---
title: "China Cryptography Law vs Cybersecurity Law"
canonical_url: "https://www.sorena.io/artifacts/apac/china-cryptography-law/china-cryptography-law-vs-cybersecurity-law"
source_url: "https://www.sorena.io/artifacts/apac/china-cryptography-law/china-cryptography-law-vs-cybersecurity-law"
author: "Sorena AI"
description: "Compare China's Cryptography Law and current Cybersecurity Law by scope, actor, product assurance, CII duties, evidence, and enforcement."
published_at: "2026-07-05"
updated_at: "2026-07-25"
keywords:
  - "China Cryptography Law"
  - "Commercial cryptography"
  - "Cryptography Law"
  - "Commercial cryptography testing"
  - "China cybersecurity"
---
**[SORENA](https://www.sorena.io/)** - AI-Powered GRC Platform

[Home](https://www.sorena.io/) | [Solutions](https://www.sorena.io/solutions) | [Artifacts](https://www.sorena.io/artifacts) | [About Us](https://www.sorena.io/about-us) | [Contact](https://www.sorena.io/contact) | [Portal](https://app.sorena.io)

---

# China Cryptography Law vs Cybersecurity Law

Compare China's Cryptography Law and current Cybersecurity Law by scope, actor, product assurance, CII duties, evidence, and enforcement.

*Comparison* *China*

## China Cryptography Law Comparison

The two laws overlap on specified network products and CII, but they answer different questions. This comparison uses the Cybersecurity Law as amended in 2025 and effective 1 January 2026.

Use both laws when a China product or system uses commercial cryptography and also operates a network, supplies a regulated network product or service, or forms part of CII. Keep the legal conclusions separate even when they use the same technical evidence.

## Definitions

### Commercial cryptography

Commercial cryptography is cryptography used to protect information that is not a state secret. It includes technologies, products, and services that use specified transformations for encryption protection or security authentication. Core and ordinary cryptography protect state-secret information and follow a separate management system.

**Why it matters here:** The commercial-cryptography classification opens the Cryptography Law analysis, but it does not by itself prove that testing, certification, an application assessment, a trade licence, or cybersecurity review is required.

Sources:

- [PRC Cryptography Law, Articles 2 and 6-8](https://www.oscca.gov.cn/sca/xxgk/2023-06/04/content_1057225.shtml?ref=sorena.io)

### Critical information infrastructure

**Term:** CII

Critical information infrastructure is infrastructure in important industries and fields, including public communications and information services, energy, transport, water, finance, public services, and electronic government, where destruction, loss of function, or data leakage could seriously harm national security, the national economy and people's livelihoods, or the public interest. The responsible protection department identifies CII under the governing rules.

**Why it matters here:** An identified CII deployment can trigger both laws: the Cybersecurity Law sets the wider protection and procurement-review duties, while the Cryptography Law and CII cryptography provisions set specific product, technology, planning, and assessment duties for commercial cryptography.

Sources:

- [PRC Cybersecurity Law, Articles 33-40](https://www.cac.gov.cn/2025-12/29/c_1768735112911946.htm?ref=sorena.io)
- [Provisions on the Use and Administration of Commercial Cryptography in Critical Information Infrastructure, Articles 2 and 5-15](https://www.oscca.gov.cn/sca/xxgk/2025-06/27/content_1061270.shtml?ref=sorena.io)

### Network operator

Under the Cybersecurity Law, a network operator is the owner or manager of a network or a network service provider. A network is a system of computers or other information terminals and related equipment that collects, stores, transmits, exchanges, or processes information under defined rules and procedures. This category is broader than a commercial cryptography provider or a CII operator.

**Why it matters here:** A business can have Cybersecurity Law duties as a network operator even when no mandatory commercial cryptography product, service, CII, or trade route applies. The two scope decisions should therefore be recorded separately.

Sources:

- [PRC Cybersecurity Law, Article 78](https://www.cac.gov.cn/2025-12/29/c_1768735112911946.htm?ref=sorena.io)

### Network security graded protection system

**Term:** graded protection

Graded protection is the Cybersecurity Law system under which network operators implement security duties appropriate to the network's protection level. Article 23 requires internal rules and accountable personnel, protections against malware and attacks, monitoring and incident records, at least six months of network-log retention, data classification, important-data backup, encryption, and other legally required measures.

**Why it matters here:** Graded protection belongs to the Cybersecurity Law track. Commercial cryptography rules can specify how cryptography supports it, and related assessments should be coordinated to avoid duplication, but a cryptography certificate or application assessment does not replace the wider graded-protection conclusion.

Sources:

- [PRC Cybersecurity Law, Article 23](https://www.cac.gov.cn/2025-12/29/c_1768735112911946.htm?ref=sorena.io)
- [Commercial Cryptography Administration Regulation, Articles 41-42](https://www.mee.gov.cn/zcwj/gwywj/202305/t20230529_1031579.shtml?ref=sorena.io)

### Critical network equipment and specialised cybersecurity products

These are network products included in the catalogue published under the Cybersecurity Law. Listed products must meet mandatory national standards and pass the qualified security-certification or security-testing route required by current Article 25 before sale or provision. The catalogue match depends on the exact product type and technical scope, not merely on the presence of encryption.

