---
title: "Commercial cryptography procurement checklist"
canonical_url: "https://www.sorena.io/artifacts/apac/china-cryptography-law/commercial-cryptography-procurement-checklist"
source_url: "https://www.sorena.io/artifacts/apac/china-cryptography-law/commercial-cryptography-procurement-checklist"
author: "Sorena AI"
description: "Procurement checks for commercial cryptography products and services used in China, including certificate scope, CII duties, and supplier changes."
published_at: "2026-07-05"
updated_at: "2026-07-25"
keywords:
  - "China Cryptography Law"
  - "Commercial cryptography"
  - "Cryptography Law"
  - "Commercial cryptography testing"
  - "China cybersecurity"
---
**[SORENA](https://www.sorena.io/)** - AI-Powered GRC Platform

[Home](https://www.sorena.io/) | [Solutions](https://www.sorena.io/solutions) | [Artifacts](https://www.sorena.io/artifacts) | [About Us](https://www.sorena.io/about-us) | [Contact](https://www.sorena.io/contact) | [Portal](https://app.sorena.io)

---

# Commercial cryptography procurement checklist

Procurement checks for commercial cryptography products and services used in China, including certificate scope, CII duties, and supplier changes.

*Cryptography* *China*

## China Cryptography Law Commercial cryptography procurement checklist

For procurement, security, and legal teams: tie each supplier claim to the exact item, version, certificate, intended system, and legal route.

Use this checklist before buying or replacing a commercial cryptography product or service for a China-market system. It separates ordinary supplier due diligence from mandatory product, service, CII, assessment, and cybersecurity review requirements.

## Definitions

### Commercial cryptography

Commercial cryptography means technology, products, and services that use specific transformations to encrypt or authenticate information that is not a state secret. It can be embedded in hardware, software, a managed service, or a wider network product. Core and ordinary cryptography are separate categories used to protect state-secret information.

**Why it matters here:** Procurement must identify the exact cryptographic function and supplied item before asking for certificates or contract evidence. A generic statement that a product uses encryption does not determine whether a voluntary, mandatory product, service, CII, or trade route applies.

Sources:

- [PRC Cryptography Law, Articles 2 and 6-8](https://www.oscca.gov.cn/sca/xxgk/2023-06/04/content_1057225.shtml?ref=sorena.io)
- [Commercial Cryptography Administration Regulation, Article 2](https://www.mee.gov.cn/zcwj/gwywj/202305/t20230529_1031579.shtml?ref=sorena.io)

### Network critical equipment and network security-specific products

These are network products covered by the catalogue jointly published under the Cybersecurity Law. A covered product must meet mandatory national standards and pass qualified security certification or security testing before sale or provision. The legal test is whether the actual product falls within that catalogue, not whether it appears in a separate voluntary commercial cryptography certification catalogue.

**Why it matters here:** For a commercial cryptography product, a catalogue match triggers the mandatory product-assurance route. If a commercial cryptography service uses a product in that catalogue, the service has its own certification requirement.

Sources:

- [PRC Cybersecurity Law, Article 25](https://www.cac.gov.cn/2025-12/29/c_1768735112911946.htm?ref=sorena.io)
- [PRC Cryptography Law, Article 26](https://www.oscca.gov.cn/sca/xxgk/2023-06/04/content_1057225.shtml?ref=sorena.io)
- [Commercial Cryptography Administration Regulation, Articles 20-21](https://www.mee.gov.cn/zcwj/gwywj/202305/t20230529_1031579.shtml?ref=sorena.io)

### Cybersecurity review

Cybersecurity review is the review conducted under the Cybersecurity Review Measures when a critical information infrastructure operator procures network products or services that affect or may affect national security. It examines national-security risks associated with the procurement and is separate from product certification and commercial cryptography application security assessment.

**Why it matters here:** For CII procurement involving commercial cryptography, the operator must determine whether this review trigger applies before using the product or service. Supplier assurance cannot replace the operator's review decision or the official review outcome.

