---
title: "China commercial cryptography compliance checklist"
canonical_url: "https://www.sorena.io/artifacts/apac/china-cryptography-law/checklist"
source_url: "https://www.sorena.io/artifacts/apac/china-cryptography-law/checklist"
author: "Sorena AI"
description: "China commercial cryptography checklist covering classification, product and service assurance, CII duties, trade controls, and retained evidence."
published_at: "2026-07-05"
updated_at: "2026-07-25"
keywords:
  - "China Cryptography Law"
  - "Commercial cryptography"
  - "Cryptography Law"
  - "Commercial cryptography testing"
  - "China cybersecurity"
---
**[SORENA](https://www.sorena.io/)** - AI-Powered GRC Platform

[Home](https://www.sorena.io/) | [Solutions](https://www.sorena.io/solutions) | [Artifacts](https://www.sorena.io/artifacts) | [About Us](https://www.sorena.io/about-us) | [Contact](https://www.sorena.io/contact) | [Portal](https://app.sorena.io)

---

# China commercial cryptography compliance checklist

China commercial cryptography checklist covering classification, product and service assurance, CII duties, trade controls, and retained evidence.

*Cryptography* *China*

## China Cryptography Law commercial cryptography compliance checklist

For product, security, legal, procurement, and trade teams: identify the protected information and exact item, test each legal trigger, resolve mandatory requirements, and keep the evidence behind the decision.

Use this checklist to classify a China commercial cryptography use and decide which product, service, network-security graded-protection, CII, assessment, electronic-certification, or import/export route needs action before launch, procurement, or shipment.

## Definitions

### Commercial cryptography

Commercial cryptography means technology, products, and services that use specific transformations to encrypt or authenticate information that is not a state secret. It is distinct from core and ordinary cryptography, which protect state-secret information. The category can cover a cryptographic algorithm, hardware or software product, or service; the product name or the mere presence of encryption does not decide which testing, certification, assessment, or trade rule applies.

**Why it matters here:** This checklist starts by placing the actual technology, product, or service in the commercial cryptography category. The team must then test each additional legal trigger separately instead of treating that classification as an approval requirement.

Sources:

- [PRC Cryptography Law, Articles 2 and 6-8](https://www.oscca.gov.cn/sca/xxgk/2023-06/04/content_1057225.shtml?ref=sorena.io)
- [Commercial Cryptography Administration Regulation, Article 2](https://www.mee.gov.cn/zcwj/gwywj/202305/t20230529_1031579.shtml?ref=sorena.io)

### Critical information infrastructure

**Term:** CII

Critical information infrastructure is infrastructure in important industries and fields, including public communications and information services, energy, transport, water, finance, public services, and electronic government, where destruction, loss of function, or data leakage could seriously harm national security, the national economy and people's livelihoods, or the public interest. The responsible protection department identifies CII under the governing rules; an organization should not infer CII status from sector or system importance alone.

**Why it matters here:** The CII-specific cryptography rules apply only after the infrastructure falls within that identification framework. For CII subject to the national requirement to use commercial cryptography, the operator must address dedicated governance, personnel, product, technology, planning, assessment, reporting, and procurement-review duties.

Sources:

- [PRC Cybersecurity Law, Article 33](https://www.cac.gov.cn/2025-12/29/c_1768735112911946.htm?ref=sorena.io)
- [Provisions on the Use and Administration of Commercial Cryptography in Critical Information Infrastructure, Article 2](https://www.oscca.gov.cn/sca/xxgk/2025-06/27/content_1061270.shtml?ref=sorena.io)

### Commercial cryptography application security assessment

A commercial cryptography application security assessment examines whether a network or information system uses commercial cryptography technology, products, and services compliantly, correctly, and effectively under the applicable laws and standards. It can assess an application plan before construction, the implemented system before operation, and the operating system at least annually when the legal trigger applies. It is a system-level assessment, not a product certificate.

