---
title: "China commercial cryptography testing evidence template"
canonical_url: "https://www.sorena.io/artifacts/apac/china-cryptography-law/commercial-cryptography-testing-evidence-template"
source_url: "https://www.sorena.io/artifacts/apac/china-cryptography-law/commercial-cryptography-testing-evidence-template"
author: "Sorena AI"
description: "Record the legal route, product or system scope, testing-body qualification, report details, gaps, and reassessment triggers for China commercial cryptography assurance."
published_at: "2026-07-05"
updated_at: "2026-07-25"
keywords:
  - "China Cryptography Law"
  - "Commercial cryptography"
  - "Cryptography Law"
  - "Commercial cryptography testing"
  - "China cybersecurity"
---
**[SORENA](https://www.sorena.io/)** - AI-Powered GRC Platform

[Home](https://www.sorena.io/) | [Solutions](https://www.sorena.io/solutions) | [Artifacts](https://www.sorena.io/artifacts) | [About Us](https://www.sorena.io/about-us) | [Contact](https://www.sorena.io/contact) | [Portal](https://app.sorena.io)

---

# China commercial cryptography testing evidence template

Record the legal route, product or system scope, testing-body qualification, report details, gaps, and reassessment triggers for China commercial cryptography assurance.

*Cryptography* *China*

## China Cryptography Law Commercial cryptography testing evidence template

A review template for China commercial cryptography product testing, certification, and application security assessment evidence.

Select the legal route first, then match the qualified body, report or certificate, assessed scope, and exact product or system version to the release decision.

Use this internal review template to decide whether China commercial cryptography assurance evidence covers a specific product, service, or network and information system. It is not an official form and does not prescribe mandatory wording. It separates voluntary certification, catalogue-triggered mandatory certification, and commercial cryptography application security assessment so that a certificate is not treated as proof of every requirement.

## Definitions

### Commercial cryptography

Commercial cryptography means technologies, products, and services that use specific transformations to encrypt or authenticate information that is not a state secret. It is legally distinct from core cryptography and ordinary cryptography, which protect state-secret information under a separate classified regime.

**Why it matters here:** This template covers evidence for commercial cryptography only. Before selecting a testing or assessment route, confirm that the product, service, or system function protects non-state-secret information and record any separate rule that requires its use.

Sources:

- [PRC Cryptography Law, Articles 2 and 6-8](https://www.oscca.gov.cn/sca/xxgk/2023-06/04/content_1057225.shtml?ref=sorena.io)
- [Commercial Cryptography Administration Regulation, Article 2](https://xzfg.moj.gov.cn/front/law/detail?LawID=1622&ref=sorena.io)

### Voluntary commercial cryptography product certification

**Term:** voluntary product certification

Voluntary product certification is the state-promoted route under Cryptography Law Article 25 for evaluating a commercial cryptography product under an applicable certification catalogue and certification rule. Article 26 separately covers products included in the network critical equipment and network security-specific product catalogue. Certification is not legally mandatory for every product outside that catalogue.

**Why it matters here:** Record the catalogue, certification rule, product category, model, and version behind a voluntary certificate. Do not present that certificate as proof that a separate mandatory product, system-assessment, import, export, or procurement-review route has been satisfied.

Sources:

- [PRC Cryptography Law, Articles 25-26](https://www.oscca.gov.cn/sca/xxgk/2023-06/04/content_1057225.shtml?ref=sorena.io)
- [Commercial Cryptography Product Certification Catalogue (First Batch) and Certification Rules](https://www.oscca.gov.cn/sca/xwdt/2020-05/11/content_1060749.shtml?ref=sorena.io)

### Qualified commercial cryptography testing body

**Term:** testing body

A testing body is an organization recognized by the National Cryptography Administration to conduct commercial cryptography product testing, network and information system commercial cryptography application security assessment, or both, and to issue data or results that others may rely on as proof. Qualification is granted for an approved business scope and a five-year term; it does not authorize work outside that scope.

