---
title: "China cryptography import, export, and security review triage"
canonical_url: "https://www.sorena.io/artifacts/apac/china-cryptography-law/import-export-and-security-assessment"
source_url: "https://www.sorena.io/artifacts/apac/china-cryptography-law/import-export-and-security-assessment"
author: "Sorena AI"
description: "Screen commercial cryptography imports under the 2020 list, exports under China's unified dual-use list, the consumer exclusion, system assessment, and CII review."
published_at: "2026-07-05"
updated_at: "2026-07-24"
keywords:
  - "China Cryptography Law"
  - "commercial cryptography import license"
  - "commercial cryptography export control"
  - "mass-market consumer products"
  - "CII national security review"
  - "Commercial cryptography"
  - "Cryptography Law"
  - "Commercial cryptography import and export"
  - "China cybersecurity"
---
**[SORENA](https://www.sorena.io/)** - AI-Powered GRC Platform

[Home](https://www.sorena.io/) | [Solutions](https://www.sorena.io/solutions) | [Artifacts](https://www.sorena.io/artifacts) | [About Us](https://www.sorena.io/about-us) | [Contact](https://www.sorena.io/contact) | [Portal](https://app.sorena.io)

---

# China cryptography import, export, and security review triage

Screen commercial cryptography imports under the 2020 list, exports under China's unified dual-use list, the consumer exclusion, system assessment, and CII review.

*Cryptography* *China*

## China Cryptography Law Commercial cryptography import, export, assessment, and security review triage

A decision path for China commercial cryptography trade controls and the separate system-assessment and CII procurement-review questions.

Screen the exact item against the published trade-control lists, document any mass-market consumer-product exception, and keep those conclusions separate from commercial cryptography application security assessment and CII national security review.

Classify a commercial cryptography item moving into or out of China separately from cryptography used in a China network and information system. Import licensing, export control, commercial cryptography application security assessment, and national security review of certain critical information infrastructure procurements each have a different trigger and evidence record.

## Definitions

### Commercial cryptography

Commercial cryptography means technologies, products, and services that use specific transformations to encrypt or authenticate information that is not a state secret. A product can contain commercial cryptography without appearing on an import licensing or export control list, so the presence of encryption is only the start of the classification.

**Why it matters here:** Identify the exact cryptographic technology, product, or service before screening a transaction. The trade conclusion must then come from the published list description and any applicable exclusion, not from the product name or the fact that it encrypts data.

Sources:

- [PRC Cryptography Law, Articles 2 and 8](https://www.oscca.gov.cn/sca/xxgk/2023-06/04/content_1057225.shtml?ref=sorena.io)
- [Commercial Cryptography Administration Regulation, Article 2](https://xzfg.moj.gov.cn/front/law/detail?LawID=1622&ref=sorena.io)

### Commercial cryptography used in mass-market consumer products

**Term:** mass-market consumer products

Cryptography Law Article 28 excludes commercial cryptography used in mass-market consumer products from its import licensing and export control system. The National Cryptography Administration explains this category as products or technologies that the public can buy without restriction through ordinary retail channels, for personal use, and whose cryptographic function cannot easily be changed. Use this official guidance alongside the statutory text and the facts of the specific product.

**Why it matters here:** Document retail availability, intended users and use, distribution restrictions, and whether the cryptographic function can readily be changed. A consumer brand, consumer-facing interface, or retail listing alone does not establish the exclusion.

Sources:

- [PRC Cryptography Law, Article 28](https://www.oscca.gov.cn/sca/xxgk/2023-06/04/content_1057225.shtml?ref=sorena.io)
- [National Cryptography Administration policy answer on mass-market consumer products](https://www.oscca.gov.cn/sca/xxgk/2020-04/02/content_1060694.shtml?ref=sorena.io)

### Dual-use items

Dual-use items are goods, technologies, and services that have both civil and military uses or can help increase military potential, especially items connected with weapons of mass destruction or their delivery systems. Since 1 December 2024, controlled commercial cryptography exports appear in the unified Dual-Use Items Export Control List. The export regime can also cover temporarily controlled or unlisted items when a statutory catch-all trigger applies.

