FAQ item index

Search every question across sub-FAQs

Find the exact question, open the source answer card, and copy a direct link to the anchored sub-FAQ response.

Indexed coverage
15of15items
Across 5 modules • Updated Jul 25, 2026
Author
Sorena AI
Published
Jul 5, 2026
Updated
Jul 25, 2026
Do imported cryptography products need special review?

When can an import licence apply?

Article 28 of the Cryptography Law and Articles 31-34 of the implementing regulation establish list-based import licensing. The operative import reference is the Commercial Cryptography Import Licence List issued with Announcement No. 63 of 2020. Listed items and technologies require an import licence from the Ministry of Commerce.

The import list has four product classes: encrypted fixed or mobile telephones; encrypted fax machines; cryptographic machines, including cryptographic cards; and equipment whose main function is IPSec or SSL VPN. The telephone and fax entries apply when the item provides encrypted data transmission and contains a symmetric algorithm with a key of at least 64 bits, an integer-factorisation asymmetric algorithm with a key of at least 768 bits, or an elliptic-curve asymmetric algorithm with a key of at least 128 bits. A cryptographic machine or card must meet one of those key-length conditions and reach at least 10 Gbps for symmetric encryption or decryption. An IPSec or SSL VPN device must meet one of the key-length conditions and reach at least 10 Gbps encrypted communication speed. These are list criteria, not examples that automatically capture every phone, fax machine, cryptographic module, or VPN product.

Match the product's technical characteristics and the imported technology to the list criteria. A listed commercial-cryptography import is handled through the dual-use item and technology import-licence process. The Ministry's current guidance directs businesses that cannot decide from the list to request a dual-use import-business consultation and identification.

For a listed import, the applicant submits the application, identity documents for the legal representative, principal business managers, and person handling the application, the contract or agreement, a technical description, final-user and final-use evidence, and any other material required by the Ministry of Commerce. The implementing regulation gives the Ministry an ordinary decision period of 45 working days after it accepts the application. The importer must obtain the licence before import and present it to Customs.

The implementing regulation also applies the licence rule to transit, transshipment, through shipment, re-export, and specified movements between overseas locations and comprehensive bonded zones, export-supervision warehouses, or bonded logistics centres. Do not assume that a movement avoids screening because it is not an ordinary domestic import.

Citations
PRC Cryptography Law

Article 28 states the import-licence and export-control criteria and assigns publication of the controlling lists to the competent authorities.

Do imported cryptography products need special review?

Which exceptions and separate reviews matter?

Article 28 and Article 31 of the implementing regulation exclude commercial cryptography used in mass-market consumer products from this import-licence and export-control system. The cited provisions do not define a complete category test, so retain the facts and legal basis for applying the exception.

Import licensing and CII procurement review are separate. Under Article 40 of the implementing regulation and the Cybersecurity Review Measures, a CII operator must apply for review when a network-product or service procurement involving commercial cryptography affects or may affect national security.

Import and export lists are no longer symmetrical. The 2020 commercial-cryptography import list remains the import reference. From 1 December 2024, the unified PRC Dual-Use Items Export Control List replaced the commercial-cryptography export list and export procedure attached to Announcement No. 63 of 2020. Exporters must also consider controls outside the unified list when the catch-all conditions in the Export Control Law apply.

  • Identify the exact model, version, cryptographic function, importer, intended users, and end use.
  • Record the current official list and the date on which it was checked.
  • Explain why the mass-market consumer-product exception does or does not apply.
  • If list coverage remains unclear, retain the consultation or identification request and the authority's response.
  • If the buyer is a CII operator, record the separate CII procurement-review conclusion.
Citations
PRC Cryptography Law

Article 28 provides the mass-market consumer-product exception; Article 27 provides the separate CII procurement national-security-review route.

Cybersecurity Review Measures

Articles 2 and 5 state the CII procurement-review condition and require the operator to assess possible national-security effects.

Do imported cryptography products need special review?

