---
title: "What is commercial cryptography in China?"
canonical_url: "https://www.sorena.io/artifacts/apac/china-cryptography-law/faq/what-is-commercial-cryptography-in-china"
source_url: "https://www.sorena.io/artifacts/apac/china-cryptography-law/faq/what-is-commercial-cryptography-in-china"
author: "Sorena AI"
description: "Commercial cryptography protects information that is not a state secret. Learn how China defines the category and which separate facts trigger product, CII, or trade controls."
published_at: "2026-07-05"
updated_at: "2026-07-24"
keywords:
  - "China Cryptography Law"
  - "Commercial cryptography"
  - "Cryptography Law"
  - "Commercial cryptography testing"
  - "China cybersecurity"
---
**[SORENA](https://www.sorena.io/)** - AI-Powered GRC Platform

[Home](https://www.sorena.io/) | [Solutions](https://www.sorena.io/solutions) | [Artifacts](https://www.sorena.io/artifacts) | [About Us](https://www.sorena.io/about-us) | [Contact](https://www.sorena.io/contact) | [Portal](https://app.sorena.io)

---

# What is commercial cryptography in China?

Commercial cryptography protects information that is not a state secret. Learn how China defines the category and which separate facts trigger product, CII, or trade controls.

*Question* *China*

## What is commercial cryptography in China? Direct answer

Commercial cryptography is the statutory category for cryptographic technologies, products, and services used to protect information that is not a state secret.

The category does not itself require testing, certification, assessment, or an import licence. Those duties depend on separate product, service, CII, or trade triggers.

Commercial cryptography is the statutory category for cryptographic technologies, products, and services used to protect information that is not a state secret. Classification comes before any decision about testing, certification, CII assessment, procurement review, or import and export controls.

## Definitions

### Commercial cryptography

Commercial cryptography is a legal category covering technologies, products, and services that use specific transformations to encrypt or authenticate information that is not a state secret. The category can cover encryption protection and security authentication; it is not limited to a standalone hardware product or to information sold for commercial purposes.

**Why it matters here:** Classifying an activity as commercial cryptography starts the compliance analysis but does not decide whether testing, certification, assessment, a licence, or a security review is required. Those results depend on the product, service, operator, deployment, and trade facts.

Sources:

- [PRC Cryptography Law](https://www.oscca.gov.cn/sca/xxgk/2023-06/04/content_1057225.shtml?ref=sorena.io)
- [Commercial Cryptography Administration Regulation](https://xzfg.moj.gov.cn/front/law/detail?LawID=1622&ref=sorena.io)

### Core cryptography and ordinary cryptography

**Term:** core and ordinary cryptography

Core and ordinary cryptography are the two Cryptography Law categories used to protect state-secret information. Core cryptography may protect information up to the top-secret level, while ordinary cryptography may protect information up to the secret level. Both categories, and the cryptography itself, are subject to strict unified state management.

**Why it matters here:** If the information is a state secret, the commercial-cryptography route described on this page is the wrong route. The applicable state-secrets and core-or-ordinary-cryptography controls must be identified instead.

Sources:

- [PRC Cryptography Law](https://www.oscca.gov.cn/sca/xxgk/2023-06/04/content_1057225.shtml?ref=sorena.io)

### Critical information infrastructure operator

**Term:** CII operator

A CII operator operates critical information infrastructure whose destruction, loss of function, or data leakage could seriously harm national security, the national economy, people's livelihoods, or the public interest. CII status is determined under China's critical-information-infrastructure framework and cannot be inferred only from an organisation's industry or use of encryption.

**Why it matters here:** CII status matters because Article 27 of the Cryptography Law and Articles 38-40 of the implementing regulation can require commercial-cryptography protection, an application security assessment, qualified products and services, reviewed cryptographic technologies, and a procurement security review.

