CryptographyChina

China Cryptography Law Penalties, fines, and liability

Remedies and fine bands for commercial cryptography violations, organized by actor and conduct.

There is no single maximum fine for every cryptography violation. The applicable rule may require correction, cessation, warning, confiscation, a fine based on illegal income or a fixed amount, licence action, personal fines, civil damages, discipline, or criminal liability.

Author
Sorena AI
Published
Jul 5, 2026
Updated
Jul 24, 2026
Sections
6

Structured answer sets in this page tree.

Primary sources
5

Cited legal and guidance references.

Publication metadata
Sorena AI
Published Jul 5, 2026
Updated Jul 24, 2026
Overview

Match the actor, conduct, and controlling instrument before quoting a fine. Legal, security, procurement, product, and compliance teams should also distinguish mandatory remedies from discretionary fines and check whether a state-organ exception or another law changes the result.

Section 1

How to identify the applicable penalty

First classify the information and activity. The Cryptography Law separates core and ordinary cryptography, used to protect state-secret information, from , used to protect information that is not a state secret. The penalties below concern commercial cryptography; Articles 33 and 34 contain separate provisions for failures involving core and ordinary cryptography.

Then identify the actor and conduct. The Cryptography Law has applied since 1 January 2020 and sets the primary duties and liabilities. The revised Administration Regulation has applied since 1 July 2023 and adds current rules for unauthorized activity, testing and certification bodies, products and services, electronic certification, CII operators, network operators, and obstruction of supervision. Later measures add more specific duties for testing bodies, CII operators, and electronic-certification providers.

  • Record whether the actor is a , seller or service provider, electronic-certification provider, , , importer or exporter, public official, or another organization or person.
  • Identify the precise duty and article, including whether testing, certification, assessment, security review, recognition, licence, report, cooperation, or import/export control was required.
  • Confirm whether a threshold uses , procurement amount, or a fixed CNY band. Do not substitute revenue, contract value, or product price for the statutory basis.
  • Separate mandatory remedies from discretionary additions. In several provisions, correction, warning, and confiscation are stated directly, while an additional fine may be imposed.
  • Check whether the actor is a state organ. For conduct listed in Regulation Articles 60-63, Article 64 substitutes correction and warning and, if the state organ refuses to correct or other serious circumstances exist, a recommendation for discipline or other action against directly responsible personnel.
  • Check later measures and other laws. Import/export violations go to commerce or customs enforcement, and criminal conduct or harm can trigger criminal or civil liability outside the administrative fine.
Section 2

Testing, certification, products, and services

The revised regulation distinguishes unauthorized activity from misconduct by an authorized body and from selling or providing a product or service that required successful testing or certification. Identify the enforcing authority as well as the fine band: cryptography authorities handle unauthorized public testing, testing-body misconduct, and electronic-government electronic certification, while market-supervision authorities act with cryptography authorities for unauthorized certification, certification-body misconduct, and covered product or service violations.

  • Unauthorized testing, unauthorized electronic-government electronic certification, or unauthorized certification activity: Article 50 provides correction or cessation, warning, and confiscation of illegal products and income. If is at least CNY 300,000, an additional fine of one to three times that income may be imposed; if there is no illegal income or it is below CNY 300,000, the additional fine may be CNY 100,000 to 300,000.
  • Testing-body misconduct: Article 51 covers acting outside the approved scope, compromised independence or integrity, false or inaccurate results, reporting failures, confidentiality failures, and other rule breaches. It uses the same CNY 300,000 threshold and fine bands; serious cases can lead to revocation of the testing qualification.
  • Certification-body misconduct: Article 52 uses the same remedies and bands for comparable certification failures, including failure to conduct effective follow-up surveillance; serious cases can lead to revocation of the certification qualification.
  • Products and services that require successful testing or certification: Article 53 provides correction or cessation, warning, and confiscation of illegal products and income. If is at least CNY 100,000, an additional fine of one to three times that income may be imposed; if there is no illegal income or it is below CNY 100,000, the additional fine may be CNY 30,000 to 100,000.
  • Testing-body procedural breaches under the 2023 measures: failure to complete specified change, training, equipment, report-signing, retention, or sample-management duties can lead to an order to correct; failure to correct on time or continued nonconformity can bring a CNY 10,000 to 100,000 fine.
  • Testing-body application misconduct: obtaining qualification by fraud, bribery, or another improper method leads to revocation and a three-year bar on reapplying. Concealing relevant facts or providing false application material leads to refusal and a one-year bar.
  • Failed capability verification or sample inspection: the testing body must rectify for at least six months and cannot conduct testing within the affected business scope during that period. It may resume only after passing the National Cryptography Administration's acceptance check. Continued failure can lead to cancellation of that scope and then cancellation of the qualification.
Section 3

CII operators, network operators, and supervision

CII penalties apply only after the infrastructure has been identified as critical information infrastructure under the relevant laws and rules. Do not apply the CII bands to every .

