China Cryptography Law Compliance Guide
Classify cryptography under China law, then check product and service assurance, system assessment, critical-infrastructure, electronic-certification, and trade requirements.
Start with classification, then test each legal trigger. The 2023 regulation applies to research, production, sale, service, testing, certification, import, export, application, and supervision within China. Network operators must follow the commercial cryptography requirements set for the network's graded-protection level. applies when a law, administrative regulation, or national provision requires a network or information system to use commercial cryptography; is one covered case. The 2025 critical-infrastructure rules and 2026 electronic-certification rules assign additional duties to their named actors.
The Cryptography Law has applied since 1 January 2020. It separates , which protect state secrets, from , which protects information that is not a state secret. The revised Commercial Cryptography Administration Regulation has applied since 1 July 2023. rules have applied since 1 August 2025, and the current electronic-certification licensing rules since 1 July 2026. Encryption alone does not trigger one approval: the product catalogue, service design, system classification, operator status, transaction, and intended use determine which route applies.
Key dates for China Cryptography Law
The visual timeline separates adoption, publication, and effective dates. The law took effect on 1 January 2020; the revised Administration Regulation was published on 27 April 2023 and took effect on 1 July 2023.
Choose the next compliance route
New to the regime? Start with the legal categories and route map. If the item is already classified, jump to the applicable product, infrastructure, shipment, evidence, deadline, or enforcement guide.
Start here: categories and duties
Understand what the law calls cryptography, how commercial cryptography differs from state-secret categories, and which facts determine the next route.
Products, services, infrastructure, and shipments
Test the distinct triggers for mandatory product or service assurance, critical information infrastructure, and controlled imports or exports.
Procurement and evidence
Turn the selected route into supplier due diligence and a reviewable testing or certification record.
Dates and enforcement
Separate historical effective dates from operational change triggers, and understand the penalties attached to particular breaches.
Compare regimes and answer focused questions
Keep cryptography decisions distinct from broader cybersecurity duties, or go directly to a concise answer for a specific scenario.
Prepare the commercial cryptography evidence file
Sorena AI turns China Cryptography Law official requirements into scoped decisions, evidence records, owner assignments, and change-trigger reviews.
- Start with the protected information, cryptographic technology, product or service, supplier, operator, China use case, and shipment that create the Cryptography Law question.
- Research Copilot keeps the official citation, decision owner, evidence record, and approval history connected.
- SSOT preserves official citations, route decisions, assurance evidence, and review history when the item, supplier, operator, catalogue, list, destination, or end use changes.