**Why it matters here:** A commercial-cryptography product that meets the Cryptography Law Article 26 conditions enters this Cybersecurity Law catalogue route. A commercial-cryptography service using catalogue products follows the separate service-certification rule in the Cryptography Law and its implementing regulation.

Sources:

- [PRC Cybersecurity Law, Article 25](https://www.cac.gov.cn/2025-12/29/c_1768735112911946.htm?ref=sorena.io)
- [PRC Cryptography Law, Article 26](https://www.oscca.gov.cn/sca/xxgk/2023-06/04/content_1057225.shtml?ref=sorena.io)

### Cybersecurity review of a CII procurement

**Term:** cybersecurity review

A CII operator must assess whether procuring a network product or service affects or may affect national security and apply to the Cybersecurity Review Office when that condition is met. The review considers supply continuity, control or disruption, data risks, supplier compliance, and other national-security factors.

**Why it matters here:** Commercial cryptography in the procurement is relevant but does not automatically trigger cybersecurity review. The buyer must be a CII operator, the procurement must concern a network product or service, and the possible national-security effect must be assessed.

Sources:

- [Cybersecurity Review Measures, Articles 2 and 5-10](https://www.cac.gov.cn/2022-01/04/c_1642894602182845.htm?ref=sorena.io)

## China Cryptography Law vs China Cybersecurity Law

The Cryptography Law governs cryptography-specific decisions. The Cybersecurity Law governs the wider network-security baseline and supplies linked product-assurance and CII review routes.

- **China Cryptography Law**: Use for the cryptography category, commercial-cryptography activities, specified products and services, electronic certification using commercial cryptography, CII cryptography use, and controlled trade.
- **China Cybersecurity Law**: Use for network operation, graded protection, network products and services, regulated network products, CII protection, incidents, and linked national security review.

