- Articles 11-21 support standards, voluntary testing and certification, qualified bodies, mandatory catalogue-product testing and certification, and service certification; Articles 31-42 support trade and CII checks.
References and citations
- Articles 10-15 identify assessment content, operator support records, self-assessment retention, filing, and incident response requirements.
- Use for qualification and supervision of commercial-cryptography product-testing and application-security-assessment bodies, including report, data, sample, and information-reporting rules.
- Articles 2-3 and 10-17 support the electronic-certification licensing, five-year term, renewal, change, annual assessment, and annual training checks effective from 1 July 2026.
- Use for cryptography categories, commercial cryptography development and management, product/service controls, CII use, import/export context, penalties, and 1 January 2020 effective date.
- Use for the current text, including Article 23 graded protection, Article 25 network critical equipment and network security-specific products, and Articles 33-40 CII duties.
- Supports the amendment's 1 January 2026 effective date.
- Articles 2 and 5-15 support the CII applicability boundary, governance, staffing, funding, product and technology checks, application plans, lifecycle assessments, annual assessment, and the operator's 31 January reporting deadline.