---
title: "Do imported cryptography products need special review?"
canonical_url: "https://www.sorena.io/artifacts/apac/china-cryptography-law/faq/do-imported-cryptography-products-need-special-review"
source_url: "https://www.sorena.io/artifacts/apac/china-cryptography-law/faq/do-imported-cryptography-products-need-special-review"
author: "Sorena AI"
description: "Not every encrypted product imported into China needs a licence. Check the 2020 commercial-cryptography import list, the consumer-product exception, and any CII procurement review."
published_at: "2026-07-05"
updated_at: "2026-07-25"
keywords:
  - "China Cryptography Law"
  - "Commercial cryptography"
  - "Cryptography Law"
  - "Commercial cryptography testing"
  - "China cybersecurity"
---
**[SORENA](https://www.sorena.io/)** - AI-Powered GRC Platform

[Home](https://www.sorena.io/) | [Solutions](https://www.sorena.io/solutions) | [Artifacts](https://www.sorena.io/artifacts) | [About Us](https://www.sorena.io/about-us) | [Contact](https://www.sorena.io/contact) | [Portal](https://app.sorena.io)

---

# Do imported cryptography products need special review?

Not every encrypted product imported into China needs a licence. Check the 2020 commercial-cryptography import list, the consumer-product exception, and any CII procurement review.

*Question* *China*

## Do imported cryptography products need special review? Direct answer

Not every imported product with encryption needs an import licence. Compare the exact item and technology with the 2020 commercial-cryptography import list and assess the mass-market consumer-product exception.

If a CII operator is procuring the product or service, assess the separate national-security-review trigger. Export screening now uses the unified dual-use export-control list, not the former 2020 cryptography export list.

Not every imported product with encryption needs an import licence or security review. Compare the exact item and technology with the commercial-cryptography import list, assess the mass-market consumer-product exception, and screen separately for CII procurement review.

## Definitions

### Commercial Cryptography Import Licence List

**Term:** commercial-cryptography import list

The Commercial Cryptography Import Licence List identifies the commercial-cryptography items and technologies that require a Chinese import licence. The operative import list was issued in the Ministry of Commerce, State Cryptography Administration, and General Administration of Customs Announcement No. 63 of 2020, effective 1 January 2021. A product must be compared with the technical scope of the list, not screened only by product name or the presence of encryption.

**Why it matters here:** If the exact imported item or technology falls within the list, the importer applies to the Ministry of Commerce for a dual-use item and technology import licence and presents the licence for customs clearance. If the match remains unclear, the Ministry's guide directs businesses to the identification or consultation process.

Sources:

- [Announcement No. 63 of 2020 on commercial-cryptography import and export controls](https://exportcontrol.mofcom.gov.cn/article/zcfg/gnzcfg/zcfggzqd/202111/416.html?ref=sorena.io)
- [Ministry of Commerce commercial-cryptography import licence guide](https://www.mofcom.gov.cn/zwdt/lywxhjsjcksp/index.html?ref=sorena.io)

### Mass-market consumer products

The Cryptography Law and the 2023 implementing regulation exclude commercial cryptography used in mass-market consumer products from the commercial-cryptography import-licence and export-control system. The cited provisions do not supply a complete legal test or make every broadly sold encrypted device exempt.

**Why it matters here:** The importer should retain the model, technical functions, intended users, distribution, end use, and list analysis supporting the exception. Uncertain cases should use the competent authority's identification or consultation process rather than an unsupported label.

Sources:

- [Commercial Cryptography Administration Regulation](https://xzfg.moj.gov.cn/front/law/detail?LawID=1622&ref=sorena.io)
- [PRC Cryptography Law](https://www.oscca.gov.cn/sca/xxgk/2023-06/04/content_1057225.shtml?ref=sorena.io)

### National-security review of a CII procurement

**Term:** CII procurement review

A critical information infrastructure operator must assess whether procuring a network product or service affects or may affect national security. When that condition is met, the operator applies to the Cybersecurity Review Office under the Cybersecurity Review Measures. The review considers supply continuity, control or disruption, data risks, supplier compliance, and other national-security factors.

**Why it matters here:** This review is separate from the import licence. An imported item may require one process, both processes, or neither, depending on list coverage, the buyer's CII status, the nature of the procurement, and its possible national-security effect.

Sources:

- [Cybersecurity Review Measures](https://www.cac.gov.cn/2022-01/04/c_1642894602182845.htm?ref=sorena.io)
- [Commercial Cryptography Administration Regulation](https://xzfg.moj.gov.cn/front/law/detail?LawID=1622&ref=sorena.io)

### Dual-use item

For this page, a dual-use item is a good, technology, or service controlled through China's dual-use import or export licensing system because it can have both civil and military uses or can otherwise affect national security and interests. Commercial-cryptography imports on the 2020 import list use the dual-use item and technology import-licence process; cryptography exports are screened against the unified Dual-Use Items Export Control List and any applicable temporary or catch-all controls.

