---
title: "China cryptography penalties, fines, and liability"
canonical_url: "https://www.sorena.io/artifacts/apac/china-cryptography-law/penalties-and-fines"
source_url: "https://www.sorena.io/artifacts/apac/china-cryptography-law/penalties-and-fines"
author: "Sorena AI"
description: "China commercial cryptography penalties by actor and violation, including fine bands, corrective orders, confiscation, licence action, and liability."
published_at: "2026-07-05"
updated_at: "2026-07-24"
keywords:
  - "China cryptography penalties"
  - "Cryptography Law fines"
  - "commercial cryptography liability"
  - "CII cryptography fine"
  - "cryptography certification penalty"
  - "China Cryptography Law"
  - "Commercial cryptography"
  - "Cryptography Law"
  - "Commercial cryptography testing"
  - "China cybersecurity"
---
**[SORENA](https://www.sorena.io/)** - AI-Powered GRC Platform

[Home](https://www.sorena.io/) | [Solutions](https://www.sorena.io/solutions) | [Artifacts](https://www.sorena.io/artifacts) | [About Us](https://www.sorena.io/about-us) | [Contact](https://www.sorena.io/contact) | [Portal](https://app.sorena.io)

---

# China cryptography penalties, fines, and liability

China commercial cryptography penalties by actor and violation, including fine bands, corrective orders, confiscation, licence action, and liability.

*Cryptography* *China*

## China Cryptography Law Penalties, fines, and liability

Remedies and fine bands for commercial cryptography violations, organized by actor and conduct.

There is no single maximum fine for every cryptography violation. The applicable rule may require correction, cessation, warning, confiscation, a fine based on illegal income or a fixed amount, licence action, personal fines, civil damages, discipline, or criminal liability.

Match the actor, commercial cryptography conduct, and controlling instrument before quoting a fine. Legal, security, procurement, product, and compliance teams should also distinguish mandatory remedies from discretionary fines and check whether a state-organ exception or another law changes the result.

## Definitions

### Commercial cryptography

Under the PRC Cryptography Law, commercial cryptography is cryptography used to protect information that is not a state secret. It can include technologies, products, and services that use specified transformations to encrypt information or provide security authentication. Core and ordinary cryptography are separate categories used to protect state-secret information.

**Why it matters here:** The liabilities covered here concern commercial cryptography conduct. Failures involving core or ordinary cryptography follow separate provisions, while theft, unlawful intrusion, criminal conduct, and harm to another person can bring liability under other laws.

Sources:

- [PRC Cryptography Law, Articles 2, 6-8, and 32-41](https://www.oscca.gov.cn/sca/xxgk/2023-06/04/content_1057225.shtml?ref=sorena.io)

### Critical information infrastructure operator

**Term:** CII operator

A CII operator operates infrastructure identified as critical information infrastructure under China's Cybersecurity Law, the Critical Information Infrastructure Security Protection Regulation, and related rules. The status depends on legal identification under that framework; it does not apply automatically to every network operator or every organization running an important system.

**Why it matters here:** CII status determines whether the operator-specific commercial cryptography duties and penalty bands apply, including CNY 100,000 to 1 million for serious use or assessment failures and a procurement-based fine for using a product or service without a required security review or after a failed review.

Sources:

- [CII Commercial Cryptography Use Management Provisions, Articles 2 and 19-20](https://www.oscca.gov.cn/sca/xxgk/2025-06/27/content_1061270.shtml?ref=sorena.io)
- [Commercial Cryptography Administration Regulation, Articles 38-40 and 60-61](https://www.mee.gov.cn/zcwj/gwywj/202305/t20230529_1031579.shtml?ref=sorena.io)

### Network operator

The PRC Cybersecurity Law defines a network operator as a network owner, network manager, or network service provider. For commercial cryptography, this broader group is subject to the cryptography duties set under the network security graded-protection system; legally identified CII operators have additional duties.

**Why it matters here:** Do not use the CII fine bands merely because an organization operates a network. Regulation Article 62 instead applies to a network operator that fails to use commercial cryptography as required by the network security graded-protection system.

