---
title: "Does using encryption trigger China Cryptography Law duties?"
canonical_url: "https://www.sorena.io/artifacts/apac/china-cryptography-law/faq/does-using-encryption-trigger-china-cryptography-law"
source_url: "https://www.sorena.io/artifacts/apac/china-cryptography-law/faq/does-using-encryption-trigger-china-cryptography-law"
author: "Sorena AI"
description: "Using encryption does not create one universal China approval duty. Check classified protection, product, service, CII, procurement, and trade triggers."
published_at: "2026-07-05"
updated_at: "2026-07-25"
keywords:
  - "China Cryptography Law"
  - "Commercial cryptography"
  - "Cryptography Law"
  - "Commercial cryptography testing"
  - "China cybersecurity"
---
**[SORENA](https://www.sorena.io/)** - AI-Powered GRC Platform

[Home](https://www.sorena.io/) | [Solutions](https://www.sorena.io/solutions) | [Artifacts](https://www.sorena.io/artifacts) | [About Us](https://www.sorena.io/about-us) | [Contact](https://www.sorena.io/contact) | [Portal](https://app.sorena.io)

---

# Does using encryption trigger China Cryptography Law duties?

Using encryption does not create one universal China approval duty. Check classified protection, product, service, CII, procurement, and trade triggers.

*Question* *China*

## Does using encryption trigger China Cryptography Law duties? Direct answer

No. Using encryption alone does not create one universal approval, testing, or licensing duty under China's Cryptography Law.

First classify the cryptographic function. Then check classified-protection, product, service, electronic-certification, CII, procurement-review, and trade triggers.

No. Using encryption alone does not create one universal approval, testing, or licensing duty under China's Cryptography Law. The applicable route depends on what the cryptography protects, how it is supplied or used, who operates the system, and whether classified-protection, product, service, electronic-certification, CII, procurement-review, or trade-list rules apply.

## Definitions

### Commercial cryptography

Commercial cryptography covers technologies, products, and services that use specific transformations to encrypt or authenticate information that is not a state secret. The definition covers encryption protection and security authentication, so the analysis is not limited to a product marketed as an encryption device.

**Why it matters here:** A use must first fall within this category before the commercial-cryptography routes on this page matter. Category status alone does not establish that approval, testing, certification, assessment, or a trade licence is required.

Sources:

- [PRC Cryptography Law](https://www.oscca.gov.cn/sca/xxgk/2023-06/04/content_1057225.shtml?ref=sorena.io)
- [Commercial Cryptography Administration Regulation](https://xzfg.moj.gov.cn/front/law/detail?LawID=1622&ref=sorena.io)

### Network-security classified-protection system

The network-security classified-protection system assigns security duties according to a network's protection level. Network operators must apply governance, technical protection, monitoring, logging, and data-protection measures under the Cybersecurity Law. The commercial-cryptography regulation requires commercial cryptography to be used according to the system and lets the state cryptography administration set use, management, and application-assessment requirements by level.

**Why it matters here:** Encryption use may be optional for an ordinary user but required for a network operator under its classified-protection obligations. The network, its level, and the applicable standards must be identified before concluding that no duty applies.

Sources:

- [PRC Cybersecurity Law](https://www.cac.gov.cn/2025-12/29/c_1768735112911946.htm?ref=sorena.io)
- [Commercial Cryptography Administration Regulation](https://xzfg.moj.gov.cn/front/law/detail?LawID=1622&ref=sorena.io)

### Electronic certification service using commercial cryptography

**Term:** electronic certification service

An electronic certification service uses electronic-signature certificates or related trust services to verify signers and electronic signatures. A provider using commercial cryptography for this service in China must meet capability and management conditions and, since 1 July 2026, hold an Electronic Certification Service Cryptography Use Licence. Electronic-government certification has a separate institution-qualification route.

**Why it matters here:** Embedding encryption in an ordinary product is different from providing a regulated electronic certification service. The provider must screen the licence before offering the service and then comply with the change, key-service, maintenance, annual assessment, remediation, and training rules.

