China Cryptography Law Commercial cryptography testing evidence template
A review template for China commercial cryptography product testing, certification, and application security assessment evidence.
Select the legal route first, then match the qualified body, report or certificate, assessed scope, and exact product or system version to the release decision.
Use this internal review template to decide whether China assurance evidence covers a specific product, service, or network and information system. It is not an official form and does not prescribe mandatory wording. It separates voluntary certification, catalogue-triggered mandatory certification, and so that a certificate is not treated as proof of every requirement.
1
Section 1
Choose the assurance route before collecting evidence
Start by naming the assurance route and its trigger. Cryptography Law Article 25 encourages voluntary testing and certification. Article 26 separately requires qualified testing and certification before a listed commercial cryptography product involving national security, the national economy and people's livelihood, or the public interest may be sold or provided. A commercial cryptography service that uses or a network security-specific product must also pass service certification.
Do not treat the voluntary product certification catalogues as the same thing as the mandatory and network security-specific product catalogue. Record the exact catalogue entry, product description, and rule that makes the route applicable.
is a system-level route. Under the 2023 Assessment Measures, it evaluates whether a network and information system uses technologies, products, and services compliantly, correctly, and effectively. It applies where laws, administrative regulations, or other national provisions require that system to use commercial cryptography protection; it is not triggered merely because a system uses encryption.
: cite Article 25 and the applicable product certification catalogue and rule.
Mandatory product or service certification: cite Article 26 and the exact entry in the applicable and network security-specific product catalogue.
Application security assessment: identify the legal or national-provision trigger, the system boundary, operator, planning, pre-operation, or annual assessment stage, and whether the operator assesses itself or uses a qualified .
-specific evidence: for critical information infrastructure, record the tested and certified products and services, the reviewed cryptographic algorithms, protocols, and key-management mechanisms, and the operator's annual reporting evidence.
No identified route: record the sources checked and the unresolved classification facts; do not describe the item as certified, exempt, or compliant.
Verify the testing, assessment, or certification body
A that conducts product testing or application security assessment and issues data or results to the public as proof must hold qualification granted by the National Cryptography Administration. Its work must stay within the approved business scope.
A certification body has a different role and qualification. It must hold certification-body qualification, act within its approved scope, issue the certification conclusion under the applicable rules, and conduct follow-up surveillance so the certified product, service, or management system continues to conform. Do not verify a certificate only against the testing-body directory.
Check the body's current public approval entry, approved scope, and qualification expiry date. The Measures set a five-year qualification term. A supplier logo, old listing, or body name alone does not establish that the body was qualified for the work on the report date.
For a testing report, verify the authorized signatory and the body's official or dedicated seal. Record any mismatch in body name, qualification scope, report scope, signatory, or validity as an open issue.
Body identity: legal name, qualification certificate number, approved business scope, issuing authority, issue date, expiry date, and date checked.
Certification record: certification-body qualification and approved scope, applicable certification rule, certificate number, covered product or service and version, issue and expiry dates, current status, surveillance conditions, suspensions or withdrawals, and date checked.
Report execution: report number, authorized signatory, seal, testing dates, issue date, standards and methods, samples or system boundary, and result.
Independence check: note any supplier, integrator, operator, or other relationship that could affect the body's independence.
Public verification: save the official directory or approval result used and the date it was accessed.
Build one record for each assurance route and exact item or system boundary. Attach the report or certificate itself; a supplier declaration can explain the evidence but cannot replace it.
The product-security or system owner should create the record, legal or compliance should confirm the legal trigger, and the release owner should approve the scoped outcome. Record those names and dates because the official rules assign duties to operators and qualified bodies but do not prescribe this internal template.
For application security assessment, separate the assessment of the application plan from the assessment of the built system. The Assessment Measures require plan assessment during planning, assessment before operation, and at least annual assessment after an in-scope important network and information system begins operating.
The Use Provisions require additional evidence for critical information infrastructure required to use commercial cryptography. From 1 August 2025, the operator must use tested and certified commercial cryptography products and services and cryptographic algorithms, protocols, and key-management mechanisms reviewed by the National Cryptography Administration. The operator must also report the prior year's commercial cryptography use and assessment work to its protection department by 31 January each year.
Decision basis: route, legal trigger, catalogue and version, scope conclusion, and whether the route is voluntary or mandatory.
Subject: supplier and operator, product or service name, model, hardware and software version, cryptographic functions, deployment purpose, and system boundary.
Evidence: complete certificate or report, identifier, standards and methods, tested sample or assessed assets, exclusions, findings, result, issue date, and expiry date if one applies.
Body verification: issuer type, qualification evidence, approved business scope, public-directory check, authorized signatory and seal for a testing report, certification rule and surveillance status for a certificate, and verification date.
Application assessment inputs: application plan, equipment inventory, network topology, management rules, configuration, operation and maintenance records, and the staff roles that supported the assessment.
controls: product and service certificates, evidence of review for algorithms, protocols, and key-management mechanisms, the operator's cryptography management rules, designated key-management and audit roles, and the annual report to the protection department.
Decision and follow-up: reviewer, decision date, release or remediation conditions, unresolved questions, linked procurement evidence, and next review date.
Record status: draft while trigger, scope, body qualification, or evidence is unresolved; conditionally accepted only when named conditions and owners are recorded; accepted only for the stated item, version, scope, and period; superseded when a later reviewed record replaces it.
A certificate or report supports only the subject, version, functions, scope, standards, and period it covers. It does not by itself establish import or export status, national security review, data compliance, or the compliance of a different configuration.
The Measures require the body to retain original testing records and reports for at least six years. The Assessment Measures impose the same minimum on an operator's self-assessment records and reports. Keep your review record for the period required by the applicable rule and any longer contractual, sectoral, or internal retention rule.
Reopen the review when a fact used to match the scope and evidence changes. If the report, catalogue, or official directory does not resolve a gap, record the release condition and obtain case-specific advice from the responsible authority or qualified counsel.
Scope change: deployment architecture, assessed assets, system boundary, intended use, operator, or legal classification.
Evidence change: catalogue or rule update, standard edition, certificate expiry, body qualification or business scope, report withdrawal, or corrected finding.
Operational change: significant security event, major cryptography security hazard, failed assessment, or remediation that changes the assessed implementation.
Supplier change: manufacturer, service provider, integrator, component source, or contract term affecting the evidence.
Articles 17-19 establish the separate commercial cryptography certification system, certification-body qualification, approved-scope requirement, responsibility for conclusions, and follow-up surveillance.
Confirms that the qualification regime covers product-testing bodies and application-security-assessment bodies and explains the report, data, sample, and supervision framework.
Articles 25-27 distinguish voluntary testing and certification, catalogue-triggered mandatory product and service certification, and commercial cryptography application security assessment.