---
title: "China Cryptography Law requirements"
canonical_url: "https://www.sorena.io/artifacts/apac/china-cryptography-law/requirements"
source_url: "https://www.sorena.io/artifacts/apac/china-cryptography-law/requirements"
author: "Sorena AI"
description: "China commercial cryptography requirements by role: standards, testing, certification, CII use and assessment, trade controls, and evidence."
published_at: "2026-07-05"
updated_at: "2026-07-24"
keywords:
  - "China Cryptography Law"
  - "Commercial cryptography"
  - "Cryptography Law"
  - "Commercial cryptography testing"
  - "China cybersecurity"
---
**[SORENA](https://www.sorena.io/)** - AI-Powered GRC Platform

[Home](https://www.sorena.io/) | [Solutions](https://www.sorena.io/solutions) | [Artifacts](https://www.sorena.io/artifacts) | [About Us](https://www.sorena.io/about-us) | [Contact](https://www.sorena.io/contact) | [Portal](https://app.sorena.io)

---

# China Cryptography Law requirements

China commercial cryptography requirements by role: standards, testing, certification, CII use and assessment, trade controls, and evidence.

*Cryptography* *China*

## China Cryptography Law Cryptography Law requirements

Identify the actor and trigger before assigning controls. The rules differ for commercial cryptography operators, product and service providers, testing and certification bodies, CII operators, importers and exporters, and electronic certification providers.

China does not impose one approval on every use of encryption. This guide maps the main commercial cryptography duties to the actor, product, service, system, or shipment that triggers them.

## Definitions

### Commercial cryptography

Commercial cryptography means technology, products, and services that use specific transformations to encrypt or authenticate information that is not a state secret. It is distinct from core and ordinary cryptography, which protect state-secret information. The category includes activities such as research, production, sale, service, testing, certification, import, export, and application, but each activity has its own trigger and responsible actor.

**Why it matters here:** This requirements map applies only after the technology, product, or service is correctly classified. Commercial cryptography status does not by itself make testing, certification, assessment, or a trade license mandatory.

Sources:

- [PRC Cryptography Law, Articles 2 and 6-8](https://www.oscca.gov.cn/sca/xxgk/2023-06/04/content_1057225.shtml?ref=sorena.io)
- [Commercial Cryptography Administration Regulation, Article 2](https://www.mee.gov.cn/zcwj/gwywj/202305/t20230529_1031579.shtml?ref=sorena.io)

### Commercial cryptography testing and certification

**Term:** testing and certification

Commercial cryptography testing produces data or results about a product or a network and information system; certification produces a certification conclusion for a product, service, or management system. Both are generally voluntary under the national commercial cryptography system. Qualified bodies must act within their approved scope. Mandatory assurance applies only where a separate rule creates it, including specified catalogue products, related services, and qualifying CII uses.

**Why it matters here:** The responsible team must record whether the route is voluntary or mandatory, verify the body's qualification, and match the report or certificate to the actual item, version, scope, and current status.

Sources:

- [Commercial Cryptography Administration Regulation, Articles 12-21](https://www.mee.gov.cn/zcwj/gwywj/202305/t20230529_1031579.shtml?ref=sorena.io)
- [Commercial Cryptography Testing Institution Measures interpretation](https://www.oscca.gov.cn/sca/xxgk/2023-10/07/content_1061110.shtml?ref=sorena.io)

### Critical information infrastructure operator

**Term:** CII operator

A CII operator is the organization responsible for operating infrastructure identified as critical information infrastructure under the Cybersecurity Law, the Critical Information Infrastructure Security Protection Regulation, and related identification rules. CII includes infrastructure in important industries and fields where destruction, loss of function, or data leakage could seriously harm national security, the national economy and people's livelihoods, or the public interest.

**Why it matters here:** For CII subject to the national requirement to use commercial cryptography, the operator has dedicated governance, staffing, funding, certified-product and service, reviewed-technology, planning, assessment, annual reporting, and procurement-review duties.

