Where do the laws connect?
First, Article 41 of the Commercial Cryptography Administration Regulation, in force since 1 July 2023, requires network operators to use commercial cryptography according to the . The state cryptography administration sets use, management, and application-assessment requirements by protection level. The rule applies to network operators beyond .
The Cybersecurity Law's classified-protection duties are broader than encryption. Article 23 also requires governance, technical protections, monitoring, at least six months of network logs, data classification, and important-data backup. Commercial cryptography can support those duties but does not replace them.
Second, Article 26 of the Cryptography Law and Article 20 of the implementing regulation require covered commercial-cryptography products to pass testing and certification before sale or provision. The product must both be commercial cryptography and fall within the current catalogue of critical network equipment and specialised cybersecurity products; an encryption feature or a listing in the separate voluntary commercial-cryptography certification catalogue does not establish the mandatory route by itself. The Cybersecurity Law separately requires listed products to pass qualified testing or certification and calls for mutual recognition to avoid duplication.
The current network-product catalogue, effective since 3 July 2023, includes routers with at least 12 Tbps bidirectional system throughput and 550,000 routing-table entries, switches with at least 30 Tbps bidirectional throughput and 10 Gpps forwarding, rack servers meeting stated CPU and memory thresholds, and PLC equipment meeting the stated instruction-time threshold. It also lists product categories such as firewalls, intrusion-detection systems, VPN products, public-key infrastructure, file-encryption products, and identity-authentication products. These are catalogue examples, not a conclusion that every listed product uses commercial cryptography or falls under Cryptography Law Article 26.
Third, qualifying operators must conduct a . The CII Commercial Cryptography Use Management Provisions have applied since 1 August 2025 and require assessment of the application plan, reassessment if that plan changes during construction, a passing assessment before operation, and assessment at least annually after operation. CII already under construction on that date follows the construction and pre-operation rules; CII already operating follows the annual-assessment rule. The Cybersecurity Law, in its current form since 1 January 2026, separately requires a CII operator to assess its network security and possible risks at least annually. The cryptography rules require coordination among the cryptography assessment, CII security testing, and classified-protection assessment, but each legal conclusion remains distinct.
Fourth, a operator procuring a network product or service involving commercial cryptography must complete a when the procurement affects or may affect national security. The operator performs the initial risk assessment and applies to the Cybersecurity Review Office when that condition is met; commercial cryptography, CII status, or a large purchase alone does not establish the condition.
Articles 26 and 27 establish the links to Cybersecurity Law product assurance, CII assessment coordination, and national-security review.
Articles 20-21 and 38-42 detail product and service assurance, CII assessment timing, procurement review, classified-protection duties, and coordination among assessments.
The current law, amended in 2025 and effective from 1 January 2026, sets classified-protection duties in Article 23, listed-product assurance and mutual recognition in Article 25, and an annual CII security-assessment duty in Article 40.
Articles 2 and 5 require cybersecurity review for a CII procurement that affects or may affect national security and place the initial risk assessment on the CII operator.
Articles 11-15 establish the plan, construction-change, pre-operation, annual, transition, and assessment-coordination rules effective from 1 August 2025.
The joint-authority catalogue supplies the current product categories and the router, switch, rack-server, and PLC thresholds; it also replaced the 2017 catalogue from 3 July 2023.