Sources:

- [Cybersecurity Review Measures, Article 2](https://www.oscca.gov.cn/sca/xxgk/2022-01/04/content_1060954.shtml?ref=sorena.io)
- [Provisions on the Use and Administration of Commercial Cryptography in Critical Information Infrastructure, Article 9](https://www.oscca.gov.cn/sca/xxgk/2025-06/27/content_1061270.shtml?ref=sorena.io)

### Critical information infrastructure

**Term:** CII

Critical information infrastructure is infrastructure in important industries and fields whose destruction, loss of function, or data leakage could seriously harm national security, the national economy and people's livelihoods, or the public interest. The competent protection department identifies it and notifies the operator under the applicable rules; a supplier, buyer, or adviser should not infer CII status from sector, system importance, or customer size alone.

**Why it matters here:** CII status changes the procurement gate. For infrastructure required to use commercial cryptography, the operator must verify tested and certified products and services, reviewed cryptographic technologies, lifecycle assessment, annual reporting, and any cybersecurity review triggered by a procurement that affects or may affect national security.

Sources:

- [Critical Information Infrastructure Security Protection Regulation, Articles 2 and 8-11](https://www.cac.gov.cn/2021-08/17/c_1630785976988160.htm?ref=sorena.io)
- [Provisions on the Use and Administration of Commercial Cryptography in Critical Information Infrastructure, Articles 2 and 5-15](https://www.oscca.gov.cn/sca/xxgk/2025-06/27/content_1061270.shtml?ref=sorena.io)

### Commercial cryptography application security assessment

This system-level assessment tests whether a network or information system uses commercial cryptography technologies, products, and services compliantly, correctly, and effectively. For a system that national rules require to use commercial cryptography, the operator must assess the application plan, assess the completed system before operation, and assess the operating system at least annually.

**Why it matters here:** The supplier must provide the technical access and records needed for the assessment, but the operator retains the assessment duty. Product or service certification cannot replace the plan assessment, pre-operation result, annual assessment, remediation, or filing.

Sources:

- [Commercial Cryptography Application Security Assessment Measures, Articles 2 and 6-14](https://www.oscca.gov.cn/sca/xxgk/2023-10/07/content_1061109.shtml?ref=sorena.io)

### Commercial cryptography used in mass-market consumer products

**Term:** mass-market consumer products

The Cryptography Law excludes commercial cryptography used in mass-market consumer products from its import-licensing and export-control system. The National Cryptography Administration describes the category as products or technologies available to the public without restriction through ordinary retail channels, intended for personal use, and whose cryptographic function cannot easily be changed.

**Why it matters here:** If procurement includes an import, the buyer and trade owner must document the model, retail availability, intended users and use, distribution restrictions, and cryptographic configurability before relying on the exclusion. The exclusion does not remove product-assurance, system-assessment, CII, or procurement-review duties.

Sources:

- [PRC Cryptography Law, Article 28](https://www.oscca.gov.cn/sca/xxgk/2023-06/04/content_1057225.shtml?ref=sorena.io)
- [National Cryptography Administration policy answer on mass-market consumer products](https://www.oscca.gov.cn/sca/xxgk/2020-04/02/content_1060694.shtml?ref=sorena.io)

## Check the item, supplier evidence, and legal route

Supplier evidence must identify the exact product or service, model, version, cryptographic function, certificate scope, intended operator, and use. A generic 'China compliant' statement does not show whether the evidence covers voluntary certification, a mandatory network-product route, a commercial cryptography service, or a CII deployment.

For non-CII procurement, determine whether the product is legally included in the catalogue of network critical equipment and network security-specific products or whether the service uses such products. For CII required to use commercial cryptography, the 2025 provisions require certified products and services, reviewed commercial cryptography technologies, commercial cryptography application security assessment throughout the lifecycle, and cybersecurity review where the procurement affects or may affect national security.