**Why it matters here:** The importer must match the exact technology and technical parameters to the import list and provide the required technical description and end-use material. A customs tariff code, an encryption feature, or a product name alone does not complete the legal classification.

Sources:

- [Ministry of Commerce dual-use item and technology import approval guide](https://www.mofcom.gov.cn/zwdt/lywxhjsjcksp/index.html?ref=sorena.io)
- [PRC Dual-Use Items Export Control List announcement](https://www.mofcom.gov.cn/zcfb/zc/art/2024/art_461aafbb5e974f47b1c23866643cb71c.html?ref=sorena.io)

## When can an import licence apply?

Article 28 of the Cryptography Law and Articles 31-34 of the implementing regulation establish list-based import licensing. The operative import reference is the Commercial Cryptography Import Licence List issued with Announcement No. 63 of 2020. Listed items and technologies require an import licence from the Ministry of Commerce.

The import list has four product classes: encrypted fixed or mobile telephones; encrypted fax machines; cryptographic machines, including cryptographic cards; and equipment whose main function is IPSec or SSL VPN. The telephone and fax entries apply when the item provides encrypted data transmission and contains a symmetric algorithm with a key of at least 64 bits, an integer-factorisation asymmetric algorithm with a key of at least 768 bits, or an elliptic-curve asymmetric algorithm with a key of at least 128 bits. A cryptographic machine or card must meet one of those key-length conditions and reach at least 10 Gbps for symmetric encryption or decryption. An IPSec or SSL VPN device must meet one of the key-length conditions and reach at least 10 Gbps encrypted communication speed. These are list criteria, not examples that automatically capture every phone, fax machine, cryptographic module, or VPN product.

Match the product's technical characteristics and the imported technology to the list criteria. A listed commercial-cryptography import is handled through the dual-use item and technology import-licence process. The Ministry's current guidance directs businesses that cannot decide from the list to request a dual-use import-business consultation and identification.

For a listed import, the applicant submits the application, identity documents for the legal representative, principal business managers, and person handling the application, the contract or agreement, a technical description, final-user and final-use evidence, and any other material required by the Ministry of Commerce. The implementing regulation gives the Ministry an ordinary decision period of 45 working days after it accepts the application. The importer must obtain the licence before import and present it to Customs.

The implementing regulation also applies the licence rule to transit, transshipment, through shipment, re-export, and specified movements between overseas locations and comprehensive bonded zones, export-supervision warehouses, or bonded logistics centres. Do not assume that a movement avoids screening because it is not an ordinary domestic import.

Sources for this answer:

- [PRC Cryptography Law](https://www.oscca.gov.cn/sca/xxgk/2023-06/04/content_1057225.shtml?ref=sorena.io) - Article 28 states the import-licence and export-control criteria and assigns publication of the controlling lists to the competent authorities.
- [Commercial Cryptography Administration Regulation](https://xzfg.moj.gov.cn/front/law/detail?LawID=1622&ref=sorena.io) - Articles 31-34 require licences for listed items and technologies, describe customs handling, identify the application materials, and set the ordinary 45-working-day decision period.
- [Announcement No. 63 of 2020 on commercial-cryptography import and export controls](https://exportcontrol.mofcom.gov.cn/article/zcfg/gnzcfg/zcfggzqd/202111/416.html?ref=sorena.io) - Official source for the commercial-cryptography import list, effective from 1 January 2021.
- [Ministry of Commerce commercial-cryptography import licence guide](https://www.mofcom.gov.cn/zwdt/lywxhjsjcksp/index.html?ref=sorena.io) - Current official application guide, list reference, required materials, process, and consultation route for uncertain product identification.
- [Ministry of Commerce dual-use licensing FAQ](https://exportcontrol.mofcom.gov.cn/article/cjwt/202504/1135.html?ref=sorena.io) - The official FAQ confirms that commercial-cryptography imports use the 2020 import list and directs uncertain classifications to the dual-use import/export consultation route.

## Which exceptions and separate reviews matter?

Article 28 and Article 31 of the implementing regulation exclude commercial cryptography used in mass-market consumer products from this import-licence and export-control system. The cited provisions do not define a complete category test, so retain the facts and legal basis for applying the exception.

Import licensing and CII procurement review are separate. Under Article 40 of the implementing regulation and the Cybersecurity Review Measures, a CII operator must apply for review when a network-product or service procurement involving commercial cryptography affects or may affect national security.