**Why it matters here:** For exports, classify the exact product, technology, service, software, or technical data against the unified list and current control announcements. Do not use the commercial cryptography export list or export procedure attached to Announcement No. 63 of 2020; Announcement No. 51 of 2024 made those parts inapplicable.

Sources:

- [Dual-Use Items Export Control Regulation, Articles 2 and 11-14](https://www.mofcom.gov.cn/zwgk/zcfb/art/2024/art_bf56a4c613eb47af85712117561d609e.html?ref=sorena.io)
- [MOFCOM Announcement No. 51 of 2024](https://www.mofcom.gov.cn/zcfb/zgdwjjmywg/art/2025/art_022ec90922004d2dba0d68d33c51a2da.html?ref=sorena.io)

### Critical information infrastructure operator

A critical information infrastructure operator is the organization responsible for operating infrastructure in important industries and fields that could seriously harm national security, the national economy and people's livelihood, or the public interest if it were destroyed, lost functionality, or suffered a data leak. The competent protection department identifies critical information infrastructure and notifies the operator; a supplier should not infer operator status from sector or customer size alone.

**Why it matters here:** The procurement-review branch depends on the buyer's actual operator status and whether the network product or service affects or may affect national security. Retain the operator's notification or other authoritative status evidence rather than relying on a vendor questionnaire alone.

Sources:

- [Critical Information Infrastructure Security Protection Regulation, Articles 2 and 8-11](https://www.cac.gov.cn/2021-08/17/c_1630785976988160.htm?ref=sorena.io)
- [Cybersecurity Review Measures, Articles 2 and 5](https://www.cac.gov.cn/2022-01/04/c_1642894602182845.htm?ref=sorena.io)

### Commercial cryptography application security assessment

A commercial cryptography application security assessment is the standards-based testing, analysis, and verification of whether a network and information system uses commercial cryptography technologies, products, and services compliantly, correctly, and effectively. It applies to systems that laws, administrative regulations, or national provisions require to use commercial cryptography protection and includes planning, pre-operation, and recurring operational stages.

**Why it matters here:** This assessment concerns the system's cryptography design and operation. It does not classify an import or export and does not replace a separate cybersecurity review of a critical information infrastructure procurement.

Sources:

- [Commercial Cryptography Application Security Assessment Measures, Articles 2 and 6-11](https://www.oscca.gov.cn/sca/xxgk/2023-10/07/content_1061109.shtml?ref=sorena.io)

### Cybersecurity review of a CII procurement

**Term:** national security review

For this page, national security review means the cybersecurity review required when a critical information infrastructure operator procures a network product or service that affects or may affect national security. The operator must assess that risk before use and apply to the Cybersecurity Review Office when the trigger is met. Review factors include illegal control or disruption, supply interruption, product and supplier security, compliance history, and risks to core data, important data, or large amounts of personal information.

**Why it matters here:** A commercial cryptography product certificate, application security assessment report, or trade licence does not decide this procurement review. Record the buyer's operator status, the procured product or service, the national-security risk analysis, the submission materials, and the written outcome separately.

Sources:

- [PRC Cryptography Law, Article 27](https://www.oscca.gov.cn/sca/xxgk/2023-06/04/content_1057225.shtml?ref=sorena.io)
- [Cybersecurity Review Measures, Articles 2 and 5-10](https://www.cac.gov.cn/2022-01/04/c_1642894602182845.htm?ref=sorena.io)

### Commercial Cryptography Import Licensing List

This is the import list published with Announcement No. 63 of 2020 for commercial cryptography involving national security or the public interest and having an encryption-protection function. It remains the basis for commercial cryptography import licensing. Announcement No. 51 of 2024 withdrew the 2020 export list and export procedure, not this import list.

**Why it matters here:** For an import, match the exact product or technology and its technical characteristics to the current import-list entry. If it is listed and no statutory exclusion applies, the importer must obtain the Ministry of Commerce licence and present it to Customs; an export classification under the unified dual-use list does not answer this import question.