| Dimension | China Cryptography Law | China Cybersecurity Law | Operational implication | Sources |
| --- | --- | --- | --- | --- |
| Scope boundary | China Cryptography Law covers commercial cryptography classification, product/service management, testing/certification, electronic certification using commercial cryptography, CII cryptography use, and import/export screening. | Cybersecurity Law Article 2 applies to building, operating, maintaining, and using networks in China and to cybersecurity supervision. It covers network operation, products and services, regulated network products, CII, network information, and incident response. | Run separate scope decisions when the same launch can trigger both China Cryptography Law and China Cybersecurity Law. | [PRC Cryptography Law](https://www.oscca.gov.cn/sca/xxgk/2023-06/04/content_1057225.shtml?ref=sorena.io) - Use for cryptography categories, commercial cryptography development and management, product/service controls, CII use, import/export context, penalties, and 1 January 2020 effective date.<br>[PRC Cybersecurity Law, amended in 2025](https://www.cac.gov.cn/2025-12/29/c_1768735112911946.htm?ref=sorena.io) - Use for the current Cybersecurity Law scope and duties described in this row. |
| Covered actors | China Cryptography Law work is usually owned by a commercial cryptography provider, product owner, electronic-certification provider, importer or exporter, procurement team, or CII team using commercial cryptography. | The Cybersecurity Law assigns duties to network operators, network product and service providers, providers of particular online services, CII operators, and public authorities. The actor depends on the activity and system. | Assign separate owners when the legal route, regulator, filing, assessment, permit, or evidence package is different. | [PRC Cryptography Law](https://www.oscca.gov.cn/sca/xxgk/2023-06/04/content_1057225.shtml?ref=sorena.io) - Use for cryptography categories, commercial cryptography development and management, product/service controls, CII use, import/export context, penalties, and 1 January 2020 effective date.<br>[PRC Cybersecurity Law, amended in 2025](https://www.cac.gov.cn/2025-12/29/c_1768735112911946.htm?ref=sorena.io) - Use for the current Cybersecurity Law scope and duties described in this row. |
| Trigger event | China Cryptography Law screening starts with cryptography product/service classification, listed product question, testing/certification dependency, security assessment, or import/export screening. | Cybersecurity Law screening starts when an organization builds, operates, maintains, or uses a network in China, supplies a network product or service, handles a regulated network product, operates CII, or procures for CII. | Record the triggering event and launch date for each route before reusing technical evidence. | [PRC Cryptography Law](https://www.oscca.gov.cn/sca/xxgk/2023-06/04/content_1057225.shtml?ref=sorena.io) - Use for cryptography categories, commercial cryptography development and management, product/service controls, CII use, import/export context, penalties, and 1 January 2020 effective date.<br>[PRC Cybersecurity Law, amended in 2025](https://www.cac.gov.cn/2025-12/29/c_1768735112911946.htm?ref=sorena.io) - Use for the current Cybersecurity Law scope and duties described in this row. |
| Product assurance and system assessment | Commercial cryptography testing and certification are generally voluntary. Mandatory assurance applies to a qualifying commercial cryptography product in the network critical equipment and network security-specific product catalogue, a commercial cryptography service using a listed product, and CII commercial cryptography products and services. Important systems required to use commercial cryptography have a separate application security assessment route. | Cybersecurity Law Article 25 requires qualified security certification or security testing for network critical equipment and network security-specific products before sale or provision. Graded protection and CII security duties assess the wider network and operator, including controls beyond the cryptographic function. | Keep the catalogue match, product or service assurance, cryptographic technology review, application security assessment, graded-protection work, and CII security assessment as distinct conclusions. Coordinate evidence where the rules call for avoiding duplicate testing or assessment. | [PRC Cryptography Law](https://www.oscca.gov.cn/sca/xxgk/2023-06/04/content_1057225.shtml?ref=sorena.io) - Articles 26-27 support linking the regimes while avoiding duplicate testing, certification, assessment, and graded-protection measurement.<br>[PRC Cybersecurity Law, amended in 2025](https://www.cac.gov.cn/2025-12/29/c_1768735112911946.htm?ref=sorena.io) - Articles 23 and 25 support graded protection and mandatory assurance for listed network critical equipment and network security-specific products. |
| Evidence package | A China Cryptography Law evidence file includes a cryptography inventory, supplier declaration, testing or certification status, assessment or import-export note, and release approval. | A Cybersecurity Law file should identify the network and operator, graded-protection controls, product or service security records, regulated-product catalogue match and assurance, incident records, and CII evidence where applicable. | Reuse common documents only after each file identifies why the document satisfies that route. | [PRC Cryptography Law](https://www.oscca.gov.cn/sca/xxgk/2023-06/04/content_1057225.shtml?ref=sorena.io) - Use for cryptography categories, commercial cryptography development and management, product/service controls, CII use, import/export context, penalties, and 1 January 2020 effective date.<br>[PRC Cybersecurity Law, amended in 2025](https://www.cac.gov.cn/2025-12/29/c_1768735112911946.htm?ref=sorena.io) - Use for the current Cybersecurity Law scope and duties described in this row. |
| Timing and refresh points | China Cryptography Law timing starts with its 1 January 2020 effective date and the revised regulation's 1 July 2023 effective date; operational dates depend on the selected route. | The Cybersecurity Law first took effect on 1 June 2017. The 2025 amendment and current renumbering took effect on 1 January 2026. Operational timing also depends on the duty, product lifecycle, incident, and CII status. | Calendar each route independently; a date in one regime does not extend or replace a date in the other. | [PRC Cryptography Law](https://www.oscca.gov.cn/sca/xxgk/2023-06/04/content_1057225.shtml?ref=sorena.io) - Use for cryptography categories, commercial cryptography development and management, product/service controls, CII use, import/export context, penalties, and 1 January 2020 effective date.<br>[PRC Cybersecurity Law, amended in 2025](https://www.cac.gov.cn/2025-12/29/c_1768735112911946.htm?ref=sorena.io) - Use for the current Cybersecurity Law scope and duties described in this row. |
| Enforcement exposure | China Cryptography Law exposure follows the breached duty and actor: testing or certification body, seller or provider, CII operator, importer or exporter, electronic-government certification provider, official, or other responsible person. | Cybersecurity Law exposure follows the breached duty and actor. The 2025 amendment revised and increased several penalty provisions, so use the current article and facts rather than an older penalty summary. | Preserve the evidence trail before launch, filing, transfer, procurement, sale, or disposal because later remediation is weaker than a dated decision record. | [PRC Cryptography Law](https://www.oscca.gov.cn/sca/xxgk/2023-06/04/content_1057225.shtml?ref=sorena.io) - Use for cryptography categories, commercial cryptography development and management, product/service controls, CII use, import/export context, penalties, and 1 January 2020 effective date.<br>[PRC Cybersecurity Law, amended in 2025](https://www.cac.gov.cn/2025-12/29/c_1768735112911946.htm?ref=sorena.io) - Use for the current Cybersecurity Law scope and duties described in this row. |
| Overlap and routing | China Cryptography Law and China Cybersecurity Law can use the same product, app, supplier, data-flow, or equipment facts, but China Cryptography Law owns the decision for commercial cryptography classification, product/service management, testing/certification, electronic-certification cryptography use, CII cryptography use, and import/export screening. | The Cybersecurity Law track owns graded protection, general product and service security, regulated network-product, CII protection, incident, and national security review conclusions. | Create linked records rather than copying one conclusion across both regimes. | [PRC Cryptography Law](https://www.oscca.gov.cn/sca/xxgk/2023-06/04/content_1057225.shtml?ref=sorena.io) - Use for cryptography categories, commercial cryptography development and management, product/service controls, CII use, import/export context, penalties, and 1 January 2020 effective date.<br>[PRC Cybersecurity Law, amended in 2025](https://www.cac.gov.cn/2025-12/29/c_1768735112911946.htm?ref=sorena.io) - Use for the current Cybersecurity Law scope and duties described in this row. |
| Practical decision rule | Choose China Cryptography Law when the immediate blocker is cryptography product/service classification, listed product question, testing/certification dependency, security assessment, or import/export screening. | Open the Cybersecurity Law track for network operation, product or service security, graded protection, a regulated network-product catalogue question, CII protection, an incident, or CII procurement review. | Run both tracks when the same China or cross-market launch creates both China Cryptography Law and China Cybersecurity Law triggers. | [PRC Cryptography Law](https://www.oscca.gov.cn/sca/xxgk/2023-06/04/content_1057225.shtml?ref=sorena.io) - Use for cryptography categories, commercial cryptography development and management, product/service controls, CII use, import/export context, penalties, and 1 January 2020 effective date.<br>[PRC Cybersecurity Law, amended in 2025](https://www.cac.gov.cn/2025-12/29/c_1768735112911946.htm?ref=sorena.io) - Use for the current Cybersecurity Law scope and duties described in this row. |