Sources:

- [Commercial Cryptography Administration Regulation](https://xzfg.moj.gov.cn/front/law/detail?LawID=1622&ref=sorena.io)
- [Electronic Certification Service Cryptography Use Management Measures](https://www.oscca.gov.cn/sca/xxgk/2026-06/03/content_1061341.shtml?ref=sorena.io)

### Critical information infrastructure

**Term:** CII

Critical information infrastructure is infrastructure identified under China's Cybersecurity Law and CII protection rules because destruction, loss of function, or data leakage could seriously harm national security, the national economy, people's livelihoods, or the public interest. An operator's industry, size, or use of encryption does not by itself establish CII status.

**Why it matters here:** Identified CII can trigger commercial-cryptography use, product, technology, lifecycle-assessment, annual-reporting, and procurement-review duties. Those CII duties do not apply to every organization that operates a network.

Sources:

- [PRC Cybersecurity Law, Article 33](https://www.cac.gov.cn/2025-12/29/c_1768735112911946.htm?ref=sorena.io)
- [CII Commercial Cryptography Use Management Provisions, Articles 2 and 5-15](https://www.oscca.gov.cn/sca/xxgk/2025-06/27/content_1061270.shtml?ref=sorena.io)

### Password as an access credential

**Term:** password

In the State Cryptography Administration's official explanation, a password used to enter a computer, phone, email account, or bank account is an access credential and a basic form of identity authentication, not cryptography within the Cryptography Law's definition. The underlying technology may still use cryptography to store, transmit, or verify that credential.

**Why it matters here:** Do not classify a feature from the interface label alone. Identify whether the product or service only accepts an access credential or also uses specific transformations for encryption protection or security authentication.

Sources:

- [State Cryptography Administration policy Q&A on cryptography and passwords](https://www.oscca.gov.cn/sca/xxgk/2020-01/08/content_1057375.shtml?ref=sorena.io)

## Why is encryption alone not the trigger?

Article 8 permits citizens, legal persons, and other organisations to use commercial cryptography to protect network and information security when the protected information is not a state secret. Official State Cryptography Administration guidance confirms that the law imposes no compulsory use requirement on ordinary users. The law does not require prior approval for every use of encryption.

A password shown in a login screen is not, by itself, cryptography under the official explanation: it is an access credential. Check the mechanism behind it. Specific transformations used to encrypt stored credentials, authenticate a user or message, or protect transmitted information can still be cryptography even when the interface calls the input a password.

The Cryptography Law has applied since 1 January 2020, and the revised Commercial Cryptography Administration Regulation has applied since 1 July 2023. If the protected information is a state secret, stop this commercial-cryptography analysis: core or ordinary cryptography and the applicable state-secrets controls govern that branch instead.

Mandatory duties depend on more specific facts. The Cryptography Law addresses specified products and services, qualifying critical information infrastructure (CII) uses and procurements, and listed imports or exports. The 2023 implementing regulation also covers electronic certification and requires network operators to use commercial cryptography according to the network-security classified-protection system. The electronic-certification measures effective 1 July 2026 require the provider to hold the named cryptography-use licence.

Voluntary testing or certification does not remove the standards duty. Any commercial-cryptography activity must still comply with applicable laws, administrative regulations, mandatory national standards, and the operator's publicly declared standards.

Sources for this answer:

- [PRC Cryptography Law](https://www.oscca.gov.cn/sca/xxgk/2023-06/04/content_1057225.shtml?ref=sorena.io) - Article 8 permits lawful commercial-cryptography use for non-state-secret information; Articles 25-28 set the narrower testing, product, CII, procurement, and trade triggers.
- [State Cryptography Administration policy Q&A on use of commercial cryptography](https://oscca.gov.cn/sca/xxgk/2020-01/28/content_1060626.shtml?ref=sorena.io) - The official Q&A states that the law does not impose a compulsory commercial-cryptography use requirement on ordinary users and distinguishes the CII route.
- [State Cryptography Administration policy Q&A on cryptography and passwords](https://www.oscca.gov.cn/sca/xxgk/2020-01/08/content_1057375.shtml?ref=sorena.io) - The official Q&A distinguishes an access password from cryptography under the Cryptography Law and explains that passwords are basic identity-authentication credentials.
- [Commercial Cryptography Administration Regulation](https://xzfg.moj.gov.cn/front/law/detail?LawID=1622&ref=sorena.io) - Articles 11 and 20-42 set the general standards duty and the product, service, electronic-certification, import/export, CII, procurement, and classified-protection requirements.
- [Electronic Certification Service Cryptography Use Management Measures](https://www.oscca.gov.cn/sca/xxgk/2026-06/03/content_1061341.shtml?ref=sorena.io) - Articles 2-3 establish the current electronic-certification cryptography-use licence route effective from 1 July 2026.