Sources:

- [MOFCOM, National Cryptography Administration, and GACC Announcement No. 63 of 2020](https://aqygzj.mofcom.gov.cn/qdml/art/2020/art_aa383a8551a64251a7d202e0c62d4ee4.html?ref=sorena.io)
- [MOFCOM Announcement No. 51 of 2024](https://www.mofcom.gov.cn/zcfb/zgdwjjmywg/art/2025/art_022ec90922004d2dba0d68d33c51a2da.html?ref=sorena.io)

### Unlisted dual-use item catch-all trigger

**Term:** catch-all trigger

China's export-control law can require a licence for an item outside the published control list and temporary controls when the exporter knows, should know, or is notified by the Ministry of Commerce that the item may endanger national security or interests, be used in weapons of mass destruction or their delivery systems, or be used for terrorism. This is commonly called a catch-all control.

**Why it matters here:** An exporter cannot close the export review merely because no list entry matches. Record end-user, end-use, destination, technical capability, warning signs, government notices, and any Ministry of Commerce classification consultation before concluding that no licence is required.

Sources:

- [PRC Export Control Law, Article 12](https://www.npc.gov.cn/englishnpc/c2759/c23934/202112/t20211209_385109.html?ref=sorena.io)
- [Dual-Use Items Export Control Regulation, Article 14](https://www.mofcom.gov.cn/zwgk/zcfb/art/2024/art_bf56a4c613eb47af85712117561d609e.html?ref=sorena.io)

## Separate the four legal questions

Encryption alone does not trigger the trade-control regime. Import and export screening now use different lists. The Commercial Cryptography Import Licensing List attached to Announcement No. 63 of 2020 remains the basis for commercial cryptography import licensing. For exports, Announcement No. 51 of 2024 replaced the 2020 commercial cryptography export list and procedure with China's unified Dual-Use Items Export Control List from 1 December 2024.

For exports, check listed dual-use items, temporary controls, and statutory catch-all cases. The 2024 Dual-Use Items Export Control Regulation also requires the exporter to understand the item's performance and main use and allows a classification consultation with the Ministry of Commerce when the exporter cannot determine whether the item is controlled.

The Law excludes commercial cryptography used in mass-market consumer products from this import licensing and export control regime. An official National Cryptography Administration policy answer describes these as products or technologies that the public can buy without restriction through ordinary retail channels, for personal use, and whose cryptographic function cannot easily be changed. Treat that description as official explanatory guidance and document the product facts; do not infer the exclusion from a consumer-facing brand name alone.

Commercial cryptography application security assessment asks whether an in-scope network and information system uses commercial cryptography compliantly, correctly, and effectively. CII national security review asks whether a critical information infrastructure operator's procurement of a network product or service involving commercial cryptography affects or may affect national security. The operator must assess that risk before use and apply to the Cybersecurity Review Office when the trigger is met. Neither that review nor an application security assessment determines whether an import or export licence is required.

- Import licence: is the exact item or technology covered by the current Commercial Cryptography Import Licensing List?
- Export control: is the exact item, technology, service, software, or technical data covered by the unified Dual-Use Items Export Control List, a temporary control, or a catch-all trigger, and what end-user and end-use facts apply?
- Application security assessment: does a law, administrative regulation, or national provision require the network and information system to use commercial cryptography protection?
- CII national security review: is the buyer a critical information infrastructure operator, does the procurement involve a network product or service using commercial cryptography, and may it affect national security?

Sources for this answer:

