---
title: "China cryptography compliance deadlines and calendar"
canonical_url: "https://www.sorena.io/artifacts/apac/china-cryptography-law/deadlines-and-compliance-calendar"
source_url: "https://www.sorena.io/artifacts/apac/china-cryptography-law/deadlines-and-compliance-calendar"
author: "Sorena AI"
description: "China cryptography effective dates, CII reports, annual assessments, licence renewals, change notices, and pre-operation checks."
published_at: "2026-07-05"
updated_at: "2026-07-25"
keywords:
  - "China cryptography deadlines"
  - "Cryptography Law effective date"
  - "commercial cryptography calendar"
  - "CII cryptography assessment"
  - "cryptography testing body report"
  - "China Cryptography Law"
  - "Commercial cryptography"
  - "Cryptography Law"
  - "Commercial cryptography testing"
  - "China cybersecurity"
---
**[SORENA](https://www.sorena.io/)** - AI-Powered GRC Platform

[Home](https://www.sorena.io/) | [Solutions](https://www.sorena.io/solutions) | [Artifacts](https://www.sorena.io/artifacts) | [About Us](https://www.sorena.io/about-us) | [Contact](https://www.sorena.io/contact) | [Portal](https://app.sorena.io)

---

# China cryptography compliance deadlines and calendar

China cryptography effective dates, CII reports, annual assessments, licence renewals, change notices, and pre-operation checks.

*Cryptography* *China*

## China Cryptography Law Compliance deadlines and calendar

Effective dates, annual duties, renewal windows, change notices, and event-driven checks under China's cryptography rules.

There is no single annual filing for every organization. Deadlines depend on the actor and activity: critical information infrastructure, commercial cryptography testing, electronic certification, or a product, service, import, or export.

This commercial cryptography calendar separates historical legal milestones, not recurring filing deadlines, from recurring duties, transaction triggers, and system-lifecycle gates. Start with the actor and activity within China; the rules do not impose one cryptography filing calendar on every organization that uses encryption.

## Definitions

### Commercial cryptography

Under the PRC Cryptography Law, commercial cryptography is cryptography used to protect information that is not a state secret. It can include technologies, products, and services that use specified transformations to encrypt information or provide security authentication. Core and ordinary cryptography are separate categories used to protect state-secret information.

**Why it matters here:** The deadlines on this page concern commercial cryptography activities. A team must still identify the product, service, system, operator status, transaction, or licensed activity that creates a specific date; ordinary use of encryption does not create one universal annual filing.

Sources:

- [PRC Cryptography Law, Articles 2 and 6-8](https://www.oscca.gov.cn/sca/xxgk/2023-06/04/content_1057225.shtml?ref=sorena.io)

### Critical information infrastructure (CII)

**Term:** critical information infrastructure

For this page, critical information infrastructure means infrastructure identified as CII under China's Cybersecurity Law, the Critical Information Infrastructure Security Protection Regulation, and related rules. The 2025 commercial cryptography provisions apply to infrastructure that has been identified through that legal framework, not automatically to every important network or every network operator.

**Why it matters here:** Once an organization operates identified CII, the operator-specific calendar includes a report by 31 January, assessments at the planning and pre-operation stages, reassessment after a plan change during construction, and an assessment at least once each year after operation.

Sources:

- [CII Commercial Cryptography Use Management Provisions, Articles 2, 5, and 11-13](https://www.oscca.gov.cn/sca/xxgk/2025-06/27/content_1061270.shtml?ref=sorena.io)

### Recognized commercial cryptography testing body

**Term:** commercial cryptography testing body

A commercial cryptography testing body is a legal entity recognized by the National Cryptography Administration to conduct approved commercial cryptography testing and issue data or results that serve as proof to the public. Its approved scope may cover commercial cryptography product testing, commercial cryptography application security assessments for networks and information systems, or both. A consultant or internal test team is not a recognized testing body merely because it performs technical testing.

**Why it matters here:** Recognition creates the testing-body dates on this page, including certificate renewal, change procedures, annual reporting and training, and minimum record retention. Those dates do not apply to every organization that buys or uses cryptography.

