---
title: "When is commercial cryptography testing or certification needed?"
canonical_url: "https://www.sorena.io/artifacts/apac/china-cryptography-law/faq/when-is-commercial-cryptography-testing-or-certification-needed"
source_url: "https://www.sorena.io/artifacts/apac/china-cryptography-law/faq/when-is-commercial-cryptography-testing-or-certification-needed"
author: "Sorena AI"
description: "Commercial-cryptography assurance is often voluntary, but specified products and services require it. Covered CII also needs application assessment and qualified cryptography."
published_at: "2026-07-05"
updated_at: "2026-07-24"
keywords:
  - "China Cryptography Law"
  - "Commercial cryptography"
  - "Cryptography Law"
  - "Commercial cryptography testing"
  - "China cybersecurity"
---
**[SORENA](https://www.sorena.io/)** - AI-Powered GRC Platform

[Home](https://www.sorena.io/) | [Solutions](https://www.sorena.io/solutions) | [Artifacts](https://www.sorena.io/artifacts) | [About Us](https://www.sorena.io/about-us) | [Contact](https://www.sorena.io/contact) | [Portal](https://app.sorena.io)

---

# When is commercial cryptography testing or certification needed?

Commercial-cryptography assurance is often voluntary, but specified products and services require it. Covered CII also needs application assessment and qualified cryptography.

*Question* *China*

## When is commercial cryptography testing or certification needed? Direct answer

Testing and certification are generally voluntary, but listed commercial-cryptography products and services using listed security products require qualified assurance before sale or provision.

Covered CII has a separate application-assessment cycle and must use qualified products and services and reviewed cryptographic technologies.

Testing and certification are generally voluntary, but they become mandatory for specified products and services. CII that is legally required to use commercial cryptography follows a separate application-assessment route and must also use qualified products and services and reviewed cryptographic technologies.

## Definitions

### Commercial-cryptography testing and certification

**Term:** testing and certification

Testing evaluates a commercial-cryptography product or application against applicable technical specifications and rules and produces test data or results. Certification is a separate conformity decision by an approved certification body for a product, service, or management system, with follow-up to confirm continued conformity. The 2023 regulation requires separate qualifications for bodies performing proof-bearing testing and bodies performing certification.

**Why it matters here:** The legal trigger determines whether assurance is voluntary or mandatory and whether the required output is a product test and certificate, a service certificate, or an application security assessment. A generic laboratory report is not automatically a substitute.

Sources:

- [Commercial Cryptography Administration Regulation](https://xzfg.moj.gov.cn/front/law/detail?LawID=1622&ref=sorena.io)
- [Commercial cryptography testing institution measures interpretation](https://www.oscca.gov.cn/sca/xxgk/2023-10/07/content_1061110.shtml?ref=sorena.io)

### Commercial-cryptography application security assessment

This assessment examines the application of commercial cryptography in a network or information system, including the cryptographic products, services, algorithms, protocols, key-management mechanisms, and operating controls. A CII operator covered by the statutory trigger may assess itself or commission a qualified commercial-cryptography testing body.

**Why it matters here:** For CII legally required to use commercial cryptography, the infrastructure must pass the assessment before operation and be assessed at least annually after operation. This application assessment does not replace a separate mandatory product or service certificate.

Sources:

- [Commercial Cryptography Administration Regulation](https://xzfg.moj.gov.cn/front/law/detail?LawID=1622&ref=sorena.io)
- [PRC Cryptography Law](https://www.oscca.gov.cn/sca/xxgk/2023-06/04/content_1057225.shtml?ref=sorena.io)

### Qualified commercial-cryptography testing or certification body

**Term:** qualified body

A testing body that performs commercial-cryptography product testing or application security assessments and issues proof-bearing data or results to the public must be recognised by the state cryptography administration and hold the relevant testing qualification. A certification body must hold certification-body approval and have the technical capacity for its approved scope.

**Why it matters here:** Before relying on a report or certificate, verify the body's qualification, approved scope, the exact product, service, or system assessed, and the report or certificate status. A body's general laboratory capability is not enough.