**Why it matters here:** When an important network and information system is required to use commercial cryptography, the checklist must capture the plan assessment, pre-operation result, recurring assessment, filing, remediation, and supporting records separately from product or service certification.

Sources:

- [Commercial Cryptography Application Security Assessment Measures, Articles 2 and 6-14](https://www.oscca.gov.cn/sca/xxgk/2023-10/07/content_1061109.shtml?ref=sorena.io)

### Cybersecurity review

Cybersecurity review is the review conducted under the Cybersecurity Review Measures when a critical information infrastructure operator procures network products or services that affect or may affect national security. It examines national-security risks associated with the procurement and is separate from product certification and commercial cryptography application security assessment.

**Why it matters here:** For CII procurement involving commercial cryptography, the operator must determine whether the review applies and retain the review conclusion separately from the supplier's certificate and the system's cryptography assessment.

Sources:

- [Cybersecurity Review Measures, Article 2](https://www.oscca.gov.cn/sca/xxgk/2022-01/04/content_1060954.shtml?ref=sorena.io)
- [Provisions on the Use and Administration of Commercial Cryptography in Critical Information Infrastructure, Article 9](https://www.oscca.gov.cn/sca/xxgk/2025-06/27/content_1061270.shtml?ref=sorena.io)

### Network critical equipment and network security-specific products

These are products covered by the catalogue published under the Cybersecurity Law. A covered product must meet mandatory national standards and pass qualified security certification or security testing before sale or provision. A separate commercial cryptography product certification catalogue supports a generally voluntary certification system and is not the same catalogue.

**Why it matters here:** A commercial cryptography product must pass qualified testing and certification under Cryptography Law Article 26 when the actual item falls within the mandatory network-product catalogue. A commercial cryptography service using a product in that catalogue must also be certified.

Sources:

- [PRC Cybersecurity Law, Article 25](https://www.cac.gov.cn/2025-12/29/c_1768735112911946.htm?ref=sorena.io)
- [PRC Cryptography Law, Article 26](https://www.oscca.gov.cn/sca/xxgk/2023-06/04/content_1057225.shtml?ref=sorena.io)

### Commercial cryptography testing and certification

**Term:** testing and certification

Commercial cryptography testing produces data or results about a product or a system's use of cryptography. Certification produces a conformity conclusion for a product, service, or management system and includes follow-up surveillance. The national system generally encourages voluntary testing and certification, while separate catalogue, service, system, or CII rules can make particular assurance mandatory.

**Why it matters here:** The checklist must identify the legal route, issuer type, body qualification, approved scope, exact covered item and version, result, validity, and current status. A report and a certificate answer different questions and neither proves every Cryptography Law duty.

Sources:

- [Commercial Cryptography Administration Regulation, Articles 12-21](https://www.mee.gov.cn/zcwj/gwywj/202305/t20230529_1031579.shtml?ref=sorena.io)

### Commercial cryptography used in mass-market consumer products

**Term:** mass-market consumer products

The Cryptography Law excludes commercial cryptography used in mass-market consumer products from its import-licensing and export-control system. The National Cryptography Administration describes this category as products or technologies available to the public without restriction through ordinary retail channels, intended for personal use, and whose cryptographic function cannot easily be changed.

**Why it matters here:** Before relying on the exclusion, the trade owner must document the exact model, retail availability, intended users and use, distribution restrictions, and whether its cryptographic function can readily be changed. The exclusion does not remove product, system-assessment, CII, or procurement-review duties.

Sources:

- [PRC Cryptography Law, Article 28](https://www.oscca.gov.cn/sca/xxgk/2023-06/04/content_1057225.shtml?ref=sorena.io)
- [National Cryptography Administration policy answer on mass-market consumer products](https://www.oscca.gov.cn/sca/xxgk/2020-04/02/content_1060694.shtml?ref=sorena.io)

## Classify the use and test each legal trigger

Start with the Cryptography Law categories. Core and ordinary cryptography protect state-secret information; commercial cryptography protects information that is not a state secret. Citizens, legal persons, and other organizations may lawfully use commercial cryptography, but particular products, services, systems, operators, and shipments can trigger additional duties.

