QuestionChina

How does cryptography compliance overlap with China cybersecurity law? Direct answer

The regimes connect through classified protection, specified-product assurance, CII assessments, and national-security review for some CII procurements.

Keep separate legal conclusions even when the same technical facts support them. Rules on coordination and mutual recognition reduce duplication but do not merge the regimes.

Author
Sorena AI
Published
Jul 5, 2026
Updated
Jul 24, 2026
Questions
3

Structured answer sets in this page tree.

Primary sources
7

Cited legal and guidance references.

Publication metadata
Sorena AI
Published Jul 5, 2026
Updated Jul 24, 2026
Overview

Cryptography and cybersecurity compliance overlap at four main points: the , specified-product assurance, coordination of assessments, and for certain CII procurements. Each route has its own trigger, responsible actor, and evidence.

Search this module

Find a question or answer quickly

3 of 3 questions
Question 1

Where do the laws connect?

First, Article 41 of the Commercial Cryptography Administration Regulation, in force since 1 July 2023, requires network operators to use commercial cryptography according to the . The state cryptography administration sets use, management, and application-assessment requirements by protection level. The rule applies to network operators beyond .

The Cybersecurity Law's classified-protection duties are broader than encryption. Article 23 also requires governance, technical protections, monitoring, at least six months of network logs, data classification, and important-data backup. Commercial cryptography can support those duties but does not replace them.

Second, Article 26 of the Cryptography Law and Article 20 of the implementing regulation require covered commercial-cryptography products to pass testing and certification before sale or provision. The product must both be commercial cryptography and fall within the current catalogue of critical network equipment and specialised cybersecurity products; an encryption feature or a listing in the separate voluntary commercial-cryptography certification catalogue does not establish the mandatory route by itself. The Cybersecurity Law separately requires listed products to pass qualified testing or certification and calls for mutual recognition to avoid duplication.

The current network-product catalogue, effective since 3 July 2023, includes routers with at least 12 Tbps bidirectional system throughput and 550,000 routing-table entries, switches with at least 30 Tbps bidirectional throughput and 10 Gpps forwarding, rack servers meeting stated CPU and memory thresholds, and PLC equipment meeting the stated instruction-time threshold. It also lists product categories such as firewalls, intrusion-detection systems, VPN products, public-key infrastructure, file-encryption products, and identity-authentication products. These are catalogue examples, not a conclusion that every listed product uses commercial cryptography or falls under Cryptography Law Article 26.

Third, qualifying operators must conduct a . The CII Commercial Cryptography Use Management Provisions have applied since 1 August 2025 and require assessment of the application plan, reassessment if that plan changes during construction, a passing assessment before operation, and assessment at least annually after operation. CII already under construction on that date follows the construction and pre-operation rules; CII already operating follows the annual-assessment rule. The Cybersecurity Law, in its current form since 1 January 2026, separately requires a CII operator to assess its network security and possible risks at least annually. The cryptography rules require coordination among the cryptography assessment, CII security testing, and classified-protection assessment, but each legal conclusion remains distinct.

Fourth, a operator procuring a network product or service involving commercial cryptography must complete a when the procurement affects or may affect national security. The operator performs the initial risk assessment and applies to the Cybersecurity Review Office when that condition is met; commercial cryptography, CII status, or a large purchase alone does not establish the condition.

Citations
PRC Cryptography Law

Articles 26 and 27 establish the links to Cybersecurity Law product assurance, CII assessment coordination, and national-security review.

PRC Cybersecurity Law

The current law, amended in 2025 and effective from 1 January 2026, sets classified-protection duties in Article 23, listed-product assurance and mutual recognition in Article 25, and an annual CII security-assessment duty in Article 40.

Cybersecurity Review Measures

Articles 2 and 5 require cybersecurity review for a CII procurement that affects or may affect national security and place the initial risk assessment on the CII operator.

Question 2

How should teams separate the decisions?

Reuse the same technical facts while recording separate legal conclusions. A product may raise an Article 26 catalogue question without being procured by a operator. A CII deployment may require an Article 27 application assessment even when the procurement does not meet the national-security-review condition.

For each route, record the legal trigger, responsible operator or supplier, competent process, supporting evidence, and the legal basis for recognising an earlier test or assessment. A direction to avoid duplication does not automatically make one report a substitute for another. The Cryptography Law cross-references also do not establish compliance with unrelated cybersecurity, data, personal-information, or sector-specific duties.

Reopen the decisions when the product model or cryptographic function changes, the catalogue or standards change, the network's classified-protection level changes, infrastructure is identified as , the commercial-cryptography application plan changes during construction, the supplier or procurement scope changes, or a new national-security risk appears. An annual assessment date does not postpone a reassessment expressly triggered during construction or by a major cryptography incident or security hazard.