- Require the supplier to identify the product or service, model, hardware and software version, cryptographic functions, algorithms, protocols, key-management mechanisms, intended China use, and applicable standards.
- Request each test report or certificate, including issuer, body qualification, certificate number, scope, covered version, issue and expiry dates, status, surveillance conditions, and limitations.
- Record whether assurance is voluntary or mandatory. For a mandatory conclusion, retain the applicable network-product catalogue entry and the basis for matching the item to it.
- For CII required to use commercial cryptography, require evidence that the product or service passed the required testing and certification and that the relevant commercial cryptography technologies passed State Cryptography Administration review and identification.
- Require supplier support for the commercial cryptography application plan, system inventory, assessment access, remediation, incident response, and any cybersecurity review.
- If the procurement is for electronic certification services using commercial cryptography in China, verify the provider's Electronic Certification Service Cryptography Use Licence, licensed service and system, term, annual compliance assessment, and change status. For electronic-government electronic certification, verify the separate provider qualification instead.
- Allocate notice, evidence refresh, cooperation, vulnerability response, replacement, and remediation duties for changes to the item, version, cryptographic function, certificate, catalogue status, supplier, or service architecture.
- If procurement includes an import into China, screen the exact item and shipment against the current import-license list. Rely on the statutory exclusion for commercial cryptography used in mass-market consumer products only when the supplied item meets that wording.

Sources for this answer:

- [PRC Cryptography Law](https://www.oscca.gov.cn/sca/xxgk/2023-06/04/content_1057225.shtml?ref=sorena.io) - Use for cryptography categories, commercial cryptography development and management, product/service controls, CII use, import/export context, penalties, and 1 January 2020 effective date.
- [Commercial cryptography testing institution measures interpretation](https://www.oscca.gov.cn/sca/xxgk/2023-10/07/content_1061110.shtml?ref=sorena.io) - Use for qualification and supervision of commercial-cryptography product-testing and application-security-assessment bodies, including report, data, sample, and information-reporting rules.
- [Commercial Cryptography Administration Regulation (State Council Order No. 760)](https://www.mee.gov.cn/zcwj/gwywj/202305/t20230529_1031579.shtml?ref=sorena.io) - Articles 12-21 support voluntary assurance, body qualifications, mandatory catalogue-product testing and certification, and service certification; Articles 38-42 support the CII checks.
- [Provisions on the Use and Administration of Commercial Cryptography in Critical Information Infrastructure](https://www.oscca.gov.cn/sca/xxgk/2025-06/27/content_1061270.shtml?ref=sorena.io) - Articles 9-15 support CII product, service, technology, procurement-review, application-plan, and lifecycle-assessment requirements.
- [Measures for the Administration of Cryptography Use in Electronic Certification Services](https://www.oscca.gov.cn/sca/xxgk/2026-06/03/content_1061341.shtml?ref=sorena.io) - Articles 2-3 and 10-17 support buyer verification of the provider's electronic-certification cryptography-use licence, term, annual assessment, changes, and renewal status.

## Complete each procurement gate and retain its evidence

The procurement gate below is Sorena's operational synthesis. The cited rules establish the legal requirements but do not prescribe this internal approval workflow.

Do not approve the item while an identified mandatory certification, CII technology review, application security assessment, or cybersecurity review requirement remains unresolved.

- Map the supplier's legal name, manufacturing and service locations, subcontractors, exact item identifiers, versions, cryptographic functions, and intended deployment.
- Verify the testing or certification body's qualification and match the report or certificate to the actual item, service, version, scope, and status.
- Record whether the buyer concluded that assurance is voluntary or mandatory, and retain the catalogue match when the mandatory route applies.
- For CII required to use commercial cryptography, assign the operator to confirm certified products and services, reviewed technologies, the application plan, pre-operation and annual assessment, required reporting, and any cybersecurity review.
- The operator retains its CII decisions and assessment duties. Contract terms and supplier certificates can provide evidence and cooperation without transferring those legal duties to the supplier.
- Contract for timely notice of vulnerability, component, algorithm, protocol, key-management, version, certificate, catalogue, ownership, subcontractor, and service-location changes.
- State the acceptance evidence for each mandatory gate: the exact catalogue match, complete report or certificate, verified body qualification and scope, technology-review evidence, assessment result, filing evidence, or written cybersecurity-review outcome. A supplier declaration alone is not acceptance evidence.
- Require the supplier to preserve versioned specifications, cryptographic component and key-management details, assessment-support records, and change notices for the contract period, while keeping any longer statutory retention duty assigned to the operator or testing body separate.
- Do not substitute a product or service until the replacement has completed the same scoped review.

