Classify cryptography under China law, then check product and service assurance, system assessment, critical-infrastructure, electronic-certification, and trade requirements.
Start with classification, then test each legal trigger. The 2023 regulation applies to research, production, sale, service, testing, certification, import, export, application, and supervision within China. Network operators must follow the commercial cryptography requirements set for the network's graded-protection level. applies when a law, administrative regulation, or national provision requires a network or information system to use commercial cryptography; is one covered case. The 2025 critical-infrastructure rules and 2026 electronic-certification rules assign additional duties to their named actors.
The Cryptography Law has applied since 1 January 2020. It separates , which protect state secrets, from , which protects information that is not a state secret. The revised Commercial Cryptography Administration Regulation has applied since 1 July 2023. rules have applied since 1 August 2025, and the current electronic-certification licensing rules since 1 July 2026. Encryption alone does not trigger one approval: the product catalogue, service design, system classification, operator status, transaction, and intended use determine which route applies.
The visual timeline separates adoption, publication, and effective dates. The law took effect on 1 January 2020; the revised Administration Regulation was published on 27 April 2023 and took effect on 1 July 2023.
New to the regime? Start with the legal categories and route map. If the item is already classified, jump to the applicable product, infrastructure, shipment, evidence, deadline, or enforcement guide.
Understand what the law calls cryptography, how commercial cryptography differs from state-secret categories, and which facts determine the next route.
Test the distinct triggers for mandatory product or service assurance, critical information infrastructure, and controlled imports or exports.
Turn the selected route into supplier due diligence and a reviewable testing or certification record.
Separate historical effective dates from operational change triggers, and understand the penalties attached to particular breaches.
Keep cryptography decisions distinct from broader cybersecurity duties, or go directly to a concise answer for a specific scenario.
Sorena AI turns China Cryptography Law official requirements into scoped decisions, evidence records, owner assignments, and change-trigger reviews.