Sources for Scope boundary - China Cryptography Law:

- [PRC Cryptography Law](https://www.oscca.gov.cn/sca/xxgk/2023-06/04/content_1057225.shtml?ref=sorena.io) - Use for cryptography categories, commercial cryptography development and management, product/service controls, CII use, import/export context, penalties, and 1 January 2020 effective date.

Sources for Scope boundary - China Cybersecurity Law:

- [PRC Cybersecurity Law, amended in 2025](https://www.cac.gov.cn/2025-12/29/c_1768735112911946.htm?ref=sorena.io) - Use for the current Cybersecurity Law scope and duties described in this row.

Sources for Scope boundary - operational implication:

- [PRC Cryptography Law](https://www.oscca.gov.cn/sca/xxgk/2023-06/04/content_1057225.shtml?ref=sorena.io) - Use for cryptography categories, commercial cryptography development and management, product/service controls, CII use, import/export context, penalties, and 1 January 2020 effective date.

Sources for Covered actors - China Cryptography Law:

- [PRC Cryptography Law](https://www.oscca.gov.cn/sca/xxgk/2023-06/04/content_1057225.shtml?ref=sorena.io) - Use for cryptography categories, commercial cryptography development and management, product/service controls, CII use, import/export context, penalties, and 1 January 2020 effective date.

Sources for Covered actors - China Cybersecurity Law:

- [PRC Cybersecurity Law, amended in 2025](https://www.cac.gov.cn/2025-12/29/c_1768735112911946.htm?ref=sorena.io) - Use for the current Cybersecurity Law scope and duties described in this row.

Sources for Covered actors - operational implication:

- [PRC Cryptography Law](https://www.oscca.gov.cn/sca/xxgk/2023-06/04/content_1057225.shtml?ref=sorena.io) - Use for cryptography categories, commercial cryptography development and management, product/service controls, CII use, import/export context, penalties, and 1 January 2020 effective date.

Sources for Trigger event - China Cryptography Law:

- [PRC Cryptography Law](https://www.oscca.gov.cn/sca/xxgk/2023-06/04/content_1057225.shtml?ref=sorena.io) - Use for cryptography categories, commercial cryptography development and management, product/service controls, CII use, import/export context, penalties, and 1 January 2020 effective date.

Sources for Trigger event - China Cybersecurity Law:

- [PRC Cybersecurity Law, amended in 2025](https://www.cac.gov.cn/2025-12/29/c_1768735112911946.htm?ref=sorena.io) - Use for the current Cybersecurity Law scope and duties described in this row.

Sources for Trigger event - operational implication:

- [PRC Cryptography Law](https://www.oscca.gov.cn/sca/xxgk/2023-06/04/content_1057225.shtml?ref=sorena.io) - Use for cryptography categories, commercial cryptography development and management, product/service controls, CII use, import/export context, penalties, and 1 January 2020 effective date.

Sources for Product assurance and system assessment - China Cryptography Law:

- [PRC Cryptography Law](https://www.oscca.gov.cn/sca/xxgk/2023-06/04/content_1057225.shtml?ref=sorena.io) - Articles 25-27 support voluntary assurance, mandatory assurance for qualifying products and related services, CII cryptography assessment, and coordination to avoid duplication.

Sources for Product assurance and system assessment - China Cybersecurity Law:

- [PRC Cybersecurity Law, amended in 2025](https://www.cac.gov.cn/2025-12/29/c_1768735112911946.htm?ref=sorena.io) - Articles 23 and 25 support graded protection and mandatory assurance for listed network critical equipment and network security-specific products.

Sources for Product assurance and system assessment - operational implication:

- [PRC Cryptography Law](https://www.oscca.gov.cn/sca/xxgk/2023-06/04/content_1057225.shtml?ref=sorena.io) - Articles 26-27 support linking the regimes while avoiding duplicate testing, certification, assessment, and graded-protection measurement.

Sources for Evidence package - China Cryptography Law:

- [PRC Cryptography Law](https://www.oscca.gov.cn/sca/xxgk/2023-06/04/content_1057225.shtml?ref=sorena.io) - Use for cryptography categories, commercial cryptography development and management, product/service controls, CII use, import/export context, penalties, and 1 January 2020 effective date.

Sources for Evidence package - China Cybersecurity Law:

- [PRC Cybersecurity Law, amended in 2025](https://www.cac.gov.cn/2025-12/29/c_1768735112911946.htm?ref=sorena.io) - Use for the current Cybersecurity Law scope and duties described in this row.

Sources for Evidence package - operational implication:

- [PRC Cryptography Law](https://www.oscca.gov.cn/sca/xxgk/2023-06/04/content_1057225.shtml?ref=sorena.io) - Use for cryptography categories, commercial cryptography development and management, product/service controls, CII use, import/export context, penalties, and 1 January 2020 effective date.