  • Article 26 product or service status and testing or certification evidence.
  • Article 27 status and the rule that requires commercial-cryptography protection.
  • Classified-protection level and the corresponding commercial-cryptography use, management, and assessment requirements.
  • , its annual cycle for covered , and its coordination with other assessments.
  • The separate annual network-security assessment required by Cybersecurity Law Article 40.
  • Separate procurement facts showing whether a network product or service may affect national security.
  • Any broader Cybersecurity Law conclusion, supported by the source that governs that duty.
  • The owner, review date, approval, next annual-assessment date, and event-based reassessment triggers for each conclusion.
Citations
PRC Cryptography Law

Articles 26 and 27 identify distinct product, CII assessment, and procurement-review triggers even where the underlying technical facts overlap.

PRC Cybersecurity Law

Articles 23 and 40 distinguish classified-protection controls and the annual CII network-security assessment from the commercial-cryptography assessment.

Question 3

What to keep as evidence

Maintain separate records for the Article 26 product or service route, the commercial-cryptography lifecycle assessment, the graded-protection conclusion, the annual CII network-security assessment, and any procurement cybersecurity review. Link shared technical facts without merging the legal results.

  • Shared product, supplier, cryptographic-function, network, and operator facts.
  • Separate Cryptography Law classification and product/service assurance conclusion, including the exact 2023 catalogue category and threshold analysis where Article 26 is considered.
  • Separate status, classified-protection level, annual cybersecurity assessment, product testing, and national-security-review conclusions.
  • Evidence showing where testing or assessment was coordinated to avoid duplication.
  • For already under construction or operating on 1 August 2025, the transition analysis and the first assessment completed under the applicable construction, pre-operation, or annual route.
  • Distinct owners, approvals, source citations, and change triggers for each regime.
Citations
PRC Cryptography Law

Articles 26 and 27 support the separate records for product assurance, CII assessment coordination, and procurement review.

Primary sources

References and citations

cac.gov.cn
Referenced sections
  • Articles 5-10 support retaining the procurement risk analysis, filing materials, supplier commitments, and review factors.
oscca.gov.cn
Referenced sections
  • Articles 26 and 27 support the separate records for product assurance, CII assessment coordination, and procurement review.
cac.gov.cn
Referenced sections
  • Articles 23 and 40 distinguish classified-protection controls and the annual CII network-security assessment from the commercial-cryptography assessment.
Related guides

Explore more topics

China commercial cryptography compliance checklist
China commercial cryptography checklist covering classification, product and service assurance, CII duties, trade controls, and retained evidence.
China commercial cryptography testing evidence template
Record the legal route, product or system scope, testing-body qualification, report details, gaps, and reassessment triggers for China commercial cryptography assurance.
China cryptography compliance deadlines and calendar
China cryptography effective dates, CII reports, annual assessments, licence renewals, change notices, and pre-operation checks.
China cryptography import, export, and security review triage
Screen commercial cryptography imports under the 2020 list, exports under China's unified dual-use list, the consumer exclusion, system assessment, and CII review.
China Cryptography Law FAQ
Answers on China's commercial-cryptography scope, product assurance, classified protection, CII assessment, procurement review, and trade controls.
China Cryptography Law requirements
China commercial cryptography requirements by role: standards, testing, certification, CII use and assessment, trade controls, and evidence.
China Cryptography Law vs Cybersecurity Law
Compare China's Cryptography Law and current Cybersecurity Law by scope, actor, product assurance, CII duties, evidence, and enforcement.
China cryptography penalties, fines, and liability
China commercial cryptography penalties by actor and violation, including fine bands, corrective orders, confiscation, licence action, and liability.
Commercial cryptography procurement checklist
Procurement checks for commercial cryptography products and services used in China, including certificate scope, CII duties, and supplier changes.
Commercial cryptography products and testing evidence
When China commercial cryptography testing or certification is voluntary or mandatory, and what product, service, body, and scope evidence to keep.
Do imported cryptography products need special review?
Not every encrypted product imported into China needs a licence. Check the 2020 commercial-cryptography import list, the consumer-product exception, and any CII procurement review.
Does using encryption trigger China Cryptography Law duties?
Using encryption does not create one universal China approval duty. Check classified protection, product, service, CII, procurement, and trade triggers.
What is commercial cryptography in China?
Commercial cryptography protects information that is not a state secret. Learn how China defines the category and which separate facts trigger product, CII, or trade controls.
When is commercial cryptography testing or certification needed?
Commercial-cryptography assurance is often voluntary, but specified products and services require it. Covered CII also needs application assessment and qualified cryptography.