ningxia.
ACM China documentation states that ACM can create, store, and renew public and private SSL/TLS certificates, and ACM-managed certificates incur no additional certificate charge. Binding still depends on the integrating service and region — for example ELB and API Gateway support ACM in documented patterns. See the ACM overview (China docs).
CloudFront is listed only in Ningxia and cannot use ACM-managed free certificates in the same way as Global CloudFront + ACM pairings; teams may need CLI-driven renewal workflows or alternate certificate strategies for CDN-fronted properties. China CloudFront documentation starts at the CloudFront Developer Guide (China); Route 53 China docs at the Route 53 Developer Guide (China).
Service availability matrix (AWS Global vs AWS China)
Yes = listed for that China region in the official table; No = not listed; Partial = listed with documented China limitations or single-region only.
Necessity: product teams cannot sign off a China architecture without per-service, per-region verification — the matrix below is the hard-gate view for common stack choices.
| Service | Beijing | Ningxia | Global | Notes |
|---|---|---|---|---|
| EC2 | Yes | Yes | Yes | China account, quotas, and instance families need separate verification |
| S3 | Yes | Yes | Yes | Domain, filing, and public-publish policy differ from Global |
| CloudFront | No | Yes | Yes | China table lists Ningxia only |
| Route 53 | No | Yes | Yes | China table lists Ningxia only |
| ACM | Yes | Yes | Yes | Free managed SSL/TLS certificates supported |
| Cognito | Yes | No | Yes | China table lists Beijing only |
| Amazon Bedrock | No | No | Yes | Not listed in China regional table |
| AWS App Runner | No | No | Yes | Not listed in China regional table |
| Amazon SES | No | No | Yes | Not listed in China regional table |
| Amazon Connect | No | No | Yes | Not listed in China regional table |
| Lambda | Yes | Yes | Yes | Core serverless available |
| EKS | Yes | Yes | Yes | Container orchestration available |
| RDS / Aurora | Yes | Yes | Yes | Confirm engine/version per region |
| DynamoDB | Yes | Yes | Yes | Available |
| VPC / ELB | Yes | Yes | Yes | Core networking available |
| GuardDuty | Yes | Yes | Yes | Confirm feature parity vs Global |
What blocks product teams on AWS China
- Treating China as a global region toggle — Organizations, consolidated billing, and shared IAM never span the partition.
- No PRC entity rail — self-service account creation expects a Chinese business license; overseas-only packs stall at registration.
- Catalog optimism — GenAI, app-platform, and engagement defaults copied from Global fail when rows are absent.
- Ignoring Beijing vs Ningxia splits — CloudFront / Route 53 / Cognito placement errors show up late in CDN and identity designs.
- Buying cloud before ICP — public endpoints stay Internal Access or blocked until filing clears.
- Global-only CI/CD and artifact feeds — pipelines that cannot reach China endpoints never become a China release train.
- Support-model surprise — Sinnet / NWCD channels and China documentation replace global ticket assumptions.
- Confusing reachability with residency — speeding access for China users to a global AWS footprint is a different problem than running workloads inside Mainland China.
When AWS China fits
Choose AWS China when residency, regulator expectations, or domestic integration require workloads inside Mainland China — and you can sustain a China-local operating model: separate payer account, Sinnet/NWCD support channels, filing, and a catalog-trimmed reference architecture.
It is usually the wrong first answer when the problem is reachability of a global AWS footprint to China users. For a side-by-side sovereign-cloud read, see Azure China. For provider-neutral route selection, see How we choose providers without selling them or start a China Readiness Assessment.
Minimum diligence before sign-off: verify every required service in both target regions where DR matters; confirm ICP status before public DNS cutover; scope IaC and CI/CD to the China partition; diff GenAI and app-platform dependencies early.
When you need a China landing partner for AWS China
Most product teams exploring Mainland China entry need a China landing partner to open or operate the China account rail, trim the architecture to the real catalog, and align ICP / hosting with the same stack — not a longer console tutorial. Your team still owns product and architecture decisions; the partner path makes entity, operator, and filing rails executable when they are not already in-house.
What we can offer?
AWS China is a separate partition — account rails, Beijing/Ningxia splits, catalog gaps, and ICP adjacency — not a global region toggle. Chinaready helps your product team decide whether AWS China fits and what must be true before public go-live:
- China Readiness Assessment — Map whether residency forces AWS China vs global reachability, which account/entity rail you can execute, and which catalog gaps block the reference architecture.
- China Access Acceleration — Keep admin paths, dependencies, and hybrid links workable while Global and China stacks stay explicitly separate.
- China Product Hosting — Place China-critical workloads on a Mainland China–operable stack where ICP/PSB and AWS China endpoints describe one coherent publish path.
- Mobile App Distribution — Ship channel launches on their own gates while backend residency and China cloud choices stay consistent with the live product boundary.
Contact us when you need an AWS China vs global decision — account rail, catalog trim, and filing adjacency — without treating China as a region checkbox.
References
- AWS China — Amazon services by region — source for catalog counts above; last checked 2026-02-28
- AWS China — about Amazon Web Services in China — operators and China overview
- AWS China — FAQs — separate credentials, business license, ICP questions
- AWS China — accounts and credentials
- AWS China — ACM overview
- AWS China — CloudFront Developer Guide
- AWS China — Route 53 Developer Guide
- AWS Global — regions and Availability Zones
- AWS Global — products and infrastructure
- Azure China — overview and comparison — Chinaready guide
- ICP and PSB filing for foreign companies — Chinaready guide
Frequently asked questions
Is AWS China just another region on my global AWS account?
No. Beijing (cn-north-1, Sinnet) and Ningxia (cn-northwest-1, NWCD) sit in the Amazon Web Services China partition. Official FAQs state you need separate China account credentials; global AWS Inc. credentials cannot access China resources, and China credentials cannot access global regions.
Who operates AWS China Beijing and Ningxia?
Beijing Sinnet Technology operates the Beijing Region; Ningxia Western Cloud Data Technology (NWCD) operates the Ningxia Region. Support, contracting, and compliance rails follow those China operators — not a global AWS region toggle.
Can my product team open an AWS China account without a PRC entity?
Self-service registration expects a valid Chinese business license and contact validation. Teams without a PRC-registered company usually need a local operating company or a China landing partner arrangement before a usable payer account exists.
Do we need ICP filing to host on AWS China?
Public-facing content on AWS China typically requires ICP filing (recordal and/or license by content type). Without filing, accounts may stay limited to internal access. Cloud purchase alone does not clear the public publish gate — see our ICP and PSB Guides.
Which AWS services are missing in China vs global?
As of the official regional table dated 2026-02-28 (120 service rows), core IaaS/PaaS is relatively strong, but generative AI (e.g. Bedrock), several app platforms (App Runner, Amplify Hosting), and customer-engagement services (Connect, Pinpoint, SES) are common architecture gaps. Always re-check the live China table before sign-off.
Can we finish AWS China onboarding without Mainland China ops?
Usually no. Separate accounts, entity rails, region splits, catalog gaps, and ICP adjacency stop most product teams before a stable China reference architecture. Use this Guide as a decision map; execute with Mainland China ops rails or a China landing partner.


