CryptographyChina

China Cryptography Law Commercial cryptography procurement checklist

Procurement checks for commercial cryptography products and services used in China, including certificate scope, CII duties, and supplier changes.

For procurement, security, and legal teams: tie each supplier claim to the exact item, version, certificate, intended system, and legal route.

Author
Sorena AI
Published
Jul 5, 2026
Updated
Jul 25, 2026
Sections
4

Structured answer sets in this page tree.

Primary sources
8

Cited legal and guidance references.

Publication metadata
Sorena AI
Published Jul 5, 2026
Updated Jul 25, 2026
Overview

Use this checklist before buying or replacing a product or service for a China-market system. It separates ordinary supplier due diligence from mandatory product, service, , assessment, and requirements.

Section 2

Complete each procurement gate and retain its evidence

The procurement gate below is Sorena's operational synthesis. The cited rules establish the legal requirements but do not prescribe this internal approval workflow.

Do not approve the item while an identified mandatory certification, technology review, application security assessment, or requirement remains unresolved.

  • Map the supplier's legal name, manufacturing and service locations, subcontractors, exact item identifiers, versions, cryptographic functions, and intended deployment.
  • Verify the testing or certification body's qualification and match the report or certificate to the actual item, service, version, scope, and status.
  • Record whether the buyer concluded that assurance is voluntary or mandatory, and retain the catalogue match when the mandatory route applies.
  • For required to use , assign the operator to confirm certified products and services, reviewed technologies, the application plan, pre-operation and annual assessment, required reporting, and any .
  • The operator retains its decisions and assessment duties. Contract terms and supplier certificates can provide evidence and cooperation without transferring those legal duties to the supplier.
  • Contract for timely notice of vulnerability, component, algorithm, protocol, key-management, version, certificate, catalogue, ownership, subcontractor, and service-location changes.
  • State the acceptance evidence for each mandatory gate: the exact catalogue match, complete report or certificate, verified body qualification and scope, technology-review evidence, assessment result, filing evidence, or written cybersecurity-review outcome. A supplier declaration alone is not acceptance evidence.
  • Require the supplier to preserve versioned specifications, cryptographic component and key-management details, assessment-support records, and change notices for the contract period, while keeping any longer statutory retention duty assigned to the operator or testing body separate.
  • Do not substitute a product or service until the replacement has completed the same scoped review.
Section 3

Evidence to keep before launch or change approval

Keep the supplier response, product specification, cryptographic bill of materials, route screening, catalogue match, reports or certificates, qualification evidence, technology review evidence, contract controls, exceptions, approvals, and review date.

Link every record to the deployed version and system. Reopen review after supplier, subcontractor, component, algorithm, protocol, key-management, version, certificate, catalogue, operator, architecture, or use-case changes.

  • Supplier identity, item identifiers, versions, architecture, cryptographic functions, standards, and intended use.
  • Voluntary-or-mandatory assurance conclusion and the applicable catalogue entry when mandatory.
  • Testing or certification body qualification, report, certificate, status, scope, surveillance, and limitations.
  • product, service, technology, application plan, assessment, reporting, and records where applicable.
  • Electronic-certification provider licence, covered service and system, annual assessment, change status, and separate electronic-government qualification where applicable.
  • Import-list match, shipment facts, mass-market consumer-product analysis if relied on, and import license where required.
  • Contractual change notice, access, evidence, vulnerability response, remediation, and replacement terms.
  • Dated procurement approval, exceptions, accountable owner, unresolved questions, and change log.
Section 4

Boundary with nearby China regimes

Product certification does not complete the application assessment or . These routes have different triggers and records even when they concern the same supplier and item.

The current Cybersecurity Law separately governs , graded protection, duties, and certain procurement reviews. An electronic-certification provider's cryptography-use licence also answers a provider-specific question; it does not certify every relying party's network or procurement. Personal-information and data-transfer conclusions require their own source-backed analysis.

  • Accepting a certificate that covers a different model, software version, cryptographic module, service, or validity period.
  • Treating a voluntary certification catalogue as proof that the mandatory network-product route applies.
  • Assuming a supplier certificate completes the operator's planning, assessment, reporting, or .
  • Allowing substitution or silent component changes without repeating the scoped review.
Primary sources

References and citations

oscca.gov.cn
Referenced sections
  • Use for cryptography categories, commercial cryptography development and management, product/service controls, CII use, import/export context, penalties, and 1 January 2020 effective date.
Related guides

Explore more topics

China commercial cryptography compliance checklist
China commercial cryptography checklist covering classification, product and service assurance, CII duties, trade controls, and retained evidence.
China commercial cryptography testing evidence template
Record the legal route, product or system scope, testing-body qualification, report details, gaps, and reassessment triggers for China commercial cryptography assurance.
China cryptography compliance deadlines and calendar
China cryptography effective dates, CII reports, annual assessments, licence renewals, change notices, and pre-operation checks.
China cryptography import, export, and security review triage
Screen commercial cryptography imports under the 2020 list, exports under China's unified dual-use list, the consumer exclusion, system assessment, and CII review.
China Cryptography Law FAQ
Answers on China's commercial-cryptography scope, product assurance, classified protection, CII assessment, procurement review, and trade controls.
China Cryptography Law requirements
China commercial cryptography requirements by role: standards, testing, certification, CII use and assessment, trade controls, and evidence.
China Cryptography Law vs Cybersecurity Law
Compare China's Cryptography Law and current Cybersecurity Law by scope, actor, product assurance, CII duties, evidence, and enforcement.
China cryptography penalties, fines, and liability
China commercial cryptography penalties by actor and violation, including fine bands, corrective orders, confiscation, licence action, and liability.
Commercial cryptography products and testing evidence
When China commercial cryptography testing or certification is voluntary or mandatory, and what product, service, body, and scope evidence to keep.
Do imported cryptography products need special review?
Not every encrypted product imported into China needs a licence. Check the 2020 commercial-cryptography import list, the consumer-product exception, and any CII procurement review.
Does using encryption trigger China Cryptography Law duties?
Using encryption does not create one universal China approval duty. Check classified protection, product, service, CII, procurement, and trade triggers.
How does cryptography compliance overlap with China cybersecurity law?
See how China's cryptography rules connect with classified protection, product assurance, CII assessment, and cybersecurity review without merging the regimes.
What is commercial cryptography in China?
Commercial cryptography protects information that is not a state secret. Learn how China defines the category and which separate facts trigger product, CII, or trade controls.
When is commercial cryptography testing or certification needed?
Commercial-cryptography assurance is often voluntary, but specified products and services require it. Covered CII also needs application assessment and qualified cryptography.