---
title: "China Cryptography Law FAQ"
canonical_url: "https://www.sorena.io/artifacts/apac/china-cryptography-law/faq"
source_url: "https://www.sorena.io/artifacts/apac/china-cryptography-law/faq"
author: "Sorena AI"
description: "Answers on China's commercial-cryptography scope, product assurance, classified protection, CII assessment, procurement review, and trade controls."
published_at: "2026-07-05"
updated_at: "2026-07-25"
keywords:
  - "China Cryptography Law"
  - "Commercial cryptography"
  - "Cryptography Law"
  - "Commercial cryptography testing"
  - "China cybersecurity"
---
**[SORENA](https://www.sorena.io/)** - AI-Powered GRC Platform

[Home](https://www.sorena.io/) | [Solutions](https://www.sorena.io/solutions) | [Artifacts](https://www.sorena.io/artifacts) | [About Us](https://www.sorena.io/about-us) | [Contact](https://www.sorena.io/contact) | [Portal](https://app.sorena.io)

---

# China Cryptography Law FAQ

Answers on China's commercial-cryptography scope, product assurance, classified protection, CII assessment, procurement review, and trade controls.

*FAQ* *China*

## China Cryptography Law FAQ

Answers on commercial-cryptography classification, product and service assurance, CII assessment, procurement review, and import or export controls.

Use the answers to identify the applicable route and the facts to retain. Product catalogues, import and export lists, classified-protection requirements, and CII conclusions still need a current, fact-specific check.

Classify commercial cryptography first, then distinguish ordinary lawful use from the separate triggers for product or service assurance, electronic-certification permission, classified-protection requirements, CII assessment, procurement review, and import or export controls.

## Definitions

### Commercial cryptography

Commercial cryptography covers technologies, products, and services that use specific transformations to encrypt or authenticate information that is not a state secret. It can include encryption protection and security authentication in software, hardware, or a supplied service; the word commercial describes the legal category, not a requirement that the information itself be sold.

**Why it matters here:** This classification is the first step. Separate rules decide whether a specific activity needs product or service assurance, electronic-certification permission, a network or CII assessment, procurement review, or an import or export licence.

Sources:

- [PRC Cryptography Law](https://www.oscca.gov.cn/sca/xxgk/2023-06/04/content_1057225.shtml?ref=sorena.io)
- [Commercial Cryptography Administration Regulation](https://xzfg.moj.gov.cn/front/law/detail?LawID=1622&ref=sorena.io)

### Commercial-cryptography application security assessment

This assessment evaluates how a network or information system applies commercial cryptography, including the applicable cryptographic products, services, algorithms, protocols, key-management mechanisms, and operating controls. A qualified outside testing body may perform the assessment when the operator commissions one, while the law also permits covered CII operators to conduct the assessment themselves.

**Why it matters here:** For CII that is legally required to use commercial cryptography, the implementing regulation requires the infrastructure to pass the assessment before operation and to be assessed at least annually after operation. Other network assessment requirements depend on classified-protection rules.

Sources:

- [Commercial Cryptography Administration Regulation](https://xzfg.moj.gov.cn/front/law/detail?LawID=1622&ref=sorena.io)
- [PRC Cryptography Law](https://www.oscca.gov.cn/sca/xxgk/2023-06/04/content_1057225.shtml?ref=sorena.io)

### Mass-market consumer products

Mass-market consumer products are the product category whose embedded commercial cryptography is excluded by the Cryptography Law and its implementing regulation from the commercial-cryptography import-licence and export-control system. The legislation states the exclusion but does not provide a complete product test in the cited provisions.

**Why it matters here:** Do not apply the exception from the presence of ordinary encryption alone. Record the exact model, users, distribution, functions, and list criteria, and use the competent authority's identification or consultation route if classification remains unclear.

Sources:

- [Commercial Cryptography Administration Regulation](https://xzfg.moj.gov.cn/front/law/detail?LawID=1622&ref=sorena.io)
- [PRC Cryptography Law](https://www.oscca.gov.cn/sca/xxgk/2023-06/04/content_1057225.shtml?ref=sorena.io)

### Critical information infrastructure

**Term:** CII

Critical information infrastructure is infrastructure in important industries and fields whose destruction, loss of function, or data leakage could seriously harm national security, the national economy and people's livelihoods, or the public interest. The competent protection department identifies the infrastructure and notifies the operator under the applicable rules; a company should not infer CII status from its sector or the importance of a system alone.

**Why it matters here:** CII status activates additional operator duties for commercial cryptography governance, products and services, reviewed cryptographic technologies, application planning, assessment, annual reporting, and procurement review. The specific cryptography duties still depend on the applicable requirement to use commercial cryptography.

