Compare China's Cryptography Law and current Cybersecurity Law by scope, actor, product assurance, CII duties, evidence, and enforcement.
The two laws overlap on specified network products and CII, but they answer different questions. This comparison uses the Cybersecurity Law as amended in 2025 and effective 1 January 2026.
Use both laws when a China product or system uses and also operates a network, supplies a regulated network product or service, or forms part of . Keep the legal conclusions separate even when they use the same technical evidence.
Comparison
China Cryptography Law vs China Cybersecurity Law
The Cryptography Law governs cryptography-specific decisions. The Cybersecurity Law governs the wider network-security baseline and supplies linked product-assurance and review routes.
Use for the cryptography category, commercial-cryptography activities, specified products and services, electronic certification using , cryptography use, and controlled trade.
Second framework
China Cybersecurity Law
Use for network operation, , network products and services, regulated network products, protection, incidents, and linked national security review.
China Cryptography Law covers classification, product/service management, testing/certification, electronic certification using commercial cryptography, cryptography use, and import/export screening.
Cybersecurity Law Article 2 applies to building, operating, maintaining, and using networks in China and to cybersecurity supervision. It covers network operation, products and services, regulated network products, , network information, and incident response.
China Cryptography Law work is usually owned by a provider, product owner, electronic-certification provider, importer or exporter, procurement team, or team using commercial cryptography.
The Cybersecurity Law assigns duties to network operators, network product and service providers, providers of particular online services, operators, and public authorities. The actor depends on the activity and system.
China Cryptography Law screening starts with cryptography product/service classification, listed product question, testing/certification dependency, security assessment, or import/export screening.
Cybersecurity Law screening starts when an organization builds, operates, maintains, or uses a network in China, supplies a network product or service, handles a regulated network product, operates , or procures for CII.
testing and certification are generally voluntary. Mandatory assurance applies to a qualifying commercial cryptography product in the network critical equipment and network security-specific product catalogue, a commercial cryptography service using a listed product, and commercial cryptography products and services. Important systems required to use commercial cryptography have a separate application security assessment route.
Cybersecurity Law Article 25 requires qualified security certification or security testing for network critical equipment and network security-specific products before sale or provision. and security duties assess the wider network and operator, including controls beyond the cryptographic function.
Keep the catalogue match, product or service assurance, cryptographic technology review, application security assessment, graded-protection work, and security assessment as distinct conclusions. Coordinate evidence where the rules call for avoiding duplicate testing or assessment.
A China Cryptography Law evidence file includes a cryptography inventory, supplier declaration, testing or certification status, assessment or import-export note, and release approval.
A Cybersecurity Law file should identify the network and operator, graded-protection controls, product or service security records, regulated-product catalogue match and assurance, incident records, and evidence where applicable.
China Cryptography Law timing starts with its 1 January 2020 effective date and the revised regulation's 1 July 2023 effective date; operational dates depend on the selected route.
The Cybersecurity Law first took effect on 1 June 2017. The 2025 amendment and current renumbering took effect on 1 January 2026. Operational timing also depends on the duty, product lifecycle, incident, and status.
China Cryptography Law exposure follows the breached duty and actor: testing or certification body, seller or provider, operator, importer or exporter, electronic-government certification provider, official, or other responsible person.
Cybersecurity Law exposure follows the breached duty and actor. The 2025 amendment revised and increased several penalty provisions, so use the current article and facts rather than an older penalty summary.
Preserve the evidence trail before launch, filing, transfer, procurement, sale, or disposal because later remediation is weaker than a dated decision record.
China Cryptography Law and China Cybersecurity Law can use the same product, app, supplier, data-flow, or equipment facts, but China Cryptography Law owns the decision for classification, product/service management, testing/certification, electronic-certification cryptography use, cryptography use, and import/export screening.
The Cybersecurity Law track owns , general product and service security, regulated network-product, protection, incident, and national security review conclusions.
Choose China Cryptography Law when the immediate blocker is cryptography product/service classification, listed product question, testing/certification dependency, security assessment, or import/export screening.
Open the Cybersecurity Law track for network operation, product or service security, , a regulated network-product catalogue question, protection, an incident, or CII procurement review.
China Cryptography Law covers classification, product/service management, testing/certification, electronic certification using commercial cryptography, cryptography use, and import/export screening.