Sources for Timing and refresh points - China Cryptography Law:

- [PRC Cryptography Law](https://www.oscca.gov.cn/sca/xxgk/2023-06/04/content_1057225.shtml?ref=sorena.io) - Use for cryptography categories, commercial cryptography development and management, product/service controls, CII use, import/export context, penalties, and 1 January 2020 effective date.

Sources for Timing and refresh points - China Cybersecurity Law:

- [PRC Cybersecurity Law, amended in 2025](https://www.cac.gov.cn/2025-12/29/c_1768735112911946.htm?ref=sorena.io) - Use for the current Cybersecurity Law scope and duties described in this row.

Sources for Timing and refresh points - operational implication:

- [PRC Cryptography Law](https://www.oscca.gov.cn/sca/xxgk/2023-06/04/content_1057225.shtml?ref=sorena.io) - Use for cryptography categories, commercial cryptography development and management, product/service controls, CII use, import/export context, penalties, and 1 January 2020 effective date.

Sources for Enforcement exposure - China Cryptography Law:

- [PRC Cryptography Law](https://www.oscca.gov.cn/sca/xxgk/2023-06/04/content_1057225.shtml?ref=sorena.io) - Use for cryptography categories, commercial cryptography development and management, product/service controls, CII use, import/export context, penalties, and 1 January 2020 effective date.

Sources for Enforcement exposure - China Cybersecurity Law:

- [PRC Cybersecurity Law, amended in 2025](https://www.cac.gov.cn/2025-12/29/c_1768735112911946.htm?ref=sorena.io) - Use for the current Cybersecurity Law scope and duties described in this row.

Sources for Enforcement exposure - operational implication:

- [PRC Cryptography Law](https://www.oscca.gov.cn/sca/xxgk/2023-06/04/content_1057225.shtml?ref=sorena.io) - Use for cryptography categories, commercial cryptography development and management, product/service controls, CII use, import/export context, penalties, and 1 January 2020 effective date.

Sources for Overlap and routing - China Cryptography Law:

- [PRC Cryptography Law](https://www.oscca.gov.cn/sca/xxgk/2023-06/04/content_1057225.shtml?ref=sorena.io) - Use for cryptography categories, commercial cryptography development and management, product/service controls, CII use, import/export context, penalties, and 1 January 2020 effective date.

Sources for Overlap and routing - China Cybersecurity Law:

- [PRC Cybersecurity Law, amended in 2025](https://www.cac.gov.cn/2025-12/29/c_1768735112911946.htm?ref=sorena.io) - Use for the current Cybersecurity Law scope and duties described in this row.

Sources for Overlap and routing - operational implication:

- [PRC Cryptography Law](https://www.oscca.gov.cn/sca/xxgk/2023-06/04/content_1057225.shtml?ref=sorena.io) - Use for cryptography categories, commercial cryptography development and management, product/service controls, CII use, import/export context, penalties, and 1 January 2020 effective date.

Sources for Practical decision rule - China Cryptography Law:

- [PRC Cryptography Law](https://www.oscca.gov.cn/sca/xxgk/2023-06/04/content_1057225.shtml?ref=sorena.io) - Use for cryptography categories, commercial cryptography development and management, product/service controls, CII use, import/export context, penalties, and 1 January 2020 effective date.

Sources for Practical decision rule - China Cybersecurity Law:

- [PRC Cybersecurity Law, amended in 2025](https://www.cac.gov.cn/2025-12/29/c_1768735112911946.htm?ref=sorena.io) - Use for the current Cybersecurity Law scope and duties described in this row.

Sources for Practical decision rule - operational implication:

- [PRC Cryptography Law](https://www.oscca.gov.cn/sca/xxgk/2023-06/04/content_1057225.shtml?ref=sorena.io) - Use for cryptography categories, commercial cryptography development and management, product/service controls, CII use, import/export context, penalties, and 1 January 2020 effective date.

### When to run one track or both

- Use China Cryptography Law when the facts match cryptography product/service classification, listed product question, testing/certification dependency, security assessment, or import/export screening.
- Use the Cybersecurity Law track for network operation, graded protection, product and service security, regulated network products, CII protection, incidents, and CII procurement review.
- Run both when the same launch creates both triggers, but keep separate approvals and official citations.

Sources for the practical decision rule:

- [PRC Cryptography Law](https://www.oscca.gov.cn/sca/xxgk/2023-06/04/content_1057225.shtml?ref=sorena.io) - Use for cryptography categories, commercial cryptography development and management, product/service controls, CII use, import/export context, penalties, and 1 January 2020 effective date.

## Run one legal track or both

The Cryptography Law classifies cryptography and regulates commercial cryptography activities, products, services, CII use, and controlled trade. Its Article 26 applies the Cybersecurity Law framework to qualifying commercial cryptography products to avoid duplicate testing and certification. Article 27 links certain CII commercial cryptography procurements to national security review and coordinates assessments.

