QuestionChina

Do imported cryptography products need special review? Direct answer

Not every imported product with encryption needs an import licence. Compare the exact item and technology with the 2020 commercial-cryptography import list and assess the mass-market consumer-product exception.

If a CII operator is procuring the product or service, assess the separate national-security-review trigger. Export screening now uses the unified dual-use export-control list, not the former 2020 cryptography export list.

Author
Sorena AI
Published
Jul 5, 2026
Updated
Jul 25, 2026
Questions
3

Structured answer sets in this page tree.

Primary sources
8

Cited legal and guidance references.

Publication metadata
Sorena AI
Published Jul 5, 2026
Updated Jul 25, 2026
Overview

Not every imported product with encryption needs an import licence or security review. Compare the exact item and technology with the , assess the mass-market consumer-product exception, and screen separately for .

Search this module

Find a question or answer quickly

3 of 3 questions
Question 1

When can an import licence apply?

Article 28 of the Cryptography Law and Articles 31-34 of the implementing regulation establish list-based import licensing. The operative import reference is the Commercial Cryptography Import Licence List issued with Announcement No. 63 of 2020. Listed items and technologies require an import licence from the Ministry of Commerce.

The import list has four product classes: encrypted fixed or mobile telephones; encrypted fax machines; cryptographic machines, including cryptographic cards; and equipment whose main function is IPSec or SSL VPN. The telephone and fax entries apply when the item provides encrypted data transmission and contains a symmetric algorithm with a key of at least 64 bits, an integer-factorisation asymmetric algorithm with a key of at least 768 bits, or an elliptic-curve asymmetric algorithm with a key of at least 128 bits. A cryptographic machine or card must meet one of those key-length conditions and reach at least 10 Gbps for symmetric encryption or decryption. An IPSec or SSL VPN device must meet one of the key-length conditions and reach at least 10 Gbps encrypted communication speed. These are list criteria, not examples that automatically capture every phone, fax machine, cryptographic module, or VPN product.

Match the product's technical characteristics and the imported technology to the list criteria. A listed commercial-cryptography import is handled through the and technology import-licence process. The Ministry's current guidance directs businesses that cannot decide from the list to request a dual-use import-business consultation and identification.

For a listed import, the applicant submits the application, identity documents for the legal representative, principal business managers, and person handling the application, the contract or agreement, a technical description, final-user and final-use evidence, and any other material required by the Ministry of Commerce. The implementing regulation gives the Ministry an ordinary decision period of 45 working days after it accepts the application. The importer must obtain the licence before import and present it to Customs.

The implementing regulation also applies the licence rule to transit, transshipment, through shipment, re-export, and specified movements between overseas locations and comprehensive bonded zones, export-supervision warehouses, or bonded logistics centres. Do not assume that a movement avoids screening because it is not an ordinary domestic import.

Citations
PRC Cryptography Law

Article 28 states the import-licence and export-control criteria and assigns publication of the controlling lists to the competent authorities.

Question 2

Which exceptions and separate reviews matter?

Article 28 and Article 31 of the implementing regulation exclude commercial cryptography used in from this import-licence and export-control system. The cited provisions do not define a complete category test, so retain the facts and legal basis for applying the exception.

Import licensing and are separate. Under Article 40 of the implementing regulation and the Cybersecurity Review Measures, a CII operator must apply for review when a network-product or service procurement involving commercial cryptography affects or may affect national security.

Import and export lists are no longer symmetrical. The 2020 remains the import reference. From 1 December 2024, the unified PRC Dual-Use Items Export Control List replaced the commercial-cryptography export list and export procedure attached to Announcement No. 63 of 2020. Exporters must also consider controls outside the unified list when the catch-all conditions in the Export Control Law apply.

  • Identify the exact model, version, cryptographic function, importer, intended users, and end use.
  • Record the current official list and the date on which it was checked.
  • Explain why the mass-market consumer-product exception does or does not apply.
  • If list coverage remains unclear, retain the consultation or identification request and the authority's response.
  • If the buyer is a CII operator, record the separate CII procurement-review conclusion.
Citations
PRC Cryptography Law

Article 28 provides the mass-market consumer-product exception; Article 27 provides the separate CII procurement national-security-review route.