- [PRC Cryptography Law](https://www.oscca.gov.cn/sca/xxgk/2023-06/04/content_1057225.shtml?ref=sorena.io) - Articles 27-28 distinguish CII commercial cryptography duties and national security review from list-based import licensing, export control, and the mass-market consumer-product exclusion.
- [Commercial Cryptography Administration Regulation](https://xzfg.moj.gov.cn/front/law/detail?LawID=1622&ref=sorena.io) - Articles 31-34 set the list-based trade-control scope, covered customs movements, licence and customs presentation duties, application materials, and review period; the revised Regulation took effect on 1 July 2023.
- [MOFCOM, National Cryptography Administration, and GACC Announcement No. 63 of 2020](https://aqygzj.mofcom.gov.cn/qdml/art/2020/art_aa383a8551a64251a7d202e0c62d4ee4.html?ref=sorena.io) - Publishes the Commercial Cryptography Import Licensing List that remains the import-screening basis; its attached export list and export procedure ceased to apply on 1 December 2024.
- [MOFCOM Announcement No. 51 of 2024](https://www.mofcom.gov.cn/zcfb/zgdwjjmywg/art/2025/art_022ec90922004d2dba0d68d33c51a2da.html?ref=sorena.io) - Made the unified Dual-Use Items Export Control List effective on 1 December 2024 and states that the 2020 commercial cryptography export list and export procedure no longer apply.
- [Dual-Use Items Export Control Regulation](https://www.mofcom.gov.cn/zwgk/zcfb/art/2024/art_bf56a4c613eb47af85712117561d609e.html?ref=sorena.io) - Articles 2 and 11-17 define export control, list, temporary-control and catch-all routes, exporter classification duties, licence types, application materials, and review timing.
- [National Cryptography Administration policy answer on mass-market consumer products](https://www.oscca.gov.cn/sca/xxgk/2020-04/02/content_1060694.shtml?ref=sorena.io) - Provides the official explanatory description of commercial cryptography used in mass-market consumer products; it is guidance rather than the statutory text.
- [Cybersecurity Review Measures](https://www.cac.gov.cn/2022-01/04/c_1642894602182845.htm?ref=sorena.io) - Articles 2 and 5 require a CII operator to assess whether a network product or service procurement affects or may affect national security and to apply for cybersecurity review when that trigger is met.

## Run the import or export screening

Classify the exact item or technology against the applicable import or export entry and technical description. Record enough detail to repeat the match: product and component names, model and version, cryptographic functions, algorithms and key lengths where relevant to the entry, whether users can change the cryptographic function, and whether software, source code, object code, technical data, or a service is transferred. A customs commodity code is a reference point, not the legal classification.

For a listed import, apply to the Ministry of Commerce for a commercial cryptography import licence under the 2020 Import Licensing List and the Commercial Cryptography Administration Regulation. For an export, apply under the Dual-Use Items Export Control Regulation. A single export licence application requires applicant identity documents, the contract or agreement, a technical description or test report, final-user and final-use evidence, and any other required materials. The export regulation sets a 45-working-day decision period after acceptance, but time for classification, expert consultation, or on-site checks is excluded, and cases requiring State Council or Central Military Commission approval are not subject to that period.

For exports, preserve final-user and final-use evidence, contracts, invoices, books, documents, and business correspondence for at least five years. If a licence is active and the item type, destination, final user, final use, or another licence fact changes, stop using the licence and follow the reapplication or change procedure before continuing.

Screen non-sale and special customs movements as well as conventional shipments. The dual-use export regime covers transfers from China to destinations abroad and provision of controlled items by Chinese persons or organizations to foreign persons or organizations. Internal movements between specified special customs supervision areas and bonded supervision sites do not require an export licence under that regime, but remain subject to customs supervision. If Customs questions whether an export is controlled, it may withhold release while the item is classified.

- Transaction: importer or exporter, consignor, consignee, final user, destination, final use, customs route, quantity, contract, and planned date.
- Technical identity: manufacturer, item and component, model, version, cryptographic function, technical parameters relevant to the list, and supporting specification.
- List analysis: list title and version, candidate entry, matching facts, non-matching facts, mass-market exclusion analysis, reviewer, and decision date.
- Licence file: application, supporting documents, licence number and validity, conditions, customs declaration, and proof that the licensed item matches the shipment.
- Uncertainty: the missing fact, owner, authority or adviser consulted, interim shipment hold or condition, and next decision date.

Sources for this answer:

- [Commercial Cryptography Administration Regulation](https://xzfg.moj.gov.cn/front/law/detail?LawID=1622&ref=sorena.io) - Articles 31-34 support the Commercial Cryptography Import Licensing List, import licence, customs, application-material, and review requirements.
- [MOFCOM commercial cryptography import and export licensing service guide](https://www.mofcom.gov.cn/zwdt/lywxhjsjcksp/index.html?ref=sorena.io) - Official service page distinguishing the unified-list export licence from the 2020-list commercial cryptography import licence, with current forms, materials, and filing routes.
- [Dual-Use Items Export Control Regulation](https://www.mofcom.gov.cn/zwgk/zcfb/art/2024/art_bf56a4c613eb47af85712117561d609e.html?ref=sorena.io) - Articles 2, 14-22, 27, and 48 support controlled transfer scope, classification consultation, licence routes, application materials, review timing, licence changes, customs presentation, release holds, five-year export-record retention, and the stated special-customs-area exception.
- [MOFCOM Announcement No. 51 of 2024](https://www.mofcom.gov.cn/zcfb/zgdwjjmywg/art/2025/art_022ec90922004d2dba0d68d33c51a2da.html?ref=sorena.io) - Direct source for the unified Dual-Use Items Export Control List and the withdrawal of the 2020 commercial cryptography export list and procedure.

## Screen system assessment and CII procurement separately

For an important network and information system that is required by law, administrative regulation, or another national provision to use commercial cryptography protection, the operator must prepare and assess its commercial cryptography application plan, assess the system before operation, conduct an assessment at least once each year after operation, and file the report and related work information within 30 days after the report is formed.

For critical information infrastructure required to use commercial cryptography, the CII Commercial Cryptography Use Provisions have applied since 1 August 2025. They require tested and certified commercial cryptography products and services, review by the National Cryptography Administration of the cryptographic algorithms, protocols, and key-management mechanisms used, and an annual operator report to the relevant protection department by 31 January covering the prior year's commercial cryptography use and assessments.

Application security assessment is distinct from the national security review in Cryptography Law Article 27. The national security review question arises when a CII operator procures a network product or service involving commercial cryptography that affects or may affect national security. Under the Cybersecurity Review Measures, the operator must assess the risk before use and apply to the Cybersecurity Review Office when the trigger is met. Record the operator status, procurement, national-security risk analysis, review submission, and outcome separately; do not infer review clearance from a cryptography assessment report or product certificate.

- Application assessment record: legal trigger, system operator and boundary, application plan, assessment stage, assessor, report, findings, remediation, filing date, and next annual due date.
- CII cryptography record: qualified product and service evidence, reviewed algorithms, protocols, and key-management mechanisms, assigned cryptography roles, annual assessment, and the report due to the protection department by 31 January.
- CII review record: evidence of CII operator status, procured network product or service, commercial cryptography involved, national-security-effect analysis, responsible review authority, submission, conditions, and outcome.
- Keep product testing or certification evidence linked but separate; it answers a product or service assurance question, not the system or procurement question.
- Keep the trade-control record linked but separate; an import or export licence does not establish assessment compliance or national security review clearance.

Sources for this answer:

- [PRC Cryptography Law](https://www.oscca.gov.cn/sca/xxgk/2023-06/04/content_1057225.shtml?ref=sorena.io) - Article 27 separately addresses CII commercial cryptography use and application security assessment, and national security review for certain CII procurements.
- [Commercial Cryptography Application Security Assessment Measures](https://www.oscca.gov.cn/sca/xxgk/2023-10/07/content_1061109.shtml?ref=sorena.io) - Articles 2 and 6-14 define the assessment, its applicability trigger, planning and operational stages, annual frequency, evidence, retention, and 30-day filing requirement.
- [Cybersecurity Review Measures](https://www.cac.gov.cn/2022-01/04/c_1642894602182845.htm?ref=sorena.io) - Articles 2 and 5-10 define the CII procurement trigger, pre-use risk assessment, submission duty, application materials, and principal review factors.
- [CII Commercial Cryptography Use Provisions](https://www.oscca.gov.cn/sca/xxgk/2025-06/27/content_1061270.shtml?ref=sorena.io) - Articles 5-15 establish CII-specific commercial cryptography governance, qualified-product and reviewed-technology requirements, lifecycle assessment, annual reporting, and the link to cybersecurity review.

## Keep the decision current

Assign separate owners for trade classification, customs execution, product security, the system assessment, and CII procurement review. They may use the same product specification and cryptography inventory, but each owner should approve only the conclusion within that route.

Reopen the record when the transaction or product no longer matches the facts reviewed. If a list description, consumer-product exclusion, CII status, or national-security-effect question remains uncertain, leave the conclusion open and seek case-specific guidance from the responsible authority or qualified counsel.