Sources:

- [Commercial Cryptography Administration Regulation](https://xzfg.moj.gov.cn/front/law/detail?LawID=1622&ref=sorena.io)
- [Commercial cryptography testing institution measures interpretation](https://www.oscca.gov.cn/sca/xxgk/2023-10/07/content_1061110.shtml?ref=sorena.io)

### Critical information infrastructure

**Term:** CII

Critical information infrastructure is infrastructure identified under China's Cybersecurity Law and CII protection rules because destruction, loss of function, or data leakage could seriously harm national security, the national economy, people's livelihoods, or the public interest. The responsible protection department identifies the infrastructure; an important system or an operator in a named sector is not automatically CII.

**Why it matters here:** CII status is necessary but not the only question. The commercial-cryptography application-assessment route applies where the governing laws, administrative regulations, or state rules require that CII to use commercial cryptography for protection.

Sources:

- [PRC Cybersecurity Law, Article 33](https://www.cac.gov.cn/2025-12/29/c_1768735112911946.htm?ref=sorena.io)
- [CII Commercial Cryptography Use Management Provisions, Articles 2 and 5](https://www.oscca.gov.cn/sca/xxgk/2025-06/27/content_1061270.shtml?ref=sorena.io)

### Critical network equipment and specialised cybersecurity products

These are network products included in the catalogue published under the Cybersecurity Law. Listed products must meet mandatory national standards and pass the qualified security-certification or security-testing route required by current Cybersecurity Law Article 25 before sale or provision. A product name or encryption feature alone does not establish catalogue coverage.

**Why it matters here:** The mandatory commercial-cryptography product route applies when a product meeting the Cryptography Law Article 26 conditions is included in this catalogue. A commercial-cryptography service using catalogue products must pass service certification.

Sources:

- [PRC Cybersecurity Law, Article 25](https://www.cac.gov.cn/2025-12/29/c_1768735112911946.htm?ref=sorena.io)
- [PRC Cryptography Law, Article 26](https://www.oscca.gov.cn/sca/xxgk/2023-06/04/content_1057225.shtml?ref=sorena.io)

## When is assurance voluntary or mandatory?

Article 25 of the Cryptography Law and Article 12 of the implementing regulation encourage voluntary commercial-cryptography testing and certification. Voluntary assurance does not waive Article 11: the activity must still comply with applicable laws, administrative regulations, mandatory national standards, and the operator's publicly declared standards. Testing and certification bodies must hold the required qualifications and work within their approved scope under the applicable technical specifications and rules.

Mandatory assurance applies to a narrower group. A commercial-cryptography product involving national security, the national economy and people's livelihoods, or the public interest must be included in the catalogue of critical network equipment and specialised cybersecurity products and pass qualified testing and certification before sale or provision. Both conditions matter: a cryptographic product outside that catalogue, or a listed network product that is not commercial cryptography, does not enter this mandatory route on those facts alone. A commercial-cryptography service that uses critical network equipment and specialised cybersecurity products must pass service certification.

The current network-product catalogue, effective since 3 July 2023, includes routers, switches, rack servers, and PLC equipment that meet stated technical thresholds, plus categories such as firewalls, intrusion-detection systems, VPN products, public-key infrastructure, file-encryption products, and identity-authentication products. Match the exact product and threshold. Do not substitute the separate commercial-cryptography product certification catalogue, which supports the national voluntary certification system, for the mandatory network-product catalogue.

Sources for this answer:

- [Commercial cryptography testing institution measures interpretation](https://www.oscca.gov.cn/sca/xxgk/2023-10/07/content_1061110.shtml?ref=sorena.io) - The official interpretation explains that bodies issuing proof-bearing data or results for product testing or application security assessments must obtain commercial-cryptography testing-body qualification.
- [PRC Cryptography Law](https://www.oscca.gov.cn/sca/xxgk/2023-06/04/content_1057225.shtml?ref=sorena.io) - Articles 25 and 26 distinguish voluntary testing and certification from mandatory assurance for specified products and services.
- [Commercial Cryptography Administration Regulation](https://xzfg.moj.gov.cn/front/law/detail?LawID=1622&ref=sorena.io) - Articles 11-21 state the standards duty, distinguish testing from certification, set body qualifications and scope controls, and state the mandatory product and service routes.
- [2023 Catalogue of Critical Network Equipment and Specialised Cybersecurity Products](https://www.miit.gov.cn/jgsj/waj/wjfb/art/2023/art_9080a8689c58416eaf56f88649c242d3.html?ref=sorena.io) - The joint-authority catalogue supplies the current categories and technical thresholds used for the mandatory product-route match.
- [Commercial Cryptography Product Certification Catalogue and Rules](https://www.oscca.gov.cn/sca/xwdt/2020-05/11/content_1060749.shtml?ref=sorena.io) - The official announcement identifies the separate commercial-cryptography product certification catalogue and certification rules; Regulation Article 17 places that catalogue within the unified voluntary certification system.

## When is a CII application assessment required?

Article 27 applies when laws, administrative regulations, or other state rules require a CII to use commercial cryptography for protection. The CII operator must conduct the commercial-cryptography application security assessment itself or commission a commercial-cryptography testing body.

Articles 38 and 39 of the implementing regulation require the operator to prepare a commercial-cryptography application plan, provide funding and professional staff, and plan, build, and operate the cryptography protection system alongside the CII. The CII provisions effective 1 August 2025 make the lifecycle explicit: assess the application plan, reassess it if it changes during construction, pass an assessment before operation, and assess at least annually after operation. CII already under construction on that date follows the construction and pre-operation route; CII already operating follows the annual route. Its commercial-cryptography products and services must be tested and certified, while its algorithms, protocols, key-management mechanisms, and other cryptographic technologies must pass state cryptography administration review and appraisal.

A failed plan assessment means the plan cannot be used as the construction basis. A failed pre-operation assessment requires modification and prevents operation during the modification period. A failed annual assessment also requires modification, but the operator must take necessary measures to keep the operating CII secure during that work. A major cryptography-related security incident, major cryptography security hazard, or special emergency must be reported promptly and can require another assessment.

When the Commercial Cryptography Application Security Assessment Measures apply, file the assessment report and related work information with the National Cryptography Administration or the relevant province-level cryptography authority within 30 days after the report is formed. An operator that performs its own assessment must retain the original records and report for at least six years. These filing and retention duties belong to the system assessment; they do not turn a product report into a system-assessment result.

Article 42 requires coordination with CII security testing and the network-security classified-protection assessment system to avoid duplicate work. Coordination does not erase the separate trigger, scope, or required conclusion for each assessment.

- Confirm the operator's CII status and identify the rule requiring commercial-cryptography protection.
- Prepare the application plan and record the funding, staff, and parallel planning, construction, and operation of the cryptography protection system.
- Separate the Article 26 product or service conclusion from the Article 27 application assessment.
- Complete the covered CII assessment before operation, then schedule it at least annually, file the report and related work information within 30 days, and retain self-assessment records and reports for at least six years.
- For CII already under construction or operating on 1 August 2025, document the applicable transition branch and the first assessment completed under it.
- Verify the product and service certificates and the review status of algorithms, protocols, and key-management mechanisms used by the covered CII.
- If commissioning a qualified body that issues proof-bearing results, verify its commercial-cryptography testing-body qualification and scope.
- Record how existing cybersecurity assessments were coordinated to avoid duplicate work.
- Reassess after a construction-stage plan change and evaluate whether a major incident, major cryptography security hazard, or special emergency requires an additional assessment.

Sources for this answer:

