---
title: "Commercial cryptography products and testing evidence"
canonical_url: "https://www.sorena.io/artifacts/apac/china-cryptography-law/commercial-cryptography-products-and-testing"
source_url: "https://www.sorena.io/artifacts/apac/china-cryptography-law/commercial-cryptography-products-and-testing"
author: "Sorena AI"
description: "When China commercial cryptography testing or certification is voluntary or mandatory, and what product, service, body, and scope evidence to keep."
published_at: "2026-07-05"
updated_at: "2026-07-25"
keywords:
  - "China Cryptography Law"
  - "Commercial cryptography"
  - "Cryptography Law"
  - "Commercial cryptography testing"
  - "China cybersecurity"
---
**[SORENA](https://www.sorena.io/)** - AI-Powered GRC Platform

[Home](https://www.sorena.io/) | [Solutions](https://www.sorena.io/solutions) | [Artifacts](https://www.sorena.io/artifacts) | [About Us](https://www.sorena.io/about-us) | [Contact](https://www.sorena.io/contact) | [Portal](https://app.sorena.io)

---

# Commercial cryptography products and testing evidence

When China commercial cryptography testing or certification is voluntary or mandatory, and what product, service, body, and scope evidence to keep.

*Cryptography* *China*

## China Cryptography Law Commercial cryptography products and testing evidence

Identify the legal trigger before relying on a certificate. General testing and certification are voluntary; mandatory routes apply to specified network products and related services, and CII has additional rules.

Use this guide to distinguish voluntary commercial cryptography testing and certification from mandatory product, service, and CII routes, then verify that the assurance evidence covers the actual item.

## Definitions

### Commercial cryptography testing and certification

**Term:** testing and certification

Commercial cryptography testing produces data or results about a product or the use of cryptography in a network and information system. Certification produces a certification conclusion for a product, service, or management system and includes follow-up surveillance intended to confirm continued conformity. The national system generally encourages voluntary testing and certification, while separate provisions make assurance mandatory for specified products, services, and CII uses.

**Why it matters here:** The evidence file must name the legal route, distinguish a test report from a certificate, verify the issuing body's qualification, and match the evidence to the actual item, version, scope, status, and validity period.

Sources:

- [Commercial Cryptography Administration Regulation, Articles 12-21](https://www.mee.gov.cn/zcwj/gwywj/202305/t20230529_1031579.shtml?ref=sorena.io)
- [Commercial Cryptography Testing Institution Measures interpretation](https://www.oscca.gov.cn/sca/xxgk/2023-10/07/content_1061110.shtml?ref=sorena.io)

### Network critical equipment and network security-specific products

These are products covered by the catalogue published under the Cybersecurity Law. A covered product must meet mandatory national standards and pass qualified security certification or security testing before sale or provision. A separate commercial cryptography product certification catalogue belongs to the national commercial cryptography certification system and does not, by itself, establish a match to the mandatory network-product catalogue.

**Why it matters here:** A commercial cryptography product that legally falls within the mandatory network-product catalogue must pass qualified testing and certification. A commercial cryptography service using a product in that catalogue must also be certified.

Sources:

- [PRC Cybersecurity Law, Article 25](https://www.cac.gov.cn/2025-12/29/c_1768735112911946.htm?ref=sorena.io)
- [PRC Cryptography Law, Article 26](https://www.oscca.gov.cn/sca/xxgk/2023-06/04/content_1057225.shtml?ref=sorena.io)
- [Commercial Cryptography Administration Regulation, Articles 20-21](https://www.mee.gov.cn/zcwj/gwywj/202305/t20230529_1031579.shtml?ref=sorena.io)

### Commercial cryptography application security assessment

A commercial cryptography application security assessment evaluates whether a network or information system uses commercial cryptography technology, products, and services compliantly, correctly, and effectively. The assessment examines the application plan or the implemented system, including scope, configuration, key management, objective evidence, and operating records. It does not certify a product model.

**Why it matters here:** For an important network and information system subject to the assessment rules, a valid product or service certificate does not replace plan assessment, pre-operation assessment, annual assessment, filing, or remediation.

Sources:

- [Commercial Cryptography Application Security Assessment Measures, Articles 2 and 6-14](https://www.oscca.gov.cn/sca/xxgk/2023-10/07/content_1061109.shtml?ref=sorena.io)

### Critical information infrastructure

**Term:** CII

Critical information infrastructure is infrastructure in important industries and fields whose destruction, loss of function, or data leakage could seriously harm national security, the national economy and people's livelihoods, or the public interest. The competent protection department identifies the infrastructure under the statutory rules and notifies the operator; sector, customer size, or system importance alone does not establish CII status.