**Why it matters here:** Match the report date and activity to the body's legal name, qualification certificate, approved scope, and qualification term. A current listing for one type of work does not validate a report for another type or a report issued outside the qualification period.

Sources:

- [Commercial Cryptography Testing Body Measures, Articles 3, 5, 12, and 15](https://www.oscca.gov.cn/sca/xxgk/2023-10/07/content_1061108.shtml?ref=sorena.io)

### Commercial cryptography application security assessment

A commercial cryptography application security assessment is the standards-based testing, analysis, and verification of whether a network and information system uses commercial cryptography technologies, products, and services compliantly, correctly, and effectively. For a system that laws, administrative regulations, or national provisions require to use commercial cryptography protection, the operator must assess the application plan, assess the completed system before operation, and assess the operating system at least annually. The operator may assess itself only if it meets the capability and governance conditions in the Assessment Measures; otherwise it must use a qualified testing body.

**Why it matters here:** This is system-level evidence. Record the legal trigger, operator, system boundary, lifecycle stage, application plan, assessed implementation, findings, filing status, and whether the assessor was qualified for the chosen route instead of treating a product certificate as a substitute.

Sources:

- [Commercial Cryptography Application Security Assessment Measures, Articles 2 and 6-14](https://www.oscca.gov.cn/sca/xxgk/2023-10/07/content_1061109.shtml?ref=sorena.io)

### Network critical equipment and network security-specific products

**Term:** network critical equipment

Network critical equipment and network security-specific products are product categories placed in a national catalogue because of their importance to network security. A commercial cryptography product involving national security, the national economy and people's livelihood, or the public interest must first fall within that catalogue before Cryptography Law Article 26 makes qualified testing and certification a condition of sale or provision.

**Why it matters here:** Identify the exact catalogue entry and technical description. Do not infer mandatory Article 26 certification from the presence of cryptography alone or from a similarly named voluntary commercial cryptography certification catalogue.

Sources:

- [PRC Cryptography Law, Article 26](https://www.oscca.gov.cn/sca/xxgk/2023-06/04/content_1057225.shtml?ref=sorena.io)

### Critical information infrastructure

**Term:** CII

Critical information infrastructure is infrastructure in important industries and fields whose destruction, loss of function, or data leakage could seriously harm national security, the national economy and people's livelihoods, or the public interest. The competent protection department identifies it and notifies the operator under the governing rules; sector, system importance, or customer size alone does not establish CII status.

**Why it matters here:** For CII required to use commercial cryptography, this evidence record must keep product and service certification, reviewed cryptographic technology, application-plan assessment, pre-operation and annual assessment, annual reporting, and procurement review as distinct evidence sets.

Sources:

- [Critical Information Infrastructure Security Protection Regulation, Articles 2 and 8-11](https://www.cac.gov.cn/2021-08/17/c_1630785976988160.htm?ref=sorena.io)
- [CII Commercial Cryptography Use Provisions, Articles 2 and 5-15](https://www.oscca.gov.cn/sca/xxgk/2025-06/27/content_1061270.shtml?ref=sorena.io)

## Choose the assurance route before collecting evidence

Start by naming the assurance route and its trigger. Cryptography Law Article 25 encourages voluntary commercial cryptography testing and certification. Article 26 separately requires qualified testing and certification before a listed commercial cryptography product involving national security, the national economy and people's livelihood, or the public interest may be sold or provided. A commercial cryptography service that uses network critical equipment or a network security-specific product must also pass service certification.

Do not treat the voluntary commercial cryptography product certification catalogues as the same thing as the mandatory network critical equipment and network security-specific product catalogue. Record the exact catalogue entry, product description, and rule that makes the route applicable.

Commercial cryptography application security assessment is a system-level route. Under the 2023 Assessment Measures, it evaluates whether a network and information system uses commercial cryptography technologies, products, and services compliantly, correctly, and effectively. It applies where laws, administrative regulations, or other national provisions require that system to use commercial cryptography protection; it is not triggered merely because a system uses encryption.

