---
title: "How does cryptography compliance overlap with China cybersecurity law?"
canonical_url: "https://www.sorena.io/artifacts/apac/china-cryptography-law/faq/how-does-cryptography-compliance-overlap-with-cybersecurity-law"
source_url: "https://www.sorena.io/artifacts/apac/china-cryptography-law/faq/how-does-cryptography-compliance-overlap-with-cybersecurity-law"
author: "Sorena AI"
description: "See how China's cryptography rules connect with classified protection, product assurance, CII assessment, and cybersecurity review without merging the regimes."
published_at: "2026-07-05"
updated_at: "2026-07-24"
keywords:
  - "China Cryptography Law"
  - "Commercial cryptography"
  - "Cryptography Law"
  - "Commercial cryptography testing"
  - "China cybersecurity"
---
**[SORENA](https://www.sorena.io/)** - AI-Powered GRC Platform

[Home](https://www.sorena.io/) | [Solutions](https://www.sorena.io/solutions) | [Artifacts](https://www.sorena.io/artifacts) | [About Us](https://www.sorena.io/about-us) | [Contact](https://www.sorena.io/contact) | [Portal](https://app.sorena.io)

---

# How does cryptography compliance overlap with China cybersecurity law?

See how China's cryptography rules connect with classified protection, product assurance, CII assessment, and cybersecurity review without merging the regimes.

*Question* *China*

## How does cryptography compliance overlap with China cybersecurity law? Direct answer

The regimes connect through classified protection, specified-product assurance, CII assessments, and national-security review for some CII procurements.

Keep separate legal conclusions even when the same technical facts support them. Rules on coordination and mutual recognition reduce duplication but do not merge the regimes.

Cryptography and cybersecurity compliance overlap at four main points: the network-security classified-protection system, specified-product assurance, coordination of CII assessments, and national-security review for certain CII procurements. Each route has its own trigger, responsible actor, and evidence.

## Definitions

### Critical information infrastructure

**Term:** CII

Critical information infrastructure is important network infrastructure and information systems whose destruction, loss of function, or data leakage could seriously harm national security, the national economy, people's livelihoods, or the public interest. Operators are identified through the applicable CII protection framework; industry, company size, or use of encryption alone does not establish CII status.

**Why it matters here:** CII status activates the overlap addressed here: commercial-cryptography application duties and assessments, qualified cryptographic products and services, and national-security review for certain procurements.

Sources:

- [Commercial Cryptography Administration Regulation](https://xzfg.moj.gov.cn/front/law/detail?LawID=1622&ref=sorena.io)
- [PRC Cybersecurity Law](https://www.cac.gov.cn/2025-12/29/c_1768735112911946.htm?ref=sorena.io)

### Network-security classified-protection system

China's network-security classified-protection system assigns security-protection duties according to a network's protection level. Under the current Cybersecurity Law, network operators must maintain governance and operating controls, technical protections, monitoring and logs, and data-protection measures. The commercial-cryptography regulation requires network operators to use commercial cryptography according to this system, with requirements set by protection level.

**Why it matters here:** A non-CII network can still have commercial-cryptography duties through classified protection. Teams should not treat Article 27's CII route as the only point where cryptography and cybersecurity requirements meet.

Sources:

- [PRC Cybersecurity Law](https://www.cac.gov.cn/2025-12/29/c_1768735112911946.htm?ref=sorena.io)
- [Commercial Cryptography Administration Regulation](https://xzfg.moj.gov.cn/front/law/detail?LawID=1622&ref=sorena.io)

### Cybersecurity review for national-security risk

**Term:** national-security review

Under the Cybersecurity Review Measures, a CII operator must assess the national-security risk of a network-product or service procurement and apply to the Cybersecurity Review Office when the procurement affects or may affect national security. The review examines supply-chain, control, disruption, data, legal-compliance, and other national-security risks.