**Why it matters here:** For CII that national rules require to use commercial cryptography, the operator must use tested and certified commercial cryptography products and services, use reviewed cryptographic technologies, assess the application plan and implemented system, and meet the recurring assessment and reporting duties. Those system duties do not turn every supplier certificate into mandatory evidence for every non-CII use.

Sources:

- [Critical Information Infrastructure Security Protection Regulation, Articles 2 and 8-11](https://www.cac.gov.cn/2021-08/17/c_1630785976988160.htm?ref=sorena.io)
- [Provisions on the Use and Administration of Commercial Cryptography in Critical Information Infrastructure, Articles 2 and 5-15](https://www.oscca.gov.cn/sca/xxgk/2025-06/27/content_1061270.shtml?ref=sorena.io)

## Choose the correct assurance route

Cryptography Law Article 25 and Commercial Cryptography Administration Regulation Article 12 encourage voluntary testing and certification. Testing and certification bodies must hold the relevant qualifications and act within their approved scope.

Article 26 creates the narrower mandatory route, together with Regulation Articles 20-21, for a commercial cryptography product legally included in the catalogue of network critical equipment and network security-specific products and for a commercial cryptography service using products in that catalogue. Treat the Article 27 CII application assessment as a separate decision. Published commercial cryptography product certification catalogues support the national certification system, but a listing in one of them is not, by itself, the Article 26 mandatory catalogue test.

Representative commercial cryptography product types in official testing materials include smart cryptographic tokens and IC cards, IPSec and SSL VPN gateways, cryptographic cards and server cryptographic machines, signing and verification servers, time-stamp servers, dynamic-token systems, security chips, cloud server cryptographic machines, random-number generators, trusted cryptographic modules, and blockchain cryptographic modules. These examples show the range of products in the assurance system; they do not prove that a specific model falls within the mandatory network-product catalogue.

- Identify the exact product or service, model, version, cryptographic function, supplier, and intended China use.
- Check whether the product is legally included in the catalogue of network critical equipment and network security-specific products and whether the actual model and cryptographic function match the catalogue scope.
- For a service, determine whether it uses a product in that catalogue; if so, the service must be certified by a commercial cryptography certification body.
- For CII that national rules require to use commercial cryptography, separately verify that all used commercial cryptography products and services passed testing and certification and that algorithms, protocols, key-management mechanisms, and other commercial cryptography technologies passed State Cryptography Administration review and identification.
- Confirm the testing or certification body's qualification and approved activity, then match the report or certificate to the actual item, version, scope, issue and expiry dates, status, surveillance conditions, and limitations.
- Distinguish the issuer and output. A qualified commercial cryptography testing institution can issue evidentiary product-test or application-assessment data and results within its approved scope; a certification body issues the certification conclusion under the applicable certification rules.
- For a testing report, confirm that an authorized signatory signed within that person's approved competence and that the institution applied its official or dedicated seal. The testing institution must keep original records and reports for at least six years; this retention duty belongs to the institution and does not replace the buyer's own evidence-retention needs.
- Keep commercial cryptography application security assessment separate. It tests the compliance, correctness, and effectiveness of cryptography in the system; a product certificate does not replace it.

Sources for this answer:

- [PRC Cryptography Law](https://www.oscca.gov.cn/sca/xxgk/2023-06/04/content_1057225.shtml?ref=sorena.io) - Use for cryptography categories, commercial cryptography development and management, product/service controls, CII use, import/export context, penalties, and 1 January 2020 effective date.
- [Commercial cryptography testing institution measures interpretation](https://www.oscca.gov.cn/sca/xxgk/2023-10/07/content_1061110.shtml?ref=sorena.io) - Use for qualification and supervision of commercial-cryptography product-testing and application-security-assessment bodies, including report, data, sample, and information-reporting rules.
- [Commercial Cryptography Administration Regulation (State Council Order No. 760)](https://www.mee.gov.cn/zcwj/gwywj/202305/t20230529_1031579.shtml?ref=sorena.io) - Articles 12-21 support voluntary assurance, testing and certification body qualifications, mandatory catalogue-product assurance, and mandatory service certification.
- [Commercial cryptography product certification catalogue (third batch)](https://oscca.gov.cn/sca/xwdt/2025-03/27/content_1061246.shtml?ref=sorena.io) - Use as a current example of the separate commercial cryptography product certification catalogue and its product descriptions and certification bases.
- [National Cryptography Administration commercial cryptography assessment knowledge points](https://www.oscca.gov.cn/sca/xwdt/2023-03/10/content_1060996.shtml?ref=sorena.io) - Lists representative commercial cryptography product types used in official assessment and testing knowledge materials; the list supports examples, not a mandatory-catalogue conclusion.
- [Provisions on the Use and Administration of Commercial Cryptography in Critical Information Infrastructure](https://www.oscca.gov.cn/sca/xxgk/2025-06/27/content_1061270.shtml?ref=sorena.io) - Articles 9 and 11-15 support the separate CII product, service, technology, and application-assessment requirements.

