ComparisonChina

China Cryptography Law Comparison

Compare China's Cryptography Law and current Cybersecurity Law by scope, actor, product assurance, CII duties, evidence, and enforcement.

The two laws overlap on specified network products and CII, but they answer different questions. This comparison uses the Cybersecurity Law as amended in 2025 and effective 1 January 2026.

Author
Sorena AI
Published
Jul 5, 2026
Updated
Jul 25, 2026
Sections
5

Structured answer sets in this page tree.

Primary sources
8

Cited legal and guidance references.

Publication metadata
Sorena AI
Published Jul 5, 2026
Updated Jul 25, 2026
Overview

Use both laws when a China product or system uses and also operates a network, supplies a regulated network product or service, or forms part of . Keep the legal conclusions separate even when they use the same technical evidence.

Comparison

China Cryptography Law vs China Cybersecurity Law

The Cryptography Law governs cryptography-specific decisions. The Cybersecurity Law governs the wider network-security baseline and supplies linked product-assurance and review routes.

Review all sources
First framework
China Cryptography Law

Use for the cryptography category, commercial-cryptography activities, specified products and services, electronic certification using , cryptography use, and controlled trade.

Second framework
China Cybersecurity Law

Use for network operation, , network products and services, regulated network products, protection, incidents, and linked national security review.

Comparison row 1

Scope boundary

China Cryptography Law

China Cryptography Law covers classification, product/service management, testing/certification, electronic certification using commercial cryptography, cryptography use, and import/export screening.

China Cybersecurity Law

Cybersecurity Law Article 2 applies to building, operating, maintaining, and using networks in China and to cybersecurity supervision. It covers network operation, products and services, regulated network products, , network information, and incident response.

Operational implication

Run separate scope decisions when the same launch can trigger both China Cryptography Law and China Cybersecurity Law.

Comparison row 2

Covered actors

China Cryptography Law

China Cryptography Law work is usually owned by a provider, product owner, electronic-certification provider, importer or exporter, procurement team, or team using commercial cryptography.

China Cybersecurity Law

The Cybersecurity Law assigns duties to network operators, network product and service providers, providers of particular online services, operators, and public authorities. The actor depends on the activity and system.

Operational implication

Assign separate owners when the legal route, regulator, filing, assessment, permit, or evidence package is different.

Comparison row 3

Trigger event

China Cryptography Law

China Cryptography Law screening starts with cryptography product/service classification, listed product question, testing/certification dependency, security assessment, or import/export screening.

China Cybersecurity Law

Cybersecurity Law screening starts when an organization builds, operates, maintains, or uses a network in China, supplies a network product or service, handles a regulated network product, operates , or procures for CII.

Operational implication

Record the triggering event and launch date for each route before reusing technical evidence.

Comparison row 4

Product assurance and system assessment

China Cryptography Law

testing and certification are generally voluntary. Mandatory assurance applies to a qualifying commercial cryptography product in the network critical equipment and network security-specific product catalogue, a commercial cryptography service using a listed product, and commercial cryptography products and services. Important systems required to use commercial cryptography have a separate application security assessment route.

China Cybersecurity Law

Cybersecurity Law Article 25 requires qualified security certification or security testing for network critical equipment and network security-specific products before sale or provision. and security duties assess the wider network and operator, including controls beyond the cryptographic function.

Operational implication

Keep the catalogue match, product or service assurance, cryptographic technology review, application security assessment, graded-protection work, and security assessment as distinct conclusions. Coordinate evidence where the rules call for avoiding duplicate testing or assessment.

Comparison row 5

Evidence package

China Cryptography Law

A China Cryptography Law evidence file includes a cryptography inventory, supplier declaration, testing or certification status, assessment or import-export note, and release approval.

China Cybersecurity Law

A Cybersecurity Law file should identify the network and operator, graded-protection controls, product or service security records, regulated-product catalogue match and assurance, incident records, and evidence where applicable.

Operational implication

Reuse common documents only after each file identifies why the document satisfies that route.

Comparison row 6

Timing and refresh points

China Cryptography Law

China Cryptography Law timing starts with its 1 January 2020 effective date and the revised regulation's 1 July 2023 effective date; operational dates depend on the selected route.

China Cybersecurity Law

The Cybersecurity Law first took effect on 1 June 2017. The 2025 amendment and current renumbering took effect on 1 January 2026. Operational timing also depends on the duty, product lifecycle, incident, and status.

