{"url_path":"/sec/sxtc/10-k/2026/item-16k","section_key":"item-16k","section_title":"Item 16K CYBERSECURITY","topic":"sec","document":{"doc_type":"20-F","doc_date":"2026-07-01","source_url":"https://www.sec.gov/Archives/edgar/data/1723980/0001213900-26-074310-index.html","accession_number":"0001213900-26-074310","cik":"0001723980","ticker":"SXTC","issuer_name":"China SXT Pharmaceuticals, Inc.","edgar_url":"https://www.sec.gov/Archives/edgar/data/1723980/0001213900-26-074310-index.html","primary_entity_key":"0001723980","primary_entity_name":"China SXT Pharmaceuticals, Inc."},"word_count":400,"has_tables":true,"body_markdown":"ITEM 16K. CYBERSECURITY \n\n \n\nRisk Management and Strategy\n\n \n\nWe recognize the importance of safeguarding the security of our computer systems, software, networks, and other technology assets. We have implemented cybersecurity measures and protocols for assessing, identifying, and managing material risks from cybersecurity threats, which are integrated into our overall risk management framework. We aim to ensure a comprehensive and proactive approach to safeguarding our assets and operations.\n\n \n\nAs of the date of this annual report, we have not experienced any material cybersecurity incidents or identified any material cybersecurity threats that have affected or are reasonably likely to materially affect us, our business strategy, results of operations or financial condition.  \n\n \n\nGovernance\n\n \n\nOur board of directors is responsible for overseeing risks related to cybersecurity. Our board of directors shall (i) maintain oversight of the disclosure related to cybersecurity matters in current reports or periodic reports of our company, (ii) review updates to the status of any material cybersecurity incidents or material risks from cybersecurity threats to our company, and the disclosure issues, if any, presented by our management on a quarterly basis, and (iii) review disclosure concerning cybersecurity matters in our annual report on Form 20-F presented by our management.\n\n \n\nAt the management level, our CEO, CFO and the head of the departments in connection with cybersecurity-related matters are responsible for assessing, identifying and managing cybersecurity risks and monitoring the prevention, detection, mitigation, and remediation of cybersecurity incidents. Our CEO and CFO report to our board of directors (i) timely updates to the status of any material cybersecurity incidents or material risks from cybersecurity threats to our company, and the disclosure issues, if any, and (ii) in connection with disclosure concerning cybersecurity matters in our annual report on Form 20-F.\n\n \n\nIf a cybersecurity incident occurs, our cybersecurity-related departments will promptly organize personnel for internal assessment. If it is further determined that the incident could potentially be a material cybersecurity event, the cybersecurity-related departments will promptly report the incident and assessment results to our CEO and CFO, and, to the extent appropriate, seek advice from external experts and legal counsels. If it is determined that the incident could potentially be a material cybersecurity event, our CEO and CFO will decide on relevant response measures and management shall promptly prepare disclosure material on the cybersecurity incident for review and approval by our board of directors before it is disseminated to the public.\n\n \n\n111\n\n \n\n \n\nPART III"}