ComparisonChina

China Cryptography Law Comparison

Comparison of cryptography-specific duties with broader China cybersecurity duties for product and security teams.

China Cryptography Law vs Cybersecurity Law explains where two compliance regimes overlap, where they diverge, and how to keep decisions, owners, evidence, and timing separate.

Author
Sorena AI
Published
Jul 5, 2026
Updated
Jul 5, 2026
Sections
1

Structured answer sets in this page tree.

Primary sources
5

Cited legal and guidance references.

Publication metadata
Sorena AI
Published Jul 5, 2026
Updated Jul 5, 2026
Overview

Comparison of cryptography-specific duties with broader China cybersecurity duties for product and security teams.

Comparison

China Cryptography Law vs China Cybersecurity Law

This comparison helps separate China Cryptography Law decisions from China Cybersecurity Law decisions without merging evidence, owners, or timing.

Review all sources
First framework
China Cryptography Law

Use for commercial cryptography classification, product/service management, testing/certification, CII cryptography use, and import/export screening. Keep its evidence and legal conclusion separate.

Second framework
China Cybersecurity Law

Use for network operator controls, CII protection, Data Security Law duties, cybersecurity review, MLPS, and app governance. Keep its evidence and legal conclusion separate.

Comparison row 1

Scope boundary

China Cryptography Law

China Cryptography Law covers commercial cryptography classification, product/service management, testing/certification, CII cryptography use, and import/export screening.

China Cybersecurity Law

China Cybersecurity Law covers network operator controls, CII protection, Data Security Law duties, cybersecurity review, MLPS, and app governance.

Operational implication

Run separate scope decisions when the same launch can trigger both China Cryptography Law and China Cybersecurity Law.

Comparison row 2

Covered actors

China Cryptography Law

China Cryptography Law work is usually owned by commercial cryptography provider, product owner, importer/exporter, procurement team, and CII team using commercial cryptography.

China Cybersecurity Law

China Cybersecurity Law work is usually owned by network operator, CII operator, data processor, app provider, platform operator, and security operations owner.

Operational implication

Assign separate owners when the legal route, regulator, filing, assessment, permit, or evidence package is different.

Comparison row 3

Trigger event

China Cryptography Law

China Cryptography Law screening starts with cryptography product/service classification, listed product question, testing/certification dependency, security assessment, or import/export screening.

China Cybersecurity Law

China Cybersecurity Law screening starts with China network operation, CII procurement, important-data handling, platform review trigger, app governance, or classified-protection mapping.

Operational implication

Record the triggering event and launch date for each route before reusing technical evidence.

Comparison row 4

Core obligations

China Cryptography Law

China Cryptography Law requires the team to translate its official articles or measures into concrete controls for commercial cryptography classification, product/service management, testing/certification, CII cryptography use, and import/export screening.

China Cybersecurity Law

China Cybersecurity Law requires controls for network operator controls, CII protection, Data Security Law duties, cybersecurity review, MLPS, and app governance.

Operational implication

Shared facts can support both routes, but the legal conclusion and required action must be written separately.

Comparison row 5

Evidence package

China Cryptography Law

A defensible China Cryptography Law file includes cryptography inventory, supplier declaration, testing/certification status, assessment/import-export note, and release approval.

China Cybersecurity Law

A defensible China Cybersecurity Law file includes role analysis, network security controls, review intake, app filing/governance records, MLPS evidence, and incident/security records.

Operational implication

Reuse common documents only after each file identifies why the document satisfies that route.

Comparison row 6

Timing and refresh points

China Cryptography Law

China Cryptography Law timing should track effective dates, filing windows, review periods, renewals, or transition dates named in its sources.

China Cybersecurity Law

China Cybersecurity Law timing should track its own effective dates, implementation windows, reporting periods, renewals, or market-entry deadlines.

Operational implication

Calendar each route independently; a date in one regime does not extend or replace a date in the other.

Comparison row 7

Enforcement exposure

China Cryptography Law

China Cryptography Law exposure usually follows the actor, regulator, and failure mode tied to cryptography product/service classification, listed product question, testing/certification dependency, security assessment, or import/export screening.

China Cybersecurity Law

China Cybersecurity Law exposure usually follows the actor, regulator, and failure mode tied to China network operation, CII procurement, important-data handling, platform review trigger, app governance, or classified-protection mapping.

Operational implication

Preserve the evidence trail before launch, filing, transfer, procurement, sale, or disposal because later remediation is weaker than a dated decision record.

Comparison row 8

Overlap and routing

China Cryptography Law

China Cryptography Law and China Cybersecurity Law can use the same product, app, supplier, data-flow, or equipment facts, but China Cryptography Law owns the decision for commercial cryptography classification, product/service management, testing/certification, CII cryptography use, and import/export screening.

China Cybersecurity Law

China Cybersecurity Law owns the decision for network operator controls, CII protection, Data Security Law duties, cybersecurity review, MLPS, and app governance.