Sources:

- [PRC Cybersecurity Law, Article 78](https://www.cac.gov.cn/2025-12/29/c_1768735112911946.htm?ref=sorena.io)
- [Commercial Cryptography Administration Regulation, Articles 41 and 62](https://www.mee.gov.cn/zcwj/gwywj/202305/t20230529_1031579.shtml?ref=sorena.io)

### Illegal income as the statutory fine basis

**Term:** illegal income

Several commercial cryptography penalty provisions use illegal income as the amount that determines which additional fine band may apply. The provisions distinguish illegal income of at least CNY 300,000 or CNY 100,000, depending on the violation, from cases with no illegal income or an amount below the relevant threshold. The cited provisions do not treat total revenue, contract value, procurement amount, or product price as interchangeable with illegal income.

**Why it matters here:** A penalty estimate must use the threshold and multiplier in the controlling article and an authority-supported calculation for the specific case. Procurement amount is a different statutory basis used for certain CII security-review violations.

Sources:

- [Commercial Cryptography Administration Regulation, Articles 50-55 and 61](https://www.mee.gov.cn/zcwj/gwywj/202305/t20230529_1031579.shtml?ref=sorena.io)

### Electronic certification provider using commercial cryptography

**Term:** electronic certification provider

An electronic certification provider uses commercial cryptography to provide electronic certification services in China. Since 1 July 2026, the provider must hold an Electronic Certification Service Cryptography Use Licence and comply with the licence, change, key-service, maintenance, annual assessment, remediation, and training rules. Electronic-government electronic certification is a separate qualified-provider route.

**Why it matters here:** The actor classification determines whether the general electronic-certification penalty in Regulation Article 54, the licence-holder remedies in the 2026 measures, or the separate electronic-government certification provisions apply.

Sources:

- [Electronic Certification Service Cryptography Use Management Measures, Articles 2-3 and 21](https://www.oscca.gov.cn/sca/xxgk/2026-06/03/content_1061341.shtml?ref=sorena.io)
- [Commercial Cryptography Administration Regulation, Articles 22-30 and 54-57](https://www.mee.gov.cn/zcwj/gwywj/202305/t20230529_1031579.shtml?ref=sorena.io)

### Qualified commercial-cryptography testing or certification body

**Term:** testing or certification body

A commercial-cryptography testing body that issues proof-bearing product-test or application-assessment results to the public must be recognized by the National Cryptography Administration and work within its approved testing scope. A commercial-cryptography certification body must hold certification-body approval, have the technical capacity for its approved scope, and conduct follow-up surveillance of certified products, services, or management systems.

**Why it matters here:** Actor status changes the penalty route. Unauthorized testing or certification falls under Regulation Article 50; misconduct by an authorized testing body or certification body falls under Articles 51 or 52; and sale or provision of a covered product or service without the required successful assurance falls under Article 53.

Sources:

- [Commercial Cryptography Administration Regulation, Articles 13-21 and 50-53](https://www.mee.gov.cn/zcwj/gwywj/202305/t20230529_1031579.shtml?ref=sorena.io)

## How to identify the applicable penalty

First classify the information and activity. The Cryptography Law separates core and ordinary cryptography, used to protect state-secret information, from commercial cryptography, used to protect information that is not a state secret. The penalties below concern commercial cryptography; Articles 33 and 34 contain separate provisions for failures involving core and ordinary cryptography.

Then identify the actor and conduct. The Cryptography Law has applied since 1 January 2020 and sets the primary duties and liabilities. The revised Commercial Cryptography Administration Regulation has applied since 1 July 2023 and adds current rules for unauthorized activity, testing and certification bodies, products and services, electronic certification, CII operators, network operators, and obstruction of supervision. Later measures add more specific duties for testing bodies, CII operators, and electronic-certification providers.

- Record whether the actor is a testing or certification body, seller or service provider, electronic-certification provider, CII operator, network operator, importer or exporter, public official, or another organization or person.
- Identify the precise duty and article, including whether testing, certification, assessment, security review, recognition, licence, report, cooperation, or import/export control was required.
- Confirm whether a threshold uses illegal income, procurement amount, or a fixed CNY band. Do not substitute revenue, contract value, or product price for the statutory basis.
- Separate mandatory remedies from discretionary additions. In several provisions, correction, warning, and confiscation are stated directly, while an additional fine may be imposed.
- Check whether the actor is a state organ. For conduct listed in Regulation Articles 60-63, Article 64 substitutes correction and warning and, if the state organ refuses to correct or other serious circumstances exist, a recommendation for discipline or other action against directly responsible personnel.
- Check later measures and other laws. Import/export violations go to commerce or customs enforcement, and criminal conduct or harm can trigger criminal or civil liability outside the administrative fine.

