TLDR; Below is the English-translated version of China’s Cryptography Law (中华人民共和国密码法, Presidential Order No. 35), promulgated October 26, 2019 and in effect since January 1, 2020.
For a foreign company, this is the law behind a recurring question: is my encryption, VPN-style security tool, TLS-inspecting gateway, or endpoint-security product subject to Chinese controls? The Cryptography Law answers it by sorting cryptography into core cryptography and ordinary cryptography, which protect State secret information (Articles 7-8), and commercial cryptography, which covers everything that is not a State secret (Article 8) — and commercial cryptography is the tier that reaches ordinary commercial products and services. For that tier the law sets out import licensing and export control (Article 28), and, for products that concern national security or the public interest, testing and certification before they may be sold or provided (Article 26), while operators of critical information infrastructure face a further security-review path (Article 27). It underpins and works alongside the Cybersecurity Law and the Data Security Law, to which it repeatedly cross-refers. Because whether a given product or service falls inside these controls turns on fact-specific classification, treat this as something to confirm with qualified counsel rather than to self-assess.
Cryptography Law of the People’s Republic of China (Adopted October 26, 2019 at the 14th Session of the Standing Committee of the 13th National People’s Congress; effective January 1, 2020)
Chapter I General Provisions
Article 1. This Law is formulated in order to regulate the application and administration of cryptography, promote the development of the cryptography cause, safeguard network and information security, safeguard national security and the public interest, and protect the lawful rights and interests of citizens, legal persons, and other organizations.
Article 2. For the purposes of this Law, “cryptography” means the technologies, products, and services that use specific transformation methods to perform encryption protection and security authentication on information and the like.
Article 3. Cryptography work shall uphold a holistic view of national security and follow the principles of unified leadership and graded responsibility, innovative development and service to the overall situation, and law-based administration and the safeguarding of security.
Article 4. The leadership of the Communist Party of China over cryptography work shall be upheld. The central leading body for cryptography work exercises unified leadership over cryptography work throughout the country, formulates major guidelines and policies for national cryptography work, coordinates major matters and important work on national cryptography in an integrated manner, and advances the development of the rule of law in national cryptography.
Article 5. The State cryptography administration department is responsible for administering cryptography work throughout the country. Local cryptography administration departments at all levels at or above the county level are responsible for administering cryptography work within their respective administrative regions.
State organs and units involved in cryptography work are responsible, within the scope of their duties, for the cryptography work of their own organ, unit, or system.
Article 6. The State applies classified administration to cryptography.
Cryptography is divided into core cryptography, ordinary cryptography, and commercial cryptography.
Article 7. Core cryptography and ordinary cryptography are used to protect State secret information. The highest classification level of information protected by core cryptography is top secret, and the highest classification level of information protected by ordinary cryptography is secret.
Core cryptography and ordinary cryptography are themselves State secrets. The cryptography administration departments, in accordance with this Law and relevant laws, administrative regulations, and relevant State provisions, apply strict and unified administration to core cryptography and ordinary cryptography.
Article 8. Commercial cryptography is used to protect information that is not a State secret.
Citizens, legal persons, and other organizations may use commercial cryptography according to law to protect network and information security.
Article 9. The State encourages and supports research into and application of cryptographic science and technology, protects intellectual property rights in the field of cryptography according to law, and promotes the progress and innovation of cryptographic science and technology.
The State strengthens the cultivation of cryptography talent and the building of its workforce, and commends and rewards, in accordance with relevant State provisions, organizations and individuals that have made outstanding contributions in cryptography work.
Article 10. The State strengthens cryptography security education through various forms, incorporates cryptography security education into the national education system and the civil servant education and training system, and enhances the cryptography security awareness of citizens, legal persons, and other organizations.
Article 11. People’s governments at or above the county level shall incorporate cryptography work into their economic and social development plans at the corresponding level, and include the necessary funds in their budgets at the corresponding level.
Article 12. No organization or individual may steal information that others have protected by encryption, or illegally intrude into the cryptography safeguard systems of others.
No organization or individual may use cryptography to engage in unlawful or criminal activities that endanger national security, the public interest, or the lawful rights and interests of others.
Chapter II Core Cryptography and Ordinary Cryptography
Article 13. The State strengthens the scientific planning, administration, and use of core cryptography and ordinary cryptography, strengthens institutional development, improves administrative measures, and enhances cryptography security safeguard capabilities.
Article 14. State secret information transmitted over wired and wireless communications, and information systems that store or process State secret information, shall use core cryptography and ordinary cryptography for encryption protection and security authentication in accordance with laws, administrative regulations, and relevant State provisions.