Sources:

- [Commercial Cryptography Testing Body Management Measures, Articles 3, 5, and 11-20](https://www.oscca.gov.cn/sca/xxgk/2023-10/07/content_1061108.shtml?ref=sorena.io)

### Commercial cryptography application security assessment

A commercial cryptography application security assessment evaluates whether a network or information system uses commercial cryptography technologies, products, and services compliantly, correctly, and effectively. For CII, the operator may conduct the assessment itself or engage a recognized commercial cryptography testing body, subject to the applicable assessment rules.

**Why it matters here:** For identified CII, the assessment is a lifecycle control rather than a single certificate: it applies to the application plan, before operation, after a plan change during construction, and at least annually after operation. A failed plan cannot be used as the construction basis, and infrastructure that fails the pre-operation assessment must be remediated before it starts operating.

Sources:

- [Commercial Cryptography Administration Regulation, Articles 38 and 42](https://www.mee.gov.cn/zcwj/gwywj/202305/t20230529_1031579.shtml?ref=sorena.io)
- [CII Commercial Cryptography Use Management Provisions, Articles 11-15](https://www.oscca.gov.cn/sca/xxgk/2025-06/27/content_1061270.shtml?ref=sorena.io)

### Licensed electronic certification provider

**Term:** electronic certification provider

An electronic certification provider uses commercial cryptography to provide electronic certification services in China and must hold an Electronic Certification Service Cryptography Use Licence issued by the National Cryptography Administration. This route is distinct from the separate qualification for an institution providing electronic-government electronic certification services.

**Why it matters here:** The five-year licence, 60-day renewal lead time, 30-day change procedure, annual compliance assessment, report submission, and annual staff-training hours on this page apply to the licensed provider, not to every organization that uses digital certificates or electronic signatures.

Sources:

- [Electronic Certification Service Cryptography Use Management Measures, Articles 2-3 and 10-17](https://www.oscca.gov.cn/sca/xxgk/2026-06/03/content_1061341.shtml?ref=sorena.io)

### Critical information infrastructure protection department

**Term:** protection department

A protection department is the government department responsible, under the national division of duties, for security protection of CII in its industry or field. It supervises operators, receives their annual commercial-cryptography reports, reports sector-level information to the national authorities, and responds to major cryptography-related cybersecurity events and threats.

**Why it matters here:** The operator sends its previous-year report to its protection department by 31 January. The protection department, not the operator, sends the sector-level report to the national cryptography, cybersecurity, and public-security authorities by 31 March.

Sources:

- [CII Commercial Cryptography Use Management Provisions, Articles 4-5](https://www.oscca.gov.cn/sca/xxgk/2025-06/27/content_1061270.shtml?ref=sorena.io)

## Which dates apply to your organization?

Identify the activity first. The Cryptography Law defines cryptography as technologies, products, and services that use specified transformations to encrypt information or provide security authentication. It separates core and ordinary cryptography, which protect state-secret information, from commercial cryptography, which protects information that is not a state secret.

Additional dates apply if the organization is a recognized commercial cryptography testing body, an operator of legally identified critical information infrastructure (CII), or a licensed electronic certification provider. Product, service, import, and export controls are usually triggered by a planned transaction or release rather than a common annual date.

- General commercial user: screen products, services, systems, and cross-border movements when they are introduced or materially changed; the sources do not set one annual filing for all users.
- CII operator: report the previous year's use and assessments by 31 January; assess the cryptography application plan, assess again before operation, repeat at least annually after operation, and reassess a plan changed during construction.
- Commercial cryptography testing body: track the 15 January annual report, certificate expiry, the three-month renewal lead time, 30-day change filings, annual training, and six-year record retention.
- Electronic certification provider: track the five-year licence, the 60-day renewal lead time, 30-day change filings, an assessment at least annually, and annual staff training.
- Importer or exporter: screen each proposed transaction against the current import-licence and export-control lists; mass-market consumer products are excluded from those controls under Cryptography Law Article 28.