What to keep as evidence

The record should show why the exact item and technology do or do not match the 2020 commercial-cryptography import list, why the mass-market consumer-product exception does or does not apply, and whether a CII procurement affects or may affect national security. If the same item will be exported, keep that conclusion separate because the unified dual-use export-control list now governs export screening.

  • Product model, cryptographic function, intended users, and evidence for or against the mass-market consumer-product exception.
  • Importer, customs classification, technical description, end use, and the current import-list check.
  • Any transit, transshipment, through-shipment, re-export, bonded-zone, warehouse, or logistics-centre movement covered by Article 32.
  • Import-licence conclusion, application and supporting materials, acceptance date, decision or identification response, Customs presentation record, decision owner, date, and official source.
  • For an export, a separate check against the unified dual-use export-control list.
  • Separate CII procurement and national-security-review screening where applicable.
  • Supplier, product, list, end-use, or operator changes that require reassessment.
Citations
PRC Cryptography Law

Articles 27 and 28 support retaining the product, list, exception, and CII procurement facts needed to reconstruct the decision.

Does using encryption trigger China Cryptography Law duties?

Why is encryption alone not the trigger?

Article 8 permits citizens, legal persons, and other organisations to use commercial cryptography to protect network and information security when the protected information is not a state secret. Official State Cryptography Administration guidance confirms that the law imposes no compulsory use requirement on ordinary users. The law does not require prior approval for every use of encryption.

A password shown in a login screen is not, by itself, cryptography under the official explanation: it is an access credential. Check the mechanism behind it. Specific transformations used to encrypt stored credentials, authenticate a user or message, or protect transmitted information can still be cryptography even when the interface calls the input a password.

The Cryptography Law has applied since 1 January 2020, and the revised Commercial Cryptography Administration Regulation has applied since 1 July 2023. If the protected information is a state secret, stop this commercial-cryptography analysis: core or ordinary cryptography and the applicable state-secrets controls govern that branch instead.

Mandatory duties depend on more specific facts. The Cryptography Law addresses specified products and services, qualifying critical information infrastructure (CII) uses and procurements, and listed imports or exports. The 2023 implementing regulation also covers electronic certification and requires network operators to use commercial cryptography according to the network-security classified-protection system. The electronic-certification measures effective 1 July 2026 require the provider to hold the named cryptography-use licence.

Voluntary testing or certification does not remove the standards duty. Any commercial-cryptography activity must still comply with applicable laws, administrative regulations, mandatory national standards, and the operator's publicly declared standards.

Citations
PRC Cryptography Law

Article 8 permits lawful commercial-cryptography use for non-state-secret information; Articles 25-28 set the narrower testing, product, CII, procurement, and trade triggers.

Does using encryption trigger China Cryptography Law duties?

Which questions decide the route?

Start with the function and protected information, not the presence of a familiar algorithm or library. Article 2 covers both encryption protection and security authentication, and it applies to technologies, products, and services.

The result can change when the product model, service design, supplier, network protection level, operator, deployment, catalogue entry, or control list changes. Reopen the analysis when one of those facts changes.

  • Does the technology, product, or service use specific transformations for encryption protection or security authentication?
  • Is it protecting state-secret information or information that is not a state secret?
  • Is the item sold or provided as a product or service covered by Article 26?
  • Is the organisation providing an electronic certification service that uses commercial cryptography?
  • What network-security classified-protection level and commercial-cryptography requirements apply to the network?
  • Is it used or procured by a CII operator in circumstances covered by Article 27?
  • Is an import covered by the commercial-cryptography import list, is an export covered by the unified dual-use export-control list, or does the mass-market consumer-product exception apply?
Citations
PRC Cryptography Law

Articles 2, 6-8, and 25-28 support the classification sequence and the separate mandatory-trigger questions.

Does using encryption trigger China Cryptography Law duties?

What to keep as evidence

The record should show why the function is or is not commercial cryptography and the result of each relevant standards, product, service, electronic-certification, network-level, CII, procurement-review, import, and export check.