Sources for this answer:

- [PRC Cryptography Law](https://www.oscca.gov.cn/sca/xxgk/2023-06/04/content_1057225.shtml?ref=sorena.io) - Use for cryptography categories, commercial cryptography development and management, product/service controls, CII use, import/export context, penalties, and 1 January 2020 effective date.
- [Commercial cryptography testing institution measures interpretation](https://www.oscca.gov.cn/sca/xxgk/2023-10/07/content_1061110.shtml?ref=sorena.io) - Use for qualification and supervision of commercial-cryptography product-testing and application-security-assessment bodies, including report, data, sample, and information-reporting rules.
- [Commercial Cryptography Application Security Assessment Measures](https://www.oscca.gov.cn/sca/xxgk/2023-10/07/content_1061109.shtml?ref=sorena.io) - Articles 7-14 support application-plan and system assessment, operator support, evidence, retention, and filing requirements relevant to supplier cooperation.
- [Commercial Cryptography Administration Regulation (State Council Order No. 760)](https://www.mee.gov.cn/zcwj/gwywj/202305/t20230529_1031579.shtml?ref=sorena.io) - Articles 31-34 support shipment-specific import licensing, customs procedures, and the mass-market consumer-product exclusion. Current exports use the separate unified dual-use control regime.

## Evidence to keep before launch or change approval

Keep the supplier response, product specification, cryptographic bill of materials, route screening, catalogue match, reports or certificates, qualification evidence, CII technology review evidence, contract controls, exceptions, approvals, and review date.

Link every record to the deployed version and system. Reopen review after supplier, subcontractor, component, algorithm, protocol, key-management, version, certificate, catalogue, operator, architecture, or use-case changes.

- Supplier identity, item identifiers, versions, architecture, cryptographic functions, standards, and intended use.
- Voluntary-or-mandatory assurance conclusion and the applicable catalogue entry when mandatory.
- Testing or certification body qualification, report, certificate, status, scope, surveillance, and limitations.
- CII product, service, technology, application plan, assessment, reporting, and cybersecurity review records where applicable.
- Electronic-certification provider licence, covered service and system, annual assessment, change status, and separate electronic-government qualification where applicable.
- Import-list match, shipment facts, mass-market consumer-product analysis if relied on, and import license where required.
- Contractual change notice, access, evidence, vulnerability response, remediation, and replacement terms.
- Dated procurement approval, exceptions, accountable owner, unresolved questions, and change log.

Sources for this answer:

- [PRC Cryptography Law](https://www.oscca.gov.cn/sca/xxgk/2023-06/04/content_1057225.shtml?ref=sorena.io) - Use for cryptography categories, commercial cryptography development and management, product/service controls, CII use, import/export context, penalties, and 1 January 2020 effective date.
- [Commercial cryptography testing institution measures interpretation](https://www.oscca.gov.cn/sca/xxgk/2023-10/07/content_1061110.shtml?ref=sorena.io) - Use for qualification and supervision of commercial-cryptography product-testing and application-security-assessment bodies, including report, data, sample, and information-reporting rules.

## Boundary with nearby China regimes

Product certification does not complete the CII application assessment or cybersecurity review. These routes have different triggers and records even when they concern the same supplier and item.

The current Cybersecurity Law separately governs network critical equipment and network security-specific products, graded protection, CII duties, and certain procurement reviews. An electronic-certification provider's cryptography-use licence also answers a provider-specific question; it does not certify every relying party's network or procurement. Personal-information and data-transfer conclusions require their own source-backed analysis.