Sources for this answer:

- [PRC Cryptography Law](https://www.oscca.gov.cn/sca/xxgk/2023-06/04/content_1057225.shtml?ref=sorena.io) - Articles 2, 6, 8, and 24-28 define the categories and establish the commercial cryptography, CII, testing, certification, and import/export routes.
- [Commercial Cryptography Administration Regulation, State Council Order No. 760](https://www.mee.gov.cn/zcwj/gwywj/202305/t20230529_1031579.shtml?ref=sorena.io) - Articles 2 and 12-42 set the current scope and the testing, certification, electronic certification, application-assessment, CII, and network-operator framework.

## Legal milestones

Adoption, promulgation, and effectiveness are different events. Use the effective date to identify when an instrument began to apply; do not describe the earlier adoption or promulgation date as a compliance deadline.

- 26 October 2019: the Standing Committee of the National People's Congress adopted the Cryptography Law.
- 1 January 2020: the Cryptography Law took effect under Article 44.
- 14 April 2023: the State Council executive meeting approved the revised Commercial Cryptography Administration Regulation draft.
- Label 27 April 2023 as promulgation: State Council Order No. 760 promulgated the revised regulation.
- Label 1 July 2023 as the revised regulation effective date: the revised Commercial Cryptography Administration Regulation took effect.
- 1 November 2023: the Commercial Cryptography Testing Body Management Measures took effect.
- 1 August 2025: the CII Commercial Cryptography Use Management Provisions took effect.
- 1 July 2026: the Electronic Certification Service Cryptography Use Management Measures took effect and replaced the 2009 measures as amended in 2017.
- CII already under construction on 1 August 2025: Article 14 requires the operator to strengthen the application-plan analysis, complete the cryptography protection system, and follow the pre-operation assessment rule in Article 12. CII already operating on that date follows the at-least-annual assessment rule in Article 13; Article 14 does not set a separate one-time transition date.

Sources for this answer:

- [PRC Cryptography Law](https://www.oscca.gov.cn/sca/xxgk/2023-06/04/content_1057225.shtml?ref=sorena.io) - The adoption statement and Article 44 support the 26 October 2019 adoption and 1 January 2020 effective dates.
- [Official notice on the Commercial Cryptography Administration Regulation interpretation](https://www.oscca.gov.cn/sca/xwdt/2023-12/05/content_1061145.shtml?ref=sorena.io) - Supports the regulation's 14 April 2023 approval, 27 April 2023 promulgation, and 1 July 2023 effective date.
- [Commercial Cryptography Testing Body Management Measures, Order No. 2](https://www.oscca.gov.cn/sca/xxgk/2023-10/07/content_1061108.shtml?ref=sorena.io) - Article 29 states that the measures took effect on 1 November 2023.
- [CII Commercial Cryptography Use Management Provisions, Order No. 5](https://www.oscca.gov.cn/sca/xxgk/2025-06/27/content_1061270.shtml?ref=sorena.io) - Article 25 states that the provisions took effect on 1 August 2025.
- [Electronic Certification Service Cryptography Use Management Measures, Order No. 6](https://www.oscca.gov.cn/sca/xxgk/2026-06/03/content_1061341.shtml?ref=sorena.io) - Article 25 states the 1 July 2026 effective date and repeal of the earlier measures.

## Recurring and event-driven deadlines

The fixed and relative deadlines below apply only to the named actor. Convert each relative period into an internal calendar date from the certificate expiry, change date, system stage, or reporting year that starts the clock.

The electronic certification rules concern providers that use commercial cryptography to provide electronic certification services in China. Separate rules apply to electronic-government certification services.