The current Cybersecurity Law applies to building, operating, maintaining, and using networks in China and to cybersecurity supervision. It separately sets graded-protection, network product and service, regulated-product, CII, incident, and information-security duties. The 2025 amendment took effect on 1 January 2026 and renumbered several provisions; this page uses the current numbering.

- Open the Cryptography Law route when the decision concerns the cryptography category, commercial cryptography standards, testing or certification, CII cryptography use, or controlled trade.
- Open the Cybersecurity Law route when the decision concerns network operator duties, graded protection, network product or service security, the regulated network-product catalogue, CII protection, or national-security review.
- Run both routes for a qualifying commercial cryptography product or CII deployment. Link shared facts, but preserve separate triggers, conclusions, owners, and citations.

Sources for this answer:

- [PRC Cryptography Law](https://www.oscca.gov.cn/sca/xxgk/2023-06/04/content_1057225.shtml?ref=sorena.io) - Use for cryptography categories, commercial cryptography development and management, product/service controls, CII use, import/export context, penalties, and 1 January 2020 effective date.
- [PRC Cybersecurity Law, amended in 2025](https://www.cac.gov.cn/2025-12/29/c_1768735112911946.htm?ref=sorena.io) - Articles 2, 23-25, and 33-40 support the current scope, graded-protection, product and service, regulated-product, and CII comparison; the amendment applies from 1 January 2026.
- [Presidential Order No. 61 promulgating the 2025 Cybersecurity Law amendment](https://www.npc.gov.cn/npc/c2/c30834/202510/t20251028_449031.html?ref=sorena.io) - Supports the amendment's adoption on 28 October 2025 and 1 January 2026 effective date.
- [Provisions on the Use and Administration of Commercial Cryptography in Critical Information Infrastructure](https://www.oscca.gov.cn/sca/xxgk/2025-06/27/content_1061270.shtml?ref=sorena.io) - Use for the detailed commercial cryptography duties that apply to identified CII from 1 August 2025.

## Compare scope, actors, and the first decision

The Cryptography Law first asks what kind of cryptography is involved and what activity is performed. Its commercial-cryptography rules cover research, production, sale, service, testing, certification, import, export, application, and supervision within China. They also create a cryptography-use licence for a provider using commercial cryptography to supply electronic certification services; electronic-government electronic certification follows a separate qualification route. The Cybersecurity Law first asks whether a network is being built, operated, maintained, or used in China and which actor owns, manages, or provides that network.

A seller of a commercial-cryptography product may need the Cryptography Law track without operating the buyer's network. A business that owns or manages an ordinary network may have Cybersecurity Law duties as a network operator even if no mandatory commercial-cryptography product, CII, or trade trigger applies.

- Cryptography Law input: protected information, cryptographic function, product or service, activity, supplier, operator, and import or export movement.
- Cybersecurity Law input: network, network operator, protection level, network product or service, CII status, data handled, and procurement facts.
- Shared result: one deployment can require both tracks, but neither classification should be inferred from the other.

Sources for this answer:

- [PRC Cryptography Law](https://www.oscca.gov.cn/sca/xxgk/2023-06/04/content_1057225.shtml?ref=sorena.io) - Articles 2, 6-8, and 21-31 establish the cryptography categories and the commercial-cryptography activities and controls.
- [PRC Cybersecurity Law, amended in 2025](https://www.cac.gov.cn/2025-12/29/c_1768735112911946.htm?ref=sorena.io) - Articles 2, 23, and 78 establish territorial scope, the network-operator concept, and the graded-protection starting point.
- [Measures for the Administration of Cryptography Use in Electronic Certification Services](https://www.oscca.gov.cn/sca/xxgk/2026-06/03/content_1061341.shtml?ref=sorena.io) - Articles 2-3 establish the electronic-certification cryptography-use licensing route in China and distinguish electronic-government electronic certification.

## Compare product and service assurance

The Cryptography Law generally encourages voluntary testing and certification. Mandatory assurance applies when a commercial-cryptography product involving national security, the national economy and people's livelihoods, or the public interest is included in the catalogue of critical network equipment and specialised cybersecurity products. A commercial-cryptography service using catalogue products must pass service certification.

The Cybersecurity Law governs the catalogue route itself. Current Article 25 requires listed critical network equipment and specialised cybersecurity products to pass qualified security certification or security testing before sale or provision and requires mutual recognition of results to avoid duplicate certification and testing. The supplier should identify the exact catalogue entry and required output instead of treating every encrypted product as listed.

- Cryptography conclusion: whether the item is a commercial-cryptography product or service and whether Cryptography Law Article 26 applies.
- Cybersecurity conclusion: whether the item is listed critical network equipment or a listed specialised cybersecurity product and which qualified assurance route applies.
- Evidence: exact model and version, catalogue entry, testing or certification body and scope, report or certificate, validity, and the legal basis for any recognised result.

Sources for this answer:

- [PRC Cryptography Law](https://www.oscca.gov.cn/sca/xxgk/2023-06/04/content_1057225.shtml?ref=sorena.io) - Articles 25-26 distinguish voluntary commercial-cryptography assurance from the mandatory catalogue product and service routes.
- [PRC Cybersecurity Law, amended in 2025](https://www.cac.gov.cn/2025-12/29/c_1768735112911946.htm?ref=sorena.io) - Article 25 establishes the current catalogue assurance and mutual-recognition rules.
- [Commercial Cryptography Administration Regulation](https://www.mee.gov.cn/zcwj/gwywj/202305/t20230529_1031579.shtml?ref=sorena.io) - Articles 12-21 distinguish testing, certification, mandatory products, and mandatory service certification.