Sources:

- [Commercial Cryptography Administration Regulation](https://xzfg.moj.gov.cn/front/law/detail?LawID=1622&ref=sorena.io)
- [PRC Cryptography Law](https://www.oscca.gov.cn/sca/xxgk/2023-06/04/content_1057225.shtml?ref=sorena.io)

### Security authentication

Security authentication is the use of cryptographic transformations to verify information, an identity, a device, a message, or another claimed security property. The Cryptography Law definition covers both encryption protection and security authentication, so commercial cryptography is not limited to tools that conceal readable data.

**Why it matters here:** A technology, product, or service can fall within commercial cryptography because of its authentication function even when confidentiality is not its main purpose. Classification still does not by itself establish a testing, certification, assessment, permission, or trade-control duty.

Sources:

- [PRC Cryptography Law, Articles 2 and 8](https://www.oscca.gov.cn/sca/xxgk/2023-06/04/content_1057225.shtml?ref=sorena.io)
- [Commercial Cryptography Administration Regulation, Article 2](https://xzfg.moj.gov.cn/front/law/detail?LawID=1622&ref=sorena.io)

### Network-security classified-protection system

The network-security classified-protection system assigns security duties according to a network's protection level. Network operators must implement governance, technical protection, monitoring, logging, and data-protection measures. The commercial-cryptography regulation requires commercial cryptography to be used according to this system and allows cryptography use, management, and application-assessment requirements to vary by level.

**Why it matters here:** A non-CII network can still have commercial-cryptography duties through its protection level. Commercial-cryptography classification alone does not determine the level or the exact controls.

Sources:

- [PRC Cybersecurity Law, Article 23](https://www.cac.gov.cn/2025-12/29/c_1768735112911946.htm?ref=sorena.io)
- [Commercial Cryptography Administration Regulation, Article 41](https://xzfg.moj.gov.cn/front/law/detail?LawID=1622&ref=sorena.io)

### Electronic certification using commercial cryptography

**Term:** electronic certification

Electronic certification uses electronic-signature certificates or related trust services to verify signers and electronic signatures. A provider using commercial cryptography to offer this service in China must hold the current cryptography-use licence; an electronic-government certification institution follows a separate qualification route.

**Why it matters here:** An ordinary product with an authentication feature is not automatically an electronic-certification service. The service model and provider role determine whether the permission and operating rules apply.

Sources:

- [Commercial Cryptography Administration Regulation, Articles 22-30](https://xzfg.moj.gov.cn/front/law/detail?LawID=1622&ref=sorena.io)
- [Electronic Certification Service Cryptography Use Management Measures, Articles 2-3](https://www.oscca.gov.cn/sca/xxgk/2026-06/03/content_1061341.shtml?ref=sorena.io)

## What does commercial cryptography cover?

Article 2 defines cryptography broadly as technologies, products, and services that use specific transformations to encrypt information or provide security authentication. The category can therefore cover a cryptographic authentication function even when confidentiality is not the main purpose. Articles 6-8 then divide cryptography into core, ordinary, and commercial categories.

Core and ordinary cryptography protect state-secret information and are subject to strict unified management. Commercial cryptography protects information that is not a state secret, and citizens, legal persons, and other organisations may lawfully use it to protect network and information security.

The word commercial describes the statutory non-state-secret category; it does not mean that only businesses use it or that every product sold commercially follows a mandatory approval route. The law also requires authorities to treat foreign-invested enterprises lawfully and equally in commercial-cryptography research, production, sale, service, and import or export activities.

The Cryptography Law took effect on 1 January 2020. The revised Commercial Cryptography Administration Regulation took effect on 1 July 2023 and applies within China to commercial-cryptography research, production, sale, service, testing, certification, import, export, application, and supervision. Its definition confirms that commercial cryptography includes technologies, products, and services used for encryption protection or security authentication of non-state-secret information.

Sources for this answer:

- [PRC Cryptography Law](https://www.oscca.gov.cn/sca/xxgk/2023-06/04/content_1057225.shtml?ref=sorena.io) - Articles 2, 6-8, and 21 define cryptography, distinguish core, ordinary, and commercial cryptography, permit lawful use for non-state-secret information, and state the non-discrimination rule for foreign-invested enterprises.
- [Commercial Cryptography Administration Regulation](https://xzfg.moj.gov.cn/front/law/detail?LawID=1622&ref=sorena.io) - Articles 2 and 67 define commercial cryptography, state the activities in China to which the regulation applies, and set 1 July 2023 as its commencement date.