**Why it matters here:** Commercial cryptography in the procurement is one relevant fact, but it does not automatically trigger review. The CII operator, the procured network product or service, and the possible national-security effect must all be assessed.

Sources:

- [Cybersecurity Review Measures](https://www.cac.gov.cn/2022-01/04/c_1642894602182845.htm?ref=sorena.io)
- [Commercial Cryptography Administration Regulation](https://xzfg.moj.gov.cn/front/law/detail?LawID=1622&ref=sorena.io)

### Commercial-cryptography application security assessment

This assessment examines whether a network or information system uses commercial cryptography correctly and whether its cryptography protection system operates effectively. For covered CII, the operator assesses the application plan, reassesses a changed plan during construction, passes an assessment before operation, and assesses at least annually after operation.

**Why it matters here:** This is a cryptography-specific assessment. It must be coordinated with CII security testing and graded-protection assessment to avoid duplicate work, but it does not replace the Cybersecurity Law's annual assessment of the CII network's wider security and risks.

Sources:

- [CII Commercial Cryptography Use Management Provisions, Articles 11-15](https://www.oscca.gov.cn/sca/xxgk/2025-06/27/content_1061270.shtml?ref=sorena.io)
- [PRC Cybersecurity Law, Article 40](https://www.cac.gov.cn/2025-12/29/c_1768735112911946.htm?ref=sorena.io)

## Where do the laws connect?

First, Article 41 of the Commercial Cryptography Administration Regulation, in force since 1 July 2023, requires network operators to use commercial cryptography according to the network-security classified-protection system. The state cryptography administration sets use, management, and application-assessment requirements by protection level. The rule applies to network operators beyond CII.

The Cybersecurity Law's classified-protection duties are broader than encryption. Article 23 also requires governance, technical protections, monitoring, at least six months of network logs, data classification, and important-data backup. Commercial cryptography can support those duties but does not replace them.

Second, Article 26 of the Cryptography Law and Article 20 of the implementing regulation require covered commercial-cryptography products to pass testing and certification before sale or provision. The product must both be commercial cryptography and fall within the current catalogue of critical network equipment and specialised cybersecurity products; an encryption feature or a listing in the separate voluntary commercial-cryptography certification catalogue does not establish the mandatory route by itself. The Cybersecurity Law separately requires listed products to pass qualified testing or certification and calls for mutual recognition to avoid duplication.

The current network-product catalogue, effective since 3 July 2023, includes routers with at least 12 Tbps bidirectional system throughput and 550,000 routing-table entries, switches with at least 30 Tbps bidirectional throughput and 10 Gpps forwarding, rack servers meeting stated CPU and memory thresholds, and PLC equipment meeting the stated instruction-time threshold. It also lists product categories such as firewalls, intrusion-detection systems, VPN products, public-key infrastructure, file-encryption products, and identity-authentication products. These are catalogue examples, not a conclusion that every listed product uses commercial cryptography or falls under Cryptography Law Article 26.

Third, qualifying CII operators must conduct a commercial-cryptography application security assessment. The CII Commercial Cryptography Use Management Provisions have applied since 1 August 2025 and require assessment of the application plan, reassessment if that plan changes during construction, a passing assessment before operation, and assessment at least annually after operation. CII already under construction on that date follows the construction and pre-operation rules; CII already operating follows the annual-assessment rule. The Cybersecurity Law, in its current form since 1 January 2026, separately requires a CII operator to assess its network security and possible risks at least annually. The cryptography rules require coordination among the cryptography assessment, CII security testing, and classified-protection assessment, but each legal conclusion remains distinct.

Fourth, a CII operator procuring a network product or service involving commercial cryptography must complete a national-security review when the procurement affects or may affect national security. The operator performs the initial risk assessment and applies to the Cybersecurity Review Office when that condition is met; commercial cryptography, CII status, or a large purchase alone does not establish the condition.