- [PRC Cryptography Law](https://www.oscca.gov.cn/sca/xxgk/2023-06/04/content_1057225.shtml?ref=sorena.io) - Article 27 sets the CII application security assessment trigger and requires coordination with related CII and classified-protection assessments.
- [Commercial cryptography testing institution measures interpretation](https://www.oscca.gov.cn/sca/xxgk/2023-10/07/content_1061110.shtml?ref=sorena.io) - The official interpretation describes qualification and supervision for product-testing and application-security-assessment bodies that issue proof-bearing results.
- [Commercial Cryptography Administration Regulation](https://xzfg.moj.gov.cn/front/law/detail?LawID=1622&ref=sorena.io) - Articles 38-42 set the application plan, resources, parallel planning, construction and operation, pre-operation and annual assessment cycle, filing, qualified-product and service requirements, technology review, and coordination with other assessments.
- [CII Commercial Cryptography Use Management Provisions](https://www.oscca.gov.cn/sca/xxgk/2025-06/27/content_1061270.shtml?ref=sorena.io) - Articles 9 and 11-15 set the qualified-product and technology requirements; plan, construction-change, pre-operation, annual, failed-assessment, transition, and coordination rules; and the 1 August 2025 effective date.
- [Commercial Cryptography Application Security Assessment Measures](https://www.oscca.gov.cn/sca/xxgk/2023-10/07/content_1061109.shtml?ref=sorena.io) - Articles 6-15 support assessment scope, lifecycle, remediation, 30-day filing, six-year self-assessment retention, and incident-driven reassessment.

## What to keep as evidence

The record should show whether assurance is voluntary, mandatory for an Article 26 product or service, or part of the CII application-assessment lifecycle. Keep the exact catalogue entry, qualified-body scope, report or certificate, CII trigger, assessment stage, result, filing, and remediation together.

- Product or service identity, version, supplier, and applicable catalogue entry or other trigger.
- Whether assurance is voluntary, mandatory under Article 26, or a CII application assessment under Article 27; for Article 26, retain both the commercial-cryptography analysis and the exact mandatory catalogue match.
- Testing or certification body identity, scope, qualification, report or certificate, and validity status.
- The legal basis and scope for recognising earlier cybersecurity testing or assessment to avoid duplication.
- For covered CII, the plan result, pre-operation result, annual assessment history, transition branch, remediation, filing evidence, and cryptographic-technology review records.
- Changes to product scope, model, cryptographic function, supplier, certificate, catalogue, standards, application plan, or CII deployment that require a new conclusion or reassessment.

Sources for this answer:

- [Commercial cryptography testing institution measures interpretation](https://www.oscca.gov.cn/sca/xxgk/2023-10/07/content_1061110.shtml?ref=sorena.io) - The official interpretation supports checking the testing body's qualification, scope, reports, data, samples, and information-reporting controls.
- [PRC Cryptography Law](https://www.oscca.gov.cn/sca/xxgk/2023-06/04/content_1057225.shtml?ref=sorena.io) - Articles 25-27 support distinguishing voluntary assurance, mandatory product or service assurance, and CII application assessment.
- [Commercial Cryptography Administration Regulation](https://xzfg.moj.gov.cn/front/law/detail?LawID=1622&ref=sorena.io) - Articles 12-21 and 38-42 support the body, scope, product, service, CII cycle, technology review, and assessment-coordination evidence.

## Primary sources

- [Commercial cryptography testing institution measures interpretation](https://www.oscca.gov.cn/sca/xxgk/2023-10/07/content_1061110.shtml?ref=sorena.io) - Official explanation of qualification and supervision for commercial-cryptography product-testing and application-security-assessment bodies.
- [PRC Cryptography Law](https://www.oscca.gov.cn/sca/xxgk/2023-06/04/content_1057225.shtml?ref=sorena.io) - Articles 25-27 distinguish voluntary assurance, mandatory specified-product and service assurance, and CII application security assessment.
- [Commercial Cryptography Administration Regulation](https://xzfg.moj.gov.cn/front/law/detail?LawID=1622&ref=sorena.io) - Current rules for testing and certification bodies, mandatory product and service assurance, and the covered-CII application-assessment cycle.
- [CII Commercial Cryptography Use Management Provisions](https://www.oscca.gov.cn/sca/xxgk/2025-06/27/content_1061270.shtml?ref=sorena.io) - Current CII product, technology, and application-assessment lifecycle requirements effective from 1 August 2025.