- Voluntary product certification: cite Article 25 and the applicable commercial cryptography product certification catalogue and rule.
- Mandatory product or service certification: cite Article 26 and the exact entry in the applicable network critical equipment and network security-specific product catalogue.
- Application security assessment: identify the legal or national-provision trigger, the system boundary, operator, planning, pre-operation, or annual assessment stage, and whether the operator assesses itself or uses a qualified testing body.
- CII-specific evidence: for critical information infrastructure, record the tested and certified commercial cryptography products and services, the reviewed cryptographic algorithms, protocols, and key-management mechanisms, and the operator's annual reporting evidence.
- No identified route: record the sources checked and the unresolved classification facts; do not describe the item as certified, exempt, or compliant.

Sources for this answer:

- [PRC Cryptography Law](https://www.oscca.gov.cn/sca/xxgk/2023-06/04/content_1057225.shtml?ref=sorena.io) - Articles 25-27 distinguish voluntary testing and certification, catalogue-triggered mandatory product and service certification, and commercial cryptography application security assessment.
- [Commercial Cryptography Application Security Assessment Measures](https://www.oscca.gov.cn/sca/xxgk/2023-10/07/content_1061109.shtml?ref=sorena.io) - Articles 2 and 6-11 define the assessment, its applicability trigger, lifecycle stages, and required assessment content; the Measures took effect on 1 November 2023.
- [Commercial Cryptography Product Certification Catalogue (First Batch) and Certification Rules](https://www.oscca.gov.cn/sca/xwdt/2020-05/11/content_1060749.shtml?ref=sorena.io) - Identifies the first batch of product categories and the rules for the nationally promoted commercial cryptography product certification scheme.
- [Commercial Cryptography Product Certification Catalogue (Second Batch)](https://www.oscca.gov.cn/sca/xwdt/2022-07/14/content_1060931.shtml?ref=sorena.io) - Adds product categories and their certification bases to the nationally promoted commercial cryptography product certification scheme.
- [CII Commercial Cryptography Use Provisions](https://www.oscca.gov.cn/sca/xxgk/2025-06/27/content_1061270.shtml?ref=sorena.io) - Articles 5, 9, and 11-15 set additional evidence requirements for critical information infrastructure from 1 August 2025, including qualified products and services, reviewed cryptographic technology, and lifecycle assessment.

## Verify the testing, assessment, or certification body

A testing body that conducts commercial cryptography product testing or application security assessment and issues data or results to the public as proof must hold qualification granted by the National Cryptography Administration. Its work must stay within the approved business scope.

A certification body has a different role and qualification. It must hold commercial cryptography certification-body qualification, act within its approved scope, issue the certification conclusion under the applicable rules, and conduct follow-up surveillance so the certified product, service, or management system continues to conform. Do not verify a certificate only against the testing-body directory.

Check the body's current public approval entry, approved scope, and qualification expiry date. The Testing Body Measures set a five-year qualification term. A supplier logo, old listing, or body name alone does not establish that the body was qualified for the work on the report date.

For a testing report, verify the authorized signatory and the body's official or dedicated seal. Record any mismatch in body name, qualification scope, report scope, signatory, or validity as an open issue.

- Body identity: legal name, qualification certificate number, approved business scope, issuing authority, issue date, expiry date, and date checked.
- Certification record: certification-body qualification and approved scope, applicable certification rule, certificate number, covered product or service and version, issue and expiry dates, current status, surveillance conditions, suspensions or withdrawals, and date checked.
- Report execution: report number, authorized signatory, seal, testing dates, issue date, standards and methods, samples or system boundary, and result.
- Independence check: note any supplier, integrator, operator, or other relationship that could affect the body's independence.
- Public verification: save the official directory or approval result used and the date it was accessed.