Sources for this answer:

- [PRC Cryptography Law](https://www.oscca.gov.cn/sca/xxgk/2023-06/04/content_1057225.shtml?ref=sorena.io) - Articles 26 and 27 establish the links to Cybersecurity Law product assurance, CII assessment coordination, and national-security review.
- [Commercial Cryptography Administration Regulation](https://xzfg.moj.gov.cn/front/law/detail?LawID=1622&ref=sorena.io) - Articles 20-21 and 38-42 detail product and service assurance, CII assessment timing, procurement review, classified-protection duties, and coordination among assessments.
- [PRC Cybersecurity Law](https://www.cac.gov.cn/2025-12/29/c_1768735112911946.htm?ref=sorena.io) - The current law, amended in 2025 and effective from 1 January 2026, sets classified-protection duties in Article 23, listed-product assurance and mutual recognition in Article 25, and an annual CII security-assessment duty in Article 40.
- [Cybersecurity Review Measures](https://www.cac.gov.cn/2022-01/04/c_1642894602182845.htm?ref=sorena.io) - Articles 2 and 5 require cybersecurity review for a CII procurement that affects or may affect national security and place the initial risk assessment on the CII operator.
- [CII Commercial Cryptography Use Management Provisions](https://www.oscca.gov.cn/sca/xxgk/2025-06/27/content_1061270.shtml?ref=sorena.io) - Articles 11-15 establish the plan, construction-change, pre-operation, annual, transition, and assessment-coordination rules effective from 1 August 2025.
- [2023 Catalogue of Critical Network Equipment and Specialised Cybersecurity Products](https://www.miit.gov.cn/jgsj/waj/wjfb/art/2023/art_9080a8689c58416eaf56f88649c242d3.html?ref=sorena.io) - The joint-authority catalogue supplies the current product categories and the router, switch, rack-server, and PLC thresholds; it also replaced the 2017 catalogue from 3 July 2023.

## How should teams separate the decisions?

Reuse the same technical facts while recording separate legal conclusions. A product may raise an Article 26 catalogue question without being procured by a CII operator. A CII deployment may require an Article 27 application assessment even when the procurement does not meet the national-security-review condition.

For each route, record the legal trigger, responsible operator or supplier, competent process, supporting evidence, and the legal basis for recognising an earlier test or assessment. A direction to avoid duplication does not automatically make one report a substitute for another. The Cryptography Law cross-references also do not establish compliance with unrelated cybersecurity, data, personal-information, or sector-specific duties.

Reopen the decisions when the product model or cryptographic function changes, the catalogue or standards change, the network's classified-protection level changes, infrastructure is identified as CII, the commercial-cryptography application plan changes during construction, the supplier or procurement scope changes, or a new national-security risk appears. An annual assessment date does not postpone a reassessment expressly triggered during construction or by a major cryptography incident or security hazard.

- Article 26 product or service status and testing or certification evidence.
- Article 27 CII status and the rule that requires commercial-cryptography protection.
- Classified-protection level and the corresponding commercial-cryptography use, management, and assessment requirements.
- Commercial-cryptography application security assessment, its annual cycle for covered CII, and its coordination with other assessments.
- The separate annual CII network-security assessment required by Cybersecurity Law Article 40.
- Separate procurement facts showing whether a network product or service may affect national security.
- Any broader Cybersecurity Law conclusion, supported by the source that governs that duty.
- The owner, review date, approval, next annual-assessment date, and event-based reassessment triggers for each conclusion.

Sources for this answer:

- [PRC Cryptography Law](https://www.oscca.gov.cn/sca/xxgk/2023-06/04/content_1057225.shtml?ref=sorena.io) - Articles 26 and 27 identify distinct product, CII assessment, and procurement-review triggers even where the underlying technical facts overlap.
- [Commercial Cryptography Administration Regulation](https://xzfg.moj.gov.cn/front/law/detail?LawID=1622&ref=sorena.io) - Articles 38-42 distinguish CII application, procurement review, classified-protection, and assessment-coordination decisions.
- [PRC Cybersecurity Law](https://www.cac.gov.cn/2025-12/29/c_1768735112911946.htm?ref=sorena.io) - Articles 23 and 40 distinguish classified-protection controls and the annual CII network-security assessment from the commercial-cryptography assessment.
- [Commercial Cryptography Application Security Assessment Measures](https://www.oscca.gov.cn/sca/xxgk/2023-10/07/content_1061109.shtml?ref=sorena.io) - Articles 6-15 support the lifecycle assessment, construction-change, annual, remediation, filing, and incident-driven reassessment triggers.

