---
title: "China Cryptography Law FAQ"
canonical_url: "https://www.sorena.io/artifacts/apac/china-cryptography-law/faq"
source_url: "https://www.sorena.io/artifacts/apac/china-cryptography-law/faq/items"
author: "Sorena AI"
description: "Answers on China's commercial-cryptography scope, product assurance, classified protection, CII assessment, procurement review, and trade controls."
published_at: "2026-07-05"
updated_at: "2026-07-25"
keywords:
  - "China Cryptography Law"
  - "Commercial cryptography"
  - "Cryptography Law"
  - "Commercial cryptography testing"
  - "China cybersecurity"
---
**[SORENA](https://www.sorena.io/)** - AI-Powered GRC Platform

[Home](https://www.sorena.io/) | [Solutions](https://www.sorena.io/solutions) | [Artifacts](https://www.sorena.io/artifacts) | [About Us](https://www.sorena.io/about-us) | [Contact](https://www.sorena.io/contact) | [Portal](https://app.sorena.io)

---

# China Cryptography Law FAQ

Answers on China's commercial-cryptography scope, product assurance, classified protection, CII assessment, procurement review, and trade controls.

*FAQ* *China*

## China Cryptography Law FAQ

Answers on commercial-cryptography classification, product and service assurance, CII assessment, procurement review, and import or export controls.

Use the answers to identify the applicable route and the facts to retain. Product catalogues, import and export lists, classified-protection requirements, and CII conclusions still need a current, fact-specific check.

Classify commercial cryptography first, then distinguish ordinary lawful use from the separate triggers for product or service assurance, electronic-certification permission, classified-protection requirements, CII assessment, procurement review, and import or export controls.

## Definitions

### Commercial cryptography

Commercial cryptography covers technologies, products, and services that use specific transformations to encrypt or authenticate information that is not a state secret. It can include encryption protection and security authentication in software, hardware, or a supplied service; the word commercial describes the legal category, not a requirement that the information itself be sold.

**Why it matters here:** This classification is the first step. Separate rules decide whether a specific activity needs product or service assurance, electronic-certification permission, a network or CII assessment, procurement review, or an import or export licence.

Sources:

- [PRC Cryptography Law](https://www.oscca.gov.cn/sca/xxgk/2023-06/04/content_1057225.shtml?ref=sorena.io)
- [Commercial Cryptography Administration Regulation](https://xzfg.moj.gov.cn/front/law/detail?LawID=1622&ref=sorena.io)

### Commercial-cryptography application security assessment

This assessment evaluates how a network or information system applies commercial cryptography, including the applicable cryptographic products, services, algorithms, protocols, key-management mechanisms, and operating controls. A qualified outside testing body may perform the assessment when the operator commissions one, while the law also permits covered CII operators to conduct the assessment themselves.

**Why it matters here:** For CII that is legally required to use commercial cryptography, the implementing regulation requires the infrastructure to pass the assessment before operation and to be assessed at least annually after operation. Other network assessment requirements depend on classified-protection rules.

Sources:

- [Commercial Cryptography Administration Regulation](https://xzfg.moj.gov.cn/front/law/detail?LawID=1622&ref=sorena.io)
- [PRC Cryptography Law](https://www.oscca.gov.cn/sca/xxgk/2023-06/04/content_1057225.shtml?ref=sorena.io)

### Mass-market consumer products

Mass-market consumer products are the product category whose embedded commercial cryptography is excluded by the Cryptography Law and its implementing regulation from the commercial-cryptography import-licence and export-control system. The legislation states the exclusion but does not provide a complete product test in the cited provisions.

**Why it matters here:** Do not apply the exception from the presence of ordinary encryption alone. Record the exact model, users, distribution, functions, and list criteria, and use the competent authority's identification or consultation route if classification remains unclear.

Sources:

- [Commercial Cryptography Administration Regulation](https://xzfg.moj.gov.cn/front/law/detail?LawID=1622&ref=sorena.io)
- [PRC Cryptography Law](https://www.oscca.gov.cn/sca/xxgk/2023-06/04/content_1057225.shtml?ref=sorena.io)

### Critical information infrastructure

**Term:** CII

Critical information infrastructure is infrastructure in important industries and fields whose destruction, loss of function, or data leakage could seriously harm national security, the national economy and people's livelihoods, or the public interest. The competent protection department identifies the infrastructure and notifies the operator under the applicable rules; a company should not infer CII status from its sector or the importance of a system alone.

**Why it matters here:** CII status activates additional operator duties for commercial cryptography governance, products and services, reviewed cryptographic technologies, application planning, assessment, annual reporting, and procurement review. The specific cryptography duties still depend on the applicable requirement to use commercial cryptography.