Sources for this answer:

- [Commercial Cryptography Testing Body Measures](https://www.oscca.gov.cn/sca/xxgk/2023-10/07/content_1061108.shtml?ref=sorena.io) - Articles 3, 5, 12, and 15-19 cover qualification, approved business scope, the five-year qualification term, independence, report execution, and record retention.
- [National Cryptography Administration testing-body approval results](https://www.oscca.gov.cn/app-zxfw/xzspsx/symmjcjiancha.jsp?channel_code=c100248#ref=sorena.io) - Use the current public approval results to verify a body's legal name, approved commercial cryptography testing scope, and qualification expiry date.
- [Commercial cryptography testing body management interpretation](https://www.oscca.gov.cn/sca/xxgk/2023-10/07/content_1061110.shtml?ref=sorena.io) - Confirms that the qualification regime covers product-testing bodies and application-security-assessment bodies and explains the report, data, sample, and supervision framework.
- [Commercial Cryptography Administration Regulation](https://www.mee.gov.cn/zcwj/gwywj/202305/t20230529_1031579.shtml?ref=sorena.io) - Articles 17-19 establish the separate commercial cryptography certification system, certification-body qualification, approved-scope requirement, responsibility for conclusions, and follow-up surveillance.

## Complete the evidence record

Build one record for each assurance route and exact item or system boundary. Attach the report or certificate itself; a supplier declaration can explain the evidence but cannot replace it.

The product-security or system owner should create the record, legal or compliance should confirm the legal trigger, and the release owner should approve the scoped outcome. Record those names and dates because the official rules assign duties to operators and qualified bodies but do not prescribe this internal template.

For application security assessment, separate the assessment of the commercial cryptography application plan from the assessment of the built system. The Assessment Measures require plan assessment during planning, assessment before operation, and at least annual assessment after an in-scope important network and information system begins operating.

The CII Commercial Cryptography Use Provisions require additional evidence for critical information infrastructure required to use commercial cryptography. From 1 August 2025, the operator must use tested and certified commercial cryptography products and services and cryptographic algorithms, protocols, and key-management mechanisms reviewed by the National Cryptography Administration. The operator must also report the prior year's commercial cryptography use and assessment work to its protection department by 31 January each year.

- Decision basis: route, legal trigger, catalogue and version, scope conclusion, and whether the route is voluntary or mandatory.
- Subject: supplier and operator, product or service name, model, hardware and software version, cryptographic functions, deployment purpose, and system boundary.
- Evidence: complete certificate or report, identifier, standards and methods, tested sample or assessed assets, exclusions, findings, result, issue date, and expiry date if one applies.
- Body verification: issuer type, qualification evidence, approved business scope, public-directory check, authorized signatory and seal for a testing report, certification rule and surveillance status for a certificate, and verification date.
- Application assessment inputs: commercial cryptography application plan, equipment inventory, network topology, management rules, configuration, operation and maintenance records, and the staff roles that supported the assessment.
- CII controls: product and service certificates, evidence of review for algorithms, protocols, and key-management mechanisms, the operator's cryptography management rules, designated key-management and audit roles, and the annual report to the protection department.
- Decision and follow-up: reviewer, decision date, release or remediation conditions, unresolved questions, linked procurement evidence, and next review date.
- Record status: draft while trigger, scope, body qualification, or evidence is unresolved; conditionally accepted only when named conditions and owners are recorded; accepted only for the stated item, version, scope, and period; superseded when a later reviewed record replaces it.

Sources for this answer:

- [Commercial Cryptography Application Security Assessment Measures](https://www.oscca.gov.cn/sca/xxgk/2023-10/07/content_1061109.shtml?ref=sorena.io) - Articles 7-14 specify plan, pre-operation, annual, evidence-input, report-retention, and filing requirements for in-scope important network and information systems.
- [Commercial Cryptography Testing Body Measures](https://www.oscca.gov.cn/sca/xxgk/2023-10/07/content_1061108.shtml?ref=sorena.io) - Articles 18-19 require testing reports to meet applicable rules and be true, objective, accurate, complete, signed by an authorized signatory, sealed, and retained with original records for at least six years by the testing body.
- [CII Commercial Cryptography Use Provisions](https://www.oscca.gov.cn/sca/xxgk/2025-06/27/content_1061270.shtml?ref=sorena.io) - Articles 5-13 establish CII-specific governance, personnel, qualified product and service, reviewed-technology, lifecycle-assessment, and annual reporting evidence.

