QuestionChina

Does using encryption trigger China Cryptography Law duties? Direct answer

No. Using encryption alone does not create one universal approval, testing, or licensing duty under China's Cryptography Law.

First classify the cryptographic function. Then check classified-protection, product, service, electronic-certification, CII, procurement-review, and trade triggers.

Author
Sorena AI
Published
Jul 5, 2026
Updated
Jul 25, 2026
Questions
3

Structured answer sets in this page tree.

Primary sources
6

Cited legal and guidance references.

Publication metadata
Sorena AI
Published Jul 5, 2026
Updated Jul 25, 2026
Overview

No. Using encryption alone does not create one universal approval, testing, or licensing duty under China's Cryptography Law. The applicable route depends on what the cryptography protects, how it is supplied or used, who operates the system, and whether classified-protection, product, service, electronic-certification, , procurement-review, or trade-list rules apply.

Search this module

Find a question or answer quickly

3 of 3 questions
Question 1

Why is encryption alone not the trigger?

Article 8 permits citizens, legal persons, and other organisations to use to protect network and information security when the protected information is not a state secret. Official State Cryptography Administration guidance confirms that the law imposes no compulsory use requirement on ordinary users. The law does not require prior approval for every use of encryption.

A shown in a login screen is not, by itself, cryptography under the official explanation: it is an access credential. Check the mechanism behind it. Specific transformations used to encrypt stored credentials, authenticate a user or message, or protect transmitted information can still be cryptography even when the interface calls the input a password.

The Cryptography Law has applied since 1 January 2020, and the revised Administration Regulation has applied since 1 July 2023. If the protected information is a state secret, stop this commercial-cryptography analysis: core or ordinary cryptography and the applicable state-secrets controls govern that branch instead.

Mandatory duties depend on more specific facts. The Cryptography Law addresses specified products and services, qualifying critical information infrastructure () uses and procurements, and listed imports or exports. The 2023 implementing regulation also covers electronic certification and requires network operators to use according to the . The electronic-certification measures effective 1 July 2026 require the provider to hold the named cryptography-use licence.

Voluntary testing or certification does not remove the standards duty. Any commercial-cryptography activity must still comply with applicable laws, administrative regulations, mandatory national standards, and the operator's publicly declared standards.

Citations
PRC Cryptography Law

Article 8 permits lawful commercial-cryptography use for non-state-secret information; Articles 25-28 set the narrower testing, product, CII, procurement, and trade triggers.

Question 2

Which questions decide the route?

Start with the function and protected information, not the presence of a familiar algorithm or library. Article 2 covers both encryption protection and security authentication, and it applies to technologies, products, and services.

The result can change when the product model, service design, supplier, network protection level, operator, deployment, catalogue entry, or control list changes. Reopen the analysis when one of those facts changes.

  • Does the technology, product, or service use specific transformations for encryption protection or security authentication?
  • Is it protecting state-secret information or information that is not a state secret?
  • Is the item sold or provided as a product or service covered by Article 26?
  • Is the organisation providing an that uses ?
  • What network-security classified-protection level and commercial-cryptography requirements apply to the network?
  • Is it used or procured by a operator in circumstances covered by Article 27?
  • Is an import covered by the commercial-cryptography import list, is an export covered by the unified dual-use export-control list, or does the mass-market consumer-product exception apply?
Citations
PRC Cryptography Law

Articles 2, 6-8, and 25-28 support the classification sequence and the separate mandatory-trigger questions.

Question 3

What to keep as evidence

The record should show why the function is or is not and the result of each relevant standards, product, service, electronic-certification, network-level, , procurement-review, import, and export check.

  • Product, service, component, version, algorithm or module, and intended protection purpose.
  • Supplier statement and the factual basis for treating the use as .
  • Applicable mandatory national standards and the operator's publicly declared standards, even where testing or certification is voluntary.
  • Catalogue or mandatory-route screening for the product or service.
  • Network protection level and the corresponding commercial-cryptography use, management, and assessment requirements.
  • Electronic-certification provider and permission screening, if the service verifies electronic signatures or certificates.
  • operator and national-security-review screening where relevant.
  • Import/export list screening and the event that will reopen the conclusion.
Citations
PRC Cryptography Law

Articles 2, 6-8, and 25-28 support the facts and trigger decisions that should be retained.

Primary sources

References and citations

oscca.gov.cn
Referenced sections
  • Articles 2, 6-8, and 25-28 support the facts and trigger decisions that should be retained.
Related guides

Explore more topics

China commercial cryptography compliance checklist
China commercial cryptography checklist covering classification, product and service assurance, CII duties, trade controls, and retained evidence.
China commercial cryptography testing evidence template
Record the legal route, product or system scope, testing-body qualification, report details, gaps, and reassessment triggers for China commercial cryptography assurance.
China cryptography compliance deadlines and calendar
China cryptography effective dates, CII reports, annual assessments, licence renewals, change notices, and pre-operation checks.
China cryptography import, export, and security review triage
Screen commercial cryptography imports under the 2020 list, exports under China's unified dual-use list, the consumer exclusion, system assessment, and CII review.
China Cryptography Law FAQ
Answers on China's commercial-cryptography scope, product assurance, classified protection, CII assessment, procurement review, and trade controls.
China Cryptography Law requirements
China commercial cryptography requirements by role: standards, testing, certification, CII use and assessment, trade controls, and evidence.
China Cryptography Law vs Cybersecurity Law
Compare China's Cryptography Law and current Cybersecurity Law by scope, actor, product assurance, CII duties, evidence, and enforcement.
China cryptography penalties, fines, and liability
China commercial cryptography penalties by actor and violation, including fine bands, corrective orders, confiscation, licence action, and liability.
Commercial cryptography procurement checklist
Procurement checks for commercial cryptography products and services used in China, including certificate scope, CII duties, and supplier changes.
Commercial cryptography products and testing evidence
When China commercial cryptography testing or certification is voluntary or mandatory, and what product, service, body, and scope evidence to keep.
Do imported cryptography products need special review?
Not every encrypted product imported into China needs a licence. Check the 2020 commercial-cryptography import list, the consumer-product exception, and any CII procurement review.
How does cryptography compliance overlap with China cybersecurity law?
See how China's cryptography rules connect with classified protection, product assurance, CII assessment, and cybersecurity review without merging the regimes.
What is commercial cryptography in China?
Commercial cryptography protects information that is not a state secret. Learn how China defines the category and which separate facts trigger product, CII, or trade controls.
When is commercial cryptography testing or certification needed?
Commercial-cryptography assurance is often voluntary, but specified products and services require it. Covered CII also needs application assessment and qualified cryptography.