CryptographyChina

China Cryptography Law Commercial cryptography testing evidence template

A review template for China commercial cryptography product testing, certification, and application security assessment evidence.

Select the legal route first, then match the qualified body, report or certificate, assessed scope, and exact product or system version to the release decision.

Author
Sorena AI
Published
Jul 5, 2026
Updated
Jul 25, 2026
Sections
4

Structured answer sets in this page tree.

Primary sources
9

Cited legal and guidance references.

Publication metadata
Sorena AI
Published Jul 5, 2026
Updated Jul 25, 2026
Overview

Use this internal review template to decide whether China assurance evidence covers a specific product, service, or network and information system. It is not an official form and does not prescribe mandatory wording. It separates voluntary certification, catalogue-triggered mandatory certification, and so that a certificate is not treated as proof of every requirement.

Section 1

Choose the assurance route before collecting evidence

Start by naming the assurance route and its trigger. Cryptography Law Article 25 encourages voluntary testing and certification. Article 26 separately requires qualified testing and certification before a listed commercial cryptography product involving national security, the national economy and people's livelihood, or the public interest may be sold or provided. A commercial cryptography service that uses or a network security-specific product must also pass service certification.

Do not treat the voluntary product certification catalogues as the same thing as the mandatory and network security-specific product catalogue. Record the exact catalogue entry, product description, and rule that makes the route applicable.

is a system-level route. Under the 2023 Assessment Measures, it evaluates whether a network and information system uses technologies, products, and services compliantly, correctly, and effectively. It applies where laws, administrative regulations, or other national provisions require that system to use commercial cryptography protection; it is not triggered merely because a system uses encryption.

  • : cite Article 25 and the applicable product certification catalogue and rule.
  • Mandatory product or service certification: cite Article 26 and the exact entry in the applicable and network security-specific product catalogue.
  • Application security assessment: identify the legal or national-provision trigger, the system boundary, operator, planning, pre-operation, or annual assessment stage, and whether the operator assesses itself or uses a qualified .
  • -specific evidence: for critical information infrastructure, record the tested and certified products and services, the reviewed cryptographic algorithms, protocols, and key-management mechanisms, and the operator's annual reporting evidence.
  • No identified route: record the sources checked and the unresolved classification facts; do not describe the item as certified, exempt, or compliant.
Section 2

Verify the testing, assessment, or certification body

A that conducts product testing or application security assessment and issues data or results to the public as proof must hold qualification granted by the National Cryptography Administration. Its work must stay within the approved business scope.

A certification body has a different role and qualification. It must hold certification-body qualification, act within its approved scope, issue the certification conclusion under the applicable rules, and conduct follow-up surveillance so the certified product, service, or management system continues to conform. Do not verify a certificate only against the testing-body directory.

Check the body's current public approval entry, approved scope, and qualification expiry date. The Measures set a five-year qualification term. A supplier logo, old listing, or body name alone does not establish that the body was qualified for the work on the report date.

For a testing report, verify the authorized signatory and the body's official or dedicated seal. Record any mismatch in body name, qualification scope, report scope, signatory, or validity as an open issue.

  • Body identity: legal name, qualification certificate number, approved business scope, issuing authority, issue date, expiry date, and date checked.
  • Certification record: certification-body qualification and approved scope, applicable certification rule, certificate number, covered product or service and version, issue and expiry dates, current status, surveillance conditions, suspensions or withdrawals, and date checked.
  • Report execution: report number, authorized signatory, seal, testing dates, issue date, standards and methods, samples or system boundary, and result.
  • Independence check: note any supplier, integrator, operator, or other relationship that could affect the body's independence.
  • Public verification: save the official directory or approval result used and the date it was accessed.
Section 3

Complete the evidence record

Build one record for each assurance route and exact item or system boundary. Attach the report or certificate itself; a supplier declaration can explain the evidence but cannot replace it.

The product-security or system owner should create the record, legal or compliance should confirm the legal trigger, and the release owner should approve the scoped outcome. Record those names and dates because the official rules assign duties to operators and qualified bodies but do not prescribe this internal template.

For application security assessment, separate the assessment of the application plan from the assessment of the built system. The Assessment Measures require plan assessment during planning, assessment before operation, and at least annual assessment after an in-scope important network and information system begins operating.

The Use Provisions require additional evidence for critical information infrastructure required to use commercial cryptography. From 1 August 2025, the operator must use tested and certified commercial cryptography products and services and cryptographic algorithms, protocols, and key-management mechanisms reviewed by the National Cryptography Administration. The operator must also report the prior year's commercial cryptography use and assessment work to its protection department by 31 January each year.