## Topic Guides

- [China commercial cryptography compliance checklist](/artifacts/apac/china-cryptography-law/checklist.md): China commercial cryptography checklist covering classification, product and service assurance, CII duties, trade controls, and retained evidence.
- [China commercial cryptography testing evidence template](/artifacts/apac/china-cryptography-law/commercial-cryptography-testing-evidence-template.md): Record the legal route, product or system scope, testing-body qualification, report details, gaps, and reassessment triggers for China commercial cryptography assurance.
- [China cryptography compliance deadlines and calendar](/artifacts/apac/china-cryptography-law/deadlines-and-compliance-calendar.md): China cryptography effective dates, CII reports, annual assessments, licence renewals, change notices, and pre-operation checks.
- [China cryptography import, export, and security review triage](/artifacts/apac/china-cryptography-law/import-export-and-security-assessment.md): Screen commercial cryptography imports under the 2020 list, exports under China's unified dual-use list, the consumer exclusion, system assessment, and CII review.
- [China Cryptography Law FAQ](/artifacts/apac/china-cryptography-law/faq.md): Answers on China's commercial-cryptography scope, product assurance, classified protection, CII assessment, procurement review, and trade controls.
- [China Cryptography Law requirements](/artifacts/apac/china-cryptography-law/requirements.md): China commercial cryptography requirements by role: standards, testing, certification, CII use and assessment, trade controls, and evidence.
- [China Cryptography Law vs Cybersecurity Law](/artifacts/apac/china-cryptography-law/china-cryptography-law-vs-cybersecurity-law.md): Compare China's Cryptography Law and current Cybersecurity Law by scope, actor, product assurance, CII duties, evidence, and enforcement.
- [China cryptography penalties, fines, and liability](/artifacts/apac/china-cryptography-law/penalties-and-fines.md): China commercial cryptography penalties by actor and violation, including fine bands, corrective orders, confiscation, licence action, and liability.
- [Commercial cryptography procurement checklist](/artifacts/apac/china-cryptography-law/commercial-cryptography-procurement-checklist.md): Procurement checks for commercial cryptography products and services used in China, including certificate scope, CII duties, and supplier changes.
- [Commercial cryptography products and testing evidence](/artifacts/apac/china-cryptography-law/commercial-cryptography-products-and-testing.md): When China commercial cryptography testing or certification is voluntary or mandatory, and what product, service, body, and scope evidence to keep.
- [Do imported cryptography products need special review?](/artifacts/apac/china-cryptography-law/faq/do-imported-cryptography-products-need-special-review.md): Not every encrypted product imported into China needs a licence. Check the 2020 commercial-cryptography import list, the consumer-product exception, and any CII procurement review.
- [Does using encryption trigger China Cryptography Law duties?](/artifacts/apac/china-cryptography-law/faq/does-using-encryption-trigger-china-cryptography-law.md): Using encryption does not create one universal China approval duty. Check classified protection, product, service, CII, procurement, and trade triggers.
- [How does cryptography compliance overlap with China cybersecurity law?](/artifacts/apac/china-cryptography-law/faq/how-does-cryptography-compliance-overlap-with-cybersecurity-law.md): See how China's cryptography rules connect with classified protection, product assurance, CII assessment, and cybersecurity review without merging the regimes.
- [What is commercial cryptography in China?](/artifacts/apac/china-cryptography-law/faq/what-is-commercial-cryptography-in-china.md): Commercial cryptography protects information that is not a state secret. Learn how China defines the category and which separate facts trigger product, CII, or trade controls.

*Document the requirement*

*Placement: Before primary sources*

## Prepare the commercial cryptography evidence file

Sorena AI helps assign controls and retain evidence for testing, certification, and application assessment.

- [Map official sources to evidence](/solutions/research-copilot.md): Research Copilot records the official citation, decision, owner, evidence, and change history.
- [Review the China route](/contact.md): Check the China Cryptography Law scope decision and unresolved launch questions with Sorena.


---

[Privacy Policy](https://www.sorena.io/privacy.md) | [Terms of Use](https://www.sorena.io/terms-of-use.md) | [DMCA](https://www.sorena.io/dmca.md) | [About Us](https://www.sorena.io/about-us.md)

(c) 2026 Sorena AB (559573-7338). All rights reserved.

Source: https://www.sorena.io/artifacts/apac/china-cryptography-law/faq/when-is-commercial-cryptography-testing-or-certification-needed.md