## Practical compliance steps

Do not describe a supplier certificate as proof of all Cryptography Law duties. It supports only the product, service, version, scope, status, and period stated in the assurance record.

The evidence workflow below is Sorena's operational synthesis. The cited rules establish the legal routes and body duties but do not prescribe this exact internal approval process.

- Name the voluntary or mandatory route and cite the provision that creates it.
- For the Article 26 route, attach the applicable network critical equipment and network security-specific product catalogue entry and explain the product match.
- Keep any commercial cryptography product certification catalogue entry as separate evidence; do not use it as a substitute for the mandatory catalogue analysis.
- Verify whether the issuer acted as a testing institution or certification body, then record its legal name, qualification, approved scope, and status for the activity performed.
- Match the report or certificate to the exact product or service, model, hardware and software version, cryptographic function, scope, status, and validity.
- For CII, keep certified product and service evidence, reviewed technology evidence, and application security assessment as three distinct checks.
- Record any coordination with Cybersecurity Law testing or CII and graded-protection assessments without merging their legal conclusions.

Sources for this answer:

- [PRC Cryptography Law](https://www.oscca.gov.cn/sca/xxgk/2023-06/04/content_1057225.shtml?ref=sorena.io) - Use for cryptography categories, commercial cryptography development and management, product/service controls, CII use, import/export context, penalties, and 1 January 2020 effective date.
- [Commercial cryptography testing institution measures interpretation](https://www.oscca.gov.cn/sca/xxgk/2023-10/07/content_1061110.shtml?ref=sorena.io) - Use for qualification and supervision of commercial-cryptography product-testing and application-security-assessment bodies, including report, data, sample, and information-reporting rules.
- [Commercial Cryptography Testing Institution Measures](https://www.oscca.gov.cn/sca/xxgk/2023-10/07/content_1061108.shtml?ref=sorena.io) - Articles 3, 5, and 15-20 support testing-body qualification and approved scope, independence, authorized-signatory and seal checks, six-year record retention, sample controls, and annual reporting.
- [Commercial Cryptography Application Security Assessment Measures](https://www.oscca.gov.cn/sca/xxgk/2023-10/07/content_1061109.shtml?ref=sorena.io) - Articles 2 and 6-15 support the distinct system-level purpose, lifecycle, evidence, retention, and filing of application security assessment.

## Evidence to keep before launch or change approval

Keep the classification decision, both catalogue checks where relevant, legal route, body qualification, approved scope, report or certificate, covered model and version, status, validity, surveillance, limitations, exceptions, and reviewer approval.

Reopen the decision when the cryptographic module, algorithm, protocol, key-management mechanism, hardware or software version, product scope, supplier, certificate, catalogue, service architecture, operator, or CII use changes.

- Exact product or service identity, versions, cryptographic functions, supplier, and intended use.
- Memo stating whether the route is voluntary or mandatory, with the applicable catalogue evidence.
- Issuer type, testing or certification qualification, approved scope, and status.
- Report or certificate number, covered item and version, scope, issue and expiry dates, status, surveillance, and limitations.
- Separate CII product or service, technology review, and application security assessment evidence where applicable.
- Dated approval, exceptions, unresolved questions, accountable owner, and change log.

Sources for this answer:

- [PRC Cryptography Law](https://www.oscca.gov.cn/sca/xxgk/2023-06/04/content_1057225.shtml?ref=sorena.io) - Use for cryptography categories, commercial cryptography development and management, product/service controls, CII use, import/export context, penalties, and 1 January 2020 effective date.
- [Commercial cryptography testing institution measures interpretation](https://www.oscca.gov.cn/sca/xxgk/2023-10/07/content_1061110.shtml?ref=sorena.io) - Use for qualification and supervision of commercial-cryptography product-testing and application-security-assessment bodies, including report, data, sample, and information-reporting rules.

