---
title: "China Cryptography Law and Commercial Cryptography Compliance Guide"
canonical_url: "https://www.sorena.io/artifacts/apac/china-cryptography-law"
source_url: "https://www.sorena.io/artifacts/apac/china-cryptography-law"
author: "Sorena AI"
description: "Classify cryptography under China law, then check product and service assurance, system assessment, critical-infrastructure, electronic-certification, and trade requirements."
published_at: "2026-07-05"
updated_at: "2026-07-16"
keywords:
  - "China Cryptography Law"
  - "Commercial cryptography"
  - "Cryptography Law"
  - "Commercial cryptography testing"
  - "China cybersecurity"
---
**[SORENA](https://www.sorena.io/)** - AI-Powered GRC Platform

[Home](https://www.sorena.io/) | [Solutions](https://www.sorena.io/solutions) | [Artifacts](https://www.sorena.io/artifacts) | [About Us](https://www.sorena.io/about-us) | [Contact](https://www.sorena.io/contact) | [Portal](https://app.sorena.io)

---

# China Cryptography Law and Commercial Cryptography Compliance Guide

Classify cryptography under China law, then check product and service assurance, system assessment, critical-infrastructure, electronic-certification, and trade requirements.

![China Cryptography Law artifact preview](https://cdn.sorena.io/cdn-cgi/image/format=auto/cheatsheets/prod/sorena-ai-china-cryptography-law-timeline-small.jpg?v=cheatsheets%2Fprod)

*Cryptography* *China*

## China Cryptography Law Compliance Guide

The Cryptography Law has applied since 1 January 2020. It separates core and ordinary cryptography, which protect state secrets, from commercial cryptography, which protects information that is not a state secret. The revised Commercial Cryptography Administration Regulation has applied since 1 July 2023. Critical information infrastructure rules have applied since 1 August 2025, and the current electronic-certification licensing rules since 1 July 2026. Encryption alone does not trigger one approval: the product catalogue, service design, system classification, operator status, transaction, and intended use determine which route applies.

[Prepare the commercial cryptography evidence file](/contact.md)

## What this hub helps you decide

- **Classify cryptography use**: Record what the technology, product, or service protects and how it is supplied. Core and ordinary cryptography protect state secrets; commercial cryptography protects non-state-secret information.
- **Check product and service route**: Testing and certification are generally voluntary. Mandatory assurance applies to commercial cryptography products included in the catalogue of network critical equipment and network security-specific products, services using those products, and qualifying critical-infrastructure uses. Network operators must also check the cryptography requirements tied to the network-security graded-protection system. System assessment, trade licensing, procurement review, and licensing for electronic certification services have separate triggers.
- **Keep supplier and release evidence**: Keep the exact product or service, model and version, cryptographic function, intended use, operator, supplier evidence, applicable catalogue or control-list entry, test or certificate scope, decision, and reassessment triggers.

By Sorena AI | Official citations | Practical launch evidence

### Quick scan

*Cryptography*

- **Classify cryptography use**: Identify what information is protected and whether the item is a technology, product, service, procurement, or critical-infrastructure deployment.
- **Check product and service route**: Check the mandatory network-product route, related service certification, graded-protection requirements for the network's confirmed protection level, application security assessment for systems that national rules require to use commercial cryptography, critical-infrastructure product and technology rules, procurement review, electronic-certification licensing, and import/export lists separately.
- **Keep supplier and release evidence**: Retain the facts and source behind the conclusion. Reopen it when the product, supplier, use case, infrastructure status, or shipment changes.