The 2025 CII provisions list the underlying failures in more detail, including use, planning, construction, pre-operation and recurring assessments, tested or certified products and services, reviewed cryptographic technologies, security review, and cooperation with supervision. Those provisions have applied since 1 August 2025 and expressly place already-operating CII on the annual-assessment route.

  • Required use or assessment for CII: correction and warning come first. Refusal to correct or other serious circumstances can bring a CNY 100,000 to 1 million fine for the operator and CNY 10,000 to 100,000 for the directly responsible manager.
  • CII procurement without the required security review, or after it fails review: cessation of use, an operator fine of one to ten times the procurement amount, and CNY 10,000 to 100,000 for directly responsible managers and other directly responsible personnel.
  • failure to use as required by the network security graded-protection system: correction and warning; refusal to correct or resulting network-security harm can bring CNY 10,000 to 100,000 for the operator and CNY 5,000 to 50,000 for the directly responsible manager.
  • CII reporting and governance failures under the 2025 provisions: failure to submit the annual operator report, establish the required management system, appoint the required key administrators, cryptography operators, and cryptography security auditors, or fund cryptography use and assessment leads to an order to correct. Article 22 does not state an additional fine for those listed failures.
  • Unjustified refusal to accept or cooperate with supervision, or interference or obstruction: correction and warning; refusal to correct or other serious circumstances can bring CNY 50,000 to 500,000 for the organization and CNY 10,000 to 100,000 for directly responsible personnel. Particularly serious cases can lead to suspension for rectification and, under the revised regulation, revocation of licences.
  • Under the 2025 CII provisions, particularly serious obstruction by a can lead to suspension for rectification; those provisions do not repeat the regulation's licence-revocation language.
  • State-organ exception: where a state organ commits conduct listed in Regulation Articles 60-63, Article 64 provides correction and warning rather than the organizational fine bands above. If it refuses to correct or other serious circumstances exist, the authorities recommend discipline or other action against directly responsible personnel.
Section 4

How the statutory calculations work

Use the amount named in the controlling article and keep the authority's calculation separate from internal estimates. The examples below apply only the stated arithmetic; they do not predict whether an authority will impose the discretionary additional fine, how it will determine or procurement amount, or where within a range it will set the penalty.

  • Example - Article 53 product or service violation with CNY 120,000 of authority-determined : the amount meets the CNY 100,000 threshold, so the possible additional fine is one to three times that income, or CNY 120,000 to 360,000. Correction or cessation, warning, and confiscation of illegal products and income remain separate stated remedies.
  • Example - the same Article 53 violation with CNY 80,000 of : the amount is below the CNY 100,000 threshold, so the possible additional fine is the fixed CNY 30,000 to 100,000 band, not one to three times CNY 80,000.
  • Example - a uses a covered product or service without the required security review, or after it fails review, and the authority determines a CNY 500,000 procurement amount: the statutory organizational fine is one to ten times that amount, or CNY 500,000 to 5 million, alongside cessation of use and the stated personal-fine route.
  • Do not add together alternative bands or use contract value, product price, group revenue, or total revenue unless the controlling rule and the authority's calculation make that amount the statutory basis.
Section 5

Electronic certification, trade, and other liability

An and an electronic-government electronic certification provider follow separate routes. Confirm which service is involved before applying the licence, recognition, or penalty provision.

Import and export provisions do not state a universal cryptography fine. They direct enforcement to the competent commerce authority or customs under the applicable trade rules.

