CryptographyChina

China Cryptography Law Commercial cryptography products and testing evidence

When China commercial cryptography testing or certification is voluntary or mandatory, and what product, service, body, and scope evidence to keep.

Identify the legal trigger before relying on a certificate. General testing and certification are voluntary; mandatory routes apply to specified network products and related services, and CII has additional rules.

Author
Sorena AI
Published
Jul 5, 2026
Updated
Jul 25, 2026
Sections
4

Structured answer sets in this page tree.

Primary sources
10

Cited legal and guidance references.

Publication metadata
Sorena AI
Published Jul 5, 2026
Updated Jul 25, 2026
Overview

Use this guide to distinguish voluntary commercial cryptography from mandatory product, service, and routes, then verify that the assurance evidence covers the actual item.

Section 1

Choose the correct assurance route

Cryptography Law Article 25 and Commercial Cryptography Administration Regulation Article 12 encourage voluntary . Testing and certification bodies must hold the relevant qualifications and act within their approved scope.

Article 26 creates the narrower mandatory route, together with Regulation Articles 20-21, for a commercial cryptography product legally included in the catalogue of and for a commercial cryptography service using products in that catalogue. Treat the Article 27 application assessment as a separate decision. Published commercial cryptography product certification catalogues support the national certification system, but a listing in one of them is not, by itself, the Article 26 mandatory catalogue test.

Representative commercial cryptography product types in official testing materials include smart cryptographic tokens and IC cards, IPSec and SSL VPN gateways, cryptographic cards and server cryptographic machines, signing and verification servers, time-stamp servers, dynamic-token systems, security chips, cloud server cryptographic machines, random-number generators, trusted cryptographic modules, and blockchain cryptographic modules. These examples show the range of products in the assurance system; they do not prove that a specific model falls within the mandatory network-product catalogue.

  • Identify the exact product or service, model, version, cryptographic function, supplier, and intended China use.
  • Check whether the product is legally included in the catalogue of and whether the actual model and cryptographic function match the catalogue scope.
  • For a service, determine whether it uses a product in that catalogue; if so, the service must be certified by a commercial cryptography certification body.
  • For that national rules require to use commercial cryptography, separately verify that all used commercial cryptography products and services passed and that algorithms, protocols, key-management mechanisms, and other commercial cryptography technologies passed State Cryptography Administration review and identification.
  • Confirm the testing or certification body's qualification and approved activity, then match the report or certificate to the actual item, version, scope, issue and expiry dates, status, surveillance conditions, and limitations.
  • Distinguish the issuer and output. A qualified commercial cryptography testing institution can issue evidentiary product-test or application-assessment data and results within its approved scope; a certification body issues the certification conclusion under the applicable certification rules.
  • For a testing report, confirm that an authorized signatory signed within that person's approved competence and that the institution applied its official or dedicated seal. The testing institution must keep original records and reports for at least six years; this retention duty belongs to the institution and does not replace the buyer's own evidence-retention needs.
  • Keep separate. It tests the compliance, correctness, and effectiveness of cryptography in the system; a product certificate does not replace it.
Section 2

Practical compliance steps

Do not describe a supplier certificate as proof of all Cryptography Law duties. It supports only the product, service, version, scope, status, and period stated in the assurance record.

The evidence workflow below is Sorena's operational synthesis. The cited rules establish the legal routes and body duties but do not prescribe this exact internal approval process.

  • Name the voluntary or mandatory route and cite the provision that creates it.
  • For the Article 26 route, attach the applicable network critical equipment and network security-specific product catalogue entry and explain the product match.
  • Keep any commercial cryptography product certification catalogue entry as separate evidence; do not use it as a substitute for the mandatory catalogue analysis.
  • Verify whether the issuer acted as a testing institution or certification body, then record its legal name, qualification, approved scope, and status for the activity performed.
  • Match the report or certificate to the exact product or service, model, hardware and software version, cryptographic function, scope, status, and validity.
  • For , keep certified product and service evidence, reviewed technology evidence, and application security assessment as three distinct checks.
  • Record any coordination with Cybersecurity Law testing or and graded-protection assessments without merging their legal conclusions.
Section 3

Evidence to keep before launch or change approval

Keep the classification decision, both catalogue checks where relevant, legal route, body qualification, approved scope, report or certificate, covered model and version, status, validity, surveillance, limitations, exceptions, and reviewer approval.

