CryptographyChina

China Cryptography Law Cryptography Law deadlines and compliance calendar

Official dates for the Cryptography Law and commercial cryptography regulation implementation.

China Cryptography Law deadlines and compliance calendar is a practical China commercial cryptography compliance timeline. It explains what to check, what evidence to keep, and when the decision should be revisited before a China launch, procurement, product change, or operating change.

Author
Sorena AI
Published
Jul 5, 2026
Updated
Jul 5, 2026
Sections
4

Structured answer sets in this page tree.

Primary sources
3

Cited legal and guidance references.

Publication metadata
Sorena AI
Published Jul 5, 2026
Updated Jul 5, 2026
Overview

Official dates for the Cryptography Law and commercial cryptography regulation implementation.

Section 1

What this guide helps you decide

China Cryptography Law deadlines and compliance calendar explains how product security, procurement, engineering, and compliance teams should apply China commercial cryptography compliance. It focuses on the decision to make, the evidence to keep, the owner to assign, and the trigger for revisiting the conclusion.

Cryptography Law Article 2 defines cryptography; Article 6 separates core, ordinary, and commercial cryptography; Article 8 addresses commercial cryptography use for non-state-secret information; Articles 24-28 are central for commercial cryptography products, services, CII use, testing/certification, and import/export context.

  • Inventory the cryptography actually used in the China product, service, supplier component, or procurement.
  • Decide whether the item is ordinary business encryption, a commercial cryptography product/service, or a CII-related use case needing closer review.
  • Check whether testing, certification, supplier qualification, or import/export screening is needed before the China release date.
  • Tie procurement evidence to product-security evidence so supplier changes reopen the classification decision.
  • Keep the official source citation, reviewer, classification reason, and change trigger with the release record.
Section 2

Calendar and change triggers

Do not treat effective dates as the whole calendar. For China Cryptography Law, the operational calendar is built around launch approvals, filings, renewals where applicable, supplier or product changes, incident response, and re-assessment triggers.

The practical point is this: China Cryptography Law is not a single document exercise. It is a route decision plus evidence that survives product, supplier, app, data, or disposal changes.

  • Decide whether the item is ordinary business encryption, a commercial cryptography product/service, or a CII-related use case needing closer review.
  • Check whether testing, certification, supplier qualification, or import/export screening is needed before the China release date.
  • Tie procurement evidence to product-security evidence so supplier changes reopen the classification decision.
  • Keep the official source citation, reviewer, classification reason, and change trigger with the release record.
  • Keep cryptography inventory.
  • Keep supplier declaration.
Section 3

Evidence to keep before launch or change approval

Keep evidence that proves the China decision was made before the launch, transfer, filing, procurement, disposal, or product change went live.

Keep the record understandable to an external reviewer: decision owner, official source citation, product, app, data-flow, or vendor identifier, approval date, and the trigger for reopening the decision.

  • Keep cryptography inventory.
  • Keep supplier declaration.
  • Keep product/service classification memo.
  • Keep testing or certification status.
  • Keep CII-use screening note.
  • Keep import/export screening note.
  • Keep release approval and change log.
Section 4

Boundary with nearby China regimes

Keep general network-security, app-governance, and important-data controls in the China cybersecurity guide; keep personal-information transfer routes in the China privacy guide.

When one launch triggers several regimes, link the shared facts such as model number, app package, data flow, supplier, or release date, but keep the legal conclusions separate.

  • Assuming all encryption use is prohibited or all encryption use is irrelevant; the law distinguishes commercial cryptography from core and ordinary cryptography.
  • Buying a cryptography product for a sensitive China use case without checking testing, certification, or CII-related requirements.
  • Separating import/export screening from the product cryptography inventory.
Operationalize the requirement

Prepare the commercial cryptography evidence file

Sorena AI helps turn the China Cryptography Law Cryptography Law deadlines and compliance calendar decision into owners, controls, and reviewer-ready records.

Primary sources

References and citations

oscca.gov.cn
Referenced sections
  • Use for cryptography categories, commercial cryptography development and management, product/service controls, CII use, import/export context, penalties, and 1 January 2020 effective date.
Related guides

Explore more topics

China commercial cryptography compliance checklist
Checklist for classifying cryptography use, supplier evidence, testing/certification status, and commercial cryptography release decisions.
China Cryptography Law FAQ
Answers to practical China Cryptography Law questions for scope, official source triggers, evidence records, and related China scope decisions.
China Cryptography Law penalties and liability
Operational view of China cryptography liability provisions and what evidence reduces avoidable release and supplier risk.
China Cryptography Law requirements
China cryptography requirements for commercial cryptography products, services, testing, import/export screening, and release evidence.
China Cryptography Law vs Cybersecurity Law
Comparison of cryptography-specific duties with broader China cybersecurity duties for product and security teams.
Commercial cryptography import, export, and security assessment triage
How product and procurement teams should record import/export and security assessment questions without overclaiming applicability.
Commercial cryptography procurement checklist
Procurement checklist for vendors and products that rely on commercial cryptography in China-market systems.
Commercial cryptography products and testing evidence
How to prepare evidence for commercial cryptography products, services, and testing institution dependencies under China sources.
Commercial cryptography testing evidence template
Evidence template for commercial cryptography testing and certification status, qualified body dependence, and supplier review.
Do imported cryptography products need special review?
Do not assume every imported encrypted product has the same route. The Cryptography Law contains import/export and security assessment concepts, so the release record should identify product category, commercial cryptography status, and whether an official list or assessment source is needed.
Does using encryption trigger China Cryptography Law duties?
Using encryption is the starting point, not the final answer. The source distinguishes commercial cryptography and other cryptography categories, so the evidence record should identify the cryptographic function, product or service route, commercial cryptography status, and whether testing, certification, import/export, or security assessment questions arise.
How does cryptography compliance overlap with China cybersecurity law?
Cryptography compliance addresses cryptographic technologies, products, services, testing and import/export questions; cybersecurity compliance addresses network operator, data security, app governance and review duties. A connected product can need both evidence sets.
What is commercial cryptography in China?
Commercial cryptography protects information that does not involve state secrets. The compliance task is to classify the product or service, record whether it is commercial cryptography, and keep supplier/testing evidence for the China-market decision.
When is commercial cryptography testing or certification needed?
Testing or certification analysis is needed when a commercial cryptography product, service, or testing result is part of the China compliance route. The testing institution source says proof-bearing commercial cryptography testing activity depends on qualified testing institutions.