- Trade change: list or procedure update, model, version, cryptographic function, technical parameter, quantity, customs route, destination, final user, or final use.
- Consumer-product change: retail availability, intended user, distribution restriction, user configurability, or cryptographic function.
- System change: operator, legal classification, system boundary, architecture, commercial cryptography application plan, or assessment result.
- Procurement change: buyer's CII status, supplier, network product or service, contract scope, deployment, or facts relevant to a possible national-security effect.
- Evidence change: licence condition or expiry, assessment finding, regulator question, customs query, report correction, or authority decision.

Sources for this answer:

- [National Cryptography Administration policy answer on mass-market consumer products](https://www.oscca.gov.cn/sca/xxgk/2020-04/02/content_1060694.shtml?ref=sorena.io) - Supports the facts to revisit when relying on the official explanatory description of a mass-market consumer product.
- [Commercial Cryptography Application Security Assessment Measures](https://www.oscca.gov.cn/sca/xxgk/2023-10/07/content_1061109.shtml?ref=sorena.io) - Articles 7-15 support lifecycle reassessment, annual assessment, filing, and event-driven reporting or assessment.
- [Dual-Use Items Export Control Regulation](https://www.mofcom.gov.cn/zwgk/zcfb/art/2024/art_bf56a4c613eb47af85712117561d609e.html?ref=sorena.io) - Articles 18 and 23-27 support renewed export review when licence facts, final users, final uses, or risk information changes.

*Use the requirement*

*Placement: Before primary sources*

## Prepare the commercial cryptography evidence file

Sorena AI helps assign owners, link official sources, and maintain separate trade, assessment, and CII review records.

- [Map official sources to evidence](/solutions/research-copilot.md): Research Copilot connects the official citation, decision, owner, retained evidence, and change history.
- [Review the China route](/contact.md): Check the China Cryptography Law scope decision and unresolved launch questions with Sorena.

## Primary sources

- [PRC Cryptography Law](https://www.oscca.gov.cn/sca/xxgk/2023-06/04/content_1057225.shtml?ref=sorena.io) - Articles 27-28 establish the principal CII assessment and review duties and the list-based commercial cryptography import and export regime.
- [Commercial Cryptography Administration Regulation](https://xzfg.moj.gov.cn/front/law/detail?LawID=1622&ref=sorena.io) - Binding regulation for commercial cryptography import and export scope, customs movements, licences, application materials, and review.
- [MOFCOM, National Cryptography Administration, and GACC Announcement No. 63 of 2020](https://aqygzj.mofcom.gov.cn/qdml/art/2020/art_aa383a8551a64251a7d202e0c62d4ee4.html?ref=sorena.io) - Official publication of the Commercial Cryptography Import Licensing List that remains the import-screening basis; its export list and procedure no longer apply.
- [MOFCOM Announcement No. 51 of 2024](https://www.mofcom.gov.cn/zcfb/zgdwjjmywg/art/2025/art_022ec90922004d2dba0d68d33c51a2da.html?ref=sorena.io) - Official publication of the unified Dual-Use Items Export Control List from 1 December 2024 and withdrawal of the 2020 commercial cryptography export list and procedure.
- [Dual-Use Items Export Control Regulation](https://www.mofcom.gov.cn/zwgk/zcfb/art/2024/art_bf56a4c613eb47af85712117561d609e.html?ref=sorena.io) - Binding export-control regulation for controlled-item classification, licensing, end users and end uses, customs presentation, records, and changed circumstances from 1 December 2024.
- [Commercial Cryptography Application Security Assessment Measures](https://www.oscca.gov.cn/sca/xxgk/2023-10/07/content_1061109.shtml?ref=sorena.io) - Binding measures for commercial cryptography application security assessment scope, lifecycle, evidence, filing, and reassessment.
- [Cybersecurity Review Measures](https://www.cac.gov.cn/2022-01/04/c_1642894602182845.htm?ref=sorena.io) - Binding measures for the CII procurement risk assessment, cybersecurity review trigger, application materials, procedure, and review factors.
- [CII Commercial Cryptography Use Provisions](https://www.oscca.gov.cn/sca/xxgk/2025-06/27/content_1061270.shtml?ref=sorena.io) - Binding CII-specific cryptography governance, technology, assessment, reporting, and procurement-review requirements from 1 August 2025.