## What to keep as evidence

Maintain separate records for the Article 26 product or service route, the CII commercial-cryptography lifecycle assessment, the graded-protection conclusion, the annual CII network-security assessment, and any procurement cybersecurity review. Link shared technical facts without merging the legal results.

- Shared product, supplier, cryptographic-function, network, and operator facts.
- Separate Cryptography Law classification and product/service assurance conclusion, including the exact 2023 catalogue category and threshold analysis where Article 26 is considered.
- Separate CII status, classified-protection level, annual cybersecurity assessment, product testing, and national-security-review conclusions.
- Evidence showing where testing or assessment was coordinated to avoid duplication.
- For CII already under construction or operating on 1 August 2025, the transition analysis and the first assessment completed under the applicable construction, pre-operation, or annual route.
- Distinct owners, approvals, source citations, and change triggers for each regime.

Sources for this answer:

- [PRC Cryptography Law](https://www.oscca.gov.cn/sca/xxgk/2023-06/04/content_1057225.shtml?ref=sorena.io) - Articles 26 and 27 support the separate records for product assurance, CII assessment coordination, and procurement review.
- [Commercial Cryptography Administration Regulation](https://xzfg.moj.gov.cn/front/law/detail?LawID=1622&ref=sorena.io) - Articles 38-42 support separate records for CII application, classified protection, procurement review, and assessment coordination.
- [Cybersecurity Review Measures](https://www.cac.gov.cn/2022-01/04/c_1642894602182845.htm?ref=sorena.io) - Articles 5-10 support retaining the procurement risk analysis, filing materials, supplier commitments, and review factors.

## Primary sources

- [PRC Cryptography Law](https://www.oscca.gov.cn/sca/xxgk/2023-06/04/content_1057225.shtml?ref=sorena.io) - Articles 26 and 27 establish the specific links between cryptography controls and Cybersecurity Law mechanisms.
- [Commercial Cryptography Administration Regulation](https://xzfg.moj.gov.cn/front/law/detail?LawID=1622&ref=sorena.io) - Articles 20-21 and 38-42 detail assurance, CII, classified-protection, procurement-review, and assessment-coordination duties.
- [PRC Cybersecurity Law](https://www.cac.gov.cn/2025-12/29/c_1768735112911946.htm?ref=sorena.io) - Current text for classified protection and critical-network-equipment and specialised-cybersecurity-product assurance.
- [Cybersecurity Review Measures](https://www.cac.gov.cn/2022-01/04/c_1642894602182845.htm?ref=sorena.io) - Current review trigger and process for CII procurements that affect or may affect national security.
- [CII Commercial Cryptography Use Management Provisions](https://www.oscca.gov.cn/sca/xxgk/2025-06/27/content_1061270.shtml?ref=sorena.io) - Current CII cryptography lifecycle and assessment-coordination requirements effective from 1 August 2025.