- By 15 January each year: a recognized commercial cryptography testing body reports its previous year's work and statistics through the provincial-level cryptography authority.
- By 31 January each year: a CII operator reports the previous year's commercial cryptography use and commercial cryptography application security assessment activity to its protection department.
- At least once each year: a CII operator completes a commercial cryptography application security assessment after the infrastructure begins operating. Assessment is also required for the application plan, before operation, and again if that plan changes during construction.
- By 31 March each year: each CII protection department reports the previous year's sector-level CII commercial cryptography management to the national cryptography, cybersecurity, and public-security authorities. This is the protection department's deadline, not a universal operator filing date.
- At least once each year: a licensed electronic certification provider conducts a cryptography-compliance assessment, corrects identified problems, and submits the report to the provincial-level cryptography authority where it is domiciled.
- Three months before expiry: a commercial cryptography testing body seeking renewal applies in writing to the National Cryptography Administration. Its qualification certificate is valid for five years.
- 60 days before expiry: an electronic certification provider seeking renewal applies in writing to the National Cryptography Administration. Its licence is valid for five years.
- Within 30 days after a listed change: a testing body applies to change its record after changes to its name, registered address, legal-person form, named senior or technical roles, authorized signatories, or approved business scope.
- Within 30 days after a listed change: an electronic-certification licensee completes the change procedure after changes to its name, domicile, legal representative, or relevant equipment or facilities, or after building or relocating its electronic-certification system.
- Within 30 days after an assessment report is formed: an operator of an important network or information system subject to commercial cryptography application security assessment submits the report and related work information for filing with the national or relevant provincial-level cryptography authority.
- Every year: testing-body professionals complete at least 40 training hours; relevant electronic-certification technical and security staff complete at least 20 training hours.
- For at least six years: commercial cryptography testing bodies retain original testing records and testing reports.

Sources for this answer:

- [Commercial Cryptography Testing Body Management Measures, Order No. 2](https://www.oscca.gov.cn/sca/xxgk/2023-10/07/content_1061108.shtml?ref=sorena.io) - Articles 12, 13, 17, 19, and 20 establish the five-year certificate, three-month renewal lead time, 30-day change procedure, annual 40-hour training, six-year retention, and 15 January report.
- [CII Commercial Cryptography Use Management Provisions, Order No. 5](https://www.oscca.gov.cn/sca/xxgk/2025-06/27/content_1061270.shtml?ref=sorena.io) - Articles 4, 5, and 11-14 establish the 31 January operator report, 31 March protection-department report, and the plan-stage, construction-change, pre-operation, and at-least-annual CII assessment duties.
- [Electronic Certification Service Cryptography Use Management Measures, Order No. 6](https://www.oscca.gov.cn/sca/xxgk/2026-06/03/content_1061341.shtml?ref=sorena.io) - Articles 10-12, 16, and 17 establish the five-year licence, 30-day change procedure, 60-day renewal lead time, annual assessment, and annual 20-hour training.
- [Commercial Cryptography Application Security Assessment Management Measures, Order No. 3](https://www.oscca.gov.cn/sca/xxgk/2023-10/07/content_1061109.shtml?ref=sorena.io) - Article 14 requires an operator of an important network or information system to submit an assessment report and related work information within 30 days after the report is formed.

## Authority decision periods are not filing deadlines

Some rules give an authority a period to decide an accepted application. These periods help with launch planning but do not extend the applicant's renewal or transaction deadline. Technical review time is excluded where the rule says so. A commercial cryptography export with major national-security, public-interest, or foreign-policy implications may be referred to the State Council without the ordinary decision limit.

- Testing-body qualification: the National Cryptography Administration ordinarily has 20 working days after accepting the application to review it and issue a written decision. Time needed for technical review is excluded, and the applicant must be told that time in writing.
- Electronic-certification licence intake: the delegated provincial-level cryptography authority has five working days after receiving the application materials to accept a complete, properly formatted application, issue a one-time request for all required corrections, or issue a reasoned non-acceptance notice. This formality check precedes the national authority's decision period.
- Electronic-certification cryptography licence: the National Cryptography Administration ordinarily has 20 working days after accepting the application to decide it. Time needed for technical review is excluded, and the applicant must be told that time in writing.
- Commercial cryptography import or export licence: the competent commerce authority ordinarily has 45 working days after accepting the application to decide it with the National Cryptography Administration. The limit does not apply when an export with major national-security, public-interest, or foreign-policy implications is referred to the State Council.