The Cryptography Law sets the main routes in Articles 24-28. The 2023 Commercial Cryptography Administration Regulation adds operational detail, and the CII-specific provisions effective 1 August 2025 apply only to infrastructure already identified as critical information infrastructure under the applicable rules.

- Product-security owner - identify the information protected, cryptographic function, product or service, model and version, supplier, operator, intended China use, and supporting architecture or specification.
- Legal or security owner - document why the use is commercial cryptography for non-state-secret information rather than a core or ordinary cryptography scenario involving state secrets.
- Product owner - check whether the item is legally included in the catalogue of network critical equipment and network security-specific products. If it is, retain the catalogue entry, match rationale, and qualified testing and certification evidence required before sale or provision. Do not substitute a voluntary commercial cryptography certification catalogue.
- Service owner - if a commercial cryptography service uses network critical equipment or a network security-specific product, retain the service certificate, issuer qualification, covered service and products, validity, status, and limitations.
- Network operator - record the network's confirmed graded-protection level and the current commercial cryptography use, management, and application-security-assessment requirements set for that level. Do not infer CII status from the protection level.
- CII operator - for infrastructure required to use commercial cryptography, retain product and service testing and certification, technology review and identification, commercial cryptography application security assessment of the plan and system, the annual report due to the protection work department by 31 January, and any cybersecurity review for procurement that affects or may affect national security.
- Electronic-certification provider - if the service uses commercial cryptography to provide electronic certification in China, retain the Electronic Certification Service Cryptography Use Licence, its five-year term and scope, annual compliance assessment, annual training, change records, and renewal filing. Apply the separate electronic-government electronic certification qualification route where the service is supplied for government activities.
- Trade owner - for each shipment, check the current import-licensing or export-control route. If relying on the exclusion for commercial cryptography used in mass-market consumer products, retain the model, retail availability, intended user and use, distribution, configurability, and legal conclusion.
- Decision owner - record the conclusion, source version and check date, evidence, unresolved question, approval date, and reassessment trigger for every route.

Sources for this answer:

- [PRC Cryptography Law](https://www.oscca.gov.cn/sca/xxgk/2023-06/04/content_1057225.shtml?ref=sorena.io) - Use for cryptography categories, commercial cryptography development and management, product/service controls, CII use, import/export context, penalties, and 1 January 2020 effective date.
- [Commercial cryptography testing institution measures interpretation](https://www.oscca.gov.cn/sca/xxgk/2023-10/07/content_1061110.shtml?ref=sorena.io) - Use for qualification and supervision of commercial-cryptography product-testing and application-security-assessment bodies, including report, data, sample, and information-reporting rules.
- [Commercial Cryptography Administration Regulation (State Council Order No. 760)](https://www.mee.gov.cn/zcwj/gwywj/202305/t20230529_1031579.shtml?ref=sorena.io) - Articles 11-21 support standards, voluntary testing and certification, qualified bodies, mandatory catalogue-product testing and certification, and service certification; Articles 31-42 support trade and CII checks.
- [Provisions on the Use and Administration of Commercial Cryptography in Critical Information Infrastructure](https://www.oscca.gov.cn/sca/xxgk/2025-06/27/content_1061270.shtml?ref=sorena.io) - Articles 2 and 5-15 support the CII applicability boundary, governance, staffing, funding, product and technology checks, application plans, lifecycle assessments, annual assessment, and the operator's 31 January reporting deadline.
- [Measures for the Administration of Cryptography Use in Electronic Certification Services](https://www.oscca.gov.cn/sca/xxgk/2026-06/03/content_1061341.shtml?ref=sorena.io) - Articles 2-3 and 10-17 support the electronic-certification licensing, five-year term, renewal, change, annual assessment, and annual training checks effective from 1 July 2026.

## Complete each gate and retain its evidence

Complete the steps in order because later evidence depends on the classification and route decision. A certificate is useful only when its product or service, model, version, scope, issuer, and status match the item under review.

