China Cryptography Law Cryptography Law requirements
China commercial cryptography requirements by role: standards, testing, certification, CII use and assessment, trade controls, and evidence.
Identify the actor and trigger before assigning controls. The rules differ for commercial cryptography operators, product and service providers, testing and certification bodies, CII operators, importers and exporters, and electronic certification providers.
China does not impose one approval on every use of encryption. This guide maps the main duties to the actor, product, service, system, or shipment that triggers them.
1
Section 1
What China Cryptography Law requires in practice
The Cryptography Law has applied since 1 January 2020. Article 8 allows citizens, legal persons, and other organizations to use lawfully to protect network and information security, while Articles 24-31 attach duties to particular commercial cryptography activities and actors. This page does not cover core or ordinary cryptography used to protect state-secret information.
The revised Administration Regulation has applied since 1 July 2023 to commercial cryptography research, production, sale, service, testing, certification, import, export, and application activities in China. The application-assessment measures have applied since 1 November 2023. The CII provisions effective 1 August 2025 apply to infrastructure identified as CII under the Cybersecurity Law, the CII Security Protection Regulation, and related rules.
activities must comply with applicable laws, administrative regulations, mandatory national standards, and the technical requirements in the operator's self-declared public standards. Recommended national and industry standards are encouraged, not converted into mandatory rules by that encouragement alone.
are encouraged voluntarily in general. A body that issues commercial cryptography product-test or application-assessment data or results with evidentiary effect must hold the required testing qualification; a certification body must hold the required certification qualification and work within its approved scope.
A product legally included in the catalogue of network critical equipment and network security-specific products must pass by qualified bodies before sale or provision. Both conditions must be documented. The current catalogue includes threshold-based routers, switches, rack servers, and PLC equipment plus categories such as firewalls, VPN products, public-key infrastructure, file-encryption products, and identity-authentication products. A commercial cryptography service using catalogue equipment or products must also be certified.
For CII subject to the national requirement to use , the 's main responsible person has overall responsibility for commercial cryptography use. The operator must establish governance, fund the work, and appoint qualified key-management and cryptography-operation personnel plus a capable cryptography security auditor. It must use tested and certified products and services and reviewed cryptographic technologies, assess the application plan, reassess a construction-stage plan change, pass assessment before operation, assess at least annually after operation, report the previous year's use and assessment work to its protection work department by 31 January, and complete cybersecurity review when procurement affects or may affect national security. CII already under construction on 1 August 2025 follows the construction and pre-operation route; CII already operating follows the annual route.
on the published import-license or export-control list requires the applicable license. The licensing route also covers transit, transshipment, through shipment, re-export, and specified movements involving customs special supervision areas or bonded sites. An ordinary application is decided within 45 working days after acceptance, but an export with major national-security, public-interest, or foreign-policy effects can be referred to the State Council without that time limit. Commercial cryptography used in is excluded from this import-license and export-control system, but the item and shipment still need a documented list and exception analysis.
Since 1 July 2026, a provider using for in China must hold the State Cryptography Administration license required by the current measures. The license is valid for five years; specified changes require a filing within 30 days, renewal must be requested at least 60 days before expiry, compliance assessment is required at least annually, and relevant professional staff need at least 20 hours of security and skills training each year. Electronic-government electronic certification services remain subject to a separate regime.
Assign a separate conclusion for each route rather than using one 'Cryptography Law compliant' checkbox. The same product can be outside the mandatory network-product catalogue route yet still require CII controls or an import or export license because the triggers differ.
The owner mapping and evidence workflow below are Sorena's operational synthesis. The cited rules establish the duties but do not prescribe this exact internal process.
Map each role: operator, product seller or provider, service provider, , importer or exporter, testing body, certification body, or electronic certification provider.
Assign the product seller or provider the Article 26 catalogue match and pre-sale assurance evidence; assign the service provider the service-certification check when its service uses a catalogue product.