Sources for this answer:

- [Commercial Cryptography Testing Body Management Measures, Order No. 2](https://www.oscca.gov.cn/sca/xxgk/2023-10/07/content_1061108.shtml?ref=sorena.io) - Article 8 establishes the 20-working-day testing-body decision period and excludes technical-review time.
- [Electronic Certification Service Cryptography Use Management Measures, Order No. 6](https://www.oscca.gov.cn/sca/xxgk/2026-06/03/content_1061341.shtml?ref=sorena.io) - Articles 7-8 establish the five-working-day formality review, the 20-working-day electronic-certification licence decision period, and the exclusion of technical-review time.
- [Commercial Cryptography Administration Regulation, State Council Order No. 760](https://www.mee.gov.cn/zcwj/gwywj/202305/t20230529_1031579.shtml?ref=sorena.io) - Article 34 establishes the 45-working-day import/export licence period and the State Council referral exception.

## What to calendar and retain

Record the legal trigger beside each date. An internal target is not a statutory deadline unless a law, regulation, licence, certificate, authority notice, or binding decision creates it.

A launch may also trigger cybersecurity, data, personal-information, or sector rules. Reuse verified facts such as the operator, system, product version, data flow, supplier, and release date, but document each legal conclusion separately.

- Instrument, article, actor, and activity that create the date.
- Certificate or licence number, scope, issue date, expiry date, and renewal submission date.
- CII status, application plan, assessment report, remediation, 31 January operator report, filing or submission evidence, and next annual assessment date.
- Testing-body annual report, staff training records, change filings, original testing records, and testing reports.
- Electronic-certification annual assessment, remediation, report submission, training records, change filings, and any technical-review notice that affects the expected decision date.
- Product or service model and version, required test or certification status, supplier evidence, and release approval.
- Import or export classification, current control-list check, licence application and acceptance dates, any State Council referral, licence decision if required, and transaction date.

Sources for this answer:

- [Commercial Cryptography Administration Regulation, State Council Order No. 760](https://www.mee.gov.cn/zcwj/gwywj/202305/t20230529_1031579.shtml?ref=sorena.io) - Articles 13-21 and 38-42 identify the qualification, certification, CII assessment, and network-security records that determine the applicable route.
- [Commercial Cryptography Testing Body Management Measures, Order No. 2](https://www.oscca.gov.cn/sca/xxgk/2023-10/07/content_1061108.shtml?ref=sorena.io) - Articles 12-20 identify testing-body certificate, change, training, report, and retention records.

*Operationalize the requirement*

*Placement: Before primary sources*

## Prepare the commercial cryptography evidence file

Sorena AI helps map each China cryptography deadline to its legal trigger, owner, evidence, and next review date.

- [Map official sources to evidence](/solutions/research-copilot.md): Research Copilot connects the official citation, decision, owner, retained evidence, and change history.
- [Review the China route](/contact.md): Check the China Cryptography Law scope decision and unresolved launch questions with Sorena.

## Primary sources

- [PRC Cryptography Law](https://www.oscca.gov.cn/sca/xxgk/2023-06/04/content_1057225.shtml?ref=sorena.io) - Primary law for cryptography categories, commercial cryptography duties, CII use, testing and certification, import/export controls, and the 1 January 2020 effective date.
- [Commercial Cryptography Administration Regulation, State Council Order No. 760](https://www.mee.gov.cn/zcwj/gwywj/202305/t20230529_1031579.shtml?ref=sorena.io) - Current administrative regulation for commercial cryptography activities, testing, certification, CII assessments, network operators, and supervision.
- [Commercial Cryptography Testing Body Management Measures, Order No. 2](https://www.oscca.gov.cn/sca/xxgk/2023-10/07/content_1061108.shtml?ref=sorena.io) - Current testing-body qualification, reporting, renewal, change, training, and retention rules.
- [CII Commercial Cryptography Use Management Provisions, Order No. 5](https://www.oscca.gov.cn/sca/xxgk/2025-06/27/content_1061270.shtml?ref=sorena.io) - Current CII planning, construction, pre-operation, annual assessment, reporting, and enforcement rules.
- [Electronic Certification Service Cryptography Use Management Measures, Order No. 6](https://www.oscca.gov.cn/sca/xxgk/2026-06/03/content_1061341.shtml?ref=sorena.io) - Current electronic-certification licence, renewal, change, annual assessment, training, and enforcement rules from 1 July 2026.
- [Commercial Cryptography Application Security Assessment Management Measures, Order No. 3](https://www.oscca.gov.cn/sca/xxgk/2023-10/07/content_1061109.shtml?ref=sorena.io) - Assessment process, evidence retention, and the 30-day assessment-report filing period for important networks and information systems.

