QuestionChina

When is commercial cryptography testing or certification needed? Direct answer

Testing and certification are generally voluntary, but listed commercial-cryptography products and services using listed security products require qualified assurance before sale or provision.

Covered CII has a separate application-assessment cycle and must use qualified products and services and reviewed cryptographic technologies.

Author
Sorena AI
Published
Jul 5, 2026
Updated
Jul 24, 2026
Questions
3

Structured answer sets in this page tree.

Primary sources
7

Cited legal and guidance references.

Publication metadata
Sorena AI
Published Jul 5, 2026
Updated Jul 24, 2026
Overview

are generally voluntary, but they become mandatory for specified products and services. that is legally required to use commercial cryptography follows a separate application-assessment route and must also use qualified products and services and reviewed cryptographic technologies.

Search this module

Find a question or answer quickly

3 of 3 questions
Question 1

When is assurance voluntary or mandatory?

Article 25 of the Cryptography Law and Article 12 of the implementing regulation encourage voluntary commercial-cryptography . Voluntary assurance does not waive Article 11: the activity must still comply with applicable laws, administrative regulations, mandatory national standards, and the operator's publicly declared standards. Testing and certification bodies must hold the required qualifications and work within their approved scope under the applicable technical specifications and rules.

Mandatory assurance applies to a narrower group. A commercial-cryptography product involving national security, the national economy and people's livelihoods, or the public interest must be included in the catalogue of and pass qualified before sale or provision. Both conditions matter: a cryptographic product outside that catalogue, or a listed network product that is not commercial cryptography, does not enter this mandatory route on those facts alone. A commercial-cryptography service that uses critical network equipment and specialised cybersecurity products must pass service certification.

The current network-product catalogue, effective since 3 July 2023, includes routers, switches, rack servers, and PLC equipment that meet stated technical thresholds, plus categories such as firewalls, intrusion-detection systems, VPN products, public-key infrastructure, file-encryption products, and identity-authentication products. Match the exact product and threshold. Do not substitute the separate commercial-cryptography product certification catalogue, which supports the national voluntary certification system, for the mandatory network-product catalogue.

Citations
PRC Cryptography Law

Articles 25 and 26 distinguish voluntary testing and certification from mandatory assurance for specified products and services.

Question 2

When is a CII application assessment required?

Article 27 applies when laws, administrative regulations, or other state rules require a to use commercial cryptography for protection. The CII operator must conduct the itself or commission a commercial-cryptography testing body.

Articles 38 and 39 of the implementing regulation require the operator to prepare a commercial-cryptography application plan, provide funding and professional staff, and plan, build, and operate the cryptography protection system alongside the . The CII provisions effective 1 August 2025 make the lifecycle explicit: assess the application plan, reassess it if it changes during construction, pass an assessment before operation, and assess at least annually after operation. CII already under construction on that date follows the construction and pre-operation route; CII already operating follows the annual route. Its commercial-cryptography products and services must be tested and certified, while its algorithms, protocols, key-management mechanisms, and other cryptographic technologies must pass state cryptography administration review and appraisal.

A failed plan assessment means the plan cannot be used as the construction basis. A failed pre-operation assessment requires modification and prevents operation during the modification period. A failed annual assessment also requires modification, but the operator must take necessary measures to keep the operating secure during that work. A major cryptography-related security incident, major cryptography security hazard, or special emergency must be reported promptly and can require another assessment.

When the Commercial Cryptography Application Security Assessment Measures apply, file the assessment report and related work information with the National Cryptography Administration or the relevant province-level cryptography authority within 30 days after the report is formed. An operator that performs its own assessment must retain the original records and report for at least six years. These filing and retention duties belong to the system assessment; they do not turn a product report into a system-assessment result.

Article 42 requires coordination with security testing and the network-security classified-protection assessment system to avoid duplicate work. Coordination does not erase the separate trigger, scope, or required conclusion for each assessment.

  • Confirm the operator's status and identify the rule requiring commercial-cryptography protection.
  • Prepare the application plan and record the funding, staff, and parallel planning, construction, and operation of the cryptography protection system.
  • Separate the Article 26 product or service conclusion from the Article 27 application assessment.
  • Complete the covered assessment before operation, then schedule it at least annually, file the report and related work information within 30 days, and retain self-assessment records and reports for at least six years.
  • For already under construction or operating on 1 August 2025, document the applicable transition branch and the first assessment completed under it.
  • Verify the product and service certificates and the review status of algorithms, protocols, and key-management mechanisms used by the covered .
  • If commissioning a that issues proof-bearing results, verify its commercial-cryptography testing-body qualification and scope.
  • Record how existing cybersecurity assessments were coordinated to avoid duplicate work.
  • Reassess after a construction-stage plan change and evaluate whether a major incident, major cryptography security hazard, or special emergency requires an additional assessment.
Citations
PRC Cryptography Law

Article 27 sets the CII application security assessment trigger and requires coordination with related CII and classified-protection assessments.