Operational implication

Create linked records rather than copying one conclusion across both regimes.

Comparison row 9

Practical decision rule

China Cryptography Law

Choose China Cryptography Law when the immediate blocker is cryptography product/service classification, listed product question, testing/certification dependency, security assessment, or import/export screening.

China Cybersecurity Law

Choose China Cybersecurity Law when the immediate blocker is China network operation, CII procurement, important-data handling, platform review trigger, app governance, or classified-protection mapping.

Operational implication

Run both tracks when the same China or cross-market launch creates both China Cryptography Law and China Cybersecurity Law triggers.

Practical decision rule

When to run one track or both

  • Use China Cryptography Law when the facts match cryptography product/service classification, listed product question, testing/certification dependency, security assessment, or import/export screening.
  • Use China Cybersecurity Law when the facts match China network operation, CII procurement, important-data handling, platform review trigger, app governance, or classified-protection mapping.
  • Run both when the same launch creates both triggers, but keep separate approvals and official citations.
Section 1

How to use this comparison

China Cryptography Law vs Cybersecurity Law compares the practical trigger, owner, timing, and evidence record for each regime so visitors can avoid collapsing two different compliance decisions into one checklist.

Start with the trigger and accountable owner, then build the evidence package for each route. A filing, assessment, permit, or policy under one regime is not proof that the other regime is complete.

  • Use the left column for the China-specific legal route and evidence package.
  • Use the right column for the compared regime or adjacent China route.
  • Keep shared facts linked, but preserve separate legal conclusions, owners, and official citations.
Operationalize the requirement

Prepare the commercial cryptography evidence file

Sorena AI helps turn the China Cryptography Law vs China Cybersecurity Law decision into owners, controls, and reviewer-ready records.

Primary sources

References and citations

cac.gov.cn
Referenced sections
  • Use for cybersecurity review scope, CII procurement filing, platform operator review triggers, review materials, special review, and 15 February 2022 effective date.
oscca.gov.cn
Referenced sections
  • Use for cryptography categories, commercial cryptography development and management, product/service controls, CII use, import/export context, penalties, and 1 January 2020 effective date.
cac.gov.cn
Referenced sections
  • Use for network operator security duties, network product/service security, CII provisions, personal-information security articles, penalties, and 1 June 2017 effective date.
cac.gov.cn
Referenced sections
  • Use for data classification and graded protection, important-data risk assessment, security management, incident response, outbound important-data context, penalties, and 1 September 2021 effective date.
Related guides

Explore more topics

China commercial cryptography compliance checklist
Checklist for classifying cryptography use, supplier evidence, testing/certification status, and commercial cryptography release decisions.
China Cryptography Law deadlines and compliance calendar
Official dates for the Cryptography Law and commercial cryptography regulation implementation.
China Cryptography Law FAQ
Answers to practical China Cryptography Law questions for scope, official source triggers, evidence records, and related China scope decisions.
China Cryptography Law penalties and liability
Operational view of China cryptography liability provisions and what evidence reduces avoidable release and supplier risk.
China Cryptography Law requirements
China cryptography requirements for commercial cryptography products, services, testing, import/export screening, and release evidence.
Commercial cryptography import, export, and security assessment triage
How product and procurement teams should record import/export and security assessment questions without overclaiming applicability.
Commercial cryptography procurement checklist
Procurement checklist for vendors and products that rely on commercial cryptography in China-market systems.
Commercial cryptography products and testing evidence
How to prepare evidence for commercial cryptography products, services, and testing institution dependencies under China sources.
Commercial cryptography testing evidence template
Evidence template for commercial cryptography testing and certification status, qualified body dependence, and supplier review.
Do imported cryptography products need special review?
Do not assume every imported encrypted product has the same route. The Cryptography Law contains import/export and security assessment concepts, so the release record should identify product category, commercial cryptography status, and whether an official list or assessment source is needed.
Does using encryption trigger China Cryptography Law duties?
Using encryption is the starting point, not the final answer. The source distinguishes commercial cryptography and other cryptography categories, so the evidence record should identify the cryptographic function, product or service route, commercial cryptography status, and whether testing, certification, import/export, or security assessment questions arise.
How does cryptography compliance overlap with China cybersecurity law?
Cryptography compliance addresses cryptographic technologies, products, services, testing and import/export questions; cybersecurity compliance addresses network operator, data security, app governance and review duties. A connected product can need both evidence sets.
What is commercial cryptography in China?
Commercial cryptography protects information that does not involve state secrets. The compliance task is to classify the product or service, record whether it is commercial cryptography, and keep supplier/testing evidence for the China-market decision.
When is commercial cryptography testing or certification needed?
Testing or certification analysis is needed when a commercial cryptography product, service, or testing result is part of the China compliance route. The testing institution source says proof-bearing commercial cryptography testing activity depends on qualified testing institutions.