Answers on commercial-cryptography classification, product and service assurance, CII assessment, procurement review, and import or export controls.
Use the answers to identify the applicable route and the facts to retain. Product catalogues, import and export lists, classified-protection requirements, and CII conclusions still need a current, fact-specific check.
Classify first, then distinguish ordinary lawful use from the separate triggers for product or service assurance, electronic-certification permission, classified-protection requirements, assessment, procurement review, and import or export controls.
Browse sub-FAQs
Choose the question set you need
These focused FAQ modules break this artifact into narrower answer sets so teams can move straight to the right source-backed guidance.
Start by identifying whether the technology, product, or service uses specific transformations for encryption protection or security authentication. Then determine whether it protects state-secret information or information that is not a state secret. is the category for the latter.
Commercial-cryptography status alone does not determine whether testing, certification, assessment, review, or a licence is mandatory. Articles 25-28 of the law set several routes, and the 2023 implementing regulation adds electronic-certification, classified-protection, and detailed application requirements.
The responsible actor changes by route. An ordinary user may lawfully choose ; a network operator must apply the classified-protection requirements for its network; a covered operator has additional application and procurement duties; and a supplier, electronic-certification service provider, importer, or exporter must check the rules for its own activity.
What is , and how does it differ from core and ordinary cryptography?
Does using encryption create a mandatory approval or certification duty?
When does Article 26 product or service assurance become mandatory?
What commercial-cryptography requirements follow from the network-security ?
When does a use or procurement trigger Article 27 assessment or national-security review?
When do Article 28 import/export lists or the mass-market consumer-product exception matter?
An FAQ answer cannot determine whether a specific product appears in a current catalogue or control list. Record the exact item, supplier, operator, use, source version and check date, conclusion, and unresolved questions.
Keep broader network-security and data-law conclusions separate even when they use the same technical facts. The implementing regulation links to classified protection, assessment, and procurement review, but it does not merge the legal regimes.
Exact product, service, component, model and version, cryptographic function, supplier, operator, and use.
Commercial-cryptography category and protected-information conclusion.
Article 26 product/service route and assurance evidence, if applicable.
Classified-protection level and the corresponding commercial-cryptography use, management, and assessment requirements.
Article 27 and national-security-review conclusions, if applicable.
Current import-list or export-list entry and exception conclusion, if applicable.
Reviewer, source, approval date, gaps, and change triggers.
Each answer below states the controlling rule first. A specific product, system, operator, or shipment still needs a current catalogue, list, protection-level, or operator-status check.
What is , and how does it differ from core and ordinary cryptography?
protects information that is not a state secret through cryptographic technologies, products, or services used for encryption protection or security authentication. Core and ordinary cryptography protect state-secret information and are subject to a separate classified regime. The word commercial identifies the legal category; it does not mean that the protected information must be sold or used for profit.
Does using encryption create a mandatory approval or certification duty?
No. Citizens, legal persons, and other organizations may lawfully use to protect network and information security. Testing and certification are generally encouraged voluntarily. A mandatory route needs an additional trigger, such as a catalogue-covered network product, a service using that product, a network or information system required by national rules to use commercial cryptography, a qualifying use or procurement, a listed import or export, or an electronic certification service that uses commercial cryptography.
When is product or service assurance mandatory under Article 26?
A product must pass qualified testing and certification before sale or provision when it is legally included in the catalogue of . A commercial cryptography service must be certified when it uses equipment or products in that catalogue. A listing in a separate commercial cryptography product certification catalogue does not by itself establish the Article 26 trigger.
Does an electronic certification service need a cryptography licence?
Yes, when a provider uses to provide electronic certification services in China. Since 1 July 2026, the provider must hold an Electronic Certification Service Cryptography Use Licence from the National Cryptography Administration. The licence is valid for five years, renewal requires an application 60 days before expiry, listed changes require a change procedure within 30 days, and the provider must conduct a cryptography-compliance assessment at least annually. Electronic-government electronic certification services follow a separate provider-qualification route.
When is a required?
The assessment is required for a network or information system that a law, administrative regulation, or national provision requires to use protection. The operator must assess the commercial cryptography application plan, must not operate a completed system that has failed the pre-operation assessment, and must assess the operating system at least annually. A covered operator may self-assess only when it has the equipment, governance, personnel, and professional capability required by the Assessment Measures; otherwise it must commission a qualified commercial cryptography testing body.
Does every network with a classified-protection level have the same duties as ?
No. A network operator must apply the requirements associated with China's and its confirmed protection level. is a separately identified category with additional governance, product, technology, assessment, reporting, and procurement-review duties. A classified-protection level does not by itself prove that the network is CII.
Does the mass-market consumer-product exclusion remove all China cryptography duties?
No. The exclusion removes used in from the Cryptography Law's import-licensing and export-control system. It does not decide product certification, network use, application security assessment, procurement review, or other cybersecurity duties. Because the cited legislation does not provide a complete product test, document the actual model, retail availability, intended users, distribution restrictions, and whether its cryptographic function can readily be changed before relying on the exclusion.
The official interpretation explains the qualification and supervision of bodies that issue proof-bearing product-testing or application-security-assessment results.
Articles 2-3, 10-12, 16-17, and 25 support the licensing trigger, five-year term, 60-day renewal lead time, 30-day change procedure, annual assessment, separate electronic-government route, and 1 July 2026 effective date.
Articles 6-8 and 25-28 support the classification, lawful-use answer, voluntary and mandatory assurance routes, CII assessment and procurement routes, and trade exclusion.