Sources:

- [PRC Cybersecurity Law, Article 33](https://www.cac.gov.cn/2025-12/29/c_1768735112911946.htm?ref=sorena.io)
- [Provisions on the Use and Administration of Commercial Cryptography in Critical Information Infrastructure, Articles 2 and 5-15](https://www.oscca.gov.cn/sca/xxgk/2025-06/27/content_1061270.shtml?ref=sorena.io)

### Electronic certification services using commercial cryptography

**Term:** electronic certification services

Electronic certification services use cryptographic mechanisms to verify electronic signatures and the identity or status associated with them. Since 1 July 2026, a provider using commercial cryptography for these services in China must hold an Electronic Certification Service Cryptography Use License from the State Cryptography Administration. Electronic-government electronic certification services remain subject to their separate qualification and operating rules.

**Why it matters here:** A provider must distinguish the general electronic-certification license from the separate electronic-government route, then retain the correct license, system evidence, annual compliance assessment, training, and change records for its service.

Sources:

- [Measures for the Administration of Cryptography Use in Electronic Certification Services, Articles 2-3 and 10-17](https://www.oscca.gov.cn/sca/xxgk/2026-06/03/content_1061341.shtml?ref=sorena.io)
- [Commercial Cryptography Administration Regulation, Articles 22-30](https://www.mee.gov.cn/zcwj/gwywj/202305/t20230529_1031579.shtml?ref=sorena.io)

### Commercial cryptography application security assessment

This assessment tests whether a network or information system uses commercial cryptography technologies, products, and services compliantly, correctly, and effectively. It applies when a law, administrative regulation, or national provision requires that system to use commercial cryptography protection. The operator must assess the application plan, assess the completed system before operation, and assess the operating system at least annually.

**Why it matters here:** The operator must keep this system-level assessment separate from product testing, service certification, and procurement review. A product certificate cannot replace the plan assessment, pre-operation result, annual assessment, remediation, or filing.

Sources:

- [Commercial Cryptography Application Security Assessment Measures, Articles 2 and 6-14](https://www.oscca.gov.cn/sca/xxgk/2023-10/07/content_1061109.shtml?ref=sorena.io)

### Commercial cryptography used in mass-market consumer products

**Term:** mass-market consumer products

The Cryptography Law excludes commercial cryptography used in mass-market consumer products from its import-licensing and export-control system. The National Cryptography Administration describes the category as products or technologies available to the public without restriction through ordinary retail channels, intended for personal use, and whose cryptographic function cannot easily be changed. That description is official guidance, while the statutory exclusion remains the controlling rule.

**Why it matters here:** The importer or exporter must document the specific model, ordinary retail availability, intended users and use, distribution restrictions, and configurability before relying on the exclusion. The exclusion does not decide product assurance, system assessment, CII, or electronic-certification duties.

Sources:

- [PRC Cryptography Law, Article 28](https://www.oscca.gov.cn/sca/xxgk/2023-06/04/content_1057225.shtml?ref=sorena.io)
- [National Cryptography Administration policy answer on mass-market consumer products](https://www.oscca.gov.cn/sca/xxgk/2020-04/02/content_1060694.shtml?ref=sorena.io)

## What China Cryptography Law requires in practice

The Cryptography Law has applied since 1 January 2020. Article 8 allows citizens, legal persons, and other organizations to use commercial cryptography lawfully to protect network and information security, while Articles 24-31 attach duties to particular commercial cryptography activities and actors. This page does not cover core or ordinary cryptography used to protect state-secret information.

The revised Commercial Cryptography Administration Regulation has applied since 1 July 2023 to commercial cryptography research, production, sale, service, testing, certification, import, export, and application activities in China. The application-assessment measures have applied since 1 November 2023. The CII provisions effective 1 August 2025 apply to infrastructure identified as CII under the Cybersecurity Law, the CII Security Protection Regulation, and related rules.