## Boundary with nearby China regimes

The current Cybersecurity Law separately requires qualified assurance for network critical equipment and network security-specific products before sale or provision. The Cryptography Law applies that framework to qualifying commercial cryptography products and seeks to avoid duplicate testing and certification.

CII commercial cryptography application assessment is also coordinated with CII security assessment and network-security graded-protection testing to avoid duplication, but each conclusion must still identify its own legal basis and scope.

- Calling all commercial cryptography certification mandatory.
- Confusing a commercial cryptography product certification catalogue with the mandatory network critical equipment and network security-specific product catalogue.
- Accepting a report or certificate for a different model, version, scope, body activity, or validity period.
- Treating product or service certification as a substitute for CII technology review or system-level application security assessment.

Sources for this answer:

- [PRC Cryptography Law](https://www.oscca.gov.cn/sca/xxgk/2023-06/04/content_1057225.shtml?ref=sorena.io) - Use for cryptography categories, commercial cryptography development and management, product/service controls, CII use, import/export context, penalties, and 1 January 2020 effective date.
- [Commercial cryptography testing institution measures interpretation](https://www.oscca.gov.cn/sca/xxgk/2023-10/07/content_1061110.shtml?ref=sorena.io) - Use for qualification and supervision of commercial-cryptography product-testing and application-security-assessment bodies, including report, data, sample, and information-reporting rules.
- [PRC Cybersecurity Law, amended in 2025](https://www.cac.gov.cn/2025-12/29/c_1768735112911946.htm?ref=sorena.io) - Article 25 supports the current network critical equipment and network security-specific product assurance requirement.
- [Presidential Order No. 61 promulgating the 2025 Cybersecurity Law amendment](https://www.npc.gov.cn/npc/c2/c30834/202510/t20251028_449031.html?ref=sorena.io) - Supports the amendment's 1 January 2026 effective date.

*Next step*

*Placement: Before primary sources*

## Prepare the commercial cryptography evidence file

Sorena AI helps turn a commercial cryptography testing or certification decision into assigned owners, controls, and records for review.

- [Map official sources to evidence](/solutions/research-copilot.md): Research Copilot connects the official citation, decision, owner, retained evidence, and change history.
- [Review the China route](/contact.md): Check the China Cryptography Law scope decision and unresolved launch questions with Sorena.

## Primary sources

- [PRC Cryptography Law](https://www.oscca.gov.cn/sca/xxgk/2023-06/04/content_1057225.shtml?ref=sorena.io) - Use for cryptography categories, commercial cryptography development and management, product/service controls, CII use, import/export context, penalties, and 1 January 2020 effective date.
- [Commercial cryptography testing institution measures interpretation](https://www.oscca.gov.cn/sca/xxgk/2023-10/07/content_1061110.shtml?ref=sorena.io) - Use for qualification and supervision of commercial-cryptography product-testing and application-security-assessment bodies, including report, data, sample, and information-reporting rules.
- [Commercial Cryptography Administration Regulation (State Council Order No. 760)](https://www.mee.gov.cn/zcwj/gwywj/202305/t20230529_1031579.shtml?ref=sorena.io) - Use for current voluntary and mandatory testing and certification routes.
- [Commercial Cryptography Testing Institution Measures](https://www.oscca.gov.cn/sca/xxgk/2023-10/07/content_1061108.shtml?ref=sorena.io) - Use for testing-body qualification and operating requirements.
- [Commercial Cryptography Application Security Assessment Measures](https://www.oscca.gov.cn/sca/xxgk/2023-10/07/content_1061109.shtml?ref=sorena.io) - Use for system-level application security assessment.
- [Commercial cryptography product certification catalogue (third batch)](https://oscca.gov.cn/sca/xwdt/2025-03/27/content_1061246.shtml?ref=sorena.io) - Use as a current official example of the commercial cryptography product certification catalogue.
- [Provisions on the Use and Administration of Commercial Cryptography in Critical Information Infrastructure](https://www.oscca.gov.cn/sca/xxgk/2025-06/27/content_1061270.shtml?ref=sorena.io) - Use for the distinct CII product, service, technology, and assessment requirements.
- [Presidential Order No. 61 promulgating the 2025 Cybersecurity Law amendment](https://www.npc.gov.cn/npc/c2/c30834/202510/t20251028_449031.html?ref=sorena.io) - Use for the 1 January 2026 effective date of the current Cybersecurity Law amendment.
- [National Cryptography Administration commercial cryptography assessment knowledge points](https://www.oscca.gov.cn/sca/xwdt/2023-03/10/content_1060996.shtml?ref=sorena.io) - Official source for representative commercial cryptography product examples, without treating those examples as proof of mandatory catalogue coverage.