## What does the classification change?

Commercial-cryptography status alone does not trigger universal approval. Article 24 of the law and Article 11 of the implementing regulation require commercial-cryptography activities to comply with applicable laws, administrative regulations, mandatory national standards, and publicly declared standards. More specific facts determine the remaining duties.

Record the protected information, cryptographic function, product or service, supplier, operator, and China use case. Check each possible route separately because a commercial-cryptography product may fall outside some mandatory routes.

- Product or service assurance: check whether the product falls in the catalogue for critical network equipment and specialised cybersecurity products, or whether a commercial-cryptography service uses such products.
- Network operation: check the commercial-cryptography requirements that apply under the network-security classified-protection system.
- CII use and procurement: determine whether a CII operator must use commercial cryptography, conduct an application security assessment, use qualified products and services, or submit a procurement for national-security review.
- Electronic certification: providing electronic certification with commercial cryptography follows the separate permission and operating requirements in the implementing regulation.
- Trade: check the current import-licence list or export-control list and the exception for commercial cryptography used in mass-market consumer products.

Sources for this answer:

- [PRC Cryptography Law](https://www.oscca.gov.cn/sca/xxgk/2023-06/04/content_1057225.shtml?ref=sorena.io) - Articles 24-28 set the standards, testing and certification, specified-product, CII, and import/export routes that must be assessed after classification.
- [Commercial Cryptography Administration Regulation](https://xzfg.moj.gov.cn/front/law/detail?LawID=1622&ref=sorena.io) - Articles 11-42 detail standards, testing and certification, electronic certification, trade controls, CII application duties, procurement review, and classified-protection requirements.

## What to keep as evidence

The record should identify the protected information, explain why it is or is not a state secret, describe the encryption-protection or security-authentication function, and keep the commercial-cryptography classification separate from every downstream approval, assurance, assessment, and trade-control decision.

- The information protected and the basis for treating it as state-secret or non-state-secret information.
- The technology, product, or service and how it is supplied or used.
- The classification conclusion and official article relied upon.
- Any mandatory product/service, electronic-certification, classified-protection, CII, or trade-control trigger checked.
- Person who approved the classification, approval date, and the product or use-case changes that require reassessment.

Sources for this answer:

- [PRC Cryptography Law](https://www.oscca.gov.cn/sca/xxgk/2023-06/04/content_1057225.shtml?ref=sorena.io) - Articles 2, 6-8, and 24-28 support the classification facts and the separate downstream trigger checks listed here.
- [Commercial Cryptography Administration Regulation](https://xzfg.moj.gov.cn/front/law/detail?LawID=1622&ref=sorena.io) - Articles 2 and 11-42 support recording the activity, application, assurance, operator, and trade facts needed for the downstream checks.

## Primary sources

- [PRC Cryptography Law](https://www.oscca.gov.cn/sca/xxgk/2023-06/04/content_1057225.shtml?ref=sorena.io) - Articles 2, 6-8, and 24-28 support the definition, category distinction, and separate product, CII, and trade-control routes.
- [Commercial Cryptography Administration Regulation](https://xzfg.moj.gov.cn/front/law/detail?LawID=1622&ref=sorena.io) - Current implementing regulation for commercial-cryptography activities, testing, certification, electronic certification, imports and exports, network use, and CII obligations.