Start with classification, then test each legal trigger. The 2023 regulation applies to commercial cryptography research, production, sale, service, testing, certification, import, export, application, and supervision within China. Network operators must follow the commercial cryptography requirements set for the network's graded-protection level. Commercial cryptography application security assessment applies when a law, administrative regulation, or national provision requires a network or information system to use commercial cryptography; critical information infrastructure is one covered case. The 2025 critical-infrastructure rules and 2026 electronic-certification rules assign additional duties to their named actors.

| Value | Metric |
| --- | --- |
| 1 Jan 2020 | Cryptography Law effective |
| 1 Jul 2023 | revised regulation effective |
| 1 Aug 2025 | critical-infrastructure rules effective |
| commercial cryptography | classification route |
| testing bodies | evidence dependency |

**Key highlights:** Classify cryptography use | Check product and service route | Keep supplier and release evidence

China's Cryptography Law separates core and ordinary cryptography from commercial cryptography. The revised Commercial Cryptography Administration Regulation governs commercial cryptography activities within China. For commercial cryptography, test the separate triggers for network critical equipment and network security-specific products, network-security graded protection, commercial cryptography application security assessment, critical information infrastructure, electronic certification services, and import or export controls.

## Definitions

### Core and ordinary cryptography

Core cryptography and ordinary cryptography protect information classified as state secrets. Core cryptography may protect information up to the top-secret level; ordinary cryptography may protect information up to the secret level. The cryptography itself is a state secret and is managed under the separate classified regime.

**Why it matters here:** This hub's commercial cryptography routes do not govern a use that protects state-secret information. Stop the commercial classification and apply the classified cryptography and secrecy rules when the protected information is a state secret.

Sources:

- [PRC Cryptography Law, Articles 6-7](https://www.oscca.gov.cn/sca/xxgk/2023-06/04/content_1057225.shtml?ref=sorena.io)

### Commercial cryptography

Commercial cryptography is technology, a product, or a service that uses specific transformations for encryption protection or security authentication of information that is not a state secret. The word commercial identifies the legal category; it does not mean that the information or cryptographic function must be sold.

**Why it matters here:** Commercial classification permits lawful use but does not itself require certification or approval. The product, service, system, operator, transaction, and intended use determine whether another route is mandatory.

Sources:

- [PRC Cryptography Law, Articles 2 and 8](https://www.oscca.gov.cn/sca/xxgk/2023-06/04/content_1057225.shtml?ref=sorena.io)

### Network critical equipment and network security-specific products

These are products within the catalogue published under the Cybersecurity Law. A covered product must meet mandatory national standards and pass qualified security certification or security testing before sale or provision. A separate commercial cryptography product certification catalogue belongs to a different, generally voluntary certification system.

**Why it matters here:** A commercial cryptography product must pass qualified testing and certification under Cryptography Law Article 26 when the actual item falls within this mandatory network-product catalogue. A commercial cryptography service using a product in the catalogue must also be certified.

Sources:

- [PRC Cybersecurity Law, Article 25](https://www.cac.gov.cn/2025-12/29/c_1768735112911946.htm?ref=sorena.io)
- [PRC Cryptography Law, Article 26](https://www.oscca.gov.cn/sca/xxgk/2023-06/04/content_1057225.shtml?ref=sorena.io)

### Commercial cryptography application security assessment

This assessment tests whether a network or information system uses commercial cryptography technologies, products, and services compliantly, correctly, and effectively. It applies when a law, administrative regulation, or national provision requires that system to use commercial cryptography protection and covers planning, pre-operation, and recurring operational stages.

**Why it matters here:** The system operator must keep this assessment separate from product testing, service certification, and procurement review. A product certificate cannot replace application-plan assessment, pre-operation assessment, annual assessment, remediation, or filing.

Sources:

- [Commercial Cryptography Application Security Assessment Measures, Articles 2 and 6-14](https://www.oscca.gov.cn/sca/xxgk/2023-10/07/content_1061109.shtml?ref=sorena.io)

### Critical information infrastructure

Critical information infrastructure is infrastructure in important industries and fields whose destruction, loss of function, or data leakage could seriously harm national security, the national economy and people's livelihoods, or the public interest. The competent protection department identifies it and notifies the operator under the applicable rules.

**Why it matters here:** For critical information infrastructure required to use commercial cryptography, the operator has additional governance, staffing, funding, tested-product and service, reviewed-technology, assessment, annual reporting, and procurement-review duties. Sector or system importance alone does not establish this status.