Operational implication

Calendar each route independently; a date in one regime does not extend or replace a date in the other.

Comparison row 7

Enforcement exposure

China Cryptography Law

China Cryptography Law exposure follows the breached duty and actor: testing or certification body, seller or provider, operator, importer or exporter, electronic-government certification provider, official, or other responsible person.

China Cybersecurity Law

Cybersecurity Law exposure follows the breached duty and actor. The 2025 amendment revised and increased several penalty provisions, so use the current article and facts rather than an older penalty summary.

Operational implication

Preserve the evidence trail before launch, filing, transfer, procurement, sale, or disposal because later remediation is weaker than a dated decision record.

Comparison row 8

Overlap and routing

China Cryptography Law

China Cryptography Law and China Cybersecurity Law can use the same product, app, supplier, data-flow, or equipment facts, but China Cryptography Law owns the decision for classification, product/service management, testing/certification, electronic-certification cryptography use, cryptography use, and import/export screening.

China Cybersecurity Law

The Cybersecurity Law track owns , general product and service security, regulated network-product, protection, incident, and national security review conclusions.

Operational implication

Create linked records rather than copying one conclusion across both regimes.

Comparison row 9

Practical decision rule

China Cryptography Law

Choose China Cryptography Law when the immediate blocker is cryptography product/service classification, listed product question, testing/certification dependency, security assessment, or import/export screening.

China Cybersecurity Law

Open the Cybersecurity Law track for network operation, product or service security, , a regulated network-product catalogue question, protection, an incident, or CII procurement review.

Operational implication

Run both tracks when the same China or cross-market launch creates both China Cryptography Law and China Cybersecurity Law triggers.

Practical decision rule

When to run one track or both

  • Use China Cryptography Law when the facts match cryptography product/service classification, listed product question, testing/certification dependency, security assessment, or import/export screening.
  • Use the Cybersecurity Law track for network operation, , product and service security, regulated network products, protection, incidents, and CII procurement review.
  • Run both when the same launch creates both triggers, but keep separate approvals and official citations.
Section 2

Compare scope, actors, and the first decision

The Cryptography Law first asks what kind of cryptography is involved and what activity is performed. Its commercial-cryptography rules cover research, production, sale, service, testing, certification, import, export, application, and supervision within China. They also create a cryptography-use licence for a provider using to supply electronic certification services; electronic-government electronic certification follows a separate qualification route. The Cybersecurity Law first asks whether a network is being built, operated, maintained, or used in China and which actor owns, manages, or provides that network.

A seller of a commercial-cryptography product may need the Cryptography Law track without operating the buyer's network. A business that owns or manages an ordinary network may have Cybersecurity Law duties as a even if no mandatory commercial-cryptography product, , or trade trigger applies.

  • Cryptography Law input: protected information, cryptographic function, product or service, activity, supplier, operator, and import or export movement.
  • Cybersecurity Law input: network, , protection level, network product or service, status, data handled, and procurement facts.
  • Shared result: one deployment can require both tracks, but neither classification should be inferred from the other.
Section 3

Compare product and service assurance

The Cryptography Law generally encourages voluntary testing and certification. Mandatory assurance applies when a commercial-cryptography product involving national security, the national economy and people's livelihoods, or the public interest is included in the catalogue of . A commercial-cryptography service using catalogue products must pass service certification.

The Cybersecurity Law governs the catalogue route itself. Current Article 25 requires listed to pass qualified security certification or security testing before sale or provision and requires mutual recognition of results to avoid duplicate certification and testing. The supplier should identify the exact catalogue entry and required output instead of treating every encrypted product as listed.

  • Cryptography conclusion: whether the item is a commercial-cryptography product or service and whether Cryptography Law Article 26 applies.
  • Cybersecurity conclusion: whether the item is listed critical network equipment or a listed specialised cybersecurity product and which qualified assurance route applies.
  • Evidence: exact model and version, catalogue entry, testing or certification body and scope, report or certificate, validity, and the legal basis for any recognised result.
Section 4

Compare CII duties and assessment cycles

The Cybersecurity Law gives identified enhanced network-security duties. It requires security measures to be planned, built, and used with the infrastructure, sets operator governance and resilience duties, requires review of procurements that may affect national security, and requires a network-security assessment at least annually.