Sources:

- [Critical Information Infrastructure Security Protection Regulation, Articles 2 and 8-11](https://www.cac.gov.cn/2021-08/17/c_1630785976988160.htm?ref=sorena.io)
- [Provisions on the Use and Administration of Commercial Cryptography in Critical Information Infrastructure, Articles 2 and 5-15](https://www.oscca.gov.cn/sca/xxgk/2025-06/27/content_1061270.shtml?ref=sorena.io)

### Network-security classified-protection system

**Term:** classified-protection system

China's network-security classified-protection system assigns a protection level to a network according to the harm that damage could cause, then applies level-specific security duties. The Commercial Cryptography Administration Regulation requires network operators to use commercial cryptography according to that system and states that the cryptography authority determines level-based use, management, and assessment requirements.

**Why it matters here:** This route can matter outside CII. Record the network's confirmed protection level and the current cryptography standards and requirements for that level; do not apply CII-only duties merely because a network has a classified-protection level.

Sources:

- [Commercial Cryptography Administration Regulation, Articles 41-42](https://xzfg.moj.gov.cn/front/law/detail?LawID=1622&ref=sorena.io)
- [PRC Cybersecurity Law, Article 23](https://www.cac.gov.cn/2025-12/29/c_1768735112911946.htm?ref=sorena.io)

### Network critical equipment and network security-specific products

These are products within the catalogue published under the Cybersecurity Law. A covered product must meet mandatory national standards and pass qualified security certification or security testing before sale or provision. A commercial cryptography product certification catalogue belongs to a different, generally voluntary certification system.

**Why it matters here:** Cryptography Law Article 26 makes qualified testing and certification mandatory for a commercial cryptography product only when the actual product falls within this network-product catalogue. A commercial cryptography service using a product in the catalogue must also be certified.

Sources:

- [PRC Cybersecurity Law, Article 25](https://www.cac.gov.cn/2025-12/29/c_1768735112911946.htm?ref=sorena.io)
- [PRC Cryptography Law, Article 26](https://www.oscca.gov.cn/sca/xxgk/2023-06/04/content_1057225.shtml?ref=sorena.io)

## Browse sub-FAQ modules

### [Do imported cryptography products need special review?](/artifacts/apac/china-cryptography-law/faq/do-imported-cryptography-products-need-special-review.md)

Not every encrypted product imported into China needs a licence. Check the 2020 commercial-cryptography import list, the consumer-product exception, and any CII procurement review.

- 3 items

### [Does using encryption trigger China Cryptography Law duties?](/artifacts/apac/china-cryptography-law/faq/does-using-encryption-trigger-china-cryptography-law.md)

Using encryption does not create one universal China approval duty. Check classified protection, product, service, CII, procurement, and trade triggers.

- 3 items

### [How does cryptography compliance overlap with China cybersecurity law?](/artifacts/apac/china-cryptography-law/faq/how-does-cryptography-compliance-overlap-with-cybersecurity-law.md)

See how China's cryptography rules connect with classified protection, product assurance, CII assessment, and cybersecurity review without merging the regimes.

- 3 items

### [What is commercial cryptography in China?](/artifacts/apac/china-cryptography-law/faq/what-is-commercial-cryptography-in-china.md)

Commercial cryptography protects information that is not a state secret. Learn how China defines the category and which separate facts trigger product, CII, or trade controls.

- 3 items

### [When is commercial cryptography testing or certification needed?](/artifacts/apac/china-cryptography-law/faq/when-is-commercial-cryptography-testing-or-certification-needed.md)

Commercial-cryptography assurance is often voluntary, but specified products and services require it. Covered CII also needs application assessment and qualified cryptography.

- 3 items

Browse all indexed questions: [/artifacts/apac/china-cryptography-law/faq/items](/artifacts/apac/china-cryptography-law/faq/items.md)

## All FAQ items

*Page 1 of 1. Showing 15 of 15 items.*

### [When can an import licence apply?](/artifacts/apac/china-cryptography-law/faq/do-imported-cryptography-products-need-special-review.md#when-can-an-import-licence-apply)

*Module: [Do imported cryptography products need special review?](/artifacts/apac/china-cryptography-law/faq/do-imported-cryptography-products-need-special-review.md)*

Article 28 of the Cryptography Law and Articles 31-34 of the implementing regulation establish list-based import licensing. The operative import reference is the Commercial Cryptography Import Licence List issued with Announcement No. 63 of 2020. Listed items and technologies require an import licence from the Ministry of Commerce.

Sources for this answer:

- [PRC Cryptography Law](https://www.oscca.gov.cn/sca/xxgk/2023-06/04/content_1057225.shtml?ref=sorena.io) - Article 28 states the import-licence and export-control criteria and assigns publication of the controlling lists to the competent authorities.
- [Commercial Cryptography Administration Regulation](https://xzfg.moj.gov.cn/front/law/detail?LawID=1622&ref=sorena.io) - Articles 31-34 require licences for listed items and technologies, describe customs handling, identify the application materials, and set the ordinary 45-working-day decision period.
- [Announcement No. 63 of 2020 on commercial-cryptography import and export controls](https://exportcontrol.mofcom.gov.cn/article/zcfg/gnzcfg/zcfggzqd/202111/416.html?ref=sorena.io) - Official source for the commercial-cryptography import list, effective from 1 January 2021.
- [Ministry of Commerce commercial-cryptography import licence guide](https://www.mofcom.gov.cn/zwdt/lywxhjsjcksp/index.html?ref=sorena.io) - Current official application guide, list reference, required materials, process, and consultation route for uncertain product identification.
- [Ministry of Commerce dual-use licensing FAQ](https://exportcontrol.mofcom.gov.cn/article/cjwt/202504/1135.html?ref=sorena.io) - The official FAQ confirms that commercial-cryptography imports use the 2020 import list and directs uncertain classifications to the dual-use import/export consultation route.