- Commercial cryptography activities must comply with applicable laws, administrative regulations, mandatory national standards, and the technical requirements in the operator's self-declared public standards. Recommended national and industry standards are encouraged, not converted into mandatory rules by that encouragement alone.
- Commercial cryptography testing and certification are encouraged voluntarily in general. A body that issues commercial cryptography product-test or application-assessment data or results with evidentiary effect must hold the required testing qualification; a certification body must hold the required certification qualification and work within its approved scope.
- A commercial cryptography product legally included in the catalogue of network critical equipment and network security-specific products must pass testing and certification by qualified bodies before sale or provision. Both conditions must be documented. The current catalogue includes threshold-based routers, switches, rack servers, and PLC equipment plus categories such as firewalls, VPN products, public-key infrastructure, file-encryption products, and identity-authentication products. A commercial cryptography service using catalogue equipment or products must also be certified.
- For CII subject to the national requirement to use commercial cryptography, the CII operator's main responsible person has overall responsibility for commercial cryptography use. The operator must establish governance, fund the work, and appoint qualified key-management and cryptography-operation personnel plus a capable cryptography security auditor. It must use tested and certified products and services and reviewed cryptographic technologies, assess the application plan, reassess a construction-stage plan change, pass assessment before operation, assess at least annually after operation, report the previous year's use and assessment work to its protection work department by 31 January, and complete cybersecurity review when procurement affects or may affect national security. CII already under construction on 1 August 2025 follows the construction and pre-operation route; CII already operating follows the annual route.
- Commercial cryptography on the published import-license or export-control list requires the applicable license. The licensing route also covers transit, transshipment, through shipment, re-export, and specified movements involving customs special supervision areas or bonded sites. An ordinary application is decided within 45 working days after acceptance, but an export with major national-security, public-interest, or foreign-policy effects can be referred to the State Council without that time limit. Commercial cryptography used in mass-market consumer products is excluded from this import-license and export-control system, but the item and shipment still need a documented list and exception analysis.
- Since 1 July 2026, a provider using commercial cryptography for electronic certification services in China must hold the State Cryptography Administration license required by the current measures. The license is valid for five years; specified changes require a filing within 30 days, renewal must be requested at least 60 days before expiry, compliance assessment is required at least annually, and relevant professional staff need at least 20 hours of security and skills training each year. Electronic-government electronic certification services remain subject to a separate regime.

Sources for this answer:

- [PRC Cryptography Law](https://www.oscca.gov.cn/sca/xxgk/2023-06/04/content_1057225.shtml?ref=sorena.io) - Use for cryptography categories, commercial cryptography development and management, product/service controls, CII use, import/export context, penalties, and 1 January 2020 effective date.
- [Commercial cryptography testing institution measures interpretation](https://www.oscca.gov.cn/sca/xxgk/2023-10/07/content_1061110.shtml?ref=sorena.io) - Use for qualification and supervision of commercial-cryptography product-testing and application-security-assessment bodies, including report, data, sample, and information-reporting rules.
- [Commercial Cryptography Administration Regulation (State Council Order No. 760)](https://www.mee.gov.cn/zcwj/gwywj/202305/t20230529_1031579.shtml?ref=sorena.io) - Articles 11-34 and 38-42 support the detailed standards, testing, certification, electronic certification, import/export, and CII requirements.
- [Provisions on the Use and Administration of Commercial Cryptography in Critical Information Infrastructure](https://www.oscca.gov.cn/sca/xxgk/2025-06/27/content_1061270.shtml?ref=sorena.io) - Articles 2 and 5-15 support the CII actor boundary, accountable main person, qualified roles, funding, product, service, technology, data-protection, planning, assessment, 31 January annual reporting, and review duties.
- [Measures for the Administration of Cryptography Use in Electronic Certification Services](https://www.oscca.gov.cn/sca/xxgk/2026-06/03/content_1061341.shtml?ref=sorena.io) - Articles 2-3 and 10-17 support the license, five-year term, 30-day change filing, renewal timing, annual compliance assessment, annual training hours, and operating requirements effective 1 July 2026.
- [2023 Catalogue of Critical Network Equipment and Specialised Cybersecurity Products](https://www.miit.gov.cn/jgsj/waj/wjfb/art/2023/art_9080a8689c58416eaf56f88649c242d3.html?ref=sorena.io) - The joint-authority catalogue supplies the current product categories and technical thresholds and records that it replaced the 2017 catalogue from 3 July 2023.

## Practical compliance steps

Assign a separate conclusion for each route rather than using one 'Cryptography Law compliant' checkbox. The same product can be outside the mandatory network-product catalogue route yet still require CII controls or an import or export license because the triggers differ.

The owner mapping and evidence workflow below are Sorena's operational synthesis. The cited rules establish the duties but do not prescribe this exact internal process.