Sources:

- [Critical Information Infrastructure Security Protection Regulation, Articles 2 and 8-11](https://www.cac.gov.cn/2021-08/17/c_1630785976988160.htm?ref=sorena.io)
- [Provisions on the Use and Administration of Commercial Cryptography in Critical Information Infrastructure, Articles 2 and 5-15](https://www.oscca.gov.cn/sca/xxgk/2025-06/27/content_1061270.shtml?ref=sorena.io)

### Network-security classified-protection system

**Term:** classified-protection system

China's network-security classified-protection system assigns a protection level to a network according to the harm that damage could cause, then applies level-specific security duties. The Commercial Cryptography Administration Regulation requires network operators to use commercial cryptography according to that system and states that the cryptography authority determines level-based use, management, and assessment requirements.

**Why it matters here:** This route can matter outside CII. Record the network's confirmed protection level and the current cryptography standards and requirements for that level; do not apply CII-only duties merely because a network has a classified-protection level.

Sources:

- [Commercial Cryptography Administration Regulation, Articles 41-42](https://xzfg.moj.gov.cn/front/law/detail?LawID=1622&ref=sorena.io)
- [PRC Cybersecurity Law, Article 23](https://www.cac.gov.cn/2025-12/29/c_1768735112911946.htm?ref=sorena.io)

### Network critical equipment and network security-specific products

These are products within the catalogue published under the Cybersecurity Law. A covered product must meet mandatory national standards and pass qualified security certification or security testing before sale or provision. A commercial cryptography product certification catalogue belongs to a different, generally voluntary certification system.

**Why it matters here:** Cryptography Law Article 26 makes qualified testing and certification mandatory for a commercial cryptography product only when the actual product falls within this network-product catalogue. A commercial cryptography service using a product in the catalogue must also be certified.

Sources:

- [PRC Cybersecurity Law, Article 25](https://www.cac.gov.cn/2025-12/29/c_1768735112911946.htm?ref=sorena.io)
- [PRC Cryptography Law, Article 26](https://www.oscca.gov.cn/sca/xxgk/2023-06/04/content_1057225.shtml?ref=sorena.io)

## Browse sub-FAQ modules

### [Do imported cryptography products need special review?](/artifacts/apac/china-cryptography-law/faq/do-imported-cryptography-products-need-special-review.md)

Not every encrypted product imported into China needs a licence. Check the 2020 commercial-cryptography import list, the consumer-product exception, and any CII procurement review.

- 3 items

### [Does using encryption trigger China Cryptography Law duties?](/artifacts/apac/china-cryptography-law/faq/does-using-encryption-trigger-china-cryptography-law.md)

Using encryption does not create one universal China approval duty. Check classified protection, product, service, CII, procurement, and trade triggers.

- 3 items

### [How does cryptography compliance overlap with China cybersecurity law?](/artifacts/apac/china-cryptography-law/faq/how-does-cryptography-compliance-overlap-with-cybersecurity-law.md)

See how China's cryptography rules connect with classified protection, product assurance, CII assessment, and cybersecurity review without merging the regimes.

- 3 items

### [What is commercial cryptography in China?](/artifacts/apac/china-cryptography-law/faq/what-is-commercial-cryptography-in-china.md)

Commercial cryptography protects information that is not a state secret. Learn how China defines the category and which separate facts trigger product, CII, or trade controls.

- 3 items

### [When is commercial cryptography testing or certification needed?](/artifacts/apac/china-cryptography-law/faq/when-is-commercial-cryptography-testing-or-certification-needed.md)

Commercial-cryptography assurance is often voluntary, but specified products and services require it. Covered CII also needs application assessment and qualified cryptography.

- 3 items

Browse all indexed questions: [/artifacts/apac/china-cryptography-law/faq/items](/artifacts/apac/china-cryptography-law/faq/items.md)

## Which decision comes first?

Start by identifying whether the technology, product, or service uses specific transformations for encryption protection or security authentication. Then determine whether it protects state-secret information or information that is not a state secret. Commercial cryptography is the category for the latter.

Commercial-cryptography status alone does not determine whether testing, certification, assessment, review, or a licence is mandatory. Articles 25-28 of the law set several routes, and the 2023 implementing regulation adds electronic-certification, classified-protection, and detailed CII application requirements.

The responsible actor changes by route. An ordinary user may lawfully choose commercial cryptography; a network operator must apply the classified-protection requirements for its network; a covered CII operator has additional application and procurement duties; and a supplier, electronic-certification service provider, importer, or exporter must check the rules for its own activity.