## Topic Guides

- [China commercial cryptography compliance checklist](/artifacts/apac/china-cryptography-law/checklist.md): China commercial cryptography checklist covering classification, product and service assurance, CII duties, trade controls, and retained evidence.
- [China commercial cryptography testing evidence template](/artifacts/apac/china-cryptography-law/commercial-cryptography-testing-evidence-template.md): Record the legal route, product or system scope, testing-body qualification, report details, gaps, and reassessment triggers for China commercial cryptography assurance.
- [China cryptography compliance deadlines and calendar](/artifacts/apac/china-cryptography-law/deadlines-and-compliance-calendar.md): China cryptography effective dates, CII reports, annual assessments, licence renewals, change notices, and pre-operation checks.
- [China cryptography import, export, and security review triage](/artifacts/apac/china-cryptography-law/import-export-and-security-assessment.md): Screen commercial cryptography imports under the 2020 list, exports under China's unified dual-use list, the consumer exclusion, system assessment, and CII review.
- [China Cryptography Law FAQ](/artifacts/apac/china-cryptography-law/faq.md): Answers on China's commercial-cryptography scope, product assurance, classified protection, CII assessment, procurement review, and trade controls.
- [China Cryptography Law requirements](/artifacts/apac/china-cryptography-law/requirements.md): China commercial cryptography requirements by role: standards, testing, certification, CII use and assessment, trade controls, and evidence.
- [China Cryptography Law vs Cybersecurity Law](/artifacts/apac/china-cryptography-law/china-cryptography-law-vs-cybersecurity-law.md): Compare China's Cryptography Law and current Cybersecurity Law by scope, actor, product assurance, CII duties, evidence, and enforcement.
- [China cryptography penalties, fines, and liability](/artifacts/apac/china-cryptography-law/penalties-and-fines.md): China commercial cryptography penalties by actor and violation, including fine bands, corrective orders, confiscation, licence action, and liability.
- [Commercial cryptography procurement checklist](/artifacts/apac/china-cryptography-law/commercial-cryptography-procurement-checklist.md): Procurement checks for commercial cryptography products and services used in China, including certificate scope, CII duties, and supplier changes.
- [Commercial cryptography products and testing evidence](/artifacts/apac/china-cryptography-law/commercial-cryptography-products-and-testing.md): When China commercial cryptography testing or certification is voluntary or mandatory, and what product, service, body, and scope evidence to keep.
- [Do imported cryptography products need special review?](/artifacts/apac/china-cryptography-law/faq/do-imported-cryptography-products-need-special-review.md): Not every encrypted product imported into China needs a licence. Check the 2020 commercial-cryptography import list, the consumer-product exception, and any CII procurement review.
- [Does using encryption trigger China Cryptography Law duties?](/artifacts/apac/china-cryptography-law/faq/does-using-encryption-trigger-china-cryptography-law.md): Using encryption does not create one universal China approval duty. Check classified protection, product, service, CII, procurement, and trade triggers.
- [What is commercial cryptography in China?](/artifacts/apac/china-cryptography-law/faq/what-is-commercial-cryptography-in-china.md): Commercial cryptography protects information that is not a state secret. Learn how China defines the category and which separate facts trigger product, CII, or trade controls.
- [When is commercial cryptography testing or certification needed?](/artifacts/apac/china-cryptography-law/faq/when-is-commercial-cryptography-testing-or-certification-needed.md): Commercial-cryptography assurance is often voluntary, but specified products and services require it. Covered CII also needs application assessment and qualified cryptography.

*Document the requirement*

*Placement: Before primary sources*

## Prepare the commercial cryptography evidence file

Sorena AI helps assign controls and retain evidence across the cryptography and cybersecurity routes.

- [Map official sources to evidence](/solutions/research-copilot.md): Research Copilot records the official citation, decision, owner, evidence, and change history.
- [Review the China route](/contact.md): Check the China Cryptography Law scope decision and unresolved launch questions with Sorena.


---

[Privacy Policy](https://www.sorena.io/privacy.md) | [Terms of Use](https://www.sorena.io/terms-of-use.md) | [DMCA](https://www.sorena.io/dmca.md) | [About Us](https://www.sorena.io/about-us.md)

(c) 2026 Sorena AB (559573-7338). All rights reserved.

Source: https://www.sorena.io/artifacts/apac/china-cryptography-law/faq/how-does-cryptography-compliance-overlap-with-cybersecurity-law.md