Cybersecurity Review Measures

Articles 2 and 5 state the CII procurement-review condition and require the operator to assess possible national-security effects.

Question 3

What to keep as evidence

The record should show why the exact item and technology do or do not match the 2020 , why the mass-market consumer-product exception does or does not apply, and whether a CII procurement affects or may affect national security. If the same item will be exported, keep that conclusion separate because the unified dual-use export-control list now governs export screening.

  • Product model, cryptographic function, intended users, and evidence for or against the mass-market consumer-product exception.
  • Importer, customs classification, technical description, end use, and the current import-list check.
  • Any transit, transshipment, through-shipment, re-export, bonded-zone, warehouse, or logistics-centre movement covered by Article 32.
  • Import-licence conclusion, application and supporting materials, acceptance date, decision or identification response, Customs presentation record, decision owner, date, and official source.
  • For an export, a separate check against the unified dual-use export-control list.
  • Separate CII procurement and national-security-review screening where applicable.
  • Supplier, product, list, end-use, or operator changes that require reassessment.
Citations
PRC Cryptography Law

Articles 27 and 28 support retaining the product, list, exception, and CII procurement facts needed to reconstruct the decision.

Primary sources

References and citations

cac.gov.cn
Referenced sections
  • Articles 2 and 5 state the CII procurement-review condition and require the operator to assess possible national-security effects.
exportcontrol.mofcom.gov.cn
Referenced sections
  • The official FAQ confirms that commercial-cryptography imports use the 2020 import list and directs uncertain classifications to the dual-use import/export consultation route.
oscca.gov.cn
Referenced sections
  • Articles 27 and 28 support retaining the product, list, exception, and CII procurement facts needed to reconstruct the decision.
Related guides

Explore more topics

China commercial cryptography compliance checklist
China commercial cryptography checklist covering classification, product and service assurance, CII duties, trade controls, and retained evidence.
China commercial cryptography testing evidence template
Record the legal route, product or system scope, testing-body qualification, report details, gaps, and reassessment triggers for China commercial cryptography assurance.
China cryptography compliance deadlines and calendar
China cryptography effective dates, CII reports, annual assessments, licence renewals, change notices, and pre-operation checks.
China cryptography import, export, and security review triage
Screen commercial cryptography imports under the 2020 list, exports under China's unified dual-use list, the consumer exclusion, system assessment, and CII review.
China Cryptography Law FAQ
Answers on China's commercial-cryptography scope, product assurance, classified protection, CII assessment, procurement review, and trade controls.
China Cryptography Law requirements
China commercial cryptography requirements by role: standards, testing, certification, CII use and assessment, trade controls, and evidence.
China Cryptography Law vs Cybersecurity Law
Compare China's Cryptography Law and current Cybersecurity Law by scope, actor, product assurance, CII duties, evidence, and enforcement.
China cryptography penalties, fines, and liability
China commercial cryptography penalties by actor and violation, including fine bands, corrective orders, confiscation, licence action, and liability.
Commercial cryptography procurement checklist
Procurement checks for commercial cryptography products and services used in China, including certificate scope, CII duties, and supplier changes.
Commercial cryptography products and testing evidence
When China commercial cryptography testing or certification is voluntary or mandatory, and what product, service, body, and scope evidence to keep.
Does using encryption trigger China Cryptography Law duties?
Using encryption does not create one universal China approval duty. Check classified protection, product, service, CII, procurement, and trade triggers.
How does cryptography compliance overlap with China cybersecurity law?
See how China's cryptography rules connect with classified protection, product assurance, CII assessment, and cybersecurity review without merging the regimes.
What is commercial cryptography in China?
Commercial cryptography protects information that is not a state secret. Learn how China defines the category and which separate facts trigger product, CII, or trade controls.
When is commercial cryptography testing or certification needed?
Commercial-cryptography assurance is often voluntary, but specified products and services require it. Covered CII also needs application assessment and qualified cryptography.