  • Product, service, component, version, algorithm or module, and intended protection purpose.
  • Supplier statement and the factual basis for treating the use as commercial cryptography.
  • Applicable mandatory national standards and the operator's publicly declared standards, even where testing or certification is voluntary.
  • Catalogue or mandatory-route screening for the product or service.
  • Network protection level and the corresponding commercial-cryptography use, management, and assessment requirements.
  • Electronic-certification provider and permission screening, if the service verifies electronic signatures or certificates.
  • CII operator and national-security-review screening where relevant.
  • Import/export list screening and the event that will reopen the conclusion.
Citations
PRC Cryptography Law

Articles 2, 6-8, and 25-28 support the facts and trigger decisions that should be retained.

How does cryptography compliance overlap with China cybersecurity law?

Where do the laws connect?

First, Article 41 of the Commercial Cryptography Administration Regulation, in force since 1 July 2023, requires network operators to use commercial cryptography according to the network-security classified-protection system. The state cryptography administration sets use, management, and application-assessment requirements by protection level. The rule applies to network operators beyond CII.

The Cybersecurity Law's classified-protection duties are broader than encryption. Article 23 also requires governance, technical protections, monitoring, at least six months of network logs, data classification, and important-data backup. Commercial cryptography can support those duties but does not replace them.

Second, Article 26 of the Cryptography Law and Article 20 of the implementing regulation require covered commercial-cryptography products to pass testing and certification before sale or provision. The product must both be commercial cryptography and fall within the current catalogue of critical network equipment and specialised cybersecurity products; an encryption feature or a listing in the separate voluntary commercial-cryptography certification catalogue does not establish the mandatory route by itself. The Cybersecurity Law separately requires listed products to pass qualified testing or certification and calls for mutual recognition to avoid duplication.

The current network-product catalogue, effective since 3 July 2023, includes routers with at least 12 Tbps bidirectional system throughput and 550,000 routing-table entries, switches with at least 30 Tbps bidirectional throughput and 10 Gpps forwarding, rack servers meeting stated CPU and memory thresholds, and PLC equipment meeting the stated instruction-time threshold. It also lists product categories such as firewalls, intrusion-detection systems, VPN products, public-key infrastructure, file-encryption products, and identity-authentication products. These are catalogue examples, not a conclusion that every listed product uses commercial cryptography or falls under Cryptography Law Article 26.

Third, qualifying CII operators must conduct a commercial-cryptography application security assessment. The CII Commercial Cryptography Use Management Provisions have applied since 1 August 2025 and require assessment of the application plan, reassessment if that plan changes during construction, a passing assessment before operation, and assessment at least annually after operation. CII already under construction on that date follows the construction and pre-operation rules; CII already operating follows the annual-assessment rule. The Cybersecurity Law, in its current form since 1 January 2026, separately requires a CII operator to assess its network security and possible risks at least annually. The cryptography rules require coordination among the cryptography assessment, CII security testing, and classified-protection assessment, but each legal conclusion remains distinct.

Fourth, a CII operator procuring a network product or service involving commercial cryptography must complete a national-security review when the procurement affects or may affect national security. The operator performs the initial risk assessment and applies to the Cybersecurity Review Office when that condition is met; commercial cryptography, CII status, or a large purchase alone does not establish the condition.

Citations
PRC Cryptography Law

Articles 26 and 27 establish the links to Cybersecurity Law product assurance, CII assessment coordination, and national-security review.

PRC Cybersecurity Law

The current law, amended in 2025 and effective from 1 January 2026, sets classified-protection duties in Article 23, listed-product assurance and mutual recognition in Article 25, and an annual CII security-assessment duty in Article 40.

Cybersecurity Review Measures

Articles 2 and 5 require cybersecurity review for a CII procurement that affects or may affect national security and place the initial risk assessment on the CII operator.

How does cryptography compliance overlap with China cybersecurity law?

How should teams separate the decisions?

Reuse the same technical facts while recording separate legal conclusions. A product may raise an Article 26 catalogue question without being procured by a CII operator. A CII deployment may require an Article 27 application assessment even when the procurement does not meet the national-security-review condition.