Sources:

- [Critical Information Infrastructure Security Protection Regulation, Articles 2 and 8-11](https://www.cac.gov.cn/2021-08/17/c_1630785976988160.htm?ref=sorena.io)
- [Provisions on the Use and Administration of Commercial Cryptography in Critical Information Infrastructure, Articles 2 and 5-15](https://www.oscca.gov.cn/sca/xxgk/2025-06/27/content_1061270.shtml?ref=sorena.io)

### Electronic certification services using commercial cryptography

**Term:** electronic certification services

Electronic certification services use cryptographic mechanisms to verify electronic signatures and the identity or status associated with them. Since 1 July 2026, a provider using commercial cryptography for these services in China must hold an Electronic Certification Service Cryptography Use License from the State Cryptography Administration. Electronic-government electronic certification services remain under their separate qualification and operating rules.

**Why it matters here:** A provider must identify whether it supplies general electronic certification or electronic-government certification, then retain the correct licence or qualification, system and key-service evidence, annual compliance assessment, training, renewal, and change records.

Sources:

- [Measures for the Administration of Cryptography Use in Electronic Certification Services, Articles 2-3 and 10-17](https://www.oscca.gov.cn/sca/xxgk/2026-06/03/content_1061341.shtml?ref=sorena.io)

## Primary sources

- [PRC Cryptography Law](https://www.oscca.gov.cn/sca/xxgk/2023-06/04/content_1057225.shtml?ref=sorena.io) - Use for cryptography categories, commercial cryptography development and management, product/service controls, CII use, import/export context, penalties, and 1 January 2020 effective date.
- [Notice announcing the Commercial Cryptography Administration Regulation interpretation](https://www.oscca.gov.cn/sca/xwdt/2023-12/05/content_1061145.shtml?ref=sorena.io) - Use for the 2023 commercial cryptography administration regulation revision context, publication, and 1 July 2023 effective date.
- [Commercial Cryptography Administration Regulation (State Council Order No. 760)](https://www.mee.gov.cn/zcwj/gwywj/202305/t20230529_1031579.shtml?ref=sorena.io) - Use for the regulation's scope, voluntary and mandatory testing and certification routes, import and export licensing process, and critical-infrastructure planning, assessment, product, service, technology, and review duties.
- [Provisions on the Use and Administration of Commercial Cryptography in Critical Information Infrastructure](https://www.oscca.gov.cn/sca/xxgk/2025-06/27/content_1061270.shtml?ref=sorena.io) - Use for the critical-infrastructure duties effective 1 August 2025, including governance, staffing, funding, tested and certified products and services, reviewed technologies, lifecycle assessments, and annual assessment.
- [Commercial cryptography testing institution measures interpretation](https://www.oscca.gov.cn/sca/xxgk/2023-10/07/content_1061110.shtml?ref=sorena.io) - Use for qualification and supervision of commercial-cryptography product-testing and application-security-assessment bodies, including report, data, sample, and information-reporting rules.
- [Commercial Cryptography Application Security Assessment Measures](https://www.oscca.gov.cn/sca/xxgk/2023-10/07/content_1061109.shtml?ref=sorena.io) - Articles 2 and 6-15 support the assessment trigger for important network and information systems, plan and pre-operation gates, annual assessment, records, filing, and incident response.
- [Measures for the Administration of Cryptography Use in Electronic Certification Services](https://www.oscca.gov.cn/sca/xxgk/2026-06/03/content_1061341.shtml?ref=sorena.io) - Articles 2-3 and 25 support the licensing rule for electronic certification services using commercial cryptography in China and its 1 July 2026 effective date.

*Recommended reading path*

## Choose the next compliance route

New to the regime? Start with the legal categories and route map. If the item is already classified, jump to the applicable product, infrastructure, shipment, evidence, deadline, or enforcement guide.

### 1. Start here: categories and duties

Understand what the law calls cryptography, how commercial cryptography differs from state-secret categories, and which facts determine the next route.