## Compare CII duties and assessment cycles

The Cybersecurity Law gives identified CII enhanced network-security duties. It requires security measures to be planned, built, and used with the infrastructure, sets operator governance and resilience duties, requires review of procurements that may affect national security, and requires a network-security assessment at least annually.

The CII commercial-cryptography route is narrower and more specific. The operator must use qualified commercial-cryptography products and services and reviewed cryptographic technologies, assess the application plan, reassess a changed plan during construction, pass an assessment before operation, and assess at least annually after operation. A failed plan cannot support construction, and a failed pre-operation assessment requires remediation before operation.

Coordination avoids duplicate work; it does not turn the annual Cybersecurity Law network assessment into the commercial-cryptography application assessment or vice versa. Record each scope, conclusion, report destination, and remediation result.

- Cybersecurity Law owner: the CII operator and the responsible CII protection department.
- Cryptography owner: the CII operator, with the protection department and cryptography authorities performing their assigned supervision and reporting roles.
- Procurement branch: apply for cybersecurity review only when the CII network-product or service procurement affects or may affect national security; commercial cryptography in the procurement is not enough by itself.

Sources for this answer:

- [PRC Cybersecurity Law, amended in 2025](https://www.cac.gov.cn/2025-12/29/c_1768735112911946.htm?ref=sorena.io) - Articles 33-40 establish CII scope, lifecycle security, operator duties, procurement review, and the annual network-security assessment.
- [Provisions on the Use and Administration of Commercial Cryptography in Critical Information Infrastructure](https://www.oscca.gov.cn/sca/xxgk/2025-06/27/content_1061270.shtml?ref=sorena.io) - Articles 2 and 5-15 establish CII identification, cryptography governance, products, technologies, planning, construction, pre-operation, annual assessment, transition, and coordination duties.
- [Cybersecurity Review Measures](https://www.cac.gov.cn/2022-01/04/c_1642894602182845.htm?ref=sorena.io) - Articles 2 and 5 place the procurement risk assessment and filing decision on the CII operator.

## Compare enforcement and keep separate evidence

The Cryptography Law and its implementing rules impose actor- and conduct-specific remedies for unauthorized testing or certification, nonconforming covered products and services, CII cryptography failures, trade-control breaches, and obstruction. The Cybersecurity Law has separate remedies for network-security, listed-product, CII, information-security, and supervision failures. One event may support more than one legal analysis; do not transfer a fine band from one provision to another.

Keep a shared technical record, then issue separate legal conclusions. At minimum, record the product or system version, cryptographic function, network and operator, CII identification, protection level, catalogue and control-list checks, reports or certificates, assessment scopes and dates, procurement risk analysis, authority submissions, remediation, and the change that requires reassessment.

- Do not treat a commercial-cryptography certificate as proof of full Cybersecurity Law compliance.
- Do not treat a graded-protection or annual CII network assessment as proof that the commercial-cryptography lifecycle assessment passed.
- For a possible breach, identify the exact actor, conduct, article, legal instrument, and current penalty provision before estimating exposure.

Sources for this answer:

- [PRC Cryptography Law](https://www.oscca.gov.cn/sca/xxgk/2023-06/04/content_1057225.shtml?ref=sorena.io) - Articles 32-41 establish the Cryptography Law liability routes.
- [Commercial Cryptography Administration Regulation](https://www.mee.gov.cn/zcwj/gwywj/202305/t20230529_1031579.shtml?ref=sorena.io) - Articles 50-66 establish the regulation-level remedies and fine bands.
- [PRC Cybersecurity Law, amended in 2025](https://www.cac.gov.cn/2025-12/29/c_1768735112911946.htm?ref=sorena.io) - The current Chapter VI contains the Cybersecurity Law remedies, including the 2025 amendments effective from 1 January 2026.

*Next step*

*Placement: Before primary sources*

## Prepare the commercial cryptography evidence file

Sorena AI helps turn the China Cryptography Law vs China Cybersecurity Law decision into owners, controls, and reviewer-ready records.

- [Map official sources to evidence](/solutions/research-copilot.md): Research Copilot connects the official citation, decision, owner, retained evidence, and change history.
- [Review the China route](/contact.md): Check the China Cryptography Law scope decision and unresolved launch questions with Sorena.