### [Which exceptions and separate reviews matter?](/artifacts/apac/china-cryptography-law/faq/do-imported-cryptography-products-need-special-review.md#which-exceptions-and-separate-reviews-matter)

*Module: [Do imported cryptography products need special review?](/artifacts/apac/china-cryptography-law/faq/do-imported-cryptography-products-need-special-review.md)*

Article 28 and Article 31 of the implementing regulation exclude commercial cryptography used in mass-market consumer products from this import-licence and export-control system. The cited provisions do not define a complete category test, so retain the facts and legal basis for applying the exception.

- Identify the exact model, version, cryptographic function, importer, intended users, and end use.
- Record the current official list and the date on which it was checked.
- Explain why the mass-market consumer-product exception does or does not apply.
- If list coverage remains unclear, retain the consultation or identification request and the authority's response.
- If the buyer is a CII operator, record the separate CII procurement-review conclusion.

Sources for this answer:

- [PRC Cryptography Law](https://www.oscca.gov.cn/sca/xxgk/2023-06/04/content_1057225.shtml?ref=sorena.io) - Article 28 provides the mass-market consumer-product exception; Article 27 provides the separate CII procurement national-security-review route.
- [PRC Dual-Use Items Export Control List announcement](https://www.mofcom.gov.cn/zcfb/zc/art/2024/art_461aafbb5e974f47b1c23866643cb71c.html?ref=sorena.io) - Announcement No. 51 of 2024 made the unified export-control list effective on 1 December 2024 and made the 2020 commercial-cryptography export list and procedure inapplicable.
- [PRC Regulation on Export Control of Dual-Use Items](https://www.mofcom.gov.cn/zwgk/zcfb/art/2024/art_bf56a4c613eb47af85712117561d609e.html?ref=sorena.io) - Articles 12-14 support temporary controls, catch-all licensing, and the current list-based dual-use export-licensing system.
- [Cybersecurity Review Measures](https://www.cac.gov.cn/2022-01/04/c_1642894602182845.htm?ref=sorena.io) - Articles 2 and 5 state the CII procurement-review condition and require the operator to assess possible national-security effects.

### [What to keep as evidence](/artifacts/apac/china-cryptography-law/faq/do-imported-cryptography-products-need-special-review.md#what-to-keep-as-evidence)

*Module: [Do imported cryptography products need special review?](/artifacts/apac/china-cryptography-law/faq/do-imported-cryptography-products-need-special-review.md)*

The record should show why the exact item and technology do or do not match the 2020 commercial-cryptography import list, why the mass-market consumer-product exception does or does not apply, and whether a CII procurement affects or may affect national security. If the same item will be exported, keep that conclusion separate because the unified dual-use export-control list now governs export screening.

- Product model, cryptographic function, intended users, and evidence for or against the mass-market consumer-product exception.
- Importer, customs classification, technical description, end use, and the current import-list check.
- Any transit, transshipment, through-shipment, re-export, bonded-zone, warehouse, or logistics-centre movement covered by Article 32.
- Import-licence conclusion, application and supporting materials, acceptance date, decision or identification response, Customs presentation record, decision owner, date, and official source.
- For an export, a separate check against the unified dual-use export-control list.
- Separate CII procurement and national-security-review screening where applicable.
- Supplier, product, list, end-use, or operator changes that require reassessment.

Sources for this answer:

- [PRC Cryptography Law](https://www.oscca.gov.cn/sca/xxgk/2023-06/04/content_1057225.shtml?ref=sorena.io) - Articles 27 and 28 support retaining the product, list, exception, and CII procurement facts needed to reconstruct the decision.
- [Commercial Cryptography Administration Regulation](https://xzfg.moj.gov.cn/front/law/detail?LawID=1622&ref=sorena.io) - Articles 31-34 identify the licence trigger, customs process, application materials, and review process.
- [PRC Dual-Use Items Export Control List announcement](https://www.mofcom.gov.cn/zcfb/zc/art/2024/art_461aafbb5e974f47b1c23866643cb71c.html?ref=sorena.io) - Current source for the shift from the former commercial-cryptography export list to the unified dual-use list.

### [Why is encryption alone not the trigger?](/artifacts/apac/china-cryptography-law/faq/does-using-encryption-trigger-china-cryptography-law.md#why-is-encryption-alone-not-the-trigger)

*Module: [Does using encryption trigger China Cryptography Law duties?](/artifacts/apac/china-cryptography-law/faq/does-using-encryption-trigger-china-cryptography-law.md)*

Article 8 permits citizens, legal persons, and other organisations to use commercial cryptography to protect network and information security when the protected information is not a state secret. Official State Cryptography Administration guidance confirms that the law imposes no compulsory use requirement on ordinary users. The law does not require prior approval for every use of encryption.