- What is commercial cryptography, and how does it differ from core and ordinary cryptography?
- Does using encryption create a mandatory approval or certification duty?
- When does Article 26 product or service assurance become mandatory?
- What commercial-cryptography requirements follow from the network-security classified-protection system?
- When does a CII use or procurement trigger Article 27 assessment or national-security review?
- When do Article 28 import/export lists or the mass-market consumer-product exception matter?

Sources for this answer:

- [PRC Cryptography Law](https://www.oscca.gov.cn/sca/xxgk/2023-06/04/content_1057225.shtml?ref=sorena.io) - Articles 2, 6-8, and 25-28 support the classification sequence, lawful ordinary use, and the separate product, service, CII, procurement, and trade routes.
- [Commercial cryptography testing institution measures interpretation](https://www.oscca.gov.cn/sca/xxgk/2023-10/07/content_1061110.shtml?ref=sorena.io) - The official interpretation explains the qualification and supervision of bodies that issue proof-bearing product-testing or application-security-assessment results.
- [Commercial Cryptography Administration Regulation](https://xzfg.moj.gov.cn/front/law/detail?LawID=1622&ref=sorena.io) - Articles 11-42 detail standards, testing and certification, electronic certification, imports and exports, CII application, classified protection, and assessment coordination.

## What should a decision record contain?

An FAQ answer cannot determine whether a specific product appears in a current catalogue or control list. Record the exact item, supplier, operator, use, source version and check date, conclusion, and unresolved questions.

Keep broader network-security and data-law conclusions separate even when they use the same technical facts. The implementing regulation links commercial cryptography to classified protection, CII assessment, and procurement review, but it does not merge the legal regimes.

- Exact product, service, component, model and version, cryptographic function, supplier, operator, and use.
- Commercial-cryptography category and protected-information conclusion.
- Article 26 product/service route and assurance evidence, if applicable.
- Classified-protection level and the corresponding commercial-cryptography use, management, and assessment requirements.
- Article 27 commercial-cryptography application security assessment and national-security-review conclusions, if applicable.
- Current import-list or export-list entry and mass-market consumer products exception conclusion, if applicable.
- Reviewer, source, approval date, gaps, and change triggers.

Sources for this answer:

- [PRC Cryptography Law](https://www.oscca.gov.cn/sca/xxgk/2023-06/04/content_1057225.shtml?ref=sorena.io) - Articles 24-28 support the separate standards, assurance, CII, procurement, and trade-control records listed here.
- [Commercial Cryptography Administration Regulation](https://xzfg.moj.gov.cn/front/law/detail?LawID=1622&ref=sorena.io) - Articles 11-42 support separate records for assurance, electronic certification, trade, CII application, classified protection, and procurement review.

## Direct answers to common scope questions

Each answer below states the controlling rule first. A specific product, system, operator, or shipment still needs a current catalogue, list, protection-level, or operator-status check.

### What is commercial cryptography, and how does it differ from core and ordinary cryptography?

Commercial cryptography protects information that is not a state secret through cryptographic technologies, products, or services used for encryption protection or security authentication. Core and ordinary cryptography protect state-secret information and are subject to a separate classified regime. The word commercial identifies the legal category; it does not mean that the protected information must be sold or used for profit.

### Does using encryption create a mandatory approval or certification duty?

No. Citizens, legal persons, and other organizations may lawfully use commercial cryptography to protect network and information security. Testing and certification are generally encouraged voluntarily. A mandatory route needs an additional trigger, such as a catalogue-covered network product, a service using that product, a network or information system required by national rules to use commercial cryptography, a qualifying CII use or procurement, a listed import or export, or an electronic certification service that uses commercial cryptography.

### When is product or service assurance mandatory under Article 26?

A commercial cryptography product must pass qualified testing and certification before sale or provision when it is legally included in the catalogue of network critical equipment and network security-specific products. A commercial cryptography service must be certified when it uses equipment or products in that catalogue. A listing in a separate commercial cryptography product certification catalogue does not by itself establish the Article 26 trigger.

### Does an electronic certification service need a cryptography licence?

Yes, when a provider uses commercial cryptography to provide electronic certification services in China. Since 1 July 2026, the provider must hold an Electronic Certification Service Cryptography Use Licence from the National Cryptography Administration. The licence is valid for five years, renewal requires an application 60 days before expiry, listed changes require a change procedure within 30 days, and the provider must conduct a cryptography-compliance assessment at least annually. Electronic-government electronic certification services follow a separate provider-qualification route.