Cybersecurity Law Article 2 applies to building, operating, maintaining, and using networks in China and to cybersecurity supervision. It covers network operation, products and services, regulated network products, , network information, and incident response.
China Cryptography Law work is usually owned by a provider, product owner, electronic-certification provider, importer or exporter, procurement team, or team using commercial cryptography.
The Cybersecurity Law assigns duties to network operators, network product and service providers, providers of particular online services, operators, and public authorities. The actor depends on the activity and system.
China Cryptography Law screening starts with cryptography product/service classification, listed product question, testing/certification dependency, security assessment, or import/export screening.
Cybersecurity Law screening starts when an organization builds, operates, maintains, or uses a network in China, supplies a network product or service, handles a regulated network product, operates , or procures for CII.
testing and certification are generally voluntary. Mandatory assurance applies to a qualifying commercial cryptography product in the network critical equipment and network security-specific product catalogue, a commercial cryptography service using a listed product, and commercial cryptography products and services. Important systems required to use commercial cryptography have a separate application security assessment route.
Cybersecurity Law Article 25 requires qualified security certification or security testing for network critical equipment and network security-specific products before sale or provision. and security duties assess the wider network and operator, including controls beyond the cryptographic function.
Keep the catalogue match, product or service assurance, cryptographic technology review, application security assessment, graded-protection work, and security assessment as distinct conclusions. Coordinate evidence where the rules call for avoiding duplicate testing or assessment.
A China Cryptography Law evidence file includes a cryptography inventory, supplier declaration, testing or certification status, assessment or import-export note, and release approval.
A Cybersecurity Law file should identify the network and operator, graded-protection controls, product or service security records, regulated-product catalogue match and assurance, incident records, and evidence where applicable.
China Cryptography Law timing starts with its 1 January 2020 effective date and the revised regulation's 1 July 2023 effective date; operational dates depend on the selected route.
The Cybersecurity Law first took effect on 1 June 2017. The 2025 amendment and current renumbering took effect on 1 January 2026. Operational timing also depends on the duty, product lifecycle, incident, and status.
China Cryptography Law exposure follows the breached duty and actor: testing or certification body, seller or provider, operator, importer or exporter, electronic-government certification provider, official, or other responsible person.
Cybersecurity Law exposure follows the breached duty and actor. The 2025 amendment revised and increased several penalty provisions, so use the current article and facts rather than an older penalty summary.
Preserve the evidence trail before launch, filing, transfer, procurement, sale, or disposal because later remediation is weaker than a dated decision record.
China Cryptography Law and China Cybersecurity Law can use the same product, app, supplier, data-flow, or equipment facts, but China Cryptography Law owns the decision for classification, product/service management, testing/certification, electronic-certification cryptography use, cryptography use, and import/export screening.
The Cybersecurity Law track owns , general product and service security, regulated network-product, protection, incident, and national security review conclusions.
Choose China Cryptography Law when the immediate blocker is cryptography product/service classification, listed product question, testing/certification dependency, security assessment, or import/export screening.
Open the Cybersecurity Law track for network operation, product or service security, , a regulated network-product catalogue question, protection, an incident, or CII procurement review.
Use China Cryptography Law when the facts match cryptography product/service classification, listed product question, testing/certification dependency, security assessment, or import/export screening.
Use the Cybersecurity Law track for network operation, , product and service security, regulated network products, protection, incidents, and CII procurement review.
Run both when the same launch creates both triggers, but keep separate approvals and official citations.
The Cryptography Law classifies cryptography and regulates activities, products, services, use, and controlled trade. Its Article 26 applies the Cybersecurity Law framework to qualifying commercial cryptography products to avoid duplicate testing and certification. Article 27 links certain CII commercial cryptography procurements to national security review and coordinates assessments.
The current Cybersecurity Law applies to building, operating, maintaining, and using networks in China and to cybersecurity supervision. It separately sets graded-protection, network product and service, regulated-product, , incident, and information-security duties. The 2025 amendment took effect on 1 January 2026 and renumbered several provisions; this page uses the current numbering.
Open the Cryptography Law route when the decision concerns the cryptography category, standards, testing or certification, cryptography use, or controlled trade.