Sources for this answer:

- [PRC Cryptography Law](https://www.oscca.gov.cn/sca/xxgk/2023-06/04/content_1057225.shtml?ref=sorena.io) - Article 8 permits lawful commercial-cryptography use for non-state-secret information; Articles 25-28 set the narrower testing, product, CII, procurement, and trade triggers.
- [State Cryptography Administration policy Q&A on use of commercial cryptography](https://oscca.gov.cn/sca/xxgk/2020-01/28/content_1060626.shtml?ref=sorena.io) - The official Q&A states that the law does not impose a compulsory commercial-cryptography use requirement on ordinary users and distinguishes the CII route.
- [State Cryptography Administration policy Q&A on cryptography and passwords](https://www.oscca.gov.cn/sca/xxgk/2020-01/08/content_1057375.shtml?ref=sorena.io) - The official Q&A distinguishes an access password from cryptography under the Cryptography Law and explains that passwords are basic identity-authentication credentials.
- [Commercial Cryptography Administration Regulation](https://xzfg.moj.gov.cn/front/law/detail?LawID=1622&ref=sorena.io) - Articles 11 and 20-42 set the general standards duty and the product, service, electronic-certification, import/export, CII, procurement, and classified-protection requirements.
- [Electronic Certification Service Cryptography Use Management Measures](https://www.oscca.gov.cn/sca/xxgk/2026-06/03/content_1061341.shtml?ref=sorena.io) - Articles 2-3 establish the current electronic-certification cryptography-use licence route effective from 1 July 2026.

### [Which questions decide the route?](/artifacts/apac/china-cryptography-law/faq/does-using-encryption-trigger-china-cryptography-law.md#which-questions-decide-the-route)

*Module: [Does using encryption trigger China Cryptography Law duties?](/artifacts/apac/china-cryptography-law/faq/does-using-encryption-trigger-china-cryptography-law.md)*

Start with the function and protected information, not the presence of a familiar algorithm or library. Article 2 covers both encryption protection and security authentication, and it applies to technologies, products, and services.

- Does the technology, product, or service use specific transformations for encryption protection or security authentication?
- Is it protecting state-secret information or information that is not a state secret?
- Is the item sold or provided as a product or service covered by Article 26?
- Is the organisation providing an electronic certification service that uses commercial cryptography?
- What network-security classified-protection level and commercial-cryptography requirements apply to the network?
- Is it used or procured by a CII operator in circumstances covered by Article 27?
- Is an import covered by the commercial-cryptography import list, is an export covered by the unified dual-use export-control list, or does the mass-market consumer-product exception apply?

Sources for this answer:

- [PRC Cryptography Law](https://www.oscca.gov.cn/sca/xxgk/2023-06/04/content_1057225.shtml?ref=sorena.io) - Articles 2, 6-8, and 25-28 support the classification sequence and the separate mandatory-trigger questions.
- [Commercial Cryptography Administration Regulation](https://xzfg.moj.gov.cn/front/law/detail?LawID=1622&ref=sorena.io) - Articles 20-42 support the product, service, electronic-certification, trade, CII, procurement, and classified-protection questions.
- [PRC Dual-Use Items Export Control List announcement](https://www.mofcom.gov.cn/zcfb/zc/art/2024/art_461aafbb5e974f47b1c23866643cb71c.html?ref=sorena.io) - The unified export-control list replaced the former commercial-cryptography export list from 1 December 2024.

### [What to keep as evidence](/artifacts/apac/china-cryptography-law/faq/does-using-encryption-trigger-china-cryptography-law.md#what-to-keep-as-evidence)

*Module: [Does using encryption trigger China Cryptography Law duties?](/artifacts/apac/china-cryptography-law/faq/does-using-encryption-trigger-china-cryptography-law.md)*

The record should show why the function is or is not commercial cryptography and the result of each relevant standards, product, service, electronic-certification, network-level, CII, procurement-review, import, and export check.

- Product, service, component, version, algorithm or module, and intended protection purpose.
- Supplier statement and the factual basis for treating the use as commercial cryptography.
- Applicable mandatory national standards and the operator's publicly declared standards, even where testing or certification is voluntary.
- Catalogue or mandatory-route screening for the product or service.
- Network protection level and the corresponding commercial-cryptography use, management, and assessment requirements.
- Electronic-certification provider and permission screening, if the service verifies electronic signatures or certificates.
- CII operator and national-security-review screening where relevant.
- Import/export list screening and the event that will reopen the conclusion.