## Related Topic Guides

- [China commercial cryptography compliance checklist](/artifacts/apac/china-cryptography-law/checklist.md): China commercial cryptography checklist covering classification, product and service assurance, CII duties, trade controls, and retained evidence.
- [China commercial cryptography testing evidence template](/artifacts/apac/china-cryptography-law/commercial-cryptography-testing-evidence-template.md): Record the legal route, product or system scope, testing-body qualification, report details, gaps, and reassessment triggers for China commercial cryptography assurance.
- [China cryptography compliance deadlines and calendar](/artifacts/apac/china-cryptography-law/deadlines-and-compliance-calendar.md): China cryptography effective dates, CII reports, annual assessments, licence renewals, change notices, and pre-operation checks.
- [China cryptography import, export, and security review triage](/artifacts/apac/china-cryptography-law/import-export-and-security-assessment.md): Screen commercial cryptography imports under the 2020 list, exports under China's unified dual-use list, the consumer exclusion, system assessment, and CII review.
- [China Cryptography Law FAQ](/artifacts/apac/china-cryptography-law/faq.md): Answers on China's commercial-cryptography scope, product assurance, classified protection, CII assessment, procurement review, and trade controls.
- [China Cryptography Law requirements](/artifacts/apac/china-cryptography-law/requirements.md): China commercial cryptography requirements by role: standards, testing, certification, CII use and assessment, trade controls, and evidence.
- [China Cryptography Law vs Cybersecurity Law](/artifacts/apac/china-cryptography-law/china-cryptography-law-vs-cybersecurity-law.md): Compare China's Cryptography Law and current Cybersecurity Law by scope, actor, product assurance, CII duties, evidence, and enforcement.
- [China cryptography penalties, fines, and liability](/artifacts/apac/china-cryptography-law/penalties-and-fines.md): China commercial cryptography penalties by actor and violation, including fine bands, corrective orders, confiscation, licence action, and liability.
- [Commercial cryptography procurement checklist](/artifacts/apac/china-cryptography-law/commercial-cryptography-procurement-checklist.md): Procurement checks for commercial cryptography products and services used in China, including certificate scope, CII duties, and supplier changes.
- [Do imported cryptography products need special review?](/artifacts/apac/china-cryptography-law/faq/do-imported-cryptography-products-need-special-review.md): Not every encrypted product imported into China needs a licence. Check the 2020 commercial-cryptography import list, the consumer-product exception, and any CII procurement review.
- [Does using encryption trigger China Cryptography Law duties?](/artifacts/apac/china-cryptography-law/faq/does-using-encryption-trigger-china-cryptography-law.md): Using encryption does not create one universal China approval duty. Check classified protection, product, service, CII, procurement, and trade triggers.
- [How does cryptography compliance overlap with China cybersecurity law?](/artifacts/apac/china-cryptography-law/faq/how-does-cryptography-compliance-overlap-with-cybersecurity-law.md): See how China's cryptography rules connect with classified protection, product assurance, CII assessment, and cybersecurity review without merging the regimes.
- [What is commercial cryptography in China?](/artifacts/apac/china-cryptography-law/faq/what-is-commercial-cryptography-in-china.md): Commercial cryptography protects information that is not a state secret. Learn how China defines the category and which separate facts trigger product, CII, or trade controls.
- [When is commercial cryptography testing or certification needed?](/artifacts/apac/china-cryptography-law/faq/when-is-commercial-cryptography-testing-or-certification-needed.md): Commercial-cryptography assurance is often voluntary, but specified products and services require it. Covered CII also needs application assessment and qualified cryptography.


---

[Privacy Policy](https://www.sorena.io/privacy.md) | [Terms of Use](https://www.sorena.io/terms-of-use.md) | [DMCA](https://www.sorena.io/dmca.md) | [About Us](https://www.sorena.io/about-us.md)

(c) 2026 Sorena AB (559573-7338). All rights reserved.

Source: https://www.sorena.io/artifacts/apac/china-cryptography-law/commercial-cryptography-products-and-testing.md