Open the Cybersecurity Law route when the decision concerns duties, , network product or service security, the regulated network-product catalogue, protection, or national-security review.
Run both routes for a qualifying product or deployment. Link shared facts, but preserve separate triggers, conclusions, owners, and citations.
The Cryptography Law first asks what kind of cryptography is involved and what activity is performed. Its commercial-cryptography rules cover research, production, sale, service, testing, certification, import, export, application, and supervision within China. They also create a cryptography-use licence for a provider using to supply electronic certification services; electronic-government electronic certification follows a separate qualification route. The Cybersecurity Law first asks whether a network is being built, operated, maintained, or used in China and which actor owns, manages, or provides that network.
A seller of a commercial-cryptography product may need the Cryptography Law track without operating the buyer's network. A business that owns or manages an ordinary network may have Cybersecurity Law duties as a even if no mandatory commercial-cryptography product, , or trade trigger applies.
Cryptography Law input: protected information, cryptographic function, product or service, activity, supplier, operator, and import or export movement.
Cybersecurity Law input: network, , protection level, network product or service, status, data handled, and procurement facts.
Shared result: one deployment can require both tracks, but neither classification should be inferred from the other.
The Cryptography Law generally encourages voluntary testing and certification. Mandatory assurance applies when a commercial-cryptography product involving national security, the national economy and people's livelihoods, or the public interest is included in the catalogue of . A commercial-cryptography service using catalogue products must pass service certification.
The Cybersecurity Law governs the catalogue route itself. Current Article 25 requires listed to pass qualified security certification or security testing before sale or provision and requires mutual recognition of results to avoid duplicate certification and testing. The supplier should identify the exact catalogue entry and required output instead of treating every encrypted product as listed.
Cryptography conclusion: whether the item is a commercial-cryptography product or service and whether Cryptography Law Article 26 applies.
Cybersecurity conclusion: whether the item is listed critical network equipment or a listed specialised cybersecurity product and which qualified assurance route applies.
Evidence: exact model and version, catalogue entry, testing or certification body and scope, report or certificate, validity, and the legal basis for any recognised result.
The Cybersecurity Law gives identified enhanced network-security duties. It requires security measures to be planned, built, and used with the infrastructure, sets operator governance and resilience duties, requires review of procurements that may affect national security, and requires a network-security assessment at least annually.
The commercial-cryptography route is narrower and more specific. The operator must use qualified commercial-cryptography products and services and reviewed cryptographic technologies, assess the application plan, reassess a changed plan during construction, pass an assessment before operation, and assess at least annually after operation. A failed plan cannot support construction, and a failed pre-operation assessment requires remediation before operation.
Coordination avoids duplicate work; it does not turn the annual Cybersecurity Law network assessment into the commercial-cryptography application assessment or vice versa. Record each scope, conclusion, report destination, and remediation result.
Cybersecurity Law owner: the operator and the responsible CII protection department.
Cryptography owner: the operator, with the protection department and cryptography authorities performing their assigned supervision and reporting roles.
Procurement branch: apply for only when the network-product or service procurement affects or may affect national security; in the procurement is not enough by itself.
The Cryptography Law and its implementing rules impose actor- and conduct-specific remedies for unauthorized testing or certification, nonconforming covered products and services, cryptography failures, trade-control breaches, and obstruction. The Cybersecurity Law has separate remedies for network-security, listed-product, CII, information-security, and supervision failures. One event may support more than one legal analysis; do not transfer a fine band from one provision to another.
Keep a shared technical record, then issue separate legal conclusions. At minimum, record the product or system version, cryptographic function, network and operator, identification, protection level, catalogue and control-list checks, reports or certificates, assessment scopes and dates, procurement risk analysis, authority submissions, remediation, and the change that requires reassessment.
Do not treat a commercial-cryptography certificate as proof of full Cybersecurity Law compliance.
Do not treat a graded-protection or annual network assessment as proof that the commercial-cryptography lifecycle assessment passed.
For a possible breach, identify the exact actor, conduct, article, legal instrument, and current penalty provision before estimating exposure.
Articles 2-3 establish the electronic-certification cryptography-use licensing route in China and distinguish electronic-government electronic certification.
Use for cryptography categories, commercial cryptography development and management, product/service controls, CII use, import/export context, penalties, and 1 January 2020 effective date.