The owner assignments, approval gate, and reassessment triggers below are Sorena's operational synthesis. The cited rules establish the legal duties; they do not prescribe this internal workflow.

- Assign a product-security owner for the item and cryptographic-function inventory.
- Assign legal or compliance owners for the mandatory product or service route, CII route, and import or export route.
- Hold launch, procurement, or shipment while an identified mandatory certification, CII assessment, cybersecurity review, or trade-license requirement remains unresolved.
- Link supplier evidence to the exact product version and route it supports.
- Approve the scoped conclusion and exceptions before launch or procurement.
- Set reassessment events for changes to the cryptographic function, product version, architecture, supplier, operator, CII status, catalogue, control list, destination, or end use.

Sources for this answer:

- [PRC Cryptography Law](https://www.oscca.gov.cn/sca/xxgk/2023-06/04/content_1057225.shtml?ref=sorena.io) - Use for cryptography categories, commercial cryptography development and management, product/service controls, CII use, import/export context, penalties, and 1 January 2020 effective date.
- [Commercial cryptography testing institution measures interpretation](https://www.oscca.gov.cn/sca/xxgk/2023-10/07/content_1061110.shtml?ref=sorena.io) - Use for qualification and supervision of commercial-cryptography product-testing and application-security-assessment bodies, including report, data, sample, and information-reporting rules.
- [Commercial Cryptography Application Security Assessment Measures](https://www.oscca.gov.cn/sca/xxgk/2023-10/07/content_1061109.shtml?ref=sorena.io) - Articles 6-15 support application-plan assessment, pre-operation and annual assessment, assessment evidence, six-year retention for self-assessments, filing within 30 days, and incident-driven reassessment.

## Evidence to keep before launch or change approval

The evidence file should identify the exact item and use reviewed. A supplier statement that an item is 'China compliant' does not identify which legal route, version, or scope it covers.

For an important network and information system subject to application security assessment, keep the application plan, system and equipment inventory, network topology, management rules, configuration and operation records, assessment inputs, report, filing evidence, remediation, and approval. Where the operator self-assesses, the official measures require original records and reports to be retained for at least six years.

- Cryptography inventory tied to the product, service, system, model, version, and intended use.
- Classification memo stating what information is protected and why the use is commercial cryptography.
- Mandatory catalogue check, voluntary certification records, and the test report or certificate scope and status.
- CII identification, accountable main person, qualified key and operation roles, funding, application plan, product or service and technology checks, assessment report, filing, annual report, remediation, and cybersecurity review conclusion where applicable.
- Network graded-protection level and the commercial cryptography use, management, and assessment requirements applied to that level.
- Electronic-certification licence or electronic-government qualification, covered service and system, annual assessment, training, change, and renewal records where applicable.
- Import license and export control list screening, mass-market consumer-product analysis if used, and any license.
- Dated decision, accountable owner, unresolved issues, approval, exceptions, and change log.

Sources for this answer:

- [PRC Cryptography Law](https://www.oscca.gov.cn/sca/xxgk/2023-06/04/content_1057225.shtml?ref=sorena.io) - Use for cryptography categories, commercial cryptography development and management, product/service controls, CII use, import/export context, penalties, and 1 January 2020 effective date.
- [Commercial Cryptography Application Security Assessment Measures](https://www.oscca.gov.cn/sca/xxgk/2023-10/07/content_1061109.shtml?ref=sorena.io) - Articles 10-15 identify assessment content, operator support records, self-assessment retention, filing, and incident response requirements.

## Boundary with nearby China regimes

The Cryptography Law route does not replace the current Cybersecurity Law route. The Cybersecurity Law separately covers network-security graded protection, network product and service duties, network critical equipment and network security-specific products, CII protection, and cybersecurity review.

The amended Cybersecurity Law has applied since 1 January 2026. Use its current article numbering when recording a cross-reference, and keep privacy, data-export, and app-governance conclusions in their own source-backed analyses.

