China Cryptography Law Commercial cryptography import, export, assessment, and security review triage
A decision path for China commercial cryptography trade controls and the separate system-assessment and CII procurement-review questions.
Screen the exact item against the published trade-control lists, document any mass-market consumer-product exception, and keep those conclusions separate from commercial cryptography application security assessment and CII national security review.
Classify a item moving into or out of China separately from cryptography used in a China network and information system. Import licensing, export control, , and of certain critical information infrastructure procurements each have a different trigger and evidence record.
1
Section 1
Separate the four legal questions
Encryption alone does not trigger the trade-control regime. Import and export screening now use different lists. The attached to Announcement No. 63 of 2020 remains the basis for import licensing. For exports, Announcement No. 51 of 2024 replaced the 2020 commercial cryptography export list and procedure with China's unified Export Control List from 1 December 2024.
For exports, check listed , temporary controls, and statutory catch-all cases. The 2024 Dual-Use Items Export Control Regulation also requires the exporter to understand the item's performance and main use and allows a classification consultation with the Ministry of Commerce when the exporter cannot determine whether the item is controlled.
The Law excludes used in from this import licensing and export control regime. An official National Cryptography Administration policy answer describes these as products or technologies that the public can buy without restriction through ordinary retail channels, for personal use, and whose cryptographic function cannot easily be changed. Treat that description as official explanatory guidance and document the product facts; do not infer the exclusion from a consumer-facing brand name alone.
asks whether an in-scope network and information system uses compliantly, correctly, and effectively. CII asks whether a 's procurement of a network product or service involving commercial cryptography affects or may affect national security. The operator must assess that risk before use and apply to the Cybersecurity Review Office when the trigger is met. Neither that review nor an application security assessment determines whether an import or export licence is required.
Import licence: is the exact item or technology covered by the current ?
Export control: is the exact item, technology, service, software, or technical data covered by the unified Export Control List, a temporary control, or a , and what end-user and end-use facts apply?
Application security assessment: does a law, administrative regulation, or national provision require the network and information system to use protection?
CII : is the buyer a , does the procurement involve a network product or service using , and may it affect national security?
Classify the exact item or technology against the applicable import or export entry and technical description. Record enough detail to repeat the match: product and component names, model and version, cryptographic functions, algorithms and key lengths where relevant to the entry, whether users can change the cryptographic function, and whether software, source code, object code, technical data, or a service is transferred. A customs commodity code is a reference point, not the legal classification.
For a listed import, apply to the Ministry of Commerce for a import licence under the 2020 Import Licensing List and the Commercial Cryptography Administration Regulation. For an export, apply under the Export Control Regulation. A single export licence application requires applicant identity documents, the contract or agreement, a technical description or test report, final-user and final-use evidence, and any other required materials. The export regulation sets a 45-working-day decision period after acceptance, but time for classification, expert consultation, or on-site checks is excluded, and cases requiring State Council or Central Military Commission approval are not subject to that period.
For exports, preserve final-user and final-use evidence, contracts, invoices, books, documents, and business correspondence for at least five years. If a licence is active and the item type, destination, final user, final use, or another licence fact changes, stop using the licence and follow the reapplication or change procedure before continuing.
Screen non-sale and special customs movements as well as conventional shipments. The dual-use export regime covers transfers from China to destinations abroad and provision of controlled items by Chinese persons or organizations to foreign persons or organizations. Internal movements between specified special customs supervision areas and bonded supervision sites do not require an export licence under that regime, but remain subject to customs supervision. If Customs questions whether an export is controlled, it may withhold release while the item is classified.
Transaction: importer or exporter, consignor, consignee, final user, destination, final use, customs route, quantity, contract, and planned date.
Technical identity: manufacturer, item and component, model, version, cryptographic function, technical parameters relevant to the list, and supporting specification.
List analysis: list title and version, candidate entry, matching facts, non-matching facts, mass-market exclusion analysis, reviewer, and decision date.
Licence file: application, supporting documents, licence number and validity, conditions, customs declaration, and proof that the licensed item matches the shipment.
Uncertainty: the missing fact, owner, authority or adviser consulted, interim shipment hold or condition, and next decision date.
Screen system assessment and CII procurement separately
For an important network and information system that is required by law, administrative regulation, or another national provision to use protection, the operator must prepare and assess its commercial cryptography application plan, assess the system before operation, conduct an assessment at least once each year after operation, and file the report and related work information within 30 days after the report is formed.
For critical information infrastructure required to use , the CII Commercial Cryptography Use Provisions have applied since 1 August 2025. They require tested and certified commercial cryptography products and services, review by the National Cryptography Administration of the cryptographic algorithms, protocols, and key-management mechanisms used, and an annual operator report to the relevant protection department by 31 January covering the prior year's commercial cryptography use and assessments.
Application security assessment is distinct from the in Cryptography Law Article 27. The national security review question arises when a CII operator procures a network product or service involving that affects or may affect national security. Under the Cybersecurity Review Measures, the operator must assess the risk before use and apply to the Cybersecurity Review Office when the trigger is met. Record the operator status, procurement, national-security risk analysis, review submission, and outcome separately; do not infer review clearance from a cryptography assessment report or product certificate.
Application assessment record: legal trigger, system operator and boundary, application plan, assessment stage, assessor, report, findings, remediation, filing date, and next annual due date.
CII cryptography record: qualified product and service evidence, reviewed algorithms, protocols, and key-management mechanisms, assigned cryptography roles, annual assessment, and the report due to the protection department by 31 January.
CII review record: evidence of CII operator status, procured network product or service, involved, national-security-effect analysis, responsible review authority, submission, conditions, and outcome.
Keep product testing or certification evidence linked but separate; it answers a product or service assurance question, not the system or procurement question.
Keep the trade-control record linked but separate; an import or export licence does not establish assessment compliance or clearance.
Assign separate owners for trade classification, customs execution, product security, the system assessment, and CII procurement review. They may use the same product specification and cryptography inventory, but each owner should approve only the conclusion within that route.
Reopen the record when the transaction or product no longer matches the facts reviewed. If a list description, consumer-product exclusion, CII status, or national-security-effect question remains uncertain, leave the conclusion open and seek case-specific guidance from the responsible authority or qualified counsel.
Trade change: list or procedure update, model, version, cryptographic function, technical parameter, quantity, customs route, destination, final user, or final use.
Consumer-product change: retail availability, intended user, distribution restriction, user configurability, or cryptographic function.
System change: operator, legal classification, system boundary, architecture, application plan, or assessment result.
Procurement change: buyer's CII status, supplier, network product or service, contract scope, deployment, or facts relevant to a possible national-security effect.
Evidence change: licence condition or expiry, assessment finding, regulator question, customs query, report correction, or authority decision.
Articles 5-15 establish CII-specific commercial cryptography governance, qualified-product and reviewed-technology requirements, lifecycle assessment, annual reporting, and the link to cybersecurity review.
Official service page distinguishing the unified-list export licence from the 2020-list commercial cryptography import licence, with current forms, materials, and filing routes.
Publishes the Commercial Cryptography Import Licensing List that remains the import-screening basis; its attached export list and export procedure ceased to apply on 1 December 2024.
Article 27 separately addresses CII commercial cryptography use and application security assessment, and national security review for certain CII procurements.