Sources for this answer:

- [PRC Cryptography Law](https://www.oscca.gov.cn/sca/xxgk/2023-06/04/content_1057225.shtml?ref=sorena.io) - Articles 2, 6, 8, and 32-41 establish classification and the law's actor- and conduct-specific liabilities.
- [Commercial Cryptography Administration Regulation, State Council Order No. 760](https://www.mee.gov.cn/zcwj/gwywj/202305/t20230529_1031579.shtml?ref=sorena.io) - Articles 50-66 provide the current regulation-level penalty structure.

## Testing, certification, products, and services

The revised regulation distinguishes unauthorized activity from misconduct by an authorized body and from selling or providing a product or service that required successful testing or certification. Identify the enforcing authority as well as the fine band: cryptography authorities handle unauthorized public testing, testing-body misconduct, and electronic-government electronic certification, while market-supervision authorities act with cryptography authorities for unauthorized certification, certification-body misconduct, and covered product or service violations.

- Unauthorized testing, unauthorized electronic-government electronic certification, or unauthorized certification activity: Article 50 provides correction or cessation, warning, and confiscation of illegal products and income. If illegal income is at least CNY 300,000, an additional fine of one to three times that income may be imposed; if there is no illegal income or it is below CNY 300,000, the additional fine may be CNY 100,000 to 300,000.
- Testing-body misconduct: Article 51 covers acting outside the approved scope, compromised independence or integrity, false or inaccurate results, reporting failures, confidentiality failures, and other rule breaches. It uses the same CNY 300,000 threshold and fine bands; serious cases can lead to revocation of the testing qualification.
- Certification-body misconduct: Article 52 uses the same remedies and bands for comparable certification failures, including failure to conduct effective follow-up surveillance; serious cases can lead to revocation of the certification qualification.
- Products and services that require successful testing or certification: Article 53 provides correction or cessation, warning, and confiscation of illegal products and income. If illegal income is at least CNY 100,000, an additional fine of one to three times that income may be imposed; if there is no illegal income or it is below CNY 100,000, the additional fine may be CNY 30,000 to 100,000.
- Testing-body procedural breaches under the 2023 measures: failure to complete specified change, training, equipment, report-signing, retention, or sample-management duties can lead to an order to correct; failure to correct on time or continued nonconformity can bring a CNY 10,000 to 100,000 fine.
- Testing-body application misconduct: obtaining qualification by fraud, bribery, or another improper method leads to revocation and a three-year bar on reapplying. Concealing relevant facts or providing false application material leads to refusal and a one-year bar.
- Failed capability verification or sample inspection: the testing body must rectify for at least six months and cannot conduct testing within the affected business scope during that period. It may resume only after passing the National Cryptography Administration's acceptance check. Continued failure can lead to cancellation of that scope and then cancellation of the qualification.

Sources for this answer:

- [Commercial Cryptography Administration Regulation, State Council Order No. 760](https://www.mee.gov.cn/zcwj/gwywj/202305/t20230529_1031579.shtml?ref=sorena.io) - Articles 50-53 support the unauthorized-activity, testing-body, certification-body, and product-or-service remedies and fine bands.
- [Commercial Cryptography Testing Body Management Measures, Order No. 2](https://www.oscca.gov.cn/sca/xxgk/2023-10/07/content_1061108.shtml?ref=sorena.io) - Articles 23-26 specify capability-verification remediation, application misconduct, testing-body violations, qualification consequences, and the CNY 10,000 to 100,000 procedural-breach band.

## CII operators, network operators, and supervision

CII penalties apply only after the infrastructure has been identified as critical information infrastructure under the relevant laws and rules. Do not apply the CII bands to every network operator.

The 2025 CII provisions list the underlying failures in more detail, including use, planning, construction, pre-operation and recurring assessments, tested or certified products and services, reviewed cryptographic technologies, security review, and cooperation with supervision. Those provisions have applied since 1 August 2025 and expressly place already-operating CII on the annual-assessment route.