## Primary sources

- [PRC Cryptography Law](https://www.oscca.gov.cn/sca/xxgk/2023-06/04/content_1057225.shtml?ref=sorena.io) - Use for cryptography categories, commercial cryptography development and management, product/service controls, CII use, import/export context, penalties, and 1 January 2020 effective date.
- [PRC Cybersecurity Law, amended in 2025](https://www.cac.gov.cn/2025-12/29/c_1768735112911946.htm?ref=sorena.io) - Use for the current Cybersecurity Law scope and duties described in this row.
- [Presidential Order No. 61 promulgating the 2025 Cybersecurity Law amendment](https://www.npc.gov.cn/npc/c2/c30834/202510/t20251028_449031.html?ref=sorena.io) - Use for the 28 October 2025 promulgation and 1 January 2026 effective date of the amendment.
- [Commercial Cryptography Administration Regulation (State Council Order No. 760)](https://www.mee.gov.cn/zcwj/gwywj/202305/t20230529_1031579.shtml?ref=sorena.io) - Articles 20-21 and 38-42 support the detailed product, service, and CII links between the regimes.
- [Provisions on the Use and Administration of Commercial Cryptography in Critical Information Infrastructure](https://www.oscca.gov.cn/sca/xxgk/2025-06/27/content_1061270.shtml?ref=sorena.io) - Use for CII-specific commercial cryptography governance, product, technology, assessment, and procurement-review requirements effective 1 August 2025.
- [Measures for the Administration of Cryptography Use in Electronic Certification Services](https://www.oscca.gov.cn/sca/xxgk/2026-06/03/content_1061341.shtml?ref=sorena.io) - Use for the electronic-certification cryptography-use licensing route effective 1 July 2026, which belongs to the cryptography track rather than the general Cybersecurity Law track.

## Related Topic Guides

- [China commercial cryptography compliance checklist](/artifacts/apac/china-cryptography-law/checklist.md): China commercial cryptography checklist covering classification, product and service assurance, CII duties, trade controls, and retained evidence.
- [China commercial cryptography testing evidence template](/artifacts/apac/china-cryptography-law/commercial-cryptography-testing-evidence-template.md): Record the legal route, product or system scope, testing-body qualification, report details, gaps, and reassessment triggers for China commercial cryptography assurance.
- [China cryptography compliance deadlines and calendar](/artifacts/apac/china-cryptography-law/deadlines-and-compliance-calendar.md): China cryptography effective dates, CII reports, annual assessments, licence renewals, change notices, and pre-operation checks.
- [China cryptography import, export, and security review triage](/artifacts/apac/china-cryptography-law/import-export-and-security-assessment.md): Screen commercial cryptography imports under the 2020 list, exports under China's unified dual-use list, the consumer exclusion, system assessment, and CII review.
- [China Cryptography Law FAQ](/artifacts/apac/china-cryptography-law/faq.md): Answers on China's commercial-cryptography scope, product assurance, classified protection, CII assessment, procurement review, and trade controls.
- [China Cryptography Law requirements](/artifacts/apac/china-cryptography-law/requirements.md): China commercial cryptography requirements by role: standards, testing, certification, CII use and assessment, trade controls, and evidence.
- [China cryptography penalties, fines, and liability](/artifacts/apac/china-cryptography-law/penalties-and-fines.md): China commercial cryptography penalties by actor and violation, including fine bands, corrective orders, confiscation, licence action, and liability.
- [Commercial cryptography procurement checklist](/artifacts/apac/china-cryptography-law/commercial-cryptography-procurement-checklist.md): Procurement checks for commercial cryptography products and services used in China, including certificate scope, CII duties, and supplier changes.
- [Commercial cryptography products and testing evidence](/artifacts/apac/china-cryptography-law/commercial-cryptography-products-and-testing.md): When China commercial cryptography testing or certification is voluntary or mandatory, and what product, service, body, and scope evidence to keep.
- [Do imported cryptography products need special review?](/artifacts/apac/china-cryptography-law/faq/do-imported-cryptography-products-need-special-review.md): Not every encrypted product imported into China needs a licence. Check the 2020 commercial-cryptography import list, the consumer-product exception, and any CII procurement review.
- [Does using encryption trigger China Cryptography Law duties?](/artifacts/apac/china-cryptography-law/faq/does-using-encryption-trigger-china-cryptography-law.md): Using encryption does not create one universal China approval duty. Check classified protection, product, service, CII, procurement, and trade triggers.
- [How does cryptography compliance overlap with China cybersecurity law?](/artifacts/apac/china-cryptography-law/faq/how-does-cryptography-compliance-overlap-with-cybersecurity-law.md): See how China's cryptography rules connect with classified protection, product assurance, CII assessment, and cybersecurity review without merging the regimes.
- [What is commercial cryptography in China?](/artifacts/apac/china-cryptography-law/faq/what-is-commercial-cryptography-in-china.md): Commercial cryptography protects information that is not a state secret. Learn how China defines the category and which separate facts trigger product, CII, or trade controls.
- [When is commercial cryptography testing or certification needed?](/artifacts/apac/china-cryptography-law/faq/when-is-commercial-cryptography-testing-or-certification-needed.md): Commercial-cryptography assurance is often voluntary, but specified products and services require it. Covered CII also needs application assessment and qualified cryptography.


---

[Privacy Policy](https://www.sorena.io/privacy.md) | [Terms of Use](https://www.sorena.io/terms-of-use.md) | [DMCA](https://www.sorena.io/dmca.md) | [About Us](https://www.sorena.io/about-us.md)

(c) 2026 Sorena AB (559573-7338). All rights reserved.

Source: https://www.sorena.io/artifacts/apac/china-cryptography-law/china-cryptography-law-vs-cybersecurity-law.md