The commercial-cryptography route is narrower and more specific. The operator must use qualified commercial-cryptography products and services and reviewed cryptographic technologies, assess the application plan, reassess a changed plan during construction, pass an assessment before operation, and assess at least annually after operation. A failed plan cannot support construction, and a failed pre-operation assessment requires remediation before operation.

Coordination avoids duplicate work; it does not turn the annual Cybersecurity Law network assessment into the commercial-cryptography application assessment or vice versa. Record each scope, conclusion, report destination, and remediation result.

  • Cybersecurity Law owner: the operator and the responsible CII protection department.
  • Cryptography owner: the operator, with the protection department and cryptography authorities performing their assigned supervision and reporting roles.
  • Procurement branch: apply for only when the network-product or service procurement affects or may affect national security; in the procurement is not enough by itself.
Section 5

Compare enforcement and keep separate evidence

The Cryptography Law and its implementing rules impose actor- and conduct-specific remedies for unauthorized testing or certification, nonconforming covered products and services, cryptography failures, trade-control breaches, and obstruction. The Cybersecurity Law has separate remedies for network-security, listed-product, CII, information-security, and supervision failures. One event may support more than one legal analysis; do not transfer a fine band from one provision to another.

Keep a shared technical record, then issue separate legal conclusions. At minimum, record the product or system version, cryptographic function, network and operator, identification, protection level, catalogue and control-list checks, reports or certificates, assessment scopes and dates, procurement risk analysis, authority submissions, remediation, and the change that requires reassessment.

  • Do not treat a commercial-cryptography certificate as proof of full Cybersecurity Law compliance.
  • Do not treat a graded-protection or annual network assessment as proof that the commercial-cryptography lifecycle assessment passed.
  • For a possible breach, identify the exact actor, conduct, article, legal instrument, and current penalty provision before estimating exposure.
Primary sources

References and citations

cac.gov.cn
Referenced sections
  • Articles 2 and 5 place the procurement risk assessment and filing decision on the CII operator.
oscca.gov.cn
Referenced sections
  • Use for cryptography categories, commercial cryptography development and management, product/service controls, CII use, import/export context, penalties, and 1 January 2020 effective date.
Related guides

Explore more topics

China commercial cryptography compliance checklist
China commercial cryptography checklist covering classification, product and service assurance, CII duties, trade controls, and retained evidence.
China commercial cryptography testing evidence template
Record the legal route, product or system scope, testing-body qualification, report details, gaps, and reassessment triggers for China commercial cryptography assurance.
China cryptography compliance deadlines and calendar
China cryptography effective dates, CII reports, annual assessments, licence renewals, change notices, and pre-operation checks.
China cryptography import, export, and security review triage
Screen commercial cryptography imports under the 2020 list, exports under China's unified dual-use list, the consumer exclusion, system assessment, and CII review.
China Cryptography Law FAQ
Answers on China's commercial-cryptography scope, product assurance, classified protection, CII assessment, procurement review, and trade controls.
China Cryptography Law requirements
China commercial cryptography requirements by role: standards, testing, certification, CII use and assessment, trade controls, and evidence.
China cryptography penalties, fines, and liability
China commercial cryptography penalties by actor and violation, including fine bands, corrective orders, confiscation, licence action, and liability.
Commercial cryptography procurement checklist
Procurement checks for commercial cryptography products and services used in China, including certificate scope, CII duties, and supplier changes.
Commercial cryptography products and testing evidence
When China commercial cryptography testing or certification is voluntary or mandatory, and what product, service, body, and scope evidence to keep.
Do imported cryptography products need special review?
Not every encrypted product imported into China needs a licence. Check the 2020 commercial-cryptography import list, the consumer-product exception, and any CII procurement review.
Does using encryption trigger China Cryptography Law duties?
Using encryption does not create one universal China approval duty. Check classified protection, product, service, CII, procurement, and trade triggers.
How does cryptography compliance overlap with China cybersecurity law?
See how China's cryptography rules connect with classified protection, product assurance, CII assessment, and cybersecurity review without merging the regimes.
What is commercial cryptography in China?
Commercial cryptography protects information that is not a state secret. Learn how China defines the category and which separate facts trigger product, CII, or trade controls.
When is commercial cryptography testing or certification needed?
Commercial-cryptography assurance is often voluntary, but specified products and services require it. Covered CII also needs application assessment and qualified cryptography.