CryptographyChina

China Cryptography Law Commercial cryptography import, export, assessment, and security review triage

A decision path for China commercial cryptography trade controls and the separate system-assessment and CII procurement-review questions.

Screen the exact item against the published trade-control lists, document any mass-market consumer-product exception, and keep those conclusions separate from commercial cryptography application security assessment and CII national security review.

Author
Sorena AI
Published
Jul 5, 2026
Updated
Jul 24, 2026
Sections
4

Structured answer sets in this page tree.

Primary sources
10

Cited legal and guidance references.

Publication metadata
Sorena AI
Published Jul 5, 2026
Updated Jul 24, 2026
Overview

Classify a item moving into or out of China separately from cryptography used in a China network and information system. Import licensing, export control, , and of certain critical information infrastructure procurements each have a different trigger and evidence record.

Section 2

Run the import or export screening

Classify the exact item or technology against the applicable import or export entry and technical description. Record enough detail to repeat the match: product and component names, model and version, cryptographic functions, algorithms and key lengths where relevant to the entry, whether users can change the cryptographic function, and whether software, source code, object code, technical data, or a service is transferred. A customs commodity code is a reference point, not the legal classification.

For a listed import, apply to the Ministry of Commerce for a import licence under the 2020 Import Licensing List and the Commercial Cryptography Administration Regulation. For an export, apply under the Export Control Regulation. A single export licence application requires applicant identity documents, the contract or agreement, a technical description or test report, final-user and final-use evidence, and any other required materials. The export regulation sets a 45-working-day decision period after acceptance, but time for classification, expert consultation, or on-site checks is excluded, and cases requiring State Council or Central Military Commission approval are not subject to that period.

For exports, preserve final-user and final-use evidence, contracts, invoices, books, documents, and business correspondence for at least five years. If a licence is active and the item type, destination, final user, final use, or another licence fact changes, stop using the licence and follow the reapplication or change procedure before continuing.

Screen non-sale and special customs movements as well as conventional shipments. The dual-use export regime covers transfers from China to destinations abroad and provision of controlled items by Chinese persons or organizations to foreign persons or organizations. Internal movements between specified special customs supervision areas and bonded supervision sites do not require an export licence under that regime, but remain subject to customs supervision. If Customs questions whether an export is controlled, it may withhold release while the item is classified.

  • Transaction: importer or exporter, consignor, consignee, final user, destination, final use, customs route, quantity, contract, and planned date.
  • Technical identity: manufacturer, item and component, model, version, cryptographic function, technical parameters relevant to the list, and supporting specification.
  • List analysis: list title and version, candidate entry, matching facts, non-matching facts, mass-market exclusion analysis, reviewer, and decision date.
  • Licence file: application, supporting documents, licence number and validity, conditions, customs declaration, and proof that the licensed item matches the shipment.
  • Uncertainty: the missing fact, owner, authority or adviser consulted, interim shipment hold or condition, and next decision date.
Section 3

Screen system assessment and CII procurement separately

For an important network and information system that is required by law, administrative regulation, or another national provision to use protection, the operator must prepare and assess its commercial cryptography application plan, assess the system before operation, conduct an assessment at least once each year after operation, and file the report and related work information within 30 days after the report is formed.

For critical information infrastructure required to use , the CII Commercial Cryptography Use Provisions have applied since 1 August 2025. They require tested and certified commercial cryptography products and services, review by the National Cryptography Administration of the cryptographic algorithms, protocols, and key-management mechanisms used, and an annual operator report to the relevant protection department by 31 January covering the prior year's commercial cryptography use and assessments.

Application security assessment is distinct from the in Cryptography Law Article 27. The national security review question arises when a CII operator procures a network product or service involving that affects or may affect national security. Under the Cybersecurity Review Measures, the operator must assess the risk before use and apply to the Cybersecurity Review Office when the trigger is met. Record the operator status, procurement, national-security risk analysis, review submission, and outcome separately; do not infer review clearance from a cryptography assessment report or product certificate.