Sources for this answer:

- [PRC Cryptography Law](https://www.oscca.gov.cn/sca/xxgk/2023-06/04/content_1057225.shtml?ref=sorena.io) - Articles 2, 6-8, and 25-28 support the facts and trigger decisions that should be retained.
- [Commercial Cryptography Administration Regulation](https://xzfg.moj.gov.cn/front/law/detail?LawID=1622&ref=sorena.io) - Articles 11 and 20-42 support retaining standards, assurance, electronic-certification, network-level, CII, procurement, and trade conclusions.

### [Where do the laws connect?](/artifacts/apac/china-cryptography-law/faq/how-does-cryptography-compliance-overlap-with-cybersecurity-law.md#where-do-the-laws-connect)

*Module: [How does cryptography compliance overlap with China cybersecurity law?](/artifacts/apac/china-cryptography-law/faq/how-does-cryptography-compliance-overlap-with-cybersecurity-law.md)*

First, Article 41 of the Commercial Cryptography Administration Regulation, in force since 1 July 2023, requires network operators to use commercial cryptography according to the network-security classified-protection system. The state cryptography administration sets use, management, and application-assessment requirements by protection level. The rule applies to network operators beyond CII.

Sources for this answer:

- [PRC Cryptography Law](https://www.oscca.gov.cn/sca/xxgk/2023-06/04/content_1057225.shtml?ref=sorena.io) - Articles 26 and 27 establish the links to Cybersecurity Law product assurance, CII assessment coordination, and national-security review.
- [Commercial Cryptography Administration Regulation](https://xzfg.moj.gov.cn/front/law/detail?LawID=1622&ref=sorena.io) - Articles 20-21 and 38-42 detail product and service assurance, CII assessment timing, procurement review, classified-protection duties, and coordination among assessments.
- [PRC Cybersecurity Law](https://www.cac.gov.cn/2025-12/29/c_1768735112911946.htm?ref=sorena.io) - The current law, amended in 2025 and effective from 1 January 2026, sets classified-protection duties in Article 23, listed-product assurance and mutual recognition in Article 25, and an annual CII security-assessment duty in Article 40.
- [Cybersecurity Review Measures](https://www.cac.gov.cn/2022-01/04/c_1642894602182845.htm?ref=sorena.io) - Articles 2 and 5 require cybersecurity review for a CII procurement that affects or may affect national security and place the initial risk assessment on the CII operator.
- [CII Commercial Cryptography Use Management Provisions](https://www.oscca.gov.cn/sca/xxgk/2025-06/27/content_1061270.shtml?ref=sorena.io) - Articles 11-15 establish the plan, construction-change, pre-operation, annual, transition, and assessment-coordination rules effective from 1 August 2025.
- [2023 Catalogue of Critical Network Equipment and Specialised Cybersecurity Products](https://www.miit.gov.cn/jgsj/waj/wjfb/art/2023/art_9080a8689c58416eaf56f88649c242d3.html?ref=sorena.io) - The joint-authority catalogue supplies the current product categories and the router, switch, rack-server, and PLC thresholds; it also replaced the 2017 catalogue from 3 July 2023.

### [How should teams separate the decisions?](/artifacts/apac/china-cryptography-law/faq/how-does-cryptography-compliance-overlap-with-cybersecurity-law.md#how-should-teams-separate-the-decisions)

*Module: [How does cryptography compliance overlap with China cybersecurity law?](/artifacts/apac/china-cryptography-law/faq/how-does-cryptography-compliance-overlap-with-cybersecurity-law.md)*

Reuse the same technical facts while recording separate legal conclusions. A product may raise an Article 26 catalogue question without being procured by a CII operator. A CII deployment may require an Article 27 application assessment even when the procurement does not meet the national-security-review condition.

- Article 26 product or service status and testing or certification evidence.
- Article 27 CII status and the rule that requires commercial-cryptography protection.
- Classified-protection level and the corresponding commercial-cryptography use, management, and assessment requirements.
- Commercial-cryptography application security assessment, its annual cycle for covered CII, and its coordination with other assessments.
- The separate annual CII network-security assessment required by Cybersecurity Law Article 40.
- Separate procurement facts showing whether a network product or service may affect national security.
- Any broader Cybersecurity Law conclusion, supported by the source that governs that duty.
- The owner, review date, approval, next annual-assessment date, and event-based reassessment triggers for each conclusion.

Sources for this answer:

- [PRC Cryptography Law](https://www.oscca.gov.cn/sca/xxgk/2023-06/04/content_1057225.shtml?ref=sorena.io) - Articles 26 and 27 identify distinct product, CII assessment, and procurement-review triggers even where the underlying technical facts overlap.
- [Commercial Cryptography Administration Regulation](https://xzfg.moj.gov.cn/front/law/detail?LawID=1622&ref=sorena.io) - Articles 38-42 distinguish CII application, procurement review, classified-protection, and assessment-coordination decisions.
- [PRC Cybersecurity Law](https://www.cac.gov.cn/2025-12/29/c_1768735112911946.htm?ref=sorena.io) - Articles 23 and 40 distinguish classified-protection controls and the annual CII network-security assessment from the commercial-cryptography assessment.
- [Commercial Cryptography Application Security Assessment Measures](https://www.oscca.gov.cn/sca/xxgk/2023-10/07/content_1061109.shtml?ref=sorena.io) - Articles 6-15 support the lifecycle assessment, construction-change, annual, remediation, filing, and incident-driven reassessment triggers.