For each route, record the legal trigger, responsible operator or supplier, competent process, supporting evidence, and the legal basis for recognising an earlier test or assessment. A direction to avoid duplication does not automatically make one report a substitute for another. The Cryptography Law cross-references also do not establish compliance with unrelated cybersecurity, data, personal-information, or sector-specific duties.

Reopen the decisions when the product model or cryptographic function changes, the catalogue or standards change, the network's classified-protection level changes, infrastructure is identified as CII, the commercial-cryptography application plan changes during construction, the supplier or procurement scope changes, or a new national-security risk appears. An annual assessment date does not postpone a reassessment expressly triggered during construction or by a major cryptography incident or security hazard.

  • Article 26 product or service status and testing or certification evidence.
  • Article 27 CII status and the rule that requires commercial-cryptography protection.
  • Classified-protection level and the corresponding commercial-cryptography use, management, and assessment requirements.
  • Commercial-cryptography application security assessment, its annual cycle for covered CII, and its coordination with other assessments.
  • The separate annual CII network-security assessment required by Cybersecurity Law Article 40.
  • Separate procurement facts showing whether a network product or service may affect national security.
  • Any broader Cybersecurity Law conclusion, supported by the source that governs that duty.
  • The owner, review date, approval, next annual-assessment date, and event-based reassessment triggers for each conclusion.
Citations
PRC Cryptography Law

Articles 26 and 27 identify distinct product, CII assessment, and procurement-review triggers even where the underlying technical facts overlap.

PRC Cybersecurity Law

Articles 23 and 40 distinguish classified-protection controls and the annual CII network-security assessment from the commercial-cryptography assessment.

How does cryptography compliance overlap with China cybersecurity law?

What to keep as evidence

Maintain separate records for the Article 26 product or service route, the CII commercial-cryptography lifecycle assessment, the graded-protection conclusion, the annual CII network-security assessment, and any procurement cybersecurity review. Link shared technical facts without merging the legal results.

  • Shared product, supplier, cryptographic-function, network, and operator facts.
  • Separate Cryptography Law classification and product/service assurance conclusion, including the exact 2023 catalogue category and threshold analysis where Article 26 is considered.
  • Separate CII status, classified-protection level, annual cybersecurity assessment, product testing, and national-security-review conclusions.
  • Evidence showing where testing or assessment was coordinated to avoid duplication.
  • For CII already under construction or operating on 1 August 2025, the transition analysis and the first assessment completed under the applicable construction, pre-operation, or annual route.
  • Distinct owners, approvals, source citations, and change triggers for each regime.
Citations
PRC Cryptography Law

Articles 26 and 27 support the separate records for product assurance, CII assessment coordination, and procurement review.

What is commercial cryptography in China?

What does commercial cryptography cover?

Article 2 defines cryptography broadly as technologies, products, and services that use specific transformations to encrypt information or provide security authentication. The category can therefore cover a cryptographic authentication function even when confidentiality is not the main purpose. Articles 6-8 then divide cryptography into core, ordinary, and commercial categories.

Core and ordinary cryptography protect state-secret information and are subject to strict unified management. Commercial cryptography protects information that is not a state secret, and citizens, legal persons, and other organisations may lawfully use it to protect network and information security.

The word commercial describes the statutory non-state-secret category; it does not mean that only businesses use it or that every product sold commercially follows a mandatory approval route. The law also requires authorities to treat foreign-invested enterprises lawfully and equally in commercial-cryptography research, production, sale, service, and import or export activities.

The Cryptography Law took effect on 1 January 2020. The revised Commercial Cryptography Administration Regulation took effect on 1 July 2023 and applies within China to commercial-cryptography research, production, sale, service, testing, certification, import, export, application, and supervision. Its definition confirms that commercial cryptography includes technologies, products, and services used for encryption protection or security authentication of non-state-secret information.

