Why is encryption alone not the trigger?
Article 8 permits citizens, legal persons, and other organisations to use to protect network and information security when the protected information is not a state secret. Official State Cryptography Administration guidance confirms that the law imposes no compulsory use requirement on ordinary users. The law does not require prior approval for every use of encryption.
A shown in a login screen is not, by itself, cryptography under the official explanation: it is an access credential. Check the mechanism behind it. Specific transformations used to encrypt stored credentials, authenticate a user or message, or protect transmitted information can still be cryptography even when the interface calls the input a password.
The Cryptography Law has applied since 1 January 2020, and the revised Administration Regulation has applied since 1 July 2023. If the protected information is a state secret, stop this commercial-cryptography analysis: core or ordinary cryptography and the applicable state-secrets controls govern that branch instead.
Mandatory duties depend on more specific facts. The Cryptography Law addresses specified products and services, qualifying critical information infrastructure () uses and procurements, and listed imports or exports. The 2023 implementing regulation also covers electronic certification and requires network operators to use according to the . The electronic-certification measures effective 1 July 2026 require the provider to hold the named cryptography-use licence.
Voluntary testing or certification does not remove the standards duty. Any commercial-cryptography activity must still comply with applicable laws, administrative regulations, mandatory national standards, and the operator's publicly declared standards.
Article 8 permits lawful commercial-cryptography use for non-state-secret information; Articles 25-28 set the narrower testing, product, CII, procurement, and trade triggers.
The official Q&A states that the law does not impose a compulsory commercial-cryptography use requirement on ordinary users and distinguishes the CII route.
The official Q&A distinguishes an access password from cryptography under the Cryptography Law and explains that passwords are basic identity-authentication credentials.
Articles 11 and 20-42 set the general standards duty and the product, service, electronic-certification, import/export, CII, procurement, and classified-protection requirements.
Articles 2-3 establish the current electronic-certification cryptography-use licence route effective from 1 July 2026.