Assign the network or system operator the application plan, pre-operation decision, annual assessment, remediation, six-year self-assessment record retention, and filing within 30 days after an assessment report is formed.
Assign the testing body its qualification, approved scope, authorized-signatory and seal controls, original records and reports retained for at least six years, and annual report due through the provincial authority by 15 January.
Record the applicable laws, regulations, mandatory standards, and self-declared public standards for each activity.
Classify assurance as voluntary or mandatory, identify the correct catalogue or rule, verify the body's qualification, and match the evidence to the actual item and scope.
For each whose infrastructure is required to use , record identification status, accountable main person, qualified role evidence and background checks, funding, tested and certified products and services, reviewed technologies, application plan, construction-stage changes, pre-operation and annual assessments, the applicable 1 August 2025 transition branch, the 31 January annual report, remediation, and procurement review.
For trade, record the exact list entry, item match, transaction type, destination, end user, end use, mass-market consumer-product analysis, application date, 45-working-day clock where it applies, customs evidence, and license outcome.
For , retain the five-year license, system and key-service evidence, change and renewal filings, annual compliance assessment and remediation, and annual training records.
Reopen the relevant conclusion after a product or cryptographic-function change, supplier or certificate change, catalogue or standards change, CII identification, construction-stage application-plan change, failed assessment, major cryptography incident or hazard, shipment or end-use change, or electronic-certification system change.
Retain separate approvals and reassessment triggers for each role and route.
Keep enough evidence to reproduce each conclusion: actor, exact item and version, cryptographic function, applicable article, catalogue or list entry and threshold, accountable operator, test or certificate scope, assessment, filing or license, reviewer, date, and unresolved question.
For a self-performed , retain original records and reports for at least six years. File the assessment report and related work information within 30 days after the report is formed when the assessment measures apply.
Cryptography inventory and classification memo.
Role map and analysis of the applicable law, standard, catalogue, and list.
Supplier declaration, testing or certification body qualification, report, certificate, scope, and status.
CII application plan, product or service and technology evidence, assessment records, report, filing, remediation, and cybersecurity review conclusion.
Import or export screening, transaction type, end-user and end-use documents, mass-market consumer-product analysis, application and customs records, and license.
Dated approval, accountable owner, unresolved issues, exceptions, and change log.
The current Cybersecurity Law separately governs network-security graded protection, product and service duties, network critical equipment and network security-specific products, CII protection, and certain procurement reviews. Its 2025 amendment took effect on 1 January 2026.
Keep personal-information, data-export, app-governance, and other network-security conclusions in their own source-backed analyses. The 2025 CII cryptography provisions require protection for core data, important data, and personal information in covered CII according to the applicable data-protection and personal-information rules, but that cryptography control does not complete those separate legal analyses.
Treating recommended standards as mandatory without another rule that makes them mandatory.
Treating every certificate as legally required, or treating a voluntary certification catalogue as the mandatory network-product catalogue.
Treating product certification as completion of CII application assessment or cybersecurity review.
Applying the mass-market consumer-product trade exception without matching the actual item and shipment to the statutory wording.
The joint-authority catalogue supplies the current product categories and technical thresholds and records that it replaced the 2017 catalogue from 3 July 2023.
Articles 5, 12, and 15-20 support approved-scope, authorized-signatory, seal, six-year retention, and 15 January annual-report duties for testing bodies.
Use for qualification and supervision of commercial-cryptography product-testing and application-security-assessment bodies, including report, data, sample, and information-reporting rules.
Articles 2-3 and 10-17 support the license, five-year term, 30-day change filing, renewal timing, annual compliance assessment, annual training hours, and operating requirements effective 1 July 2026.
Use for cryptography categories, commercial cryptography development and management, product/service controls, CII use, import/export context, penalties, and 1 January 2020 effective date.
Articles 2 and 5-15 support the CII actor boundary, accountable main person, qualified roles, funding, product, service, technology, data-protection, planning, assessment, 31 January annual reporting, and review duties.