Import and export lists are no longer symmetrical. The 2020 commercial-cryptography import list remains the import reference. From 1 December 2024, the unified PRC Dual-Use Items Export Control List replaced the commercial-cryptography export list and export procedure attached to Announcement No. 63 of 2020. Exporters must also consider controls outside the unified list when the catch-all conditions in the Export Control Law apply.

- Identify the exact model, version, cryptographic function, importer, intended users, and end use.
- Record the current official list and the date on which it was checked.
- Explain why the mass-market consumer-product exception does or does not apply.
- If list coverage remains unclear, retain the consultation or identification request and the authority's response.
- If the buyer is a CII operator, record the separate CII procurement-review conclusion.

Sources for this answer:

- [PRC Cryptography Law](https://www.oscca.gov.cn/sca/xxgk/2023-06/04/content_1057225.shtml?ref=sorena.io) - Article 28 provides the mass-market consumer-product exception; Article 27 provides the separate CII procurement national-security-review route.
- [PRC Dual-Use Items Export Control List announcement](https://www.mofcom.gov.cn/zcfb/zc/art/2024/art_461aafbb5e974f47b1c23866643cb71c.html?ref=sorena.io) - Announcement No. 51 of 2024 made the unified export-control list effective on 1 December 2024 and made the 2020 commercial-cryptography export list and procedure inapplicable.
- [PRC Regulation on Export Control of Dual-Use Items](https://www.mofcom.gov.cn/zwgk/zcfb/art/2024/art_bf56a4c613eb47af85712117561d609e.html?ref=sorena.io) - Articles 12-14 support temporary controls, catch-all licensing, and the current list-based dual-use export-licensing system.
- [Cybersecurity Review Measures](https://www.cac.gov.cn/2022-01/04/c_1642894602182845.htm?ref=sorena.io) - Articles 2 and 5 state the CII procurement-review condition and require the operator to assess possible national-security effects.

## What to keep as evidence

The record should show why the exact item and technology do or do not match the 2020 commercial-cryptography import list, why the mass-market consumer-product exception does or does not apply, and whether a CII procurement affects or may affect national security. If the same item will be exported, keep that conclusion separate because the unified dual-use export-control list now governs export screening.

- Product model, cryptographic function, intended users, and evidence for or against the mass-market consumer-product exception.
- Importer, customs classification, technical description, end use, and the current import-list check.
- Any transit, transshipment, through-shipment, re-export, bonded-zone, warehouse, or logistics-centre movement covered by Article 32.
- Import-licence conclusion, application and supporting materials, acceptance date, decision or identification response, Customs presentation record, decision owner, date, and official source.
- For an export, a separate check against the unified dual-use export-control list.
- Separate CII procurement and national-security-review screening where applicable.
- Supplier, product, list, end-use, or operator changes that require reassessment.

Sources for this answer:

- [PRC Cryptography Law](https://www.oscca.gov.cn/sca/xxgk/2023-06/04/content_1057225.shtml?ref=sorena.io) - Articles 27 and 28 support retaining the product, list, exception, and CII procurement facts needed to reconstruct the decision.
- [Commercial Cryptography Administration Regulation](https://xzfg.moj.gov.cn/front/law/detail?LawID=1622&ref=sorena.io) - Articles 31-34 identify the licence trigger, customs process, application materials, and review process.
- [PRC Dual-Use Items Export Control List announcement](https://www.mofcom.gov.cn/zcfb/zc/art/2024/art_461aafbb5e974f47b1c23866643cb71c.html?ref=sorena.io) - Current source for the shift from the former commercial-cryptography export list to the unified dual-use list.

## Primary sources

- [PRC Cryptography Law](https://www.oscca.gov.cn/sca/xxgk/2023-06/04/content_1057225.shtml?ref=sorena.io) - Articles 27 and 28 support the list-based import and export controls, mass-market exception, and separate CII procurement review.
- [Commercial Cryptography Administration Regulation](https://xzfg.moj.gov.cn/front/law/detail?LawID=1622&ref=sorena.io) - Articles 31-34 and 40 detail import and export licensing and the separate CII procurement review.
- [Announcement No. 63 of 2020 on commercial-cryptography import and export controls](https://exportcontrol.mofcom.gov.cn/article/zcfg/gnzcfg/zcfggzqd/202111/416.html?ref=sorena.io) - Official source for the commercial-cryptography import list that remains the Ministry's import-licence reference.
- [PRC Dual-Use Items Export Control List announcement](https://www.mofcom.gov.cn/zcfb/zc/art/2024/art_461aafbb5e974f47b1c23866643cb71c.html?ref=sorena.io) - Official source for the unified export list and the 1 December 2024 replacement of the former commercial-cryptography export list.
- [Ministry of Commerce dual-use licensing FAQ](https://exportcontrol.mofcom.gov.cn/article/cjwt/202504/1135.html?ref=sorena.io) - Current official confirmation that commercial-cryptography imports use the 2020 import list and uncertain classifications can use the consultation route.
- [Cybersecurity Review Measures](https://www.cac.gov.cn/2022-01/04/c_1642894602182845.htm?ref=sorena.io) - Current review trigger for CII procurement that affects or may affect national security.

