China’s CII Commercial Cryptography Rules Take Effect
Effective August 1, 2025, China’s rules govern commercial cryptography in critical information infrastructure, including operational safeguards and security assessments.
China’s Provisions on the Administration of Commercial Cryptography Use in Critical Information Infrastructure took effect on August 1, 2025. They regulate the use of commercial cryptography to protect critical information infrastructure, drawing on China’s Cryptography Law, Data Security Law, Personal Information Protection Law and related laws and administrative regulations.
Below is an English translation of the full text reproduced in the original article. This is an unofficial translation for reference, not an official English legal text or legal advice. The provisions concern critical information infrastructure designated under Chinese law; they are not general requirements for every website worldwide.
Provisions on commercial cryptography use in critical information infrastructure
Article 1. These Provisions are formulated to regulate commercial cryptography use in critical information infrastructure and protect its security, pursuant to the Cryptography Law, Cybersecurity Law, Data Security Law and Personal Information Protