CryptographyChina

China Cryptography Law commercial cryptography compliance checklist

China commercial cryptography checklist covering classification, product and service assurance, CII duties, trade controls, and retained evidence.

For product, security, legal, procurement, and trade teams: identify the protected information and exact item, test each legal trigger, resolve mandatory requirements, and keep the evidence behind the decision.

Author
Sorena AI
Published
Jul 5, 2026
Updated
Jul 25, 2026
Sections
4

Structured answer sets in this page tree.

Primary sources
8

Cited legal and guidance references.

Publication metadata
Sorena AI
Published Jul 5, 2026
Updated Jul 25, 2026
Overview

Use this checklist to classify a China use and decide which product, service, network-security graded-protection, , assessment, electronic-certification, or import/export route needs action before launch, procurement, or shipment.

Section 2

Complete each gate and retain its evidence

Complete the steps in order because later evidence depends on the classification and route decision. A certificate is useful only when its product or service, model, version, scope, issuer, and status match the item under review.

The owner assignments, approval gate, and reassessment triggers below are Sorena's operational synthesis. The cited rules establish the legal duties; they do not prescribe this internal workflow.

  • Assign a product-security owner for the item and cryptographic-function inventory.
  • Assign legal or compliance owners for the mandatory product or service route, route, and import or export route.
  • Hold launch, procurement, or shipment while an identified mandatory certification, assessment, , or trade-license requirement remains unresolved.
  • Link supplier evidence to the exact product version and route it supports.
  • Approve the scoped conclusion and exceptions before launch or procurement.
  • Set reassessment events for changes to the cryptographic function, product version, architecture, supplier, operator, status, catalogue, control list, destination, or end use.
Section 3

Evidence to keep before launch or change approval

The evidence file should identify the exact item and use reviewed. A supplier statement that an item is 'China compliant' does not identify which legal route, version, or scope it covers.

For an important network and information system subject to application security assessment, keep the application plan, system and equipment inventory, network topology, management rules, configuration and operation records, assessment inputs, report, filing evidence, remediation, and approval. Where the operator self-assesses, the official measures require original records and reports to be retained for at least six years.

  • Cryptography inventory tied to the product, service, system, model, version, and intended use.
  • Classification memo stating what information is protected and why the use is .
  • Mandatory catalogue check, voluntary certification records, and the test report or certificate scope and status.
  • identification, accountable main person, qualified key and operation roles, funding, application plan, product or service and technology checks, assessment report, filing, annual report, remediation, and conclusion where applicable.
  • Network graded-protection level and the use, management, and assessment requirements applied to that level.
  • Electronic-certification licence or electronic-government qualification, covered service and system, annual assessment, training, change, and renewal records where applicable.
  • Import license and export control list screening, mass-market consumer-product analysis if used, and any license.
  • Dated decision, accountable owner, unresolved issues, approval, exceptions, and change log.
Section 4

Boundary with nearby China regimes

The Cryptography Law route does not replace the current Cybersecurity Law route. The Cybersecurity Law separately covers network-security graded protection, network product and service duties, , protection, and .

The amended Cybersecurity Law has applied since 1 January 2026. Use its current article numbering when recording a cross-reference, and keep privacy, data-export, and app-governance conclusions in their own source-backed analyses.

  • Treating every use of encryption as subject to mandatory certification.
  • Treating a voluntary product certification catalogue as the mandatory network-product catalogue test.
  • Relying on a product certificate as proof that a application assessment or is complete.
  • Screening import or export controls without the same product identity, cryptographic function, destination, end user, and end use used in the product inventory.
Primary sources

References and citations

oscca.gov.cn
Referenced sections
  • Use for cryptography categories, commercial cryptography development and management, product/service controls, CII use, import/export context, penalties, and 1 January 2020 effective date.
cac.gov.cn
Referenced sections
  • Use for the current text, including Article 23 graded protection, Article 25 network critical equipment and network security-specific products, and Articles 33-40 CII duties.
Related guides

Explore more topics

China commercial cryptography testing evidence template
Record the legal route, product or system scope, testing-body qualification, report details, gaps, and reassessment triggers for China commercial cryptography assurance.
China cryptography compliance deadlines and calendar
China cryptography effective dates, CII reports, annual assessments, licence renewals, change notices, and pre-operation checks.
China cryptography import, export, and security review triage
Screen commercial cryptography imports under the 2020 list, exports under China's unified dual-use list, the consumer exclusion, system assessment, and CII review.
China Cryptography Law FAQ
Answers on China's commercial-cryptography scope, product assurance, classified protection, CII assessment, procurement review, and trade controls.
China Cryptography Law requirements
China commercial cryptography requirements by role: standards, testing, certification, CII use and assessment, trade controls, and evidence.
China Cryptography Law vs Cybersecurity Law
Compare China's Cryptography Law and current Cybersecurity Law by scope, actor, product assurance, CII duties, evidence, and enforcement.
China cryptography penalties, fines, and liability
China commercial cryptography penalties by actor and violation, including fine bands, corrective orders, confiscation, licence action, and liability.
Commercial cryptography procurement checklist
Procurement checks for commercial cryptography products and services used in China, including certificate scope, CII duties, and supplier changes.
Commercial cryptography products and testing evidence
When China commercial cryptography testing or certification is voluntary or mandatory, and what product, service, body, and scope evidence to keep.
Do imported cryptography products need special review?
Not every encrypted product imported into China needs a licence. Check the 2020 commercial-cryptography import list, the consumer-product exception, and any CII procurement review.
Does using encryption trigger China Cryptography Law duties?
Using encryption does not create one universal China approval duty. Check classified protection, product, service, CII, procurement, and trade triggers.
How does cryptography compliance overlap with China cybersecurity law?
See how China's cryptography rules connect with classified protection, product assurance, CII assessment, and cybersecurity review without merging the regimes.
What is commercial cryptography in China?
Commercial cryptography protects information that is not a state secret. Learn how China defines the category and which separate facts trigger product, CII, or trade controls.
When is commercial cryptography testing or certification needed?
Commercial-cryptography assurance is often voluntary, but specified products and services require it. Covered CII also needs application assessment and qualified cryptography.