Citations
PRC Cryptography Law

Articles 2, 6-8, and 21 define cryptography, distinguish core, ordinary, and commercial cryptography, permit lawful use for non-state-secret information, and state the non-discrimination rule for foreign-invested enterprises.

What is commercial cryptography in China?

What does the classification change?

Commercial-cryptography status alone does not trigger universal approval. Article 24 of the law and Article 11 of the implementing regulation require commercial-cryptography activities to comply with applicable laws, administrative regulations, mandatory national standards, and publicly declared standards. More specific facts determine the remaining duties.

Record the protected information, cryptographic function, product or service, supplier, operator, and China use case. Check each possible route separately because a commercial-cryptography product may fall outside some mandatory routes.

  • Product or service assurance: check whether the product falls in the catalogue for critical network equipment and specialised cybersecurity products, or whether a commercial-cryptography service uses such products.
  • Network operation: check the commercial-cryptography requirements that apply under the network-security classified-protection system.
  • CII use and procurement: determine whether a CII operator must use commercial cryptography, conduct an application security assessment, use qualified products and services, or submit a procurement for national-security review.
  • Electronic certification: providing electronic certification with commercial cryptography follows the separate permission and operating requirements in the implementing regulation.
  • Trade: check the current import-licence list or export-control list and the exception for commercial cryptography used in mass-market consumer products.
Citations
PRC Cryptography Law

Articles 24-28 set the standards, testing and certification, specified-product, CII, and import/export routes that must be assessed after classification.

What is commercial cryptography in China?

What to keep as evidence

The record should identify the protected information, explain why it is or is not a state secret, describe the encryption-protection or security-authentication function, and keep the commercial-cryptography classification separate from every downstream approval, assurance, assessment, and trade-control decision.

  • The information protected and the basis for treating it as state-secret or non-state-secret information.
  • The technology, product, or service and how it is supplied or used.
  • The classification conclusion and official article relied upon.
  • Any mandatory product/service, electronic-certification, classified-protection, CII, or trade-control trigger checked.
  • Person who approved the classification, approval date, and the product or use-case changes that require reassessment.
Citations
PRC Cryptography Law

Articles 2, 6-8, and 24-28 support the classification facts and the separate downstream trigger checks listed here.

When is commercial cryptography testing or certification needed?

When is assurance voluntary or mandatory?

Article 25 of the Cryptography Law and Article 12 of the implementing regulation encourage voluntary commercial-cryptography testing and certification. Voluntary assurance does not waive Article 11: the activity must still comply with applicable laws, administrative regulations, mandatory national standards, and the operator's publicly declared standards. Testing and certification bodies must hold the required qualifications and work within their approved scope under the applicable technical specifications and rules.

Mandatory assurance applies to a narrower group. A commercial-cryptography product involving national security, the national economy and people's livelihoods, or the public interest must be included in the catalogue of critical network equipment and specialised cybersecurity products and pass qualified testing and certification before sale or provision. Both conditions matter: a cryptographic product outside that catalogue, or a listed network product that is not commercial cryptography, does not enter this mandatory route on those facts alone. A commercial-cryptography service that uses critical network equipment and specialised cybersecurity products must pass service certification.

The current network-product catalogue, effective since 3 July 2023, includes routers, switches, rack servers, and PLC equipment that meet stated technical thresholds, plus categories such as firewalls, intrusion-detection systems, VPN products, public-key infrastructure, file-encryption products, and identity-authentication products. Match the exact product and threshold. Do not substitute the separate commercial-cryptography product certification catalogue, which supports the national voluntary certification system, for the mandatory network-product catalogue.

Citations
PRC Cryptography Law

Articles 25 and 26 distinguish voluntary testing and certification from mandatory assurance for specified products and services.

When is commercial cryptography testing or certification needed?

When is a CII application assessment required?

Article 27 applies when laws, administrative regulations, or other state rules require a CII to use commercial cryptography for protection. The CII operator must conduct the commercial-cryptography application security assessment itself or commission a commercial-cryptography testing body.