  • Decision basis: route, legal trigger, catalogue and version, scope conclusion, and whether the route is voluntary or mandatory.
  • Subject: supplier and operator, product or service name, model, hardware and software version, cryptographic functions, deployment purpose, and system boundary.
  • Evidence: complete certificate or report, identifier, standards and methods, tested sample or assessed assets, exclusions, findings, result, issue date, and expiry date if one applies.
  • Body verification: issuer type, qualification evidence, approved business scope, public-directory check, authorized signatory and seal for a testing report, certification rule and surveillance status for a certificate, and verification date.
  • Application assessment inputs: application plan, equipment inventory, network topology, management rules, configuration, operation and maintenance records, and the staff roles that supported the assessment.
  • controls: product and service certificates, evidence of review for algorithms, protocols, and key-management mechanisms, the operator's cryptography management rules, designated key-management and audit roles, and the annual report to the protection department.
  • Decision and follow-up: reviewer, decision date, release or remediation conditions, unresolved questions, linked procurement evidence, and next review date.
  • Record status: draft while trigger, scope, body qualification, or evidence is unresolved; conditionally accepted only when named conditions and owners are recorded; accepted only for the stated item, version, scope, and period; superseded when a later reviewed record replaces it.
Section 4

Review gaps, retention, and change triggers

A certificate or report supports only the subject, version, functions, scope, standards, and period it covers. It does not by itself establish import or export status, national security review, data compliance, or the compliance of a different configuration.

The Measures require the body to retain original testing records and reports for at least six years. The Assessment Measures impose the same minimum on an operator's self-assessment records and reports. Keep your review record for the period required by the applicable rule and any longer contractual, sectoral, or internal retention rule.

Reopen the review when a fact used to match the scope and evidence changes. If the report, catalogue, or official directory does not resolve a gap, record the release condition and obtain case-specific advice from the responsible authority or qualified counsel.

  • Product change: model, cryptographic module, algorithm, key-management design, firmware, software, interface, or claimed function.
  • Scope change: deployment architecture, assessed assets, system boundary, intended use, operator, or legal classification.
  • Evidence change: catalogue or rule update, standard edition, certificate expiry, body qualification or business scope, report withdrawal, or corrected finding.
  • Operational change: significant security event, major cryptography security hazard, failed assessment, or remediation that changes the assessed implementation.
  • Supplier change: manufacturer, service provider, integrator, component source, or contract term affecting the evidence.
Primary sources

References and citations

oscca.gov.cn
Referenced sections
  • Articles 5-13 establish CII-specific governance, personnel, qualified product and service, reviewed-technology, lifecycle-assessment, and annual reporting evidence.
mee.gov.cn
Referenced sections
  • Articles 17-19 establish the separate commercial cryptography certification system, certification-body qualification, approved-scope requirement, responsibility for conclusions, and follow-up surveillance.
oscca.gov.cn
Referenced sections
  • Articles 13-19 support qualification-change checks, approved-scope checks, report controls, and the testing body's six-year minimum retention period.
oscca.gov.cn
Referenced sections
  • Articles 25-27 distinguish voluntary testing and certification, catalogue-triggered mandatory product and service certification, and commercial cryptography application security assessment.
Related guides

Explore more topics

China commercial cryptography compliance checklist
China commercial cryptography checklist covering classification, product and service assurance, CII duties, trade controls, and retained evidence.
China cryptography compliance deadlines and calendar
China cryptography effective dates, CII reports, annual assessments, licence renewals, change notices, and pre-operation checks.
China cryptography import, export, and security review triage
Screen commercial cryptography imports under the 2020 list, exports under China's unified dual-use list, the consumer exclusion, system assessment, and CII review.
China Cryptography Law FAQ
Answers on China's commercial-cryptography scope, product assurance, classified protection, CII assessment, procurement review, and trade controls.
China Cryptography Law requirements
China commercial cryptography requirements by role: standards, testing, certification, CII use and assessment, trade controls, and evidence.
China Cryptography Law vs Cybersecurity Law
Compare China's Cryptography Law and current Cybersecurity Law by scope, actor, product assurance, CII duties, evidence, and enforcement.
China cryptography penalties, fines, and liability
China commercial cryptography penalties by actor and violation, including fine bands, corrective orders, confiscation, licence action, and liability.
Commercial cryptography procurement checklist
Procurement checks for commercial cryptography products and services used in China, including certificate scope, CII duties, and supplier changes.
Commercial cryptography products and testing evidence
When China commercial cryptography testing or certification is voluntary or mandatory, and what product, service, body, and scope evidence to keep.
Do imported cryptography products need special review?
Not every encrypted product imported into China needs a licence. Check the 2020 commercial-cryptography import list, the consumer-product exception, and any CII procurement review.
Does using encryption trigger China Cryptography Law duties?
Using encryption does not create one universal China approval duty. Check classified protection, product, service, CII, procurement, and trade triggers.
How does cryptography compliance overlap with China cybersecurity law?
See how China's cryptography rules connect with classified protection, product assurance, CII assessment, and cybersecurity review without merging the regimes.
What is commercial cryptography in China?
Commercial cryptography protects information that is not a state secret. Learn how China defines the category and which separate facts trigger product, CII, or trade controls.
When is commercial cryptography testing or certification needed?
Commercial-cryptography assurance is often voluntary, but specified products and services require it. Covered CII also needs application assessment and qualified cryptography.