## Review gaps, retention, and change triggers

A certificate or report supports only the subject, version, functions, scope, standards, and period it covers. It does not by itself establish import or export status, national security review, data compliance, or the compliance of a different configuration.

The Testing Body Measures require the body to retain original testing records and reports for at least six years. The Assessment Measures impose the same minimum on an operator's self-assessment records and reports. Keep your review record for the period required by the applicable rule and any longer contractual, sectoral, or internal retention rule.

Reopen the review when a fact used to match the scope and evidence changes. If the report, catalogue, or official directory does not resolve a gap, record the release condition and obtain case-specific advice from the responsible authority or qualified counsel.

- Product change: model, cryptographic module, algorithm, key-management design, firmware, software, interface, or claimed function.
- Scope change: deployment architecture, assessed assets, system boundary, intended use, operator, or legal classification.
- Evidence change: catalogue or rule update, standard edition, certificate expiry, body qualification or business scope, report withdrawal, or corrected finding.
- Operational change: significant security event, major cryptography security hazard, failed assessment, or remediation that changes the assessed implementation.
- Supplier change: manufacturer, service provider, integrator, component source, or contract term affecting the evidence.

Sources for this answer:

- [Commercial Cryptography Testing Body Measures](https://www.oscca.gov.cn/sca/xxgk/2023-10/07/content_1061108.shtml?ref=sorena.io) - Articles 13-19 support qualification-change checks, approved-scope checks, report controls, and the testing body's six-year minimum retention period.
- [Commercial Cryptography Application Security Assessment Measures](https://www.oscca.gov.cn/sca/xxgk/2023-10/07/content_1061109.shtml?ref=sorena.io) - Articles 9 and 13-15 support annual reassessment, operator retention, filing, and event-driven reporting or reassessment.

*Use the requirement*

*Placement: Before primary sources*

## Prepare the commercial cryptography evidence file

Sorena AI helps assign owners, link official sources, and maintain the evidence record for this commercial cryptography decision.

- [Map official sources to evidence](/solutions/research-copilot.md): Research Copilot connects the official citation, decision, owner, retained evidence, and change history.
- [Review the China route](/contact.md): Check the China Cryptography Law scope decision and unresolved launch questions with Sorena.

## Primary sources

- [PRC Cryptography Law](https://www.oscca.gov.cn/sca/xxgk/2023-06/04/content_1057225.shtml?ref=sorena.io) - Articles 25-27 establish the principal commercial cryptography testing, certification, and application security assessment routes.
- [Commercial Cryptography Testing Body Measures](https://www.oscca.gov.cn/sca/xxgk/2023-10/07/content_1061108.shtml?ref=sorena.io) - Governs testing-body qualification, approved scope, independence, report controls, and record retention from 1 November 2023.
- [Commercial Cryptography Application Security Assessment Measures](https://www.oscca.gov.cn/sca/xxgk/2023-10/07/content_1061109.shtml?ref=sorena.io) - Governs the scope, lifecycle, evidence, reporting, retention, and filing of commercial cryptography application security assessments from 1 November 2023.
- [National Cryptography Administration testing-body approval results](https://www.oscca.gov.cn/app-zxfw/xzspsx/symmjcjiancha.jsp?channel_code=c100248#ref=sorena.io) - Current public lookup for a commercial cryptography testing body's approved business scope and qualification expiry date.
- [CII Commercial Cryptography Use Provisions](https://www.oscca.gov.cn/sca/xxgk/2025-06/27/content_1061270.shtml?ref=sorena.io) - Binding CII-specific commercial cryptography requirements in force from 1 August 2025, including product, service, technology, assessment, governance, and reporting evidence.
- [Commercial Cryptography Administration Regulation](https://www.mee.gov.cn/zcwj/gwywj/202305/t20230529_1031579.shtml?ref=sorena.io) - Use to distinguish commercial cryptography certification-body qualification and surveillance from testing-body qualification and reports.