Articles 38 and 39 of the implementing regulation require the operator to prepare a commercial-cryptography application plan, provide funding and professional staff, and plan, build, and operate the cryptography protection system alongside the CII. The CII provisions effective 1 August 2025 make the lifecycle explicit: assess the application plan, reassess it if it changes during construction, pass an assessment before operation, and assess at least annually after operation. CII already under construction on that date follows the construction and pre-operation route; CII already operating follows the annual route. Its commercial-cryptography products and services must be tested and certified, while its algorithms, protocols, key-management mechanisms, and other cryptographic technologies must pass state cryptography administration review and appraisal.

A failed plan assessment means the plan cannot be used as the construction basis. A failed pre-operation assessment requires modification and prevents operation during the modification period. A failed annual assessment also requires modification, but the operator must take necessary measures to keep the operating CII secure during that work. A major cryptography-related security incident, major cryptography security hazard, or special emergency must be reported promptly and can require another assessment.

When the Commercial Cryptography Application Security Assessment Measures apply, file the assessment report and related work information with the National Cryptography Administration or the relevant province-level cryptography authority within 30 days after the report is formed. An operator that performs its own assessment must retain the original records and report for at least six years. These filing and retention duties belong to the system assessment; they do not turn a product report into a system-assessment result.

Article 42 requires coordination with CII security testing and the network-security classified-protection assessment system to avoid duplicate work. Coordination does not erase the separate trigger, scope, or required conclusion for each assessment.

  • Confirm the operator's CII status and identify the rule requiring commercial-cryptography protection.
  • Prepare the application plan and record the funding, staff, and parallel planning, construction, and operation of the cryptography protection system.
  • Separate the Article 26 product or service conclusion from the Article 27 application assessment.
  • Complete the covered CII assessment before operation, then schedule it at least annually, file the report and related work information within 30 days, and retain self-assessment records and reports for at least six years.
  • For CII already under construction or operating on 1 August 2025, document the applicable transition branch and the first assessment completed under it.
  • Verify the product and service certificates and the review status of algorithms, protocols, and key-management mechanisms used by the covered CII.
  • If commissioning a qualified body that issues proof-bearing results, verify its commercial-cryptography testing-body qualification and scope.
  • Record how existing cybersecurity assessments were coordinated to avoid duplicate work.
  • Reassess after a construction-stage plan change and evaluate whether a major incident, major cryptography security hazard, or special emergency requires an additional assessment.
Citations
PRC Cryptography Law

Article 27 sets the CII application security assessment trigger and requires coordination with related CII and classified-protection assessments.

Commercial Cryptography Administration Regulation

Articles 38-42 set the application plan, resources, parallel planning, construction and operation, pre-operation and annual assessment cycle, filing, qualified-product and service requirements, technology review, and coordination with other assessments.

When is commercial cryptography testing or certification needed?

What to keep as evidence

The record should show whether assurance is voluntary, mandatory for an Article 26 product or service, or part of the CII application-assessment lifecycle. Keep the exact catalogue entry, qualified-body scope, report or certificate, CII trigger, assessment stage, result, filing, and remediation together.

  • Product or service identity, version, supplier, and applicable catalogue entry or other trigger.
  • Whether assurance is voluntary, mandatory under Article 26, or a CII application assessment under Article 27; for Article 26, retain both the commercial-cryptography analysis and the exact mandatory catalogue match.
  • Testing or certification body identity, scope, qualification, report or certificate, and validity status.
  • The legal basis and scope for recognising earlier cybersecurity testing or assessment to avoid duplication.
  • For covered CII, the plan result, pre-operation result, annual assessment history, transition branch, remediation, filing evidence, and cryptographic-technology review records.
  • Changes to product scope, model, cryptographic function, supplier, certificate, catalogue, standards, application plan, or CII deployment that require a new conclusion or reassessment.
Citations
PRC Cryptography Law

Articles 25-27 support distinguishing voluntary assurance, mandatory product or service assurance, and CII application assessment.

Page 1 of 1
Previous1Next