Article 15. Institutions engaged in work such as the research, production, service, testing, equipment, use, and destruction of core cryptography and ordinary cryptography (hereinafter collectively referred to as “cryptography work institutions”) shall, in accordance with the requirements of laws, administrative regulations, relevant State provisions, and the standards for core cryptography and ordinary cryptography, establish and improve security management systems, and adopt strict confidentiality measures and a confidentiality responsibility system, so as to ensure the security of core cryptography and ordinary cryptography.
Article 16. The cryptography administration departments shall, in accordance with law, guide, supervise, and inspect the core cryptography and ordinary cryptography work of cryptography work institutions, and the cryptography work institutions shall cooperate.
Article 17. The cryptography administration departments shall, as needed for their work and together with the relevant departments, establish collaborative mechanisms for core cryptography and ordinary cryptography, such as security monitoring and early warning, security risk assessment, information notification, consultation on major matters, and emergency response, so as to ensure that the security administration of core cryptography and ordinary cryptography is coordinated, orderly, and efficient.
Where a cryptography work institution discovers a leak of core cryptography or ordinary cryptography, or a major problem or latent risk affecting the security of core cryptography or ordinary cryptography, it shall immediately take response measures and promptly report to the secrecy administration department and the cryptography administration department; the secrecy administration department and the cryptography administration department shall, together with the relevant departments, organize and carry out investigation and disposal, and guide the relevant cryptography work institution to eliminate the security risk in a timely manner.
Article 18. The State strengthens the development of cryptography work institutions and safeguards their performance of their duties.
The State establishes personnel administration systems adapted to the needs of core cryptography and ordinary cryptography work, covering matters such as recruitment, selection and transfer, confidentiality, appraisal, training, remuneration, rewards and punishments, exchange, and exit.
Article 19. Where necessary for their work, the cryptography administration departments may, in accordance with relevant State provisions, request departments such as public security, transportation, and customs to provide conveniences such as exemption from inspection for articles and personnel related to core cryptography and ordinary cryptography, and the relevant departments shall provide assistance.
Article 20. The cryptography administration departments and cryptography work institutions shall establish and improve strict supervision and security review systems, supervise their staff’s compliance with laws and discipline and the like, and take necessary measures according to law to organize and carry out security reviews on a regular or irregular basis.
Chapter III Commercial Cryptography
Article 21. The State encourages the research and development, academic exchange, transformation of achievements, and promotion and application of commercial cryptography technology; improves a unified, open, competitive, and orderly commercial cryptography market system; and encourages and promotes the development of the commercial cryptography industry.
People’s governments at all levels and their relevant departments shall follow the principle of non-discrimination and, according to law, treat equally the entities engaged in the research, production, sale, service, and import and export of commercial cryptography, including foreign-invested enterprises (hereinafter collectively referred to as “commercial cryptography practitioner entities”). The State encourages commercial cryptography technology cooperation to be carried out in the course of foreign investment on the basis of the principle of voluntariness and commercial rules. Administrative organs and their staff shall not use administrative means to compel the transfer of commercial cryptography technology.
The research, production, sale, service, and import and export of commercial cryptography shall not harm national security, the public interest, or the lawful rights and interests of others.
Article 22. The State establishes and improves the commercial cryptography standards system.
The standardization administrative department of the State Council and the State cryptography administration department shall, in accordance with their respective duties, organize the formulation of national standards and industry standards for commercial cryptography.
The State supports social organizations and enterprises in using independently innovated technology to formulate group standards and enterprise standards for commercial cryptography whose relevant technical requirements are higher than the national and industry standards.
Article 23. The State promotes participation in international standardization activities for commercial cryptography, participates in formulating international standards for commercial cryptography, and advances the conversion and application between China’s standards and foreign standards for commercial cryptography.
The State encourages enterprises, social organizations, and educational and scientific research institutions, among others, to participate in international standardization activities for commercial cryptography.
Article 24. Where a commercial cryptography practitioner entity carries out commercial cryptography activities, it shall conform to the technical requirements of relevant laws, administrative regulations, the mandatory national standards for commercial cryptography, and the standards publicly disclosed by that practitioner entity.
The State encourages commercial cryptography practitioner entities to adopt the recommended national standards and industry standards for commercial cryptography, so as to enhance the protective capability of commercial cryptography and safeguard the lawful rights and interests of users.
Article 25. The State advances the development of the commercial cryptography testing and certification system, formulates technical specifications and rules for commercial cryptography testing and certification, and encourages commercial cryptography practitioner entities to voluntarily undergo commercial cryptography testing and certification in order to enhance their market competitiveness.