## Topic Guides

- [China commercial cryptography compliance checklist](/artifacts/apac/china-cryptography-law/checklist.md): China commercial cryptography checklist covering classification, product and service assurance, CII duties, trade controls, and retained evidence.
- [China commercial cryptography testing evidence template](/artifacts/apac/china-cryptography-law/commercial-cryptography-testing-evidence-template.md): Record the legal route, product or system scope, testing-body qualification, report details, gaps, and reassessment triggers for China commercial cryptography assurance.
- [China cryptography compliance deadlines and calendar](/artifacts/apac/china-cryptography-law/deadlines-and-compliance-calendar.md): China cryptography effective dates, CII reports, annual assessments, licence renewals, change notices, and pre-operation checks.
- [China cryptography import, export, and security review triage](/artifacts/apac/china-cryptography-law/import-export-and-security-assessment.md): Screen commercial cryptography imports under the 2020 list, exports under China's unified dual-use list, the consumer exclusion, system assessment, and CII review.
- [China Cryptography Law FAQ](/artifacts/apac/china-cryptography-law/faq.md): Answers on China's commercial-cryptography scope, product assurance, classified protection, CII assessment, procurement review, and trade controls.
- [China Cryptography Law requirements](/artifacts/apac/china-cryptography-law/requirements.md): China commercial cryptography requirements by role: standards, testing, certification, CII use and assessment, trade controls, and evidence.
- [China Cryptography Law vs Cybersecurity Law](/artifacts/apac/china-cryptography-law/china-cryptography-law-vs-cybersecurity-law.md): Compare China's Cryptography Law and current Cybersecurity Law by scope, actor, product assurance, CII duties, evidence, and enforcement.
- [China cryptography penalties, fines, and liability](/artifacts/apac/china-cryptography-law/penalties-and-fines.md): China commercial cryptography penalties by actor and violation, including fine bands, corrective orders, confiscation, licence action, and liability.
- [Commercial cryptography procurement checklist](/artifacts/apac/china-cryptography-law/commercial-cryptography-procurement-checklist.md): Procurement checks for commercial cryptography products and services used in China, including certificate scope, CII duties, and supplier changes.
- [Commercial cryptography products and testing evidence](/artifacts/apac/china-cryptography-law/commercial-cryptography-products-and-testing.md): When China commercial cryptography testing or certification is voluntary or mandatory, and what product, service, body, and scope evidence to keep.
- [Do imported cryptography products need special review?](/artifacts/apac/china-cryptography-law/faq/do-imported-cryptography-products-need-special-review.md): Not every encrypted product imported into China needs a licence. Check the 2020 commercial-cryptography import list, the consumer-product exception, and any CII procurement review.
- [Does using encryption trigger China Cryptography Law duties?](/artifacts/apac/china-cryptography-law/faq/does-using-encryption-trigger-china-cryptography-law.md): Using encryption does not create one universal China approval duty. Check classified protection, product, service, CII, procurement, and trade triggers.
- [How does cryptography compliance overlap with China cybersecurity law?](/artifacts/apac/china-cryptography-law/faq/how-does-cryptography-compliance-overlap-with-cybersecurity-law.md): See how China's cryptography rules connect with classified protection, product assurance, CII assessment, and cybersecurity review without merging the regimes.
- [When is commercial cryptography testing or certification needed?](/artifacts/apac/china-cryptography-law/faq/when-is-commercial-cryptography-testing-or-certification-needed.md): Commercial-cryptography assurance is often voluntary, but specified products and services require it. Covered CII also needs application assessment and qualified cryptography.

*Document the requirement*

*Placement: Before primary sources*

## Prepare the commercial cryptography evidence file

Sorena AI helps assign controls and retain evidence for the commercial-cryptography classification.

- [Map official sources to evidence](/solutions/research-copilot.md): Research Copilot records the official citation, decision, owner, evidence, and change history.
- [Review the China route](/contact.md): Check the China Cryptography Law scope decision and unresolved launch questions with Sorena.


---

[Privacy Policy](https://www.sorena.io/privacy.md) | [Terms of Use](https://www.sorena.io/terms-of-use.md) | [DMCA](https://www.sorena.io/dmca.md) | [About Us](https://www.sorena.io/about-us.md)

(c) 2026 Sorena AB (559573-7338). All rights reserved.

Source: https://www.sorena.io/artifacts/apac/china-cryptography-law/faq/what-is-commercial-cryptography-in-china.md