1. [China Cryptography Law requirements](/artifacts/apac/china-cryptography-law/requirements.md): China commercial cryptography requirements by role: standards, testing, certification, CII use and assessment, trade controls, and evidence.
2. [China commercial cryptography compliance checklist](/artifacts/apac/china-cryptography-law/checklist.md): China commercial cryptography checklist covering classification, product and service assurance, CII duties, trade controls, and retained evidence.

### 2. Products, services, infrastructure, and shipments

Test the distinct triggers for mandatory product or service assurance, critical information infrastructure, and controlled imports or exports.

3. [Commercial cryptography products and testing evidence](/artifacts/apac/china-cryptography-law/commercial-cryptography-products-and-testing.md): When China commercial cryptography testing or certification is voluntary or mandatory, and what product, service, body, and scope evidence to keep.
4. [China cryptography import, export, and security review triage](/artifacts/apac/china-cryptography-law/import-export-and-security-assessment.md): Screen commercial cryptography imports under the 2020 list, exports under China's unified dual-use list, the consumer exclusion, system assessment, and CII review.

### 3. Procurement and evidence

Turn the selected route into supplier due diligence and a reviewable testing or certification record.

5. [Commercial cryptography procurement checklist](/artifacts/apac/china-cryptography-law/commercial-cryptography-procurement-checklist.md): Procurement checks for commercial cryptography products and services used in China, including certificate scope, CII duties, and supplier changes.
6. [China commercial cryptography testing evidence template](/artifacts/apac/china-cryptography-law/commercial-cryptography-testing-evidence-template.md): Record the legal route, product or system scope, testing-body qualification, report details, gaps, and reassessment triggers for China commercial cryptography assurance.

### 4. Dates and enforcement

Separate historical effective dates from operational change triggers, and understand the penalties attached to particular breaches.

7. [China cryptography compliance deadlines and calendar](/artifacts/apac/china-cryptography-law/deadlines-and-compliance-calendar.md): China cryptography effective dates, CII reports, annual assessments, licence renewals, change notices, and pre-operation checks.
8. [China cryptography penalties, fines, and liability](/artifacts/apac/china-cryptography-law/penalties-and-fines.md): China commercial cryptography penalties by actor and violation, including fine bands, corrective orders, confiscation, licence action, and liability.

### 5. Compare regimes and answer focused questions

Keep cryptography decisions distinct from broader cybersecurity duties, or go directly to a concise answer for a specific scenario.

9. [China Cryptography Law vs Cybersecurity Law](/artifacts/apac/china-cryptography-law/china-cryptography-law-vs-cybersecurity-law.md): Compare China's Cryptography Law and current Cybersecurity Law by scope, actor, product assurance, CII duties, evidence, and enforcement.
10. [China Cryptography Law FAQ](/artifacts/apac/china-cryptography-law/faq.md): Answers on China's commercial-cryptography scope, product assurance, classified protection, CII assessment, procurement review, and trade controls.

### 6. More guides

Additional guidance related to this artifact.

11. [Do imported cryptography products need special review?](/artifacts/apac/china-cryptography-law/faq/do-imported-cryptography-products-need-special-review.md): Not every encrypted product imported into China needs a licence. Check the 2020 commercial-cryptography import list, the consumer-product exception, and any CII procurement review.
12. [Does using encryption trigger China Cryptography Law duties?](/artifacts/apac/china-cryptography-law/faq/does-using-encryption-trigger-china-cryptography-law.md): Using encryption does not create one universal China approval duty. Check classified protection, product, service, CII, procurement, and trade triggers.
13. [How does cryptography compliance overlap with China cybersecurity law?](/artifacts/apac/china-cryptography-law/faq/how-does-cryptography-compliance-overlap-with-cybersecurity-law.md): See how China's cryptography rules connect with classified protection, product assurance, CII assessment, and cybersecurity review without merging the regimes.
14. [What is commercial cryptography in China?](/artifacts/apac/china-cryptography-law/faq/what-is-commercial-cryptography-in-china.md): Commercial cryptography protects information that is not a state secret. Learn how China defines the category and which separate facts trigger product, CII, or trade controls.
15. [When is commercial cryptography testing or certification needed?](/artifacts/apac/china-cryptography-law/faq/when-is-commercial-cryptography-testing-or-certification-needed.md): Commercial-cryptography assurance is often voluntary, but specified products and services require it. Covered CII also needs application assessment and qualified cryptography.