  • Electronic-certification provider misuse of cryptography: revised regulation Article 54 uses correction or cessation, warning, confiscation, the CNY 300,000 illegal-income threshold and related bands, and possible revocation of the proof document in serious cases. For conduct after 1 July 2026, also check the licence and staged remedies in the Electronic Certification Service Cryptography Use Management Measures.
  • Electronic-certification licence-holder breaches under the rules effective 1 July 2026: specified failures involving changes, key services, maintenance, annual assessment, remediation, or training first lead to a time-limited correction order. If not corrected on time, warning and formal criticism follow; serious cases can bring a CNY 10,000 to 100,000 fine.
  • Electronic-government electronic-certification provider misconduct: revised regulation Article 55 uses the CNY 300,000 threshold and related bands, with possible suspension for rectification or qualification revocation in serious cases. Article 56 also creates compensation liability where the provider cannot prove it was without fault for covered losses.
  • Use of an electronic-certification service in specified government activities when it was not provided by a lawfully established electronic-government certification institution: correction and warning; refusal to correct or other serious circumstances can lead to recommended discipline or other action against directly responsible personnel.
  • Import or export violations: the competent commerce authority or customs imposes penalties under the applicable rules; neither Cryptography Law Article 38 nor revised regulation Article 58 supplies one general fine.
  • Theft of encrypted information, unlawful intrusion into a cryptography protection system, or other unlawful use of cryptography may trigger liability under the Cybersecurity Law and other laws. A criminal offence can lead to criminal liability, and harm to another person can lead to civil liability.
Section 6

Evidence to preserve during triage

Preserve the facts before changing systems, supplier records, reports, or approvals. Evidence can establish the actor, duty, timing, scope, and remediation, but keeping evidence does not itself reduce or eliminate a statutory sanction.

If a possible breach is identified, obtain advice from China-qualified counsel on the controlling text, authority, procedure, available defenses, and interaction with other laws. The penalty cannot be determined without the case facts, the authority's statutory-basis calculation, and any applicable administrative-enforcement procedure.

  • Actor and role analysis, including CII or network-operator status.
  • Product, service, system, algorithm, protocol, key-management mechanism, model, and version.
  • Testing, certification, licence, recognition, assessment, and security-review status.
  • Illegal-income calculation, procurement amount, transaction records, and affected period where relevant.
  • Import or export classification, control-list result, customs records, and licence decision.
  • Reports, change filings, training and retention records, regulator communications, remediation decisions, owners, and dates.
  • A chronology that separates discovery, containment, correction, authority contact, and resumed activity.
Primary sources

References and citations

oscca.gov.cn
Referenced sections
  • Articles 32, 38-41 support cross-reference enforcement, trade enforcement, official discipline, criminal liability, and civil liability.
Related guides

Explore more topics

China commercial cryptography compliance checklist
China commercial cryptography checklist covering classification, product and service assurance, CII duties, trade controls, and retained evidence.
China commercial cryptography testing evidence template
Record the legal route, product or system scope, testing-body qualification, report details, gaps, and reassessment triggers for China commercial cryptography assurance.
China cryptography compliance deadlines and calendar
China cryptography effective dates, CII reports, annual assessments, licence renewals, change notices, and pre-operation checks.
China cryptography import, export, and security review triage
Screen commercial cryptography imports under the 2020 list, exports under China's unified dual-use list, the consumer exclusion, system assessment, and CII review.
China Cryptography Law FAQ
Answers on China's commercial-cryptography scope, product assurance, classified protection, CII assessment, procurement review, and trade controls.
China Cryptography Law requirements
China commercial cryptography requirements by role: standards, testing, certification, CII use and assessment, trade controls, and evidence.
China Cryptography Law vs Cybersecurity Law
Compare China's Cryptography Law and current Cybersecurity Law by scope, actor, product assurance, CII duties, evidence, and enforcement.
Commercial cryptography procurement checklist
Procurement checks for commercial cryptography products and services used in China, including certificate scope, CII duties, and supplier changes.
Commercial cryptography products and testing evidence
When China commercial cryptography testing or certification is voluntary or mandatory, and what product, service, body, and scope evidence to keep.
Do imported cryptography products need special review?
Not every encrypted product imported into China needs a licence. Check the 2020 commercial-cryptography import list, the consumer-product exception, and any CII procurement review.
Does using encryption trigger China Cryptography Law duties?
Using encryption does not create one universal China approval duty. Check classified protection, product, service, CII, procurement, and trade triggers.
How does cryptography compliance overlap with China cybersecurity law?
See how China's cryptography rules connect with classified protection, product assurance, CII assessment, and cybersecurity review without merging the regimes.
What is commercial cryptography in China?
Commercial cryptography protects information that is not a state secret. Learn how China defines the category and which separate facts trigger product, CII, or trade controls.
When is commercial cryptography testing or certification needed?
Commercial-cryptography assurance is often voluntary, but specified products and services require it. Covered CII also needs application assessment and qualified cryptography.