## Related Topic Guides

- [China commercial cryptography compliance checklist](/artifacts/apac/china-cryptography-law/checklist.md): China commercial cryptography checklist covering classification, product and service assurance, CII duties, trade controls, and retained evidence.
- [China commercial cryptography testing evidence template](/artifacts/apac/china-cryptography-law/commercial-cryptography-testing-evidence-template.md): Record the legal route, product or system scope, testing-body qualification, report details, gaps, and reassessment triggers for China commercial cryptography assurance.
- [China cryptography import, export, and security review triage](/artifacts/apac/china-cryptography-law/import-export-and-security-assessment.md): Screen commercial cryptography imports under the 2020 list, exports under China's unified dual-use list, the consumer exclusion, system assessment, and CII review.
- [China Cryptography Law FAQ](/artifacts/apac/china-cryptography-law/faq.md): Answers on China's commercial-cryptography scope, product assurance, classified protection, CII assessment, procurement review, and trade controls.
- [China Cryptography Law requirements](/artifacts/apac/china-cryptography-law/requirements.md): China commercial cryptography requirements by role: standards, testing, certification, CII use and assessment, trade controls, and evidence.
- [China Cryptography Law vs Cybersecurity Law](/artifacts/apac/china-cryptography-law/china-cryptography-law-vs-cybersecurity-law.md): Compare China's Cryptography Law and current Cybersecurity Law by scope, actor, product assurance, CII duties, evidence, and enforcement.
- [China cryptography penalties, fines, and liability](/artifacts/apac/china-cryptography-law/penalties-and-fines.md): China commercial cryptography penalties by actor and violation, including fine bands, corrective orders, confiscation, licence action, and liability.
- [Commercial cryptography procurement checklist](/artifacts/apac/china-cryptography-law/commercial-cryptography-procurement-checklist.md): Procurement checks for commercial cryptography products and services used in China, including certificate scope, CII duties, and supplier changes.
- [Commercial cryptography products and testing evidence](/artifacts/apac/china-cryptography-law/commercial-cryptography-products-and-testing.md): When China commercial cryptography testing or certification is voluntary or mandatory, and what product, service, body, and scope evidence to keep.
- [Do imported cryptography products need special review?](/artifacts/apac/china-cryptography-law/faq/do-imported-cryptography-products-need-special-review.md): Not every encrypted product imported into China needs a licence. Check the 2020 commercial-cryptography import list, the consumer-product exception, and any CII procurement review.
- [Does using encryption trigger China Cryptography Law duties?](/artifacts/apac/china-cryptography-law/faq/does-using-encryption-trigger-china-cryptography-law.md): Using encryption does not create one universal China approval duty. Check classified protection, product, service, CII, procurement, and trade triggers.
- [How does cryptography compliance overlap with China cybersecurity law?](/artifacts/apac/china-cryptography-law/faq/how-does-cryptography-compliance-overlap-with-cybersecurity-law.md): See how China's cryptography rules connect with classified protection, product assurance, CII assessment, and cybersecurity review without merging the regimes.
- [What is commercial cryptography in China?](/artifacts/apac/china-cryptography-law/faq/what-is-commercial-cryptography-in-china.md): Commercial cryptography protects information that is not a state secret. Learn how China defines the category and which separate facts trigger product, CII, or trade controls.
- [When is commercial cryptography testing or certification needed?](/artifacts/apac/china-cryptography-law/faq/when-is-commercial-cryptography-testing-or-certification-needed.md): Commercial-cryptography assurance is often voluntary, but specified products and services require it. Covered CII also needs application assessment and qualified cryptography.


---

[Privacy Policy](https://www.sorena.io/privacy.md) | [Terms of Use](https://www.sorena.io/terms-of-use.md) | [DMCA](https://www.sorena.io/dmca.md) | [About Us](https://www.sorena.io/about-us.md)

(c) 2026 Sorena AB (559573-7338). All rights reserved.

Source: https://www.sorena.io/artifacts/apac/china-cryptography-law/deadlines-and-compliance-calendar.md
