QuestionChina

What is commercial cryptography in China? Direct answer

Commercial cryptography is the statutory category for cryptographic technologies, products, and services used to protect information that is not a state secret.

The category does not itself require testing, certification, assessment, or an import licence. Those duties depend on separate product, service, CII, or trade triggers.

Author
Sorena AI
Published
Jul 5, 2026
Updated
Jul 24, 2026
Questions
3

Structured answer sets in this page tree.

Primary sources
2

Cited legal and guidance references.

Publication metadata
Sorena AI
Published Jul 5, 2026
Updated Jul 24, 2026
Overview

is the statutory category for cryptographic technologies, products, and services used to protect information that is not a state secret. Classification comes before any decision about testing, certification, CII assessment, procurement review, or import and export controls.

Search this module

Find a question or answer quickly

3 of 3 questions
Question 1

What does commercial cryptography cover?

Article 2 defines cryptography broadly as technologies, products, and services that use specific transformations to encrypt information or provide . The category can therefore cover a cryptographic authentication function even when confidentiality is not the main purpose. Articles 6-8 then divide cryptography into core, ordinary, and commercial categories.

protect state-secret information and are subject to strict unified management. protects information that is not a state secret, and citizens, legal persons, and other organisations may lawfully use it to protect network and information security.

The word commercial describes the statutory non-state-secret category; it does not mean that only businesses use it or that every product sold commercially follows a mandatory approval route. The law also requires authorities to treat foreign-invested enterprises lawfully and equally in commercial-cryptography research, production, sale, service, and import or export activities.

The Cryptography Law took effect on 1 January 2020. The revised Administration Regulation took effect on 1 July 2023 and applies within China to commercial-cryptography research, production, sale, service, testing, certification, import, export, application, and supervision. Its definition confirms that commercial cryptography includes technologies, products, and services used for encryption protection or of non-state-secret information.

Citations
PRC Cryptography Law

Articles 2, 6-8, and 21 define cryptography, distinguish core, ordinary, and commercial cryptography, permit lawful use for non-state-secret information, and state the non-discrimination rule for foreign-invested enterprises.

Question 2

What does the classification change?

Commercial-cryptography status alone does not trigger universal approval. Article 24 of the law and Article 11 of the implementing regulation require commercial-cryptography activities to comply with applicable laws, administrative regulations, mandatory national standards, and publicly declared standards. More specific facts determine the remaining duties.

Record the protected information, cryptographic function, product or service, supplier, operator, and China use case. Check each possible route separately because a commercial-cryptography product may fall outside some mandatory routes.

  • Product or service assurance: check whether the product falls in the catalogue for critical network equipment and specialised cybersecurity products, or whether a commercial-cryptography service uses such products.
  • Network operation: check the commercial-cryptography requirements that apply under the .
  • CII use and procurement: determine whether a must use , conduct an application security assessment, use qualified products and services, or submit a procurement for national-security review.
  • : providing electronic certification with follows the separate permission and operating requirements in the implementing regulation.
  • Trade: check the current import-licence list or export-control list and the exception for used in mass-market consumer products.
Citations
PRC Cryptography Law

Articles 24-28 set the standards, testing and certification, specified-product, CII, and import/export routes that must be assessed after classification.

Question 3

What to keep as evidence

The record should identify the protected information, explain why it is or is not a state secret, describe the encryption-protection or security-authentication function, and keep the commercial-cryptography classification separate from every downstream approval, assurance, assessment, and trade-control decision.

  • The information protected and the basis for treating it as state-secret or non-state-secret information.
  • The technology, product, or service and how it is supplied or used.
  • The classification conclusion and official article relied upon.
  • Any mandatory product/service, electronic-certification, classified-protection, CII, or trade-control trigger checked.
  • Person who approved the classification, approval date, and the product or use-case changes that require reassessment.
Citations
PRC Cryptography Law

Articles 2, 6-8, and 24-28 support the classification facts and the separate downstream trigger checks listed here.

Primary sources

References and citations

oscca.gov.cn
Referenced sections
  • Articles 2, 6-8, and 24-28 support the classification facts and the separate downstream trigger checks listed here.
Related guides

Explore more topics

China commercial cryptography compliance checklist
China commercial cryptography checklist covering classification, product and service assurance, CII duties, trade controls, and retained evidence.
China commercial cryptography testing evidence template
Record the legal route, product or system scope, testing-body qualification, report details, gaps, and reassessment triggers for China commercial cryptography assurance.
China cryptography compliance deadlines and calendar
China cryptography effective dates, CII reports, annual assessments, licence renewals, change notices, and pre-operation checks.
China cryptography import, export, and security review triage
Screen commercial cryptography imports under the 2020 list, exports under China's unified dual-use list, the consumer exclusion, system assessment, and CII review.
China Cryptography Law FAQ
Answers on China's commercial-cryptography scope, product assurance, classified protection, CII assessment, procurement review, and trade controls.
China Cryptography Law requirements
China commercial cryptography requirements by role: standards, testing, certification, CII use and assessment, trade controls, and evidence.
China Cryptography Law vs Cybersecurity Law
Compare China's Cryptography Law and current Cybersecurity Law by scope, actor, product assurance, CII duties, evidence, and enforcement.
China cryptography penalties, fines, and liability
China commercial cryptography penalties by actor and violation, including fine bands, corrective orders, confiscation, licence action, and liability.
Commercial cryptography procurement checklist
Procurement checks for commercial cryptography products and services used in China, including certificate scope, CII duties, and supplier changes.
Commercial cryptography products and testing evidence
When China commercial cryptography testing or certification is voluntary or mandatory, and what product, service, body, and scope evidence to keep.
Do imported cryptography products need special review?
Not every encrypted product imported into China needs a licence. Check the 2020 commercial-cryptography import list, the consumer-product exception, and any CII procurement review.
Does using encryption trigger China Cryptography Law duties?
Using encryption does not create one universal China approval duty. Check classified protection, product, service, CII, procurement, and trade triggers.
How does cryptography compliance overlap with China cybersecurity law?
See how China's cryptography rules connect with classified protection, product assurance, CII assessment, and cybersecurity review without merging the regimes.
When is commercial cryptography testing or certification needed?
Commercial-cryptography assurance is often voluntary, but specified products and services require it. Covered CII also needs application assessment and qualified cryptography.