- Required use or assessment for CII: correction and warning come first. Refusal to correct or other serious circumstances can bring a CNY 100,000 to 1 million fine for the operator and CNY 10,000 to 100,000 for the directly responsible manager.
- CII procurement without the required security review, or after it fails review: cessation of use, an operator fine of one to ten times the procurement amount, and CNY 10,000 to 100,000 for directly responsible managers and other directly responsible personnel.
- Network operator failure to use commercial cryptography as required by the network security graded-protection system: correction and warning; refusal to correct or resulting network-security harm can bring CNY 10,000 to 100,000 for the operator and CNY 5,000 to 50,000 for the directly responsible manager.
- CII reporting and governance failures under the 2025 provisions: failure to submit the annual operator report, establish the required management system, appoint the required key administrators, cryptography operators, and cryptography security auditors, or fund cryptography use and assessment leads to an order to correct. Article 22 does not state an additional fine for those listed failures.
- Unjustified refusal to accept or cooperate with supervision, or interference or obstruction: correction and warning; refusal to correct or other serious circumstances can bring CNY 50,000 to 500,000 for the organization and CNY 10,000 to 100,000 for directly responsible personnel. Particularly serious cases can lead to suspension for rectification and, under the revised regulation, revocation of commercial cryptography licences.
- Under the 2025 CII provisions, particularly serious obstruction by a CII operator can lead to suspension for rectification; those provisions do not repeat the regulation's licence-revocation language.
- State-organ exception: where a state organ commits conduct listed in Regulation Articles 60-63, Article 64 provides correction and warning rather than the organizational fine bands above. If it refuses to correct or other serious circumstances exist, the authorities recommend discipline or other action against directly responsible personnel.

Sources for this answer:

- [Commercial Cryptography Administration Regulation, State Council Order No. 760](https://www.mee.gov.cn/zcwj/gwywj/202305/t20230529_1031579.shtml?ref=sorena.io) - Articles 60-64 establish the CII, network-operator, security-review, obstruction, and state-organ remedies and fine bands.
- [CII Commercial Cryptography Use Management Provisions, Order No. 5](https://www.oscca.gov.cn/sca/xxgk/2025-06/27/content_1061270.shtml?ref=sorena.io) - Articles 19-22 identify the specific CII failures and distinguish serious assessment or use violations, security-review failures, obstruction, and correction-only duties.

## How the statutory calculations work

Use the amount named in the controlling article and keep the authority's calculation separate from internal estimates. The examples below apply only the stated arithmetic; they do not predict whether an authority will impose the discretionary additional fine, how it will determine illegal income or procurement amount, or where within a range it will set the penalty.

- Example - Article 53 product or service violation with CNY 120,000 of authority-determined illegal income: the amount meets the CNY 100,000 threshold, so the possible additional fine is one to three times that income, or CNY 120,000 to 360,000. Correction or cessation, warning, and confiscation of illegal products and income remain separate stated remedies.
- Example - the same Article 53 violation with CNY 80,000 of illegal income: the amount is below the CNY 100,000 threshold, so the possible additional fine is the fixed CNY 30,000 to 100,000 band, not one to three times CNY 80,000.
- Example - a CII operator uses a covered product or service without the required security review, or after it fails review, and the authority determines a CNY 500,000 procurement amount: the statutory organizational fine is one to ten times that amount, or CNY 500,000 to 5 million, alongside cessation of use and the stated personal-fine route.
- Do not add together alternative bands or use contract value, product price, group revenue, or total revenue unless the controlling rule and the authority's calculation make that amount the statutory basis.

Sources for this answer:

- [Commercial Cryptography Administration Regulation, State Council Order No. 760](https://www.mee.gov.cn/zcwj/gwywj/202305/t20230529_1031579.shtml?ref=sorena.io) - Articles 50-55 and 61 supply the illegal-income thresholds, one-to-three-times multipliers, fixed bands, procurement-amount multiplier, and accompanying remedies used in the examples.

## Electronic certification, trade, and other liability

An electronic certification provider and an electronic-government electronic certification provider follow separate routes. Confirm which service is involved before applying the licence, recognition, or penalty provision.

Import and export provisions do not state a universal cryptography fine. They direct enforcement to the competent commerce authority or customs under the applicable trade rules.