## Related Topic Guides

- [China commercial cryptography compliance checklist](/artifacts/apac/china-cryptography-law/checklist.md): China commercial cryptography checklist covering classification, product and service assurance, CII duties, trade controls, and retained evidence.
- [China cryptography compliance deadlines and calendar](/artifacts/apac/china-cryptography-law/deadlines-and-compliance-calendar.md): China cryptography effective dates, CII reports, annual assessments, licence renewals, change notices, and pre-operation checks.
- [China cryptography import, export, and security review triage](/artifacts/apac/china-cryptography-law/import-export-and-security-assessment.md): Screen commercial cryptography imports under the 2020 list, exports under China's unified dual-use list, the consumer exclusion, system assessment, and CII review.
- [China Cryptography Law FAQ](/artifacts/apac/china-cryptography-law/faq.md): Answers on China's commercial-cryptography scope, product assurance, classified protection, CII assessment, procurement review, and trade controls.
- [China Cryptography Law requirements](/artifacts/apac/china-cryptography-law/requirements.md): China commercial cryptography requirements by role: standards, testing, certification, CII use and assessment, trade controls, and evidence.
- [China Cryptography Law vs Cybersecurity Law](/artifacts/apac/china-cryptography-law/china-cryptography-law-vs-cybersecurity-law.md): Compare China's Cryptography Law and current Cybersecurity Law by scope, actor, product assurance, CII duties, evidence, and enforcement.
- [China cryptography penalties, fines, and liability](/artifacts/apac/china-cryptography-law/penalties-and-fines.md): China commercial cryptography penalties by actor and violation, including fine bands, corrective orders, confiscation, licence action, and liability.
- [Commercial cryptography procurement checklist](/artifacts/apac/china-cryptography-law/commercial-cryptography-procurement-checklist.md): Procurement checks for commercial cryptography products and services used in China, including certificate scope, CII duties, and supplier changes.
- [Commercial cryptography products and testing evidence](/artifacts/apac/china-cryptography-law/commercial-cryptography-products-and-testing.md): When China commercial cryptography testing or certification is voluntary or mandatory, and what product, service, body, and scope evidence to keep.
- [Do imported cryptography products need special review?](/artifacts/apac/china-cryptography-law/faq/do-imported-cryptography-products-need-special-review.md): Not every encrypted product imported into China needs a licence. Check the 2020 commercial-cryptography import list, the consumer-product exception, and any CII procurement review.
- [Does using encryption trigger China Cryptography Law duties?](/artifacts/apac/china-cryptography-law/faq/does-using-encryption-trigger-china-cryptography-law.md): Using encryption does not create one universal China approval duty. Check classified protection, product, service, CII, procurement, and trade triggers.
- [How does cryptography compliance overlap with China cybersecurity law?](/artifacts/apac/china-cryptography-law/faq/how-does-cryptography-compliance-overlap-with-cybersecurity-law.md): See how China's cryptography rules connect with classified protection, product assurance, CII assessment, and cybersecurity review without merging the regimes.
- [What is commercial cryptography in China?](/artifacts/apac/china-cryptography-law/faq/what-is-commercial-cryptography-in-china.md): Commercial cryptography protects information that is not a state secret. Learn how China defines the category and which separate facts trigger product, CII, or trade controls.
- [When is commercial cryptography testing or certification needed?](/artifacts/apac/china-cryptography-law/faq/when-is-commercial-cryptography-testing-or-certification-needed.md): Commercial-cryptography assurance is often voluntary, but specified products and services require it. Covered CII also needs application assessment and qualified cryptography.


---

[Privacy Policy](https://www.sorena.io/privacy.md) | [Terms of Use](https://www.sorena.io/terms-of-use.md) | [DMCA](https://www.sorena.io/dmca.md) | [About Us](https://www.sorena.io/about-us.md)

(c) 2026 Sorena AB (559573-7338). All rights reserved.

Source: https://www.sorena.io/artifacts/apac/china-cryptography-law/commercial-cryptography-testing-evidence-template.md