- Accepting a certificate that covers a different model, software version, cryptographic module, service, or validity period.
- Treating a voluntary commercial cryptography certification catalogue as proof that the mandatory network-product route applies.
- Assuming a supplier certificate completes the operator's CII planning, assessment, reporting, or cybersecurity review.
- Allowing substitution or silent component changes without repeating the scoped review.

Sources for this answer:

- [PRC Cryptography Law](https://www.oscca.gov.cn/sca/xxgk/2023-06/04/content_1057225.shtml?ref=sorena.io) - Use for cryptography categories, commercial cryptography development and management, product/service controls, CII use, import/export context, penalties, and 1 January 2020 effective date.
- [Commercial cryptography testing institution measures interpretation](https://www.oscca.gov.cn/sca/xxgk/2023-10/07/content_1061110.shtml?ref=sorena.io) - Use for qualification and supervision of commercial-cryptography product-testing and application-security-assessment bodies, including report, data, sample, and information-reporting rules.
- [PRC Cybersecurity Law, amended in 2025](https://www.cac.gov.cn/2025-12/29/c_1768735112911946.htm?ref=sorena.io) - Articles 25 and 33-40 support the separate network-product, CII, and procurement-review boundaries.
- [Presidential Order No. 61 promulgating the 2025 Cybersecurity Law amendment](https://www.npc.gov.cn/npc/c2/c30834/202510/t20251028_449031.html?ref=sorena.io) - Supports the amendment's 1 January 2026 effective date.

*Next step*

*Placement: Before primary sources*

## Prepare the commercial cryptography evidence file

Sorena AI helps turn a commercial cryptography procurement decision into assigned owners, controls, and records for review.

- [Map official sources to evidence](/solutions/research-copilot.md): Research Copilot connects the official citation, decision, owner, retained evidence, and change history.
- [Review the China route](/contact.md): Check the China Cryptography Law scope decision and unresolved launch questions with Sorena.

## Primary sources

- [PRC Cryptography Law](https://www.oscca.gov.cn/sca/xxgk/2023-06/04/content_1057225.shtml?ref=sorena.io) - Use for cryptography categories, commercial cryptography development and management, product/service controls, CII use, import/export context, penalties, and 1 January 2020 effective date.
- [Commercial cryptography testing institution measures interpretation](https://www.oscca.gov.cn/sca/xxgk/2023-10/07/content_1061110.shtml?ref=sorena.io) - Use for qualification and supervision of commercial-cryptography product-testing and application-security-assessment bodies, including report, data, sample, and information-reporting rules.
- [Commercial Cryptography Administration Regulation (State Council Order No. 760)](https://www.mee.gov.cn/zcwj/gwywj/202305/t20230529_1031579.shtml?ref=sorena.io) - Use for testing, certification, body qualification, and CII procurement requirements.
- [Provisions on the Use and Administration of Commercial Cryptography in Critical Information Infrastructure](https://www.oscca.gov.cn/sca/xxgk/2025-06/27/content_1061270.shtml?ref=sorena.io) - Use for CII supplier, product, service, technology, assessment, and cybersecurity review requirements effective 1 August 2025.
- [Commercial Cryptography Application Security Assessment Measures](https://www.oscca.gov.cn/sca/xxgk/2023-10/07/content_1061109.shtml?ref=sorena.io) - Use for assessment records and supplier support requirements.
- [Presidential Order No. 61 promulgating the 2025 Cybersecurity Law amendment](https://www.npc.gov.cn/npc/c2/c30834/202510/t20251028_449031.html?ref=sorena.io) - Use for the 1 January 2026 effective date of the current Cybersecurity Law amendment.
- [Measures for the Administration of Cryptography Use in Electronic Certification Services](https://www.oscca.gov.cn/sca/xxgk/2026-06/03/content_1061341.shtml?ref=sorena.io) - Use for procurement checks on providers using commercial cryptography to provide electronic certification services in China from 1 July 2026.