### [What to keep as evidence](/artifacts/apac/china-cryptography-law/faq/how-does-cryptography-compliance-overlap-with-cybersecurity-law.md#what-to-keep-as-evidence)

*Module: [How does cryptography compliance overlap with China cybersecurity law?](/artifacts/apac/china-cryptography-law/faq/how-does-cryptography-compliance-overlap-with-cybersecurity-law.md)*

Maintain separate records for the Article 26 product or service route, the CII commercial-cryptography lifecycle assessment, the graded-protection conclusion, the annual CII network-security assessment, and any procurement cybersecurity review. Link shared technical facts without merging the legal results.

- Shared product, supplier, cryptographic-function, network, and operator facts.
- Separate Cryptography Law classification and product/service assurance conclusion, including the exact 2023 catalogue category and threshold analysis where Article 26 is considered.
- Separate CII status, classified-protection level, annual cybersecurity assessment, product testing, and national-security-review conclusions.
- Evidence showing where testing or assessment was coordinated to avoid duplication.
- For CII already under construction or operating on 1 August 2025, the transition analysis and the first assessment completed under the applicable construction, pre-operation, or annual route.
- Distinct owners, approvals, source citations, and change triggers for each regime.

Sources for this answer:

- [PRC Cryptography Law](https://www.oscca.gov.cn/sca/xxgk/2023-06/04/content_1057225.shtml?ref=sorena.io) - Articles 26 and 27 support the separate records for product assurance, CII assessment coordination, and procurement review.
- [Commercial Cryptography Administration Regulation](https://xzfg.moj.gov.cn/front/law/detail?LawID=1622&ref=sorena.io) - Articles 38-42 support separate records for CII application, classified protection, procurement review, and assessment coordination.
- [Cybersecurity Review Measures](https://www.cac.gov.cn/2022-01/04/c_1642894602182845.htm?ref=sorena.io) - Articles 5-10 support retaining the procurement risk analysis, filing materials, supplier commitments, and review factors.

### [What does commercial cryptography cover?](/artifacts/apac/china-cryptography-law/faq/what-is-commercial-cryptography-in-china.md#what-does-commercial-cryptography-cover)

*Module: [What is commercial cryptography in China?](/artifacts/apac/china-cryptography-law/faq/what-is-commercial-cryptography-in-china.md)*

Article 2 defines cryptography broadly as technologies, products, and services that use specific transformations to encrypt information or provide security authentication. The category can therefore cover a cryptographic authentication function even when confidentiality is not the main purpose. Articles 6-8 then divide cryptography into core, ordinary, and commercial categories.

Sources for this answer:

- [PRC Cryptography Law](https://www.oscca.gov.cn/sca/xxgk/2023-06/04/content_1057225.shtml?ref=sorena.io) - Articles 2, 6-8, and 21 define cryptography, distinguish core, ordinary, and commercial cryptography, permit lawful use for non-state-secret information, and state the non-discrimination rule for foreign-invested enterprises.
- [Commercial Cryptography Administration Regulation](https://xzfg.moj.gov.cn/front/law/detail?LawID=1622&ref=sorena.io) - Articles 2 and 67 define commercial cryptography, state the activities in China to which the regulation applies, and set 1 July 2023 as its commencement date.

### [What does the classification change?](/artifacts/apac/china-cryptography-law/faq/what-is-commercial-cryptography-in-china.md#what-does-the-classification-change)

*Module: [What is commercial cryptography in China?](/artifacts/apac/china-cryptography-law/faq/what-is-commercial-cryptography-in-china.md)*

Commercial-cryptography status alone does not trigger universal approval. Article 24 of the law and Article 11 of the implementing regulation require commercial-cryptography activities to comply with applicable laws, administrative regulations, mandatory national standards, and publicly declared standards. More specific facts determine the remaining duties.

- Product or service assurance: check whether the product falls in the catalogue for critical network equipment and specialised cybersecurity products, or whether a commercial-cryptography service uses such products.
- Network operation: check the commercial-cryptography requirements that apply under the network-security classified-protection system.
- CII use and procurement: determine whether a CII operator must use commercial cryptography, conduct an application security assessment, use qualified products and services, or submit a procurement for national-security review.
- Electronic certification: providing electronic certification with commercial cryptography follows the separate permission and operating requirements in the implementing regulation.
- Trade: check the current import-licence list or export-control list and the exception for commercial cryptography used in mass-market consumer products.

Sources for this answer:

- [PRC Cryptography Law](https://www.oscca.gov.cn/sca/xxgk/2023-06/04/content_1057225.shtml?ref=sorena.io) - Articles 24-28 set the standards, testing and certification, specified-product, CII, and import/export routes that must be assessed after classification.
- [Commercial Cryptography Administration Regulation](https://xzfg.moj.gov.cn/front/law/detail?LawID=1622&ref=sorena.io) - Articles 11-42 detail standards, testing and certification, electronic certification, trade controls, CII application duties, procurement review, and classified-protection requirements.

