FAQChina

China Cryptography Law FAQ

Answers on commercial-cryptography classification, product and service assurance, CII assessment, procurement review, and import or export controls.

Use the answers to identify the applicable route and the facts to retain. Product catalogues, import and export lists, classified-protection requirements, and CII conclusions still need a current, fact-specific check.

Author
Sorena AI
Published
Jul 5, 2026
Updated
Jul 25, 2026
FAQ modules
5

Structured answer sets in this page tree.

Primary sources
5

Cited legal and guidance references.

Publication metadata
Sorena AI
Published Jul 5, 2026
Updated Jul 25, 2026
Overview

Classify first, then distinguish ordinary lawful use from the separate triggers for product or service assurance, electronic-certification permission, classified-protection requirements, assessment, procurement review, and import or export controls.

Browse sub-FAQs

Choose the question set you need

These focused FAQ modules break this artifact into narrower answer sets so teams can move straight to the right source-backed guidance.

Browse all FAQ items15
Focused FAQ modules
5
Showing 5 of 5
Question 1

Which decision comes first?

Start by identifying whether the technology, product, or service uses specific transformations for encryption protection or security authentication. Then determine whether it protects state-secret information or information that is not a state secret. is the category for the latter.

Commercial-cryptography status alone does not determine whether testing, certification, assessment, review, or a licence is mandatory. Articles 25-28 of the law set several routes, and the 2023 implementing regulation adds electronic-certification, classified-protection, and detailed application requirements.

The responsible actor changes by route. An ordinary user may lawfully choose ; a network operator must apply the classified-protection requirements for its network; a covered operator has additional application and procurement duties; and a supplier, electronic-certification service provider, importer, or exporter must check the rules for its own activity.

  • What is , and how does it differ from core and ordinary cryptography?
  • Does using encryption create a mandatory approval or certification duty?
  • When does Article 26 product or service assurance become mandatory?
  • What commercial-cryptography requirements follow from the network-security ?
  • When does a use or procurement trigger Article 27 assessment or national-security review?
  • When do Article 28 import/export lists or the mass-market consumer-product exception matter?
Question 2

What should a decision record contain?

An FAQ answer cannot determine whether a specific product appears in a current catalogue or control list. Record the exact item, supplier, operator, use, source version and check date, conclusion, and unresolved questions.

Keep broader network-security and data-law conclusions separate even when they use the same technical facts. The implementing regulation links to classified protection, assessment, and procurement review, but it does not merge the legal regimes.

  • Exact product, service, component, model and version, cryptographic function, supplier, operator, and use.
  • Commercial-cryptography category and protected-information conclusion.
  • Article 26 product/service route and assurance evidence, if applicable.
  • Classified-protection level and the corresponding commercial-cryptography use, management, and assessment requirements.
  • Article 27 and national-security-review conclusions, if applicable.
  • Current import-list or export-list entry and exception conclusion, if applicable.
  • Reviewer, source, approval date, gaps, and change triggers.
Question 3

Direct answers to common scope questions

Each answer below states the controlling rule first. A specific product, system, operator, or shipment still needs a current catalogue, list, protection-level, or operator-status check.

What is , and how does it differ from core and ordinary cryptography?

protects information that is not a state secret through cryptographic technologies, products, or services used for encryption protection or security authentication. Core and ordinary cryptography protect state-secret information and are subject to a separate classified regime. The word commercial identifies the legal category; it does not mean that the protected information must be sold or used for profit.

Does using encryption create a mandatory approval or certification duty?

No. Citizens, legal persons, and other organizations may lawfully use to protect network and information security. Testing and certification are generally encouraged voluntarily. A mandatory route needs an additional trigger, such as a catalogue-covered network product, a service using that product, a network or information system required by national rules to use commercial cryptography, a qualifying use or procurement, a listed import or export, or an electronic certification service that uses commercial cryptography.

When is product or service assurance mandatory under Article 26?

A product must pass qualified testing and certification before sale or provision when it is legally included in the catalogue of . A commercial cryptography service must be certified when it uses equipment or products in that catalogue. A listing in a separate commercial cryptography product certification catalogue does not by itself establish the Article 26 trigger.

Does an electronic certification service need a cryptography licence?

Yes, when a provider uses to provide electronic certification services in China. Since 1 July 2026, the provider must hold an Electronic Certification Service Cryptography Use Licence from the National Cryptography Administration. The licence is valid for five years, renewal requires an application 60 days before expiry, listed changes require a change procedure within 30 days, and the provider must conduct a cryptography-compliance assessment at least annually. Electronic-government electronic certification services follow a separate provider-qualification route.

When is a required?

The assessment is required for a network or information system that a law, administrative regulation, or national provision requires to use protection. The operator must assess the commercial cryptography application plan, must not operate a completed system that has failed the pre-operation assessment, and must assess the operating system at least annually. A covered operator may self-assess only when it has the equipment, governance, personnel, and professional capability required by the Assessment Measures; otherwise it must commission a qualified commercial cryptography testing body.

Does every network with a classified-protection level have the same duties as ?

No. A network operator must apply the requirements associated with China's and its confirmed protection level. is a separately identified category with additional governance, product, technology, assessment, reporting, and procurement-review duties. A classified-protection level does not by itself prove that the network is CII.

Does the mass-market consumer-product exclusion remove all China cryptography duties?

No. The exclusion removes used in from the Cryptography Law's import-licensing and export-control system. It does not decide product certification, network use, application security assessment, procurement review, or other cybersecurity duties. Because the cited legislation does not provide a complete product test, document the actual model, retail availability, intended users, distribution restrictions, and whether its cryptographic function can readily be changed before relying on the exclusion.

Primary sources

References and citations

oscca.gov.cn
Referenced sections
  • Articles 6-8 and 25-28 support the classification, lawful-use answer, voluntary and mandatory assurance routes, CII assessment and procurement routes, and trade exclusion.
Related guides

Explore more topics

China commercial cryptography compliance checklist
China commercial cryptography checklist covering classification, product and service assurance, CII duties, trade controls, and retained evidence.
China commercial cryptography testing evidence template
Record the legal route, product or system scope, testing-body qualification, report details, gaps, and reassessment triggers for China commercial cryptography assurance.
China cryptography compliance deadlines and calendar
China cryptography effective dates, CII reports, annual assessments, licence renewals, change notices, and pre-operation checks.
China cryptography import, export, and security review triage
Screen commercial cryptography imports under the 2020 list, exports under China's unified dual-use list, the consumer exclusion, system assessment, and CII review.
China Cryptography Law requirements
China commercial cryptography requirements by role: standards, testing, certification, CII use and assessment, trade controls, and evidence.
China Cryptography Law vs Cybersecurity Law
Compare China's Cryptography Law and current Cybersecurity Law by scope, actor, product assurance, CII duties, evidence, and enforcement.
China cryptography penalties, fines, and liability
China commercial cryptography penalties by actor and violation, including fine bands, corrective orders, confiscation, licence action, and liability.
Commercial cryptography procurement checklist
Procurement checks for commercial cryptography products and services used in China, including certificate scope, CII duties, and supplier changes.
Commercial cryptography products and testing evidence
When China commercial cryptography testing or certification is voluntary or mandatory, and what product, service, body, and scope evidence to keep.