## Related Topic Guides

- [China commercial cryptography compliance checklist](/artifacts/apac/china-cryptography-law/checklist.md): China commercial cryptography checklist covering classification, product and service assurance, CII duties, trade controls, and retained evidence.
- [China commercial cryptography testing evidence template](/artifacts/apac/china-cryptography-law/commercial-cryptography-testing-evidence-template.md): Record the legal route, product or system scope, testing-body qualification, report details, gaps, and reassessment triggers for China commercial cryptography assurance.
- [China cryptography compliance deadlines and calendar](/artifacts/apac/china-cryptography-law/deadlines-and-compliance-calendar.md): China cryptography effective dates, CII reports, annual assessments, licence renewals, change notices, and pre-operation checks.
- [China Cryptography Law FAQ](/artifacts/apac/china-cryptography-law/faq.md): Answers on China's commercial-cryptography scope, product assurance, classified protection, CII assessment, procurement review, and trade controls.
- [China Cryptography Law requirements](/artifacts/apac/china-cryptography-law/requirements.md): China commercial cryptography requirements by role: standards, testing, certification, CII use and assessment, trade controls, and evidence.
- [China Cryptography Law vs Cybersecurity Law](/artifacts/apac/china-cryptography-law/china-cryptography-law-vs-cybersecurity-law.md): Compare China's Cryptography Law and current Cybersecurity Law by scope, actor, product assurance, CII duties, evidence, and enforcement.
- [China cryptography penalties, fines, and liability](/artifacts/apac/china-cryptography-law/penalties-and-fines.md): China commercial cryptography penalties by actor and violation, including fine bands, corrective orders, confiscation, licence action, and liability.
- [Commercial cryptography procurement checklist](/artifacts/apac/china-cryptography-law/commercial-cryptography-procurement-checklist.md): Procurement checks for commercial cryptography products and services used in China, including certificate scope, CII duties, and supplier changes.
- [Commercial cryptography products and testing evidence](/artifacts/apac/china-cryptography-law/commercial-cryptography-products-and-testing.md): When China commercial cryptography testing or certification is voluntary or mandatory, and what product, service, body, and scope evidence to keep.
- [Do imported cryptography products need special review?](/artifacts/apac/china-cryptography-law/faq/do-imported-cryptography-products-need-special-review.md): Not every encrypted product imported into China needs a licence. Check the 2020 commercial-cryptography import list, the consumer-product exception, and any CII procurement review.
- [Does using encryption trigger China Cryptography Law duties?](/artifacts/apac/china-cryptography-law/faq/does-using-encryption-trigger-china-cryptography-law.md): Using encryption does not create one universal China approval duty. Check classified protection, product, service, CII, procurement, and trade triggers.
- [How does cryptography compliance overlap with China cybersecurity law?](/artifacts/apac/china-cryptography-law/faq/how-does-cryptography-compliance-overlap-with-cybersecurity-law.md): See how China's cryptography rules connect with classified protection, product assurance, CII assessment, and cybersecurity review without merging the regimes.
- [What is commercial cryptography in China?](/artifacts/apac/china-cryptography-law/faq/what-is-commercial-cryptography-in-china.md): Commercial cryptography protects information that is not a state secret. Learn how China defines the category and which separate facts trigger product, CII, or trade controls.
- [When is commercial cryptography testing or certification needed?](/artifacts/apac/china-cryptography-law/faq/when-is-commercial-cryptography-testing-or-certification-needed.md): Commercial-cryptography assurance is often voluntary, but specified products and services require it. Covered CII also needs application assessment and qualified cryptography.


---

[Privacy Policy](https://www.sorena.io/privacy.md) | [Terms of Use](https://www.sorena.io/terms-of-use.md) | [DMCA](https://www.sorena.io/dmca.md) | [About Us](https://www.sorena.io/about-us.md)

(c) 2026 Sorena AB (559573-7338). All rights reserved.

Source: https://www.sorena.io/artifacts/apac/china-cryptography-law/import-export-and-security-assessment.md