### [What to keep as evidence](/artifacts/apac/china-cryptography-law/faq/what-is-commercial-cryptography-in-china.md#what-to-keep-as-evidence)

*Module: [What is commercial cryptography in China?](/artifacts/apac/china-cryptography-law/faq/what-is-commercial-cryptography-in-china.md)*

The record should identify the protected information, explain why it is or is not a state secret, describe the encryption-protection or security-authentication function, and keep the commercial-cryptography classification separate from every downstream approval, assurance, assessment, and trade-control decision.

- The information protected and the basis for treating it as state-secret or non-state-secret information.
- The technology, product, or service and how it is supplied or used.
- The classification conclusion and official article relied upon.
- Any mandatory product/service, electronic-certification, classified-protection, CII, or trade-control trigger checked.
- Person who approved the classification, approval date, and the product or use-case changes that require reassessment.

Sources for this answer:

- [PRC Cryptography Law](https://www.oscca.gov.cn/sca/xxgk/2023-06/04/content_1057225.shtml?ref=sorena.io) - Articles 2, 6-8, and 24-28 support the classification facts and the separate downstream trigger checks listed here.
- [Commercial Cryptography Administration Regulation](https://xzfg.moj.gov.cn/front/law/detail?LawID=1622&ref=sorena.io) - Articles 2 and 11-42 support recording the activity, application, assurance, operator, and trade facts needed for the downstream checks.

### [When is assurance voluntary or mandatory?](/artifacts/apac/china-cryptography-law/faq/when-is-commercial-cryptography-testing-or-certification-needed.md#when-is-assurance-voluntary-or-mandatory)

*Module: [When is commercial cryptography testing or certification needed?](/artifacts/apac/china-cryptography-law/faq/when-is-commercial-cryptography-testing-or-certification-needed.md)*

Article 25 of the Cryptography Law and Article 12 of the implementing regulation encourage voluntary commercial-cryptography testing and certification. Voluntary assurance does not waive Article 11: the activity must still comply with applicable laws, administrative regulations, mandatory national standards, and the operator's publicly declared standards. Testing and certification bodies must hold the required qualifications and work within their approved scope under the applicable technical specifications and rules.

Sources for this answer:

- [Commercial cryptography testing institution measures interpretation](https://www.oscca.gov.cn/sca/xxgk/2023-10/07/content_1061110.shtml?ref=sorena.io) - The official interpretation explains that bodies issuing proof-bearing data or results for product testing or application security assessments must obtain commercial-cryptography testing-body qualification.
- [PRC Cryptography Law](https://www.oscca.gov.cn/sca/xxgk/2023-06/04/content_1057225.shtml?ref=sorena.io) - Articles 25 and 26 distinguish voluntary testing and certification from mandatory assurance for specified products and services.
- [Commercial Cryptography Administration Regulation](https://xzfg.moj.gov.cn/front/law/detail?LawID=1622&ref=sorena.io) - Articles 11-21 state the standards duty, distinguish testing from certification, set body qualifications and scope controls, and state the mandatory product and service routes.
- [2023 Catalogue of Critical Network Equipment and Specialised Cybersecurity Products](https://www.miit.gov.cn/jgsj/waj/wjfb/art/2023/art_9080a8689c58416eaf56f88649c242d3.html?ref=sorena.io) - The joint-authority catalogue supplies the current categories and technical thresholds used for the mandatory product-route match.
- [Commercial Cryptography Product Certification Catalogue and Rules](https://www.oscca.gov.cn/sca/xwdt/2020-05/11/content_1060749.shtml?ref=sorena.io) - The official announcement identifies the separate commercial-cryptography product certification catalogue and certification rules; Regulation Article 17 places that catalogue within the unified voluntary certification system.

### [When is a CII application assessment required?](/artifacts/apac/china-cryptography-law/faq/when-is-commercial-cryptography-testing-or-certification-needed.md#when-is-a-cii-application-assessment-required)

*Module: [When is commercial cryptography testing or certification needed?](/artifacts/apac/china-cryptography-law/faq/when-is-commercial-cryptography-testing-or-certification-needed.md)*

Article 27 applies when laws, administrative regulations, or other state rules require a CII to use commercial cryptography for protection. The CII operator must conduct the commercial-cryptography application security assessment itself or commission a commercial-cryptography testing body.

- Confirm the operator's CII status and identify the rule requiring commercial-cryptography protection.
- Prepare the application plan and record the funding, staff, and parallel planning, construction, and operation of the cryptography protection system.
- Separate the Article 26 product or service conclusion from the Article 27 application assessment.
- Complete the covered CII assessment before operation, then schedule it at least annually, file the report and related work information within 30 days, and retain self-assessment records and reports for at least six years.
- For CII already under construction or operating on 1 August 2025, document the applicable transition branch and the first assessment completed under it.
- Verify the product and service certificates and the review status of algorithms, protocols, and key-management mechanisms used by the covered CII.
- If commissioning a qualified body that issues proof-bearing results, verify its commercial-cryptography testing-body qualification and scope.
- Record how existing cybersecurity assessments were coordinated to avoid duplicate work.
- Reassess after a construction-stage plan change and evaluate whether a major incident, major cryptography security hazard, or special emergency requires an additional assessment.