- Electronic-certification provider misuse of cryptography: revised regulation Article 54 uses correction or cessation, warning, confiscation, the CNY 300,000 illegal-income threshold and related bands, and possible revocation of the proof document in serious cases. For conduct after 1 July 2026, also check the licence and staged remedies in the Electronic Certification Service Cryptography Use Management Measures.
- Electronic-certification licence-holder breaches under the rules effective 1 July 2026: specified failures involving changes, key services, maintenance, annual assessment, remediation, or training first lead to a time-limited correction order. If not corrected on time, warning and formal criticism follow; serious cases can bring a CNY 10,000 to 100,000 fine.
- Electronic-government electronic-certification provider misconduct: revised regulation Article 55 uses the CNY 300,000 threshold and related bands, with possible suspension for rectification or qualification revocation in serious cases. Article 56 also creates compensation liability where the provider cannot prove it was without fault for covered losses.
- Use of an electronic-certification service in specified government activities when it was not provided by a lawfully established electronic-government certification institution: correction and warning; refusal to correct or other serious circumstances can lead to recommended discipline or other action against directly responsible personnel.
- Import or export violations: the competent commerce authority or customs imposes penalties under the applicable rules; neither Cryptography Law Article 38 nor revised regulation Article 58 supplies one general fine.
- Theft of encrypted information, unlawful intrusion into a cryptography protection system, or other unlawful use of cryptography may trigger liability under the Cybersecurity Law and other laws. A criminal offence can lead to criminal liability, and harm to another person can lead to civil liability.

Sources for this answer:

- [PRC Cryptography Law](https://www.oscca.gov.cn/sca/xxgk/2023-06/04/content_1057225.shtml?ref=sorena.io) - Articles 32, 38-41 support cross-reference enforcement, trade enforcement, official discipline, criminal liability, and civil liability.
- [Commercial Cryptography Administration Regulation, State Council Order No. 760](https://www.mee.gov.cn/zcwj/gwywj/202305/t20230529_1031579.shtml?ref=sorena.io) - Articles 54-59 and 65-66 support electronic-certification, electronic-government certification, trade, other-law, official, criminal, and civil consequences.
- [Electronic Certification Service Cryptography Use Management Measures, Order No. 6](https://www.oscca.gov.cn/sca/xxgk/2026-06/03/content_1061341.shtml?ref=sorena.io) - Article 21 establishes the staged remedies and CNY 10,000 to 100,000 fine for specified licence-holder breaches.

## Evidence to preserve during triage

Preserve the facts before changing systems, supplier records, reports, or approvals. Evidence can establish the actor, duty, timing, scope, and remediation, but keeping evidence does not itself reduce or eliminate a statutory sanction.

If a possible breach is identified, obtain advice from China-qualified counsel on the controlling text, authority, procedure, available defenses, and interaction with other laws. The penalty cannot be determined without the case facts, the authority's statutory-basis calculation, and any applicable administrative-enforcement procedure.

- Actor and role analysis, including CII or network-operator status.
- Product, service, system, algorithm, protocol, key-management mechanism, model, and version.
- Testing, certification, licence, recognition, assessment, and security-review status.
- Illegal-income calculation, procurement amount, transaction records, and affected period where relevant.
- Import or export classification, control-list result, customs records, and licence decision.
- Reports, change filings, training and retention records, regulator communications, remediation decisions, owners, and dates.
- A chronology that separates discovery, containment, correction, authority contact, and resumed activity.

Sources for this answer:

- [Commercial Cryptography Administration Regulation, State Council Order No. 760](https://www.mee.gov.cn/zcwj/gwywj/202305/t20230529_1031579.shtml?ref=sorena.io) - Articles 45-49 describe supervisory powers and cooperation, while Articles 50-66 show which actor, conduct, income, procurement, and remediation facts affect the penalty route.

*Operationalize the requirement*

*Placement: Before primary sources*

## Prepare the commercial cryptography evidence file

Sorena AI helps connect the actor, conduct, controlling article, evidence, remediation, and owner for a China cryptography issue.

- [Map official sources to evidence](/solutions/research-copilot.md): Research Copilot connects the official citation, decision, owner, retained evidence, and change history.
- [Review the China route](/contact.md): Check the China Cryptography Law scope decision and unresolved launch questions with Sorena.

## Primary sources

- [PRC Cryptography Law](https://www.oscca.gov.cn/sca/xxgk/2023-06/04/content_1057225.shtml?ref=sorena.io) - Primary law for cryptography categories, commercial cryptography duties, and Articles 32-41 liability.
- [Commercial Cryptography Administration Regulation, State Council Order No. 760](https://www.mee.gov.cn/zcwj/gwywj/202305/t20230529_1031579.shtml?ref=sorena.io) - Current regulation-level penalty provisions in Articles 50-66.
- [Commercial Cryptography Testing Body Management Measures, Order No. 2](https://www.oscca.gov.cn/sca/xxgk/2023-10/07/content_1061108.shtml?ref=sorena.io) - Current testing-body violations and remedies in Articles 24-26.
- [CII Commercial Cryptography Use Management Provisions, Order No. 5](https://www.oscca.gov.cn/sca/xxgk/2025-06/27/content_1061270.shtml?ref=sorena.io) - Current CII-specific violations and remedies in Articles 19-22.
- [Electronic Certification Service Cryptography Use Management Measures, Order No. 6](https://www.oscca.gov.cn/sca/xxgk/2026-06/03/content_1061341.shtml?ref=sorena.io) - Current electronic-certification licence-holder violations and remedies in Article 21.

