| Scope boundary | China Cryptography Law covers commercial cryptography classification, product/service management, testing/certification, CII cryptography use, and import/export screening. | China Cybersecurity Law covers network operator controls, CII protection, Data Security Law duties, cybersecurity review, MLPS, and app governance. | Run separate scope decisions when the same launch can trigger both China Cryptography Law and China Cybersecurity Law. |
|---|
| Covered actors | China Cryptography Law work is usually owned by commercial cryptography provider, product owner, importer/exporter, procurement team, and CII team using commercial cryptography. | China Cybersecurity Law work is usually owned by network operator, CII operator, data processor, app provider, platform operator, and security operations owner. | Assign separate owners when the legal route, regulator, filing, assessment, permit, or evidence package is different. |
|---|
| Trigger event | China Cryptography Law screening starts with cryptography product/service classification, listed product question, testing/certification dependency, security assessment, or import/export screening. | China Cybersecurity Law screening starts with China network operation, CII procurement, important-data handling, platform review trigger, app governance, or classified-protection mapping. | Record the triggering event and launch date for each route before reusing technical evidence. |
|---|
| Core obligations | China Cryptography Law requires the team to translate its official articles or measures into concrete controls for commercial cryptography classification, product/service management, testing/certification, CII cryptography use, and import/export screening. | China Cybersecurity Law requires controls for network operator controls, CII protection, Data Security Law duties, cybersecurity review, MLPS, and app governance. | Shared facts can support both routes, but the legal conclusion and required action must be written separately. |
|---|
| Evidence package | A defensible China Cryptography Law file includes cryptography inventory, supplier declaration, testing/certification status, assessment/import-export note, and release approval. | A defensible China Cybersecurity Law file includes role analysis, network security controls, review intake, app filing/governance records, MLPS evidence, and incident/security records. | Reuse common documents only after each file identifies why the document satisfies that route. |
|---|
| Timing and refresh points | China Cryptography Law timing should track effective dates, filing windows, review periods, renewals, or transition dates named in its sources. | China Cybersecurity Law timing should track its own effective dates, implementation windows, reporting periods, renewals, or market-entry deadlines. | Calendar each route independently; a date in one regime does not extend or replace a date in the other. |
|---|
| Enforcement exposure | China Cryptography Law exposure usually follows the actor, regulator, and failure mode tied to cryptography product/service classification, listed product question, testing/certification dependency, security assessment, or import/export screening. | China Cybersecurity Law exposure usually follows the actor, regulator, and failure mode tied to China network operation, CII procurement, important-data handling, platform review trigger, app governance, or classified-protection mapping. | Preserve the evidence trail before launch, filing, transfer, procurement, sale, or disposal because later remediation is weaker than a dated decision record. |
|---|
| Overlap and routing | China Cryptography Law and China Cybersecurity Law can use the same product, app, supplier, data-flow, or equipment facts, but China Cryptography Law owns the decision for commercial cryptography classification, product/service management, testing/certification, CII cryptography use, and import/export screening. | China Cybersecurity Law owns the decision for network operator controls, CII protection, Data Security Law duties, cybersecurity review, MLPS, and app governance. | Create linked records rather than copying one conclusion across both regimes. |
|---|
| Practical decision rule | Choose China Cryptography Law when the immediate blocker is cryptography product/service classification, listed product question, testing/certification dependency, security assessment, or import/export screening. | Choose China Cybersecurity Law when the immediate blocker is China network operation, CII procurement, important-data handling, platform review trigger, app governance, or classified-protection mapping. | Run both tracks when the same China or cross-market launch creates both China Cryptography Law and China Cybersecurity Law triggers. |
|---|