Commercial cryptography testing and certification institutions shall obtain the relevant qualifications according to law, and carry out commercial cryptography testing and certification in accordance with the provisions of laws and administrative regulations and the technical specifications and rules for commercial cryptography testing and certification.
Commercial cryptography testing and certification institutions shall bear a confidentiality obligation with respect to the State secrets and trade secrets of which they become aware in the course of commercial cryptography testing and certification.
Article 26. Commercial cryptography products that concern national security, the national economy and people’s livelihood, or the public interest shall, according to law, be included in the catalogue of critical network equipment and specialized cybersecurity products, and may be sold or provided only after being tested and certified as qualified by a qualified institution. The testing and certification of commercial cryptography products shall apply the relevant provisions of the Cybersecurity Law of the People’s Republic of China, so as to avoid duplicate testing and certification.
Where a commercial cryptography service uses critical network equipment or specialized cybersecurity products, that commercial cryptography service shall be certified as qualified by a commercial cryptography certification institution.
Article 27. For critical information infrastructure that laws, administrative regulations, and relevant State provisions require to be protected using commercial cryptography, the operator shall use commercial cryptography for protection, and shall, on its own or by entrusting a commercial cryptography testing institution, carry out a commercial cryptography application security assessment. The commercial cryptography application security assessment shall be linked with the security testing and assessment of critical information infrastructure and with the cybersecurity classified protection evaluation system, so as to avoid duplicate assessment and evaluation.
Where an operator of critical information infrastructure purchases network products and services that involve commercial cryptography and that may affect national security, it shall, in accordance with the provisions of the Cybersecurity Law of the People’s Republic of China, pass the national security review organized by the State cyberspace administration department together with the State cryptography administration department and other relevant departments.
Article 28. The competent commerce department of the State Council and the State cryptography administration department shall, according to law, impose import licensing on commercial cryptography that concerns national security or the public interest and that has encryption protection functions, and shall impose export control on commercial cryptography that concerns national security, the public interest, or the international obligations undertaken by China. The import licensing list and the export control list for commercial cryptography shall be formulated and published by the competent commerce department of the State Council together with the State cryptography administration department and the General Administration of Customs.
Commercial cryptography used in mass consumer products is not subject to the import licensing and export control systems.
Article 29. The State cryptography administration department shall accredit institutions that use commercial cryptography technology to engage in electronic certification services for e-government, and shall, together with the relevant departments, be responsible for the administration of the use of electronic signatures and data messages in government affairs activities.
Article 30. Industry associations and other organizations in the field of commercial cryptography shall, in accordance with laws, administrative regulations, and their own charters, provide services such as information, technology, and training to commercial cryptography practitioner entities; guide and urge commercial cryptography practitioner entities to carry out commercial cryptography activities according to law; strengthen industry self-regulation; promote the building of industry integrity; and promote the healthy development of the industry.
Article 31. The cryptography administration departments and the relevant departments shall establish an in-process and ex-post supervision system for commercial cryptography that combines routine supervision with random spot checks, establish a unified information platform for the supervision and administration of commercial cryptography, advance the linkage of in-process and ex-post supervision with the social credit system, and strengthen the self-regulation of commercial cryptography practitioner entities and social supervision.
The cryptography administration departments and the relevant departments and their staff shall not require commercial cryptography practitioner entities or commercial cryptography testing and certification institutions to disclose to them cryptography-related proprietary information such as source code, and shall keep strictly confidential the trade secrets and personal privacy of which they become aware in the course of performing their duties, and shall not leak or unlawfully provide such information to others.
Chapter IV Legal Liability
Article 32. Whoever, in violation of the provisions of Article 12 of this Law, steals information that others have protected by encryption, illegally intrudes into the cryptography safeguard systems of others, or uses cryptography to engage in unlawful activities that endanger national security, the public interest, or the lawful rights and interests of others, shall be held legally liable by the relevant departments in accordance with the provisions of the Cybersecurity Law of the People’s Republic of China and other relevant laws and administrative regulations.
Article 33. Whoever, in violation of the provisions of Article 14 of this Law, fails to use core cryptography or ordinary cryptography as required shall be ordered by the cryptography administration department to make corrections or to cease the unlawful conduct and shall be given a warning; where the circumstances are serious, the cryptography administration department shall recommend that the relevant State organ or unit impose sanctions or other handling according to law on the directly responsible person in charge and other directly responsible persons.
Article 34. Where, in violation of the provisions of this Law, a case of leakage of core cryptography or ordinary cryptography occurs, the secrecy administration department and the cryptography administration department shall recommend that the relevant State organ or unit impose sanctions or other handling according to law on the directly responsible person in charge and other directly responsible persons.