Sources for this answer:

- [PRC Cryptography Law](https://www.oscca.gov.cn/sca/xxgk/2023-06/04/content_1057225.shtml?ref=sorena.io) - Article 27 sets the CII application security assessment trigger and requires coordination with related CII and classified-protection assessments.
- [Commercial cryptography testing institution measures interpretation](https://www.oscca.gov.cn/sca/xxgk/2023-10/07/content_1061110.shtml?ref=sorena.io) - The official interpretation describes qualification and supervision for product-testing and application-security-assessment bodies that issue proof-bearing results.
- [Commercial Cryptography Administration Regulation](https://xzfg.moj.gov.cn/front/law/detail?LawID=1622&ref=sorena.io) - Articles 38-42 set the application plan, resources, parallel planning, construction and operation, pre-operation and annual assessment cycle, filing, qualified-product and service requirements, technology review, and coordination with other assessments.
- [CII Commercial Cryptography Use Management Provisions](https://www.oscca.gov.cn/sca/xxgk/2025-06/27/content_1061270.shtml?ref=sorena.io) - Articles 9 and 11-15 set the qualified-product and technology requirements; plan, construction-change, pre-operation, annual, failed-assessment, transition, and coordination rules; and the 1 August 2025 effective date.
- [Commercial Cryptography Application Security Assessment Measures](https://www.oscca.gov.cn/sca/xxgk/2023-10/07/content_1061109.shtml?ref=sorena.io) - Articles 6-15 support assessment scope, lifecycle, remediation, 30-day filing, six-year self-assessment retention, and incident-driven reassessment.

### [What to keep as evidence](/artifacts/apac/china-cryptography-law/faq/when-is-commercial-cryptography-testing-or-certification-needed.md#what-to-keep-as-evidence)

*Module: [When is commercial cryptography testing or certification needed?](/artifacts/apac/china-cryptography-law/faq/when-is-commercial-cryptography-testing-or-certification-needed.md)*

The record should show whether assurance is voluntary, mandatory for an Article 26 product or service, or part of the CII application-assessment lifecycle. Keep the exact catalogue entry, qualified-body scope, report or certificate, CII trigger, assessment stage, result, filing, and remediation together.

- Product or service identity, version, supplier, and applicable catalogue entry or other trigger.
- Whether assurance is voluntary, mandatory under Article 26, or a CII application assessment under Article 27; for Article 26, retain both the commercial-cryptography analysis and the exact mandatory catalogue match.
- Testing or certification body identity, scope, qualification, report or certificate, and validity status.
- The legal basis and scope for recognising earlier cybersecurity testing or assessment to avoid duplication.
- For covered CII, the plan result, pre-operation result, annual assessment history, transition branch, remediation, filing evidence, and cryptographic-technology review records.
- Changes to product scope, model, cryptographic function, supplier, certificate, catalogue, standards, application plan, or CII deployment that require a new conclusion or reassessment.

Sources for this answer:

- [Commercial cryptography testing institution measures interpretation](https://www.oscca.gov.cn/sca/xxgk/2023-10/07/content_1061110.shtml?ref=sorena.io) - The official interpretation supports checking the testing body's qualification, scope, reports, data, samples, and information-reporting controls.
- [PRC Cryptography Law](https://www.oscca.gov.cn/sca/xxgk/2023-06/04/content_1057225.shtml?ref=sorena.io) - Articles 25-27 support distinguishing voluntary assurance, mandatory product or service assurance, and CII application assessment.
- [Commercial Cryptography Administration Regulation](https://xzfg.moj.gov.cn/front/law/detail?LawID=1622&ref=sorena.io) - Articles 12-21 and 38-42 support the body, scope, product, service, CII cycle, technology review, and assessment-coordination evidence.

*Document the requirement*

*Placement: Before primary sources*

## Prepare the commercial cryptography evidence file

Sorena AI helps assign owners, document controls, and retain the records behind each FAQ decision.

- [Map official sources to evidence](/solutions/research-copilot.md): Research Copilot records the official citation, decision, owner, evidence, and change history.
- [Review the China route](/contact.md): Check the China Cryptography Law scope decision and unresolved launch questions with Sorena.


---

[Privacy Policy](https://www.sorena.io/privacy.md) | [Terms of Use](https://www.sorena.io/terms-of-use.md) | [DMCA](https://www.sorena.io/dmca.md) | [About Us](https://www.sorena.io/about-us.md)

(c) 2026 Sorena AB (559573-7338). All rights reserved.

Source: https://www.sorena.io/artifacts/apac/china-cryptography-law/faq/items.md