Reopen the decision when the cryptographic module, algorithm, protocol, key-management mechanism, hardware or software version, product scope, supplier, certificate, catalogue, service architecture, operator, or use changes.

  • Exact product or service identity, versions, cryptographic functions, supplier, and intended use.
  • Memo stating whether the route is voluntary or mandatory, with the applicable catalogue evidence.
  • Issuer type, testing or certification qualification, approved scope, and status.
  • Report or certificate number, covered item and version, scope, issue and expiry dates, status, surveillance, and limitations.
  • Separate product or service, technology review, and application security assessment evidence where applicable.
  • Dated approval, exceptions, unresolved questions, accountable owner, and change log.
Section 4

Boundary with nearby China regimes

The current Cybersecurity Law separately requires qualified assurance for before sale or provision. The Cryptography Law applies that framework to qualifying commercial cryptography products and seeks to avoid duplicate .

commercial cryptography application assessment is also coordinated with CII security assessment and network-security graded-protection testing to avoid duplication, but each conclusion must still identify its own legal basis and scope.

  • Calling all commercial cryptography certification mandatory.
  • Confusing a commercial cryptography product certification catalogue with the mandatory network critical equipment and network security-specific product catalogue.
  • Accepting a report or certificate for a different model, version, scope, body activity, or validity period.
  • Treating product or service certification as a substitute for technology review or system-level application security assessment.
Primary sources

References and citations

oscca.gov.cn
Referenced sections
  • Articles 3, 5, and 15-20 support testing-body qualification and approved scope, independence, authorized-signatory and seal checks, six-year record retention, sample controls, and annual reporting.
oscca.gov.cn
Referenced sections
  • Use for cryptography categories, commercial cryptography development and management, product/service controls, CII use, import/export context, penalties, and 1 January 2020 effective date.
Related guides

Explore more topics

China commercial cryptography compliance checklist
China commercial cryptography checklist covering classification, product and service assurance, CII duties, trade controls, and retained evidence.
China commercial cryptography testing evidence template
Record the legal route, product or system scope, testing-body qualification, report details, gaps, and reassessment triggers for China commercial cryptography assurance.
China cryptography compliance deadlines and calendar
China cryptography effective dates, CII reports, annual assessments, licence renewals, change notices, and pre-operation checks.
China cryptography import, export, and security review triage
Screen commercial cryptography imports under the 2020 list, exports under China's unified dual-use list, the consumer exclusion, system assessment, and CII review.
China Cryptography Law FAQ
Answers on China's commercial-cryptography scope, product assurance, classified protection, CII assessment, procurement review, and trade controls.
China Cryptography Law requirements
China commercial cryptography requirements by role: standards, testing, certification, CII use and assessment, trade controls, and evidence.
China Cryptography Law vs Cybersecurity Law
Compare China's Cryptography Law and current Cybersecurity Law by scope, actor, product assurance, CII duties, evidence, and enforcement.
China cryptography penalties, fines, and liability
China commercial cryptography penalties by actor and violation, including fine bands, corrective orders, confiscation, licence action, and liability.
Commercial cryptography procurement checklist
Procurement checks for commercial cryptography products and services used in China, including certificate scope, CII duties, and supplier changes.
Do imported cryptography products need special review?
Not every encrypted product imported into China needs a licence. Check the 2020 commercial-cryptography import list, the consumer-product exception, and any CII procurement review.
Does using encryption trigger China Cryptography Law duties?
Using encryption does not create one universal China approval duty. Check classified protection, product, service, CII, procurement, and trade triggers.
How does cryptography compliance overlap with China cybersecurity law?
See how China's cryptography rules connect with classified protection, product assurance, CII assessment, and cybersecurity review without merging the regimes.
What is commercial cryptography in China?
Commercial cryptography protects information that is not a state secret. Learn how China defines the category and which separate facts trigger product, CII, or trade controls.
When is commercial cryptography testing or certification needed?
Commercial-cryptography assurance is often voluntary, but specified products and services require it. Covered CII also needs application assessment and qualified cryptography.