## Which questions decide the route?

Start with the function and protected information, not the presence of a familiar algorithm or library. Article 2 covers both encryption protection and security authentication, and it applies to technologies, products, and services.

The result can change when the product model, service design, supplier, network protection level, operator, deployment, catalogue entry, or control list changes. Reopen the analysis when one of those facts changes.

- Does the technology, product, or service use specific transformations for encryption protection or security authentication?
- Is it protecting state-secret information or information that is not a state secret?
- Is the item sold or provided as a product or service covered by Article 26?
- Is the organisation providing an electronic certification service that uses commercial cryptography?
- What network-security classified-protection level and commercial-cryptography requirements apply to the network?
- Is it used or procured by a CII operator in circumstances covered by Article 27?
- Is an import covered by the commercial-cryptography import list, is an export covered by the unified dual-use export-control list, or does the mass-market consumer-product exception apply?

Sources for this answer:

- [PRC Cryptography Law](https://www.oscca.gov.cn/sca/xxgk/2023-06/04/content_1057225.shtml?ref=sorena.io) - Articles 2, 6-8, and 25-28 support the classification sequence and the separate mandatory-trigger questions.
- [Commercial Cryptography Administration Regulation](https://xzfg.moj.gov.cn/front/law/detail?LawID=1622&ref=sorena.io) - Articles 20-42 support the product, service, electronic-certification, trade, CII, procurement, and classified-protection questions.
- [PRC Dual-Use Items Export Control List announcement](https://www.mofcom.gov.cn/zcfb/zc/art/2024/art_461aafbb5e974f47b1c23866643cb71c.html?ref=sorena.io) - The unified export-control list replaced the former commercial-cryptography export list from 1 December 2024.

## What to keep as evidence

The record should show why the function is or is not commercial cryptography and the result of each relevant standards, product, service, electronic-certification, network-level, CII, procurement-review, import, and export check.

- Product, service, component, version, algorithm or module, and intended protection purpose.
- Supplier statement and the factual basis for treating the use as commercial cryptography.
- Applicable mandatory national standards and the operator's publicly declared standards, even where testing or certification is voluntary.
- Catalogue or mandatory-route screening for the product or service.
- Network protection level and the corresponding commercial-cryptography use, management, and assessment requirements.
- Electronic-certification provider and permission screening, if the service verifies electronic signatures or certificates.
- CII operator and national-security-review screening where relevant.
- Import/export list screening and the event that will reopen the conclusion.

Sources for this answer:

- [PRC Cryptography Law](https://www.oscca.gov.cn/sca/xxgk/2023-06/04/content_1057225.shtml?ref=sorena.io) - Articles 2, 6-8, and 25-28 support the facts and trigger decisions that should be retained.
- [Commercial Cryptography Administration Regulation](https://xzfg.moj.gov.cn/front/law/detail?LawID=1622&ref=sorena.io) - Articles 11 and 20-42 support retaining standards, assurance, electronic-certification, network-level, CII, procurement, and trade conclusions.

## Primary sources

- [PRC Cryptography Law](https://www.oscca.gov.cn/sca/xxgk/2023-06/04/content_1057225.shtml?ref=sorena.io) - Articles 2, 6-8, and 25-28 support the definition, lawful-use rule, and separate product, CII, procurement, and trade routes.
- [Commercial Cryptography Administration Regulation](https://xzfg.moj.gov.cn/front/law/detail?LawID=1622&ref=sorena.io) - Current implementing rules for product, service, electronic-certification, trade, network, CII, and procurement duties.
- [State Cryptography Administration policy Q&A on use of commercial cryptography](https://oscca.gov.cn/sca/xxgk/2020-01/28/content_1060626.shtml?ref=sorena.io) - Official explanation that ordinary users do not have a compulsory commercial-cryptography use requirement under the law.
- [Electronic Certification Service Cryptography Use Management Measures](https://www.oscca.gov.cn/sca/xxgk/2026-06/03/content_1061341.shtml?ref=sorena.io) - Current licence and operating requirements for providers using commercial cryptography to provide electronic certification services.