- Treating every use of encryption as subject to mandatory certification.
- Treating a voluntary commercial cryptography product certification catalogue as the mandatory network-product catalogue test.
- Relying on a product certificate as proof that a CII application assessment or cybersecurity review is complete.
- Screening import or export controls without the same product identity, cryptographic function, destination, end user, and end use used in the product inventory.

Sources for this answer:

- [PRC Cryptography Law](https://www.oscca.gov.cn/sca/xxgk/2023-06/04/content_1057225.shtml?ref=sorena.io) - Use for cryptography categories, commercial cryptography development and management, product/service controls, CII use, import/export context, penalties, and 1 January 2020 effective date.
- [PRC Cybersecurity Law, amended in 2025](https://www.cac.gov.cn/2025-12/29/c_1768735112911946.htm?ref=sorena.io) - Use for the current text, including Article 23 graded protection, Article 25 network critical equipment and network security-specific products, and Articles 33-40 CII duties.
- [Presidential Order No. 61 promulgating the 2025 Cybersecurity Law amendment](https://www.npc.gov.cn/npc/c2/c30834/202510/t20251028_449031.html?ref=sorena.io) - Supports the amendment's 1 January 2026 effective date.

*Next step*

*Placement: Before primary sources*

## Prepare the commercial cryptography evidence file

Sorena AI helps assign owners, controls, and review records for each China commercial cryptography decision.

- [Map official sources to evidence](/solutions/research-copilot.md): Research Copilot connects the official citation, decision, owner, retained evidence, and change history.
- [Review the China route](/contact.md): Check the China Cryptography Law scope decision and unresolved launch questions with Sorena.

## Primary sources

- [PRC Cryptography Law](https://www.oscca.gov.cn/sca/xxgk/2023-06/04/content_1057225.shtml?ref=sorena.io) - Use for cryptography categories, commercial cryptography development and management, product/service controls, CII use, import/export context, penalties, and 1 January 2020 effective date.
- [Commercial cryptography testing institution measures interpretation](https://www.oscca.gov.cn/sca/xxgk/2023-10/07/content_1061110.shtml?ref=sorena.io) - Use for qualification and supervision of commercial-cryptography product-testing and application-security-assessment bodies, including report, data, sample, and information-reporting rules.
- [Commercial Cryptography Administration Regulation (State Council Order No. 760)](https://www.mee.gov.cn/zcwj/gwywj/202305/t20230529_1031579.shtml?ref=sorena.io) - Use for the detailed testing, certification, trade, and CII requirements that implement the Cryptography Law.
- [Provisions on the Use and Administration of Commercial Cryptography in Critical Information Infrastructure](https://www.oscca.gov.cn/sca/xxgk/2025-06/27/content_1061270.shtml?ref=sorena.io) - Use for CII-specific requirements effective 1 August 2025.
- [Commercial Cryptography Application Security Assessment Measures](https://www.oscca.gov.cn/sca/xxgk/2023-10/07/content_1061109.shtml?ref=sorena.io) - Use for assessment planning, performance, evidence, retention, filing, and incident triggers.
- [PRC Cybersecurity Law, amended in 2025](https://www.cac.gov.cn/2025-12/29/c_1768735112911946.htm?ref=sorena.io) - Use for the current Cybersecurity Law boundaries and cross-referenced network-product and CII duties.
- [Presidential Order No. 61 promulgating the 2025 Cybersecurity Law amendment](https://www.npc.gov.cn/npc/c2/c30834/202510/t20251028_449031.html?ref=sorena.io) - Use for the amendment's 1 January 2026 effective date.
- [Measures for the Administration of Cryptography Use in Electronic Certification Services](https://www.oscca.gov.cn/sca/xxgk/2026-06/03/content_1061341.shtml?ref=sorena.io) - Use for the licensing and recurring duties of electronic certification providers using commercial cryptography in China from 1 July 2026.