Commercial Cryptography Administration Regulation

Articles 38-42 set the application plan, resources, parallel planning, construction and operation, pre-operation and annual assessment cycle, filing, qualified-product and service requirements, technology review, and coordination with other assessments.

Question 3

What to keep as evidence

The record should show whether assurance is voluntary, mandatory for an Article 26 product or service, or part of the application-assessment lifecycle. Keep the exact catalogue entry, qualified-body scope, report or certificate, CII trigger, assessment stage, result, filing, and remediation together.

  • Product or service identity, version, supplier, and applicable catalogue entry or other trigger.
  • Whether assurance is voluntary, mandatory under Article 26, or a application assessment under Article 27; for Article 26, retain both the commercial-cryptography analysis and the exact mandatory catalogue match.
  • Testing or certification body identity, scope, qualification, report or certificate, and validity status.
  • The legal basis and scope for recognising earlier cybersecurity testing or assessment to avoid duplication.
  • For covered , the plan result, pre-operation result, annual assessment history, transition branch, remediation, filing evidence, and cryptographic-technology review records.
  • Changes to product scope, model, cryptographic function, supplier, certificate, catalogue, standards, application plan, or deployment that require a new conclusion or reassessment.
Citations
PRC Cryptography Law

Articles 25-27 support distinguishing voluntary assurance, mandatory product or service assurance, and CII application assessment.

Primary sources

References and citations

oscca.gov.cn
Referenced sections
  • Articles 9 and 11-15 set the qualified-product and technology requirements; plan, construction-change, pre-operation, annual, failed-assessment, transition, and coordination rules; and the 1 August 2025 effective date.
oscca.gov.cn
Referenced sections
  • Articles 25-27 support distinguishing voluntary assurance, mandatory product or service assurance, and CII application assessment.
Related guides

Explore more topics

China commercial cryptography compliance checklist
China commercial cryptography checklist covering classification, product and service assurance, CII duties, trade controls, and retained evidence.
China commercial cryptography testing evidence template
Record the legal route, product or system scope, testing-body qualification, report details, gaps, and reassessment triggers for China commercial cryptography assurance.
China cryptography compliance deadlines and calendar
China cryptography effective dates, CII reports, annual assessments, licence renewals, change notices, and pre-operation checks.
China cryptography import, export, and security review triage
Screen commercial cryptography imports under the 2020 list, exports under China's unified dual-use list, the consumer exclusion, system assessment, and CII review.
China Cryptography Law FAQ
Answers on China's commercial-cryptography scope, product assurance, classified protection, CII assessment, procurement review, and trade controls.
China Cryptography Law requirements
China commercial cryptography requirements by role: standards, testing, certification, CII use and assessment, trade controls, and evidence.
China Cryptography Law vs Cybersecurity Law
Compare China's Cryptography Law and current Cybersecurity Law by scope, actor, product assurance, CII duties, evidence, and enforcement.
China cryptography penalties, fines, and liability
China commercial cryptography penalties by actor and violation, including fine bands, corrective orders, confiscation, licence action, and liability.
Commercial cryptography procurement checklist
Procurement checks for commercial cryptography products and services used in China, including certificate scope, CII duties, and supplier changes.
Commercial cryptography products and testing evidence
When China commercial cryptography testing or certification is voluntary or mandatory, and what product, service, body, and scope evidence to keep.
Do imported cryptography products need special review?
Not every encrypted product imported into China needs a licence. Check the 2020 commercial-cryptography import list, the consumer-product exception, and any CII procurement review.
Does using encryption trigger China Cryptography Law duties?
Using encryption does not create one universal China approval duty. Check classified protection, product, service, CII, procurement, and trade triggers.
How does cryptography compliance overlap with China cybersecurity law?
See how China's cryptography rules connect with classified protection, product assurance, CII assessment, and cybersecurity review without merging the regimes.
What is commercial cryptography in China?
Commercial cryptography protects information that is not a state secret. Learn how China defines the category and which separate facts trigger product, CII, or trade controls.