CryptographyChina

China Cryptography Law Compliance deadlines and calendar

Effective dates, annual duties, renewal windows, change notices, and event-driven checks under China's cryptography rules.

There is no single annual filing for every organization. Deadlines depend on the actor and activity: critical information infrastructure, commercial cryptography testing, electronic certification, or a product, service, import, or export.

Author
Sorena AI
Published
Jul 5, 2026
Updated
Jul 25, 2026
Sections
5

Structured answer sets in this page tree.

Primary sources
7

Cited legal and guidance references.

Publication metadata
Sorena AI
Published Jul 5, 2026
Updated Jul 25, 2026
Overview

This calendar separates historical legal milestones, not recurring filing deadlines, from recurring duties, transaction triggers, and system-lifecycle gates. Start with the actor and activity within China; the rules do not impose one cryptography filing calendar on every organization that uses encryption.

Section 1

Which dates apply to your organization?

Identify the activity first. The Cryptography Law defines cryptography as technologies, products, and services that use specified transformations to encrypt information or provide security authentication. It separates core and ordinary cryptography, which protect state-secret information, from , which protects information that is not a state secret.

Additional dates apply if the organization is a recognized , an operator of legally identified (CII), or a licensed . Product, service, import, and export controls are usually triggered by a planned transaction or release rather than a common annual date.

  • General commercial user: screen products, services, systems, and cross-border movements when they are introduced or materially changed; the sources do not set one annual filing for all users.
  • CII operator: report the previous year's use and assessments by 31 January; assess the cryptography application plan, assess again before operation, repeat at least annually after operation, and reassess a plan changed during construction.
  • : track the 15 January annual report, certificate expiry, the three-month renewal lead time, 30-day change filings, annual training, and six-year record retention.
  • : track the five-year licence, the 60-day renewal lead time, 30-day change filings, an assessment at least annually, and annual staff training.
  • Importer or exporter: screen each proposed transaction against the current import-licence and export-control lists; mass-market consumer products are excluded from those controls under Cryptography Law Article 28.
Section 3

Recurring and event-driven deadlines

The fixed and relative deadlines below apply only to the named actor. Convert each relative period into an internal calendar date from the certificate expiry, change date, system stage, or reporting year that starts the clock.

The electronic certification rules concern providers that use to provide electronic certification services in China. Separate rules apply to electronic-government certification services.

  • By 15 January each year: a recognized reports its previous year's work and statistics through the provincial-level cryptography authority.
  • By 31 January each year: a CII operator reports the previous year's use and activity to its .
  • At least once each year: a CII operator completes a after the infrastructure begins operating. Assessment is also required for the application plan, before operation, and again if that plan changes during construction.
  • By 31 March each year: each CII reports the previous year's sector-level CII management to the national cryptography, cybersecurity, and public-security authorities. This is the protection department's deadline, not a universal operator filing date.
  • At least once each year: a licensed conducts a cryptography-compliance assessment, corrects identified problems, and submits the report to the provincial-level cryptography authority where it is domiciled.
  • Three months before expiry: a seeking renewal applies in writing to the National Cryptography Administration. Its qualification certificate is valid for five years.
  • 60 days before expiry: an seeking renewal applies in writing to the National Cryptography Administration. Its licence is valid for five years.
  • Within 30 days after a listed change: a testing body applies to change its record after changes to its name, registered address, legal-person form, named senior or technical roles, authorized signatories, or approved business scope.
  • Within 30 days after a listed change: an electronic-certification licensee completes the change procedure after changes to its name, domicile, legal representative, or relevant equipment or facilities, or after building or relocating its electronic-certification system.
  • Within 30 days after an assessment report is formed: an operator of an important network or information system subject to submits the report and related work information for filing with the national or relevant provincial-level cryptography authority.
  • Every year: testing-body professionals complete at least 40 training hours; relevant electronic-certification technical and security staff complete at least 20 training hours.
  • For at least six years: testing bodies retain original testing records and testing reports.
Section 4

Authority decision periods are not filing deadlines

Some rules give an authority a period to decide an accepted application. These periods help with launch planning but do not extend the applicant's renewal or transaction deadline. Technical review time is excluded where the rule says so. A export with major national-security, public-interest, or foreign-policy implications may be referred to the State Council without the ordinary decision limit.