Where, in violation of the provisions of the second paragraph of Article 17 of this Law, a leak of core cryptography or ordinary cryptography, or a major problem or latent risk affecting the security of core cryptography or ordinary cryptography, is discovered but response measures are not immediately taken or a timely report is not made, the secrecy administration department and the cryptography administration department shall recommend that the relevant State organ or unit impose sanctions or other handling according to law on the directly responsible person in charge and other directly responsible persons.
Article 35. Where a commercial cryptography testing or certification institution carries out commercial cryptography testing or certification in violation of the provisions of the second and third paragraphs of Article 25 of this Law, the market regulation department together with the cryptography administration department shall order it to make corrections or to cease the unlawful conduct, give it a warning, and confiscate its illegal gains; where the illegal gains are RMB 300,000 or more, a fine of not less than 1 time but not more than 3 times the illegal gains may also be imposed; where there are no illegal gains or the illegal gains are less than RMB 300,000, a fine of not less than RMB 100,000 but not more than RMB 300,000 may also be imposed; where the circumstances are serious, the relevant qualification shall be revoked according to law.
Article 36. Whoever, in violation of the provisions of Article 26 of this Law, sells or provides commercial cryptography products that have not been tested and certified or that have failed testing and certification, or provides commercial cryptography services that have not been certified or that have failed certification, shall be ordered by the market regulation department together with the cryptography administration department to make corrections or to cease the unlawful conduct, be given a warning, and have the unlawful products and illegal gains confiscated; where the illegal gains are RMB 100,000 or more, a fine of not less than 1 time but not more than 3 times the illegal gains may also be imposed; where there are no illegal gains or the illegal gains are less than RMB 100,000, a fine of not less than RMB 30,000 but not more than RMB 100,000 may also be imposed.
Article 37. Where an operator of critical information infrastructure, in violation of the provisions of the first paragraph of Article 27 of this Law, fails to use commercial cryptography as required or fails to carry out a commercial cryptography application security assessment as required, the cryptography administration department shall order it to make corrections and give it a warning; where it refuses to make corrections or where consequences such as harm to cybersecurity result, a fine of not less than RMB 100,000 but not more than RMB 1 million shall be imposed, and a fine of not less than RMB 10,000 but not more than RMB 100,000 shall be imposed on the directly responsible person in charge.
Where an operator of critical information infrastructure, in violation of the provisions of the second paragraph of Article 27 of this Law, uses a product or service that has not undergone a security review or that has failed a security review, the relevant competent department shall order it to cease using the product or service and shall impose a fine of not less than 1 time but not more than 10 times the purchase amount; and a fine of not less than RMB 10,000 but not more than RMB 100,000 shall be imposed on the directly responsible person in charge and other directly responsible persons.
Article 38. Whoever imports or exports commercial cryptography in violation of the provisions of Article 28 of this Law on import licensing and export control shall be punished according to law by the competent commerce department of the State Council or by customs.
Article 39. Whoever, in violation of the provisions of Article 29 of this Law, engages in electronic certification services for e-government without accreditation shall be ordered by the cryptography administration department to make corrections or to cease the unlawful conduct, be given a warning, and have the unlawful products and illegal gains confiscated; where the illegal gains are RMB 300,000 or more, a fine of not less than 1 time but not more than 3 times the illegal gains may also be imposed; where there are no illegal gains or the illegal gains are less than RMB 300,000, a fine of not less than RMB 100,000 but not more than RMB 300,000 may also be imposed.
Article 40. Where a staff member of the cryptography administration departments or of the relevant departments or units abuses power, neglects duty, or engages in malpractice for personal gain in cryptography work, or leaks or unlawfully provides to others trade secrets or personal privacy of which they became aware in the course of performing their duties, a sanction shall be imposed according to law.
Article 41. Whoever violates the provisions of this Law and constitutes a crime shall be held criminally liable according to law; whoever causes damage to others shall bear civil liability according to law.
Chapter V Supplementary Provisions
Article 42. The State cryptography administration department shall formulate cryptography administration rules in accordance with the provisions of laws and administrative regulations.
Article 43. The measures for the administration of cryptography work of the Chinese People’s Liberation Army and the Chinese People’s Armed Police Force shall be formulated by the Central Military Commission in accordance with this Law.
Article 44. This Law shall take effect on January 1, 2020.
Primary source: 《中华人民共和国密码法》(主席令第35号), full text published by the National People’s Congress: npc.gov.cn. The detailed rules for commercial cryptography are set out in the Regulation on the Administration of Commercial Cryptography (State Council Order No. 760, as revised, effective July 1, 2023), which is not reproduced here.
This translation is ours and is provided for orientation only. Where the English and the Chinese differ, the Chinese governs. This page is not legal advice; confirm your position with qualified counsel.