## Related Topic Guides

- [China commercial cryptography compliance checklist](/artifacts/apac/china-cryptography-law/checklist.md): China commercial cryptography checklist covering classification, product and service assurance, CII duties, trade controls, and retained evidence.
- [China commercial cryptography testing evidence template](/artifacts/apac/china-cryptography-law/commercial-cryptography-testing-evidence-template.md): Record the legal route, product or system scope, testing-body qualification, report details, gaps, and reassessment triggers for China commercial cryptography assurance.
- [China cryptography compliance deadlines and calendar](/artifacts/apac/china-cryptography-law/deadlines-and-compliance-calendar.md): China cryptography effective dates, CII reports, annual assessments, licence renewals, change notices, and pre-operation checks.
- [China cryptography import, export, and security review triage](/artifacts/apac/china-cryptography-law/import-export-and-security-assessment.md): Screen commercial cryptography imports under the 2020 list, exports under China's unified dual-use list, the consumer exclusion, system assessment, and CII review.
- [China Cryptography Law FAQ](/artifacts/apac/china-cryptography-law/faq.md): Answers on China's commercial-cryptography scope, product assurance, classified protection, CII assessment, procurement review, and trade controls.
- [China Cryptography Law requirements](/artifacts/apac/china-cryptography-law/requirements.md): China commercial cryptography requirements by role: standards, testing, certification, CII use and assessment, trade controls, and evidence.
- [China Cryptography Law vs Cybersecurity Law](/artifacts/apac/china-cryptography-law/china-cryptography-law-vs-cybersecurity-law.md): Compare China's Cryptography Law and current Cybersecurity Law by scope, actor, product assurance, CII duties, evidence, and enforcement.
- [Commercial cryptography procurement checklist](/artifacts/apac/china-cryptography-law/commercial-cryptography-procurement-checklist.md): Procurement checks for commercial cryptography products and services used in China, including certificate scope, CII duties, and supplier changes.
- [Commercial cryptography products and testing evidence](/artifacts/apac/china-cryptography-law/commercial-cryptography-products-and-testing.md): When China commercial cryptography testing or certification is voluntary or mandatory, and what product, service, body, and scope evidence to keep.
- [Do imported cryptography products need special review?](/artifacts/apac/china-cryptography-law/faq/do-imported-cryptography-products-need-special-review.md): Not every encrypted product imported into China needs a licence. Check the 2020 commercial-cryptography import list, the consumer-product exception, and any CII procurement review.
- [Does using encryption trigger China Cryptography Law duties?](/artifacts/apac/china-cryptography-law/faq/does-using-encryption-trigger-china-cryptography-law.md): Using encryption does not create one universal China approval duty. Check classified protection, product, service, CII, procurement, and trade triggers.
- [How does cryptography compliance overlap with China cybersecurity law?](/artifacts/apac/china-cryptography-law/faq/how-does-cryptography-compliance-overlap-with-cybersecurity-law.md): See how China's cryptography rules connect with classified protection, product assurance, CII assessment, and cybersecurity review without merging the regimes.
- [What is commercial cryptography in China?](/artifacts/apac/china-cryptography-law/faq/what-is-commercial-cryptography-in-china.md): Commercial cryptography protects information that is not a state secret. Learn how China defines the category and which separate facts trigger product, CII, or trade controls.
- [When is commercial cryptography testing or certification needed?](/artifacts/apac/china-cryptography-law/faq/when-is-commercial-cryptography-testing-or-certification-needed.md): Commercial-cryptography assurance is often voluntary, but specified products and services require it. Covered CII also needs application assessment and qualified cryptography.


---

[Privacy Policy](https://www.sorena.io/privacy.md) | [Terms of Use](https://www.sorena.io/terms-of-use.md) | [DMCA](https://www.sorena.io/dmca.md) | [About Us](https://www.sorena.io/about-us.md)

(c) 2026 Sorena AB (559573-7338). All rights reserved.

Source: https://www.sorena.io/artifacts/apac/china-cryptography-law/penalties-and-fines.md