## Topic Guides

- [China commercial cryptography compliance checklist](/artifacts/apac/china-cryptography-law/checklist.md): China commercial cryptography checklist covering classification, product and service assurance, CII duties, trade controls, and retained evidence.
- [China commercial cryptography testing evidence template](/artifacts/apac/china-cryptography-law/commercial-cryptography-testing-evidence-template.md): Record the legal route, product or system scope, testing-body qualification, report details, gaps, and reassessment triggers for China commercial cryptography assurance.
- [China cryptography compliance deadlines and calendar](/artifacts/apac/china-cryptography-law/deadlines-and-compliance-calendar.md): China cryptography effective dates, CII reports, annual assessments, licence renewals, change notices, and pre-operation checks.
- [China cryptography import, export, and security review triage](/artifacts/apac/china-cryptography-law/import-export-and-security-assessment.md): Screen commercial cryptography imports under the 2020 list, exports under China's unified dual-use list, the consumer exclusion, system assessment, and CII review.
- [China Cryptography Law FAQ](/artifacts/apac/china-cryptography-law/faq.md): Answers on China's commercial-cryptography scope, product assurance, classified protection, CII assessment, procurement review, and trade controls.
- [China Cryptography Law requirements](/artifacts/apac/china-cryptography-law/requirements.md): China commercial cryptography requirements by role: standards, testing, certification, CII use and assessment, trade controls, and evidence.
- [China Cryptography Law vs Cybersecurity Law](/artifacts/apac/china-cryptography-law/china-cryptography-law-vs-cybersecurity-law.md): Compare China's Cryptography Law and current Cybersecurity Law by scope, actor, product assurance, CII duties, evidence, and enforcement.
- [China cryptography penalties, fines, and liability](/artifacts/apac/china-cryptography-law/penalties-and-fines.md): China commercial cryptography penalties by actor and violation, including fine bands, corrective orders, confiscation, licence action, and liability.
- [Commercial cryptography procurement checklist](/artifacts/apac/china-cryptography-law/commercial-cryptography-procurement-checklist.md): Procurement checks for commercial cryptography products and services used in China, including certificate scope, CII duties, and supplier changes.
- [Commercial cryptography products and testing evidence](/artifacts/apac/china-cryptography-law/commercial-cryptography-products-and-testing.md): When China commercial cryptography testing or certification is voluntary or mandatory, and what product, service, body, and scope evidence to keep.
- [Do imported cryptography products need special review?](/artifacts/apac/china-cryptography-law/faq/do-imported-cryptography-products-need-special-review.md): Not every encrypted product imported into China needs a licence. Check the 2020 commercial-cryptography import list, the consumer-product exception, and any CII procurement review.
- [How does cryptography compliance overlap with China cybersecurity law?](/artifacts/apac/china-cryptography-law/faq/how-does-cryptography-compliance-overlap-with-cybersecurity-law.md): See how China's cryptography rules connect with classified protection, product assurance, CII assessment, and cybersecurity review without merging the regimes.
- [What is commercial cryptography in China?](/artifacts/apac/china-cryptography-law/faq/what-is-commercial-cryptography-in-china.md): Commercial cryptography protects information that is not a state secret. Learn how China defines the category and which separate facts trigger product, CII, or trade controls.
- [When is commercial cryptography testing or certification needed?](/artifacts/apac/china-cryptography-law/faq/when-is-commercial-cryptography-testing-or-certification-needed.md): Commercial-cryptography assurance is often voluntary, but specified products and services require it. Covered CII also needs application assessment and qualified cryptography.

*Document the requirement*

*Placement: Before primary sources*

## Prepare the commercial cryptography evidence file

Sorena AI helps assign controls and retain evidence for each applicable encryption-use route.

- [Map official sources to evidence](/solutions/research-copilot.md): Research Copilot records the official citation, decision, owner, evidence, and change history.
- [Review the China route](/contact.md): Check the China Cryptography Law scope decision and unresolved launch questions with Sorena.


---

[Privacy Policy](https://www.sorena.io/privacy.md) | [Terms of Use](https://www.sorena.io/terms-of-use.md) | [DMCA](https://www.sorena.io/dmca.md) | [About Us](https://www.sorena.io/about-us.md)

(c) 2026 Sorena AB (559573-7338). All rights reserved.

Source: https://www.sorena.io/artifacts/apac/china-cryptography-law/faq/does-using-encryption-trigger-china-cryptography-law.md