### When is a commercial-cryptography application security assessment required?

The assessment is required for a network or information system that a law, administrative regulation, or national provision requires to use commercial cryptography protection. The operator must assess the commercial cryptography application plan, must not operate a completed system that has failed the pre-operation assessment, and must assess the operating system at least annually. A covered operator may self-assess only when it has the equipment, governance, personnel, and professional capability required by the Assessment Measures; otherwise it must commission a qualified commercial cryptography testing body.

### Does every network with a classified-protection level have the same commercial cryptography duties as CII?

No. A network operator must apply the commercial cryptography requirements associated with China's classified-protection system and its confirmed protection level. CII is a separately identified category with additional governance, product, technology, assessment, reporting, and procurement-review duties. A classified-protection level does not by itself prove that the network is CII.

### Does the mass-market consumer-product exclusion remove all China cryptography duties?

No. The exclusion removes commercial cryptography used in mass-market consumer products from the Cryptography Law's import-licensing and export-control system. It does not decide product certification, network use, application security assessment, CII procurement review, or other cybersecurity duties. Because the cited legislation does not provide a complete product test, document the actual model, retail availability, intended users, distribution restrictions, and whether its cryptographic function can readily be changed before relying on the exclusion.

Sources for this answer:

- [PRC Cryptography Law](https://www.oscca.gov.cn/sca/xxgk/2023-06/04/content_1057225.shtml?ref=sorena.io) - Articles 6-8 and 25-28 support the classification, lawful-use answer, voluntary and mandatory assurance routes, CII assessment and procurement routes, and trade exclusion.
- [Commercial Cryptography Administration Regulation](https://xzfg.moj.gov.cn/front/law/detail?LawID=1622&ref=sorena.io) - Articles 12-21, 31-42 support the product, service, import, export, assessment, classified-protection, and CII distinctions in these answers.
- [Commercial Cryptography Application Security Assessment Measures](https://www.oscca.gov.cn/sca/xxgk/2023-10/07/content_1061109.shtml?ref=sorena.io) - Articles 6-14 support the assessment trigger, plan and pre-operation gates, annual frequency, self-assessment conditions, records, and filing.
- [Measures for the Administration of Cryptography Use in Electronic Certification Services](https://www.oscca.gov.cn/sca/xxgk/2026-06/03/content_1061341.shtml?ref=sorena.io) - Articles 2-3, 10-12, 16-17, and 25 support the licensing trigger, five-year term, 60-day renewal lead time, 30-day change procedure, annual assessment, separate electronic-government route, and 1 July 2026 effective date.

*Document the requirement*

*Placement: Before primary sources*

## Prepare the commercial cryptography evidence file

Sorena AI helps assign owners, document controls, and retain the records behind each FAQ decision.

- [Map official sources to evidence](/solutions/research-copilot.md): Research Copilot records the official citation, decision, owner, evidence, and change history.
- [Review the China route](/contact.md): Check the China Cryptography Law scope decision and unresolved launch questions with Sorena.

## Primary sources

- [PRC Cryptography Law](https://www.oscca.gov.cn/sca/xxgk/2023-06/04/content_1057225.shtml?ref=sorena.io) - Primary law for cryptography classification and the standards, testing, product, service, CII, procurement, and trade-control routes in Articles 2, 6-8, and 24-28.
- [Commercial cryptography testing institution measures interpretation](https://www.oscca.gov.cn/sca/xxgk/2023-10/07/content_1061110.shtml?ref=sorena.io) - Official explanation of qualification and supervision for bodies issuing proof-bearing commercial-cryptography product-testing and application-security-assessment results.
- [Commercial Cryptography Administration Regulation](https://xzfg.moj.gov.cn/front/law/detail?LawID=1622&ref=sorena.io) - Current implementing rules for commercial-cryptography assurance, electronic certification, trade, network use, CII application, and procurement review.
- [Measures for the Administration of Cryptography Use in Electronic Certification Services](https://www.oscca.gov.cn/sca/xxgk/2026-06/03/content_1061341.shtml?ref=sorena.io) - Current licensing, renewal, change, assessment, and training rules for electronic certification providers using commercial cryptography in China from 1 July 2026.


---

[Privacy Policy](https://www.sorena.io/privacy.md) | [Terms of Use](https://www.sorena.io/terms-of-use.md) | [DMCA](https://www.sorena.io/dmca.md) | [About Us](https://www.sorena.io/about-us.md)

(c) 2026 Sorena AB (559573-7338). All rights reserved.

Source: https://www.sorena.io/artifacts/apac/china-cryptography-law/faq.md