## Related Topic Guides

- [China commercial cryptography testing evidence template](/artifacts/apac/china-cryptography-law/commercial-cryptography-testing-evidence-template.md): Record the legal route, product or system scope, testing-body qualification, report details, gaps, and reassessment triggers for China commercial cryptography assurance.
- [China cryptography compliance deadlines and calendar](/artifacts/apac/china-cryptography-law/deadlines-and-compliance-calendar.md): China cryptography effective dates, CII reports, annual assessments, licence renewals, change notices, and pre-operation checks.
- [China cryptography import, export, and security review triage](/artifacts/apac/china-cryptography-law/import-export-and-security-assessment.md): Screen commercial cryptography imports under the 2020 list, exports under China's unified dual-use list, the consumer exclusion, system assessment, and CII review.
- [China Cryptography Law FAQ](/artifacts/apac/china-cryptography-law/faq.md): Answers on China's commercial-cryptography scope, product assurance, classified protection, CII assessment, procurement review, and trade controls.
- [China Cryptography Law requirements](/artifacts/apac/china-cryptography-law/requirements.md): China commercial cryptography requirements by role: standards, testing, certification, CII use and assessment, trade controls, and evidence.
- [China Cryptography Law vs Cybersecurity Law](/artifacts/apac/china-cryptography-law/china-cryptography-law-vs-cybersecurity-law.md): Compare China's Cryptography Law and current Cybersecurity Law by scope, actor, product assurance, CII duties, evidence, and enforcement.
- [China cryptography penalties, fines, and liability](/artifacts/apac/china-cryptography-law/penalties-and-fines.md): China commercial cryptography penalties by actor and violation, including fine bands, corrective orders, confiscation, licence action, and liability.
- [Commercial cryptography procurement checklist](/artifacts/apac/china-cryptography-law/commercial-cryptography-procurement-checklist.md): Procurement checks for commercial cryptography products and services used in China, including certificate scope, CII duties, and supplier changes.
- [Commercial cryptography products and testing evidence](/artifacts/apac/china-cryptography-law/commercial-cryptography-products-and-testing.md): When China commercial cryptography testing or certification is voluntary or mandatory, and what product, service, body, and scope evidence to keep.
- [Do imported cryptography products need special review?](/artifacts/apac/china-cryptography-law/faq/do-imported-cryptography-products-need-special-review.md): Not every encrypted product imported into China needs a licence. Check the 2020 commercial-cryptography import list, the consumer-product exception, and any CII procurement review.
- [Does using encryption trigger China Cryptography Law duties?](/artifacts/apac/china-cryptography-law/faq/does-using-encryption-trigger-china-cryptography-law.md): Using encryption does not create one universal China approval duty. Check classified protection, product, service, CII, procurement, and trade triggers.
- [How does cryptography compliance overlap with China cybersecurity law?](/artifacts/apac/china-cryptography-law/faq/how-does-cryptography-compliance-overlap-with-cybersecurity-law.md): See how China's cryptography rules connect with classified protection, product assurance, CII assessment, and cybersecurity review without merging the regimes.
- [What is commercial cryptography in China?](/artifacts/apac/china-cryptography-law/faq/what-is-commercial-cryptography-in-china.md): Commercial cryptography protects information that is not a state secret. Learn how China defines the category and which separate facts trigger product, CII, or trade controls.
- [When is commercial cryptography testing or certification needed?](/artifacts/apac/china-cryptography-law/faq/when-is-commercial-cryptography-testing-or-certification-needed.md): Commercial-cryptography assurance is often voluntary, but specified products and services require it. Covered CII also needs application assessment and qualified cryptography.


---

[Privacy Policy](https://www.sorena.io/privacy.md) | [Terms of Use](https://www.sorena.io/terms-of-use.md) | [DMCA](https://www.sorena.io/dmca.md) | [About Us](https://www.sorena.io/about-us.md)

(c) 2026 Sorena AB (559573-7338). All rights reserved.

Source: https://www.sorena.io/artifacts/apac/china-cryptography-law/checklist.md