  • Application assessment record: legal trigger, system operator and boundary, application plan, assessment stage, assessor, report, findings, remediation, filing date, and next annual due date.
  • CII cryptography record: qualified product and service evidence, reviewed algorithms, protocols, and key-management mechanisms, assigned cryptography roles, annual assessment, and the report due to the protection department by 31 January.
  • CII review record: evidence of CII operator status, procured network product or service, involved, national-security-effect analysis, responsible review authority, submission, conditions, and outcome.
  • Keep product testing or certification evidence linked but separate; it answers a product or service assurance question, not the system or procurement question.
  • Keep the trade-control record linked but separate; an import or export licence does not establish assessment compliance or clearance.
Section 4

Keep the decision current

Assign separate owners for trade classification, customs execution, product security, the system assessment, and CII procurement review. They may use the same product specification and cryptography inventory, but each owner should approve only the conclusion within that route.

Reopen the record when the transaction or product no longer matches the facts reviewed. If a list description, consumer-product exclusion, CII status, or national-security-effect question remains uncertain, leave the conclusion open and seek case-specific guidance from the responsible authority or qualified counsel.

  • Trade change: list or procedure update, model, version, cryptographic function, technical parameter, quantity, customs route, destination, final user, or final use.
  • Consumer-product change: retail availability, intended user, distribution restriction, user configurability, or cryptographic function.
  • System change: operator, legal classification, system boundary, architecture, application plan, or assessment result.
  • Procurement change: buyer's CII status, supplier, network product or service, contract scope, deployment, or facts relevant to a possible national-security effect.
  • Evidence change: licence condition or expiry, assessment finding, regulator question, customs query, report correction, or authority decision.
Primary sources

References and citations

oscca.gov.cn
Referenced sections
  • Articles 5-15 establish CII-specific commercial cryptography governance, qualified-product and reviewed-technology requirements, lifecycle assessment, annual reporting, and the link to cybersecurity review.
cac.gov.cn
Referenced sections
  • Articles 2 and 5-10 define the CII procurement trigger, pre-use risk assessment, submission duty, application materials, and principal review factors.
mofcom.gov.cn
Referenced sections
  • Direct source for the unified Dual-Use Items Export Control List and the withdrawal of the 2020 commercial cryptography export list and procedure.
oscca.gov.cn
Referenced sections
  • Article 27 separately addresses CII commercial cryptography use and application security assessment, and national security review for certain CII procurements.
Related guides

Explore more topics

China commercial cryptography compliance checklist
China commercial cryptography checklist covering classification, product and service assurance, CII duties, trade controls, and retained evidence.
China commercial cryptography testing evidence template
Record the legal route, product or system scope, testing-body qualification, report details, gaps, and reassessment triggers for China commercial cryptography assurance.
China cryptography compliance deadlines and calendar
China cryptography effective dates, CII reports, annual assessments, licence renewals, change notices, and pre-operation checks.
China Cryptography Law FAQ
Answers on China's commercial-cryptography scope, product assurance, classified protection, CII assessment, procurement review, and trade controls.
China Cryptography Law requirements
China commercial cryptography requirements by role: standards, testing, certification, CII use and assessment, trade controls, and evidence.
China Cryptography Law vs Cybersecurity Law
Compare China's Cryptography Law and current Cybersecurity Law by scope, actor, product assurance, CII duties, evidence, and enforcement.
China cryptography penalties, fines, and liability
China commercial cryptography penalties by actor and violation, including fine bands, corrective orders, confiscation, licence action, and liability.
Commercial cryptography procurement checklist
Procurement checks for commercial cryptography products and services used in China, including certificate scope, CII duties, and supplier changes.
Commercial cryptography products and testing evidence
When China commercial cryptography testing or certification is voluntary or mandatory, and what product, service, body, and scope evidence to keep.
Do imported cryptography products need special review?
Not every encrypted product imported into China needs a licence. Check the 2020 commercial-cryptography import list, the consumer-product exception, and any CII procurement review.
Does using encryption trigger China Cryptography Law duties?
Using encryption does not create one universal China approval duty. Check classified protection, product, service, CII, procurement, and trade triggers.
How does cryptography compliance overlap with China cybersecurity law?
See how China's cryptography rules connect with classified protection, product assurance, CII assessment, and cybersecurity review without merging the regimes.
What is commercial cryptography in China?
Commercial cryptography protects information that is not a state secret. Learn how China defines the category and which separate facts trigger product, CII, or trade controls.
When is commercial cryptography testing or certification needed?
Commercial-cryptography assurance is often voluntary, but specified products and services require it. Covered CII also needs application assessment and qualified cryptography.