- Map each role: commercial cryptography operator, product seller or provider, service provider, CII operator, importer or exporter, testing body, certification body, or electronic certification provider.
- Assign the product seller or provider the Article 26 catalogue match and pre-sale assurance evidence; assign the service provider the service-certification check when its service uses a catalogue product.
- Assign the network or system operator the commercial cryptography application plan, pre-operation decision, annual assessment, remediation, six-year self-assessment record retention, and filing within 30 days after an assessment report is formed.
- Assign the testing body its qualification, approved scope, authorized-signatory and seal controls, original records and reports retained for at least six years, and annual report due through the provincial authority by 15 January.
- Record the applicable laws, regulations, mandatory standards, and self-declared public standards for each commercial cryptography activity.
- Classify assurance as voluntary or mandatory, identify the correct catalogue or rule, verify the body's qualification, and match the evidence to the actual item and scope.
- For each CII operator whose infrastructure is required to use commercial cryptography, record identification status, accountable main person, qualified role evidence and background checks, funding, tested and certified products and services, reviewed technologies, application plan, construction-stage changes, pre-operation and annual assessments, the applicable 1 August 2025 transition branch, the 31 January annual report, remediation, and procurement review.
- For trade, record the exact list entry, item match, transaction type, destination, end user, end use, mass-market consumer-product analysis, application date, 45-working-day clock where it applies, customs evidence, and license outcome.
- For electronic certification services, retain the five-year license, system and key-service evidence, change and renewal filings, annual compliance assessment and remediation, and annual training records.
- Reopen the relevant conclusion after a product or cryptographic-function change, supplier or certificate change, catalogue or standards change, CII identification, construction-stage application-plan change, failed assessment, major cryptography incident or hazard, shipment or end-use change, or electronic-certification system change.
- Retain separate approvals and reassessment triggers for each role and route.

Sources for this answer:

- [PRC Cryptography Law](https://www.oscca.gov.cn/sca/xxgk/2023-06/04/content_1057225.shtml?ref=sorena.io) - Use for cryptography categories, commercial cryptography development and management, product/service controls, CII use, import/export context, penalties, and 1 January 2020 effective date.
- [Commercial cryptography testing institution measures interpretation](https://www.oscca.gov.cn/sca/xxgk/2023-10/07/content_1061110.shtml?ref=sorena.io) - Use for qualification and supervision of commercial-cryptography product-testing and application-security-assessment bodies, including report, data, sample, and information-reporting rules.
- [Commercial Cryptography Testing Institution Measures](https://www.oscca.gov.cn/sca/xxgk/2023-10/07/content_1061108.shtml?ref=sorena.io) - Articles 5, 12, and 15-20 support approved-scope, authorized-signatory, seal, six-year retention, and 15 January annual-report duties for testing bodies.
- [Commercial Cryptography Application Security Assessment Measures](https://www.oscca.gov.cn/sca/xxgk/2023-10/07/content_1061109.shtml?ref=sorena.io) - Articles 6-15 and 21 support assessment planning, pre-operation and annual assessment, evidence, retention, filing, incident response, and the 1 November 2023 effective date.

## Evidence to keep before launch or change approval

Keep enough evidence to reproduce each conclusion: actor, exact item and version, cryptographic function, applicable article, catalogue or list entry and threshold, accountable operator, test or certificate scope, assessment, filing or license, reviewer, date, and unresolved question.

For a self-performed commercial cryptography application security assessment, retain original records and reports for at least six years. File the assessment report and related work information within 30 days after the report is formed when the assessment measures apply.

- Cryptography inventory and classification memo.
- Role map and analysis of the applicable law, standard, catalogue, and list.
- Supplier declaration, testing or certification body qualification, report, certificate, scope, and status.
- CII application plan, product or service and technology evidence, assessment records, report, filing, remediation, and cybersecurity review conclusion.
- Import or export screening, transaction type, end-user and end-use documents, mass-market consumer-product analysis, application and customs records, and license.
- Dated approval, accountable owner, unresolved issues, exceptions, and change log.

Sources for this answer:

- [PRC Cryptography Law](https://www.oscca.gov.cn/sca/xxgk/2023-06/04/content_1057225.shtml?ref=sorena.io) - Use for cryptography categories, commercial cryptography development and management, product/service controls, CII use, import/export context, penalties, and 1 January 2020 effective date.
- [Commercial Cryptography Application Security Assessment Measures](https://www.oscca.gov.cn/sca/xxgk/2023-10/07/content_1061109.shtml?ref=sorena.io) - Articles 13-15 support self-assessment sign-off, six-year retention, filing within 30 days, sampling, and incident response.

## Boundary with nearby China regimes

The current Cybersecurity Law separately governs network-security graded protection, product and service duties, network critical equipment and network security-specific products, CII protection, and certain procurement reviews. Its 2025 amendment took effect on 1 January 2026.

Keep personal-information, data-export, app-governance, and other network-security conclusions in their own source-backed analyses. The 2025 CII cryptography provisions require commercial cryptography protection for core data, important data, and personal information in covered CII according to the applicable data-protection and personal-information rules, but that cryptography control does not complete those separate legal analyses.

- Treating recommended standards as mandatory without another rule that makes them mandatory.
- Treating every commercial cryptography certificate as legally required, or treating a voluntary certification catalogue as the mandatory network-product catalogue.
- Treating product certification as completion of CII application assessment or cybersecurity review.
- Applying the mass-market consumer-product trade exception without matching the actual item and shipment to the statutory wording.

Sources for this answer:

- [PRC Cryptography Law](https://www.oscca.gov.cn/sca/xxgk/2023-06/04/content_1057225.shtml?ref=sorena.io) - Use for cryptography categories, commercial cryptography development and management, product/service controls, CII use, import/export context, penalties, and 1 January 2020 effective date.
- [PRC Cybersecurity Law, amended in 2025](https://www.cac.gov.cn/2025-12/29/c_1768735112911946.htm?ref=sorena.io) - Use for the current text, including Article 23 graded protection, Article 25 product assurance, and Articles 33-40 CII duties.
- [Presidential Order No. 61 promulgating the 2025 Cybersecurity Law amendment](https://www.npc.gov.cn/npc/c2/c30834/202510/t20251028_449031.html?ref=sorena.io) - Supports the amendment's 1 January 2026 effective date.

*Next step*

*Placement: Before primary sources*

## Prepare the commercial cryptography evidence file

Sorena AI helps turn a China Cryptography Law decision into assigned owners, controls, and records for review.

- [Map official sources to evidence](/solutions/research-copilot.md): Research Copilot connects the official citation, decision, owner, retained evidence, and change history.
- [Review the China route](/contact.md): Check the China Cryptography Law scope decision and unresolved launch questions with Sorena.

## Primary sources

- [PRC Cryptography Law](https://www.oscca.gov.cn/sca/xxgk/2023-06/04/content_1057225.shtml?ref=sorena.io) - Use for cryptography categories, commercial cryptography development and management, product/service controls, CII use, import/export context, penalties, and 1 January 2020 effective date.
- [Commercial cryptography testing institution measures interpretation](https://www.oscca.gov.cn/sca/xxgk/2023-10/07/content_1061110.shtml?ref=sorena.io) - Use for qualification and supervision of commercial-cryptography product-testing and application-security-assessment bodies, including report, data, sample, and information-reporting rules.
- [Commercial Cryptography Administration Regulation (State Council Order No. 760)](https://www.mee.gov.cn/zcwj/gwywj/202305/t20230529_1031579.shtml?ref=sorena.io) - Use for current operational requirements under the Cryptography Law.
- [Provisions on the Use and Administration of Commercial Cryptography in Critical Information Infrastructure](https://www.oscca.gov.cn/sca/xxgk/2025-06/27/content_1061270.shtml?ref=sorena.io) - Use for CII-specific commercial cryptography requirements effective 1 August 2025.
- [Commercial Cryptography Application Security Assessment Measures](https://www.oscca.gov.cn/sca/xxgk/2023-10/07/content_1061109.shtml?ref=sorena.io) - Use for assessment scope, lifecycle, records, retention, filing, and incident response.
- [Measures for the Administration of Cryptography Use in Electronic Certification Services](https://www.oscca.gov.cn/sca/xxgk/2026-06/03/content_1061341.shtml?ref=sorena.io) - Use for the current license and operating requirements for electronic certification services using commercial cryptography, effective 1 July 2026.
- [Presidential Order No. 61 promulgating the 2025 Cybersecurity Law amendment](https://www.npc.gov.cn/npc/c2/c30834/202510/t20251028_449031.html?ref=sorena.io) - Use for the 1 January 2026 effective date of the current Cybersecurity Law amendment.

## Related Topic Guides

- [China commercial cryptography compliance checklist](/artifacts/apac/china-cryptography-law/checklist.md): China commercial cryptography checklist covering classification, product and service assurance, CII duties, trade controls, and retained evidence.
- [China commercial cryptography testing evidence template](/artifacts/apac/china-cryptography-law/commercial-cryptography-testing-evidence-template.md): Record the legal route, product or system scope, testing-body qualification, report details, gaps, and reassessment triggers for China commercial cryptography assurance.
- [China cryptography compliance deadlines and calendar](/artifacts/apac/china-cryptography-law/deadlines-and-compliance-calendar.md): China cryptography effective dates, CII reports, annual assessments, licence renewals, change notices, and pre-operation checks.
- [China cryptography import, export, and security review triage](/artifacts/apac/china-cryptography-law/import-export-and-security-assessment.md): Screen commercial cryptography imports under the 2020 list, exports under China's unified dual-use list, the consumer exclusion, system assessment, and CII review.
- [China Cryptography Law FAQ](/artifacts/apac/china-cryptography-law/faq.md): Answers on China's commercial-cryptography scope, product assurance, classified protection, CII assessment, procurement review, and trade controls.
- [China Cryptography Law vs Cybersecurity Law](/artifacts/apac/china-cryptography-law/china-cryptography-law-vs-cybersecurity-law.md): Compare China's Cryptography Law and current Cybersecurity Law by scope, actor, product assurance, CII duties, evidence, and enforcement.
- [China cryptography penalties, fines, and liability](/artifacts/apac/china-cryptography-law/penalties-and-fines.md): China commercial cryptography penalties by actor and violation, including fine bands, corrective orders, confiscation, licence action, and liability.
- [Commercial cryptography procurement checklist](/artifacts/apac/china-cryptography-law/commercial-cryptography-procurement-checklist.md): Procurement checks for commercial cryptography products and services used in China, including certificate scope, CII duties, and supplier changes.
- [Commercial cryptography products and testing evidence](/artifacts/apac/china-cryptography-law/commercial-cryptography-products-and-testing.md): When China commercial cryptography testing or certification is voluntary or mandatory, and what product, service, body, and scope evidence to keep.
- [Do imported cryptography products need special review?](/artifacts/apac/china-cryptography-law/faq/do-imported-cryptography-products-need-special-review.md): Not every encrypted product imported into China needs a licence. Check the 2020 commercial-cryptography import list, the consumer-product exception, and any CII procurement review.
- [Does using encryption trigger China Cryptography Law duties?](/artifacts/apac/china-cryptography-law/faq/does-using-encryption-trigger-china-cryptography-law.md): Using encryption does not create one universal China approval duty. Check classified protection, product, service, CII, procurement, and trade triggers.
- [How does cryptography compliance overlap with China cybersecurity law?](/artifacts/apac/china-cryptography-law/faq/how-does-cryptography-compliance-overlap-with-cybersecurity-law.md): See how China's cryptography rules connect with classified protection, product assurance, CII assessment, and cybersecurity review without merging the regimes.
- [What is commercial cryptography in China?](/artifacts/apac/china-cryptography-law/faq/what-is-commercial-cryptography-in-china.md): Commercial cryptography protects information that is not a state secret. Learn how China defines the category and which separate facts trigger product, CII, or trade controls.
- [When is commercial cryptography testing or certification needed?](/artifacts/apac/china-cryptography-law/faq/when-is-commercial-cryptography-testing-or-certification-needed.md): Commercial-cryptography assurance is often voluntary, but specified products and services require it. Covered CII also needs application assessment and qualified cryptography.


---

[Privacy Policy](https://www.sorena.io/privacy.md) | [Terms of Use](https://www.sorena.io/terms-of-use.md) | [DMCA](https://www.sorena.io/dmca.md) | [About Us](https://www.sorena.io/about-us.md)

(c) 2026 Sorena AB (559573-7338). All rights reserved.

Source: https://www.sorena.io/artifacts/apac/china-cryptography-law/requirements.md