## Topic Guides

- [China commercial cryptography compliance checklist](/artifacts/apac/china-cryptography-law/checklist.md): China commercial cryptography checklist covering classification, product and service assurance, CII duties, trade controls, and retained evidence.
- [China commercial cryptography testing evidence template](/artifacts/apac/china-cryptography-law/commercial-cryptography-testing-evidence-template.md): Record the legal route, product or system scope, testing-body qualification, report details, gaps, and reassessment triggers for China commercial cryptography assurance.
- [China cryptography compliance deadlines and calendar](/artifacts/apac/china-cryptography-law/deadlines-and-compliance-calendar.md): China cryptography effective dates, CII reports, annual assessments, licence renewals, change notices, and pre-operation checks.
- [China cryptography import, export, and security review triage](/artifacts/apac/china-cryptography-law/import-export-and-security-assessment.md): Screen commercial cryptography imports under the 2020 list, exports under China's unified dual-use list, the consumer exclusion, system assessment, and CII review.
- [China Cryptography Law FAQ](/artifacts/apac/china-cryptography-law/faq.md): Answers on China's commercial-cryptography scope, product assurance, classified protection, CII assessment, procurement review, and trade controls.
- [China Cryptography Law requirements](/artifacts/apac/china-cryptography-law/requirements.md): China commercial cryptography requirements by role: standards, testing, certification, CII use and assessment, trade controls, and evidence.
- [China Cryptography Law vs Cybersecurity Law](/artifacts/apac/china-cryptography-law/china-cryptography-law-vs-cybersecurity-law.md): Compare China's Cryptography Law and current Cybersecurity Law by scope, actor, product assurance, CII duties, evidence, and enforcement.
- [China cryptography penalties, fines, and liability](/artifacts/apac/china-cryptography-law/penalties-and-fines.md): China commercial cryptography penalties by actor and violation, including fine bands, corrective orders, confiscation, licence action, and liability.
- [Commercial cryptography procurement checklist](/artifacts/apac/china-cryptography-law/commercial-cryptography-procurement-checklist.md): Procurement checks for commercial cryptography products and services used in China, including certificate scope, CII duties, and supplier changes.
- [Commercial cryptography products and testing evidence](/artifacts/apac/china-cryptography-law/commercial-cryptography-products-and-testing.md): When China commercial cryptography testing or certification is voluntary or mandatory, and what product, service, body, and scope evidence to keep.
- [Does using encryption trigger China Cryptography Law duties?](/artifacts/apac/china-cryptography-law/faq/does-using-encryption-trigger-china-cryptography-law.md): Using encryption does not create one universal China approval duty. Check classified protection, product, service, CII, procurement, and trade triggers.
- [How does cryptography compliance overlap with China cybersecurity law?](/artifacts/apac/china-cryptography-law/faq/how-does-cryptography-compliance-overlap-with-cybersecurity-law.md): See how China's cryptography rules connect with classified protection, product assurance, CII assessment, and cybersecurity review without merging the regimes.
- [What is commercial cryptography in China?](/artifacts/apac/china-cryptography-law/faq/what-is-commercial-cryptography-in-china.md): Commercial cryptography protects information that is not a state secret. Learn how China defines the category and which separate facts trigger product, CII, or trade controls.
- [When is commercial cryptography testing or certification needed?](/artifacts/apac/china-cryptography-law/faq/when-is-commercial-cryptography-testing-or-certification-needed.md): Commercial-cryptography assurance is often voluntary, but specified products and services require it. Covered CII also needs application assessment and qualified cryptography.

*Document the requirement*

*Placement: Before primary sources*

## Prepare the commercial cryptography evidence file

Sorena AI helps assign controls and retain evidence for import licensing and any separate procurement review.

- [Map official sources to evidence](/solutions/research-copilot.md): Research Copilot records the official citation, decision, owner, evidence, and change history.
- [Review the China route](/contact.md): Check the China Cryptography Law scope decision and unresolved launch questions with Sorena.


---

[Privacy Policy](https://www.sorena.io/privacy.md) | [Terms of Use](https://www.sorena.io/terms-of-use.md) | [DMCA](https://www.sorena.io/dmca.md) | [About Us](https://www.sorena.io/about-us.md)

(c) 2026 Sorena AB (559573-7338). All rights reserved.

Source: https://www.sorena.io/artifacts/apac/china-cryptography-law/faq/do-imported-cryptography-products-need-special-review.md