## Key dates for China Cryptography Law

*China Timeline*

The visual timeline separates adoption, publication, and effective dates. The law took effect on 1 January 2020; the revised Commercial Cryptography Administration Regulation was published on 27 April 2023 and took effect on 1 July 2023.

*Next step*

## Prepare the commercial cryptography evidence file

Sorena AI turns China Cryptography Law official requirements into scoped decisions, evidence records, owner assignments, and change-trigger reviews.

- Start with the protected information, cryptographic technology, product or service, supplier, operator, China use case, and shipment that create the Cryptography Law question.
- Research Copilot keeps the official citation, decision owner, evidence record, and approval history connected.
- SSOT preserves official citations, route decisions, assurance evidence, and review history when the item, supplier, operator, catalogue, list, destination, or end use changes.

- [Open Research Copilot](/solutions/research-copilot.md): Map commercial cryptography classification, product/service route, testing, certification, import/export screening, and release records to official citations, owners, and review checkpoints.
- [Open SSOT](/solutions/ssot.md): Keep official citations, decisions, approvals, and evidence records connected to governed product and compliance files.
- [Review unresolved triggers](/contact.md): Check unresolved product, service, critical-infrastructure, testing-body, import, or export triggers before release or procurement.

## Compliance Timeline

| Date | Event | Category | Reference |
| --- | --- | --- | --- |
| 2019-10-26 | Cryptography Law adopted | Law | [Source](https://www.oscca.gov.cn/sca/xxgk/2023-06/04/content_1057225.shtml?ref=sorena.io) |
| 2020-01-01 | Cryptography Law takes effect | Law | [Source](https://www.oscca.gov.cn/sca/xxgk/2023-06/04/content_1057225.shtml?ref=sorena.io) |
| 2023-04-14 | Commercial Cryptography Administration Regulation revision approved | Commercial cryptography | [Source](https://www.oscca.gov.cn/sca/xwdt/2023-12/05/content_1061145.shtml?ref=sorena.io) |
| 2023-04-27 | Revised commercial cryptography regulation published | Commercial cryptography | [Source](https://www.oscca.gov.cn/sca/xwdt/2023-12/05/content_1061145.shtml?ref=sorena.io) |
| 2023-07-01 | Revised commercial cryptography regulation takes effect | Commercial cryptography | [Source](https://www.oscca.gov.cn/sca/xwdt/2023-12/05/content_1061145.shtml?ref=sorena.io) |

**Event details:**

- **2019-10-26 - Cryptography Law adopted**: The PRC Cryptography Law was adopted by the Standing Committee of the National People's Congress on 26 October 2019.
- **2020-01-01 - Cryptography Law takes effect**: Article 44 states that the Cryptography Law takes effect on 1 January 2020.
- **2023-04-14 - Commercial Cryptography Administration Regulation revision approved**: The State Council executive meeting reviewed and adopted the revised commercial cryptography regulation draft on 14 April 2023.
- **2023-04-27 - Revised commercial cryptography regulation published**: State Council Order No. 760 published the revised Commercial Cryptography Administration Regulation on 27 April 2023.
- **2023-07-01 - Revised commercial cryptography regulation takes effect**: The revised Commercial Cryptography Administration Regulation took effect on 1 July 2023.


---

[Privacy Policy](https://www.sorena.io/privacy.md) | [Terms of Use](https://www.sorena.io/terms-of-use.md) | [DMCA](https://www.sorena.io/dmca.md) | [About Us](https://www.sorena.io/about-us.md)

(c) 2026 Sorena AB (559573-7338). All rights reserved.

Source: https://www.sorena.io/artifacts/apac/china-cryptography-law.md