## Related Topic Guides

- [China commercial cryptography compliance checklist](/artifacts/apac/china-cryptography-law/checklist.md): China commercial cryptography checklist covering classification, product and service assurance, CII duties, trade controls, and retained evidence.
- [China commercial cryptography testing evidence template](/artifacts/apac/china-cryptography-law/commercial-cryptography-testing-evidence-template.md): Record the legal route, product or system scope, testing-body qualification, report details, gaps, and reassessment triggers for China commercial cryptography assurance.
- [China cryptography compliance deadlines and calendar](/artifacts/apac/china-cryptography-law/deadlines-and-compliance-calendar.md): China cryptography effective dates, CII reports, annual assessments, licence renewals, change notices, and pre-operation checks.
- [China cryptography import, export, and security review triage](/artifacts/apac/china-cryptography-law/import-export-and-security-assessment.md): Screen commercial cryptography imports under the 2020 list, exports under China's unified dual-use list, the consumer exclusion, system assessment, and CII review.
- [China Cryptography Law FAQ](/artifacts/apac/china-cryptography-law/faq.md): Answers on China's commercial-cryptography scope, product assurance, classified protection, CII assessment, procurement review, and trade controls.
- [China Cryptography Law requirements](/artifacts/apac/china-cryptography-law/requirements.md): China commercial cryptography requirements by role: standards, testing, certification, CII use and assessment, trade controls, and evidence.
- [China Cryptography Law vs Cybersecurity Law](/artifacts/apac/china-cryptography-law/china-cryptography-law-vs-cybersecurity-law.md): Compare China's Cryptography Law and current Cybersecurity Law by scope, actor, product assurance, CII duties, evidence, and enforcement.
- [China cryptography penalties, fines, and liability](/artifacts/apac/china-cryptography-law/penalties-and-fines.md): China commercial cryptography penalties by actor and violation, including fine bands, corrective orders, confiscation, licence action, and liability.
- [Commercial cryptography products and testing evidence](/artifacts/apac/china-cryptography-law/commercial-cryptography-products-and-testing.md): When China commercial cryptography testing or certification is voluntary or mandatory, and what product, service, body, and scope evidence to keep.
- [Do imported cryptography products need special review?](/artifacts/apac/china-cryptography-law/faq/do-imported-cryptography-products-need-special-review.md): Not every encrypted product imported into China needs a licence. Check the 2020 commercial-cryptography import list, the consumer-product exception, and any CII procurement review.
- [Does using encryption trigger China Cryptography Law duties?](/artifacts/apac/china-cryptography-law/faq/does-using-encryption-trigger-china-cryptography-law.md): Using encryption does not create one universal China approval duty. Check classified protection, product, service, CII, procurement, and trade triggers.
- [How does cryptography compliance overlap with China cybersecurity law?](/artifacts/apac/china-cryptography-law/faq/how-does-cryptography-compliance-overlap-with-cybersecurity-law.md): See how China's cryptography rules connect with classified protection, product assurance, CII assessment, and cybersecurity review without merging the regimes.
- [What is commercial cryptography in China?](/artifacts/apac/china-cryptography-law/faq/what-is-commercial-cryptography-in-china.md): Commercial cryptography protects information that is not a state secret. Learn how China defines the category and which separate facts trigger product, CII, or trade controls.
- [When is commercial cryptography testing or certification needed?](/artifacts/apac/china-cryptography-law/faq/when-is-commercial-cryptography-testing-or-certification-needed.md): Commercial-cryptography assurance is often voluntary, but specified products and services require it. Covered CII also needs application assessment and qualified cryptography.


---

[Privacy Policy](https://www.sorena.io/privacy.md) | [Terms of Use](https://www.sorena.io/terms-of-use.md) | [DMCA](https://www.sorena.io/dmca.md) | [About Us](https://www.sorena.io/about-us.md)

(c) 2026 Sorena AB (559573-7338). All rights reserved.

Source: https://www.sorena.io/artifacts/apac/china-cryptography-law/commercial-cryptography-procurement-checklist.md