  • Testing-body qualification: the National Cryptography Administration ordinarily has 20 working days after accepting the application to review it and issue a written decision. Time needed for technical review is excluded, and the applicant must be told that time in writing.
  • Electronic-certification licence intake: the delegated provincial-level cryptography authority has five working days after receiving the application materials to accept a complete, properly formatted application, issue a one-time request for all required corrections, or issue a reasoned non-acceptance notice. This formality check precedes the national authority's decision period.
  • Electronic-certification cryptography licence: the National Cryptography Administration ordinarily has 20 working days after accepting the application to decide it. Time needed for technical review is excluded, and the applicant must be told that time in writing.
  • import or export licence: the competent commerce authority ordinarily has 45 working days after accepting the application to decide it with the National Cryptography Administration. The limit does not apply when an export with major national-security, public-interest, or foreign-policy implications is referred to the State Council.
Section 5

What to calendar and retain

Record the legal trigger beside each date. An internal target is not a statutory deadline unless a law, regulation, licence, certificate, authority notice, or binding decision creates it.

A launch may also trigger cybersecurity, data, personal-information, or sector rules. Reuse verified facts such as the operator, system, product version, data flow, supplier, and release date, but document each legal conclusion separately.

  • Instrument, article, actor, and activity that create the date.
  • Certificate or licence number, scope, issue date, expiry date, and renewal submission date.
  • CII status, application plan, assessment report, remediation, 31 January operator report, filing or submission evidence, and next annual assessment date.
  • Testing-body annual report, staff training records, change filings, original testing records, and testing reports.
  • Electronic-certification annual assessment, remediation, report submission, training records, change filings, and any technical-review notice that affects the expected decision date.
  • Product or service model and version, required test or certification status, supplier evidence, and release approval.
  • Import or export classification, current control-list check, licence application and acceptance dates, any State Council referral, licence decision if required, and transaction date.
Primary sources

References and citations

oscca.gov.cn
Referenced sections
  • The adoption statement and Article 44 support the 26 October 2019 adoption and 1 January 2020 effective dates.
Related guides

Explore more topics

China commercial cryptography compliance checklist
China commercial cryptography checklist covering classification, product and service assurance, CII duties, trade controls, and retained evidence.
China commercial cryptography testing evidence template
Record the legal route, product or system scope, testing-body qualification, report details, gaps, and reassessment triggers for China commercial cryptography assurance.
China cryptography import, export, and security review triage
Screen commercial cryptography imports under the 2020 list, exports under China's unified dual-use list, the consumer exclusion, system assessment, and CII review.
China Cryptography Law FAQ
Answers on China's commercial-cryptography scope, product assurance, classified protection, CII assessment, procurement review, and trade controls.
China Cryptography Law requirements
China commercial cryptography requirements by role: standards, testing, certification, CII use and assessment, trade controls, and evidence.
China Cryptography Law vs Cybersecurity Law
Compare China's Cryptography Law and current Cybersecurity Law by scope, actor, product assurance, CII duties, evidence, and enforcement.
China cryptography penalties, fines, and liability
China commercial cryptography penalties by actor and violation, including fine bands, corrective orders, confiscation, licence action, and liability.
Commercial cryptography procurement checklist
Procurement checks for commercial cryptography products and services used in China, including certificate scope, CII duties, and supplier changes.
Commercial cryptography products and testing evidence
When China commercial cryptography testing or certification is voluntary or mandatory, and what product, service, body, and scope evidence to keep.
Do imported cryptography products need special review?
Not every encrypted product imported into China needs a licence. Check the 2020 commercial-cryptography import list, the consumer-product exception, and any CII procurement review.
Does using encryption trigger China Cryptography Law duties?
Using encryption does not create one universal China approval duty. Check classified protection, product, service, CII, procurement, and trade triggers.
How does cryptography compliance overlap with China cybersecurity law?
See how China's cryptography rules connect with classified protection, product assurance, CII assessment, and cybersecurity review without merging the regimes.
What is commercial cryptography in China?
Commercial cryptography protects information that is not a state secret. Learn how China defines the category and which separate facts trigger product, CII, or trade controls.
When is commercial cryptography testing or certification needed?
Commercial-cryptography assurance is often voluntary, but specified products and services require it. Covered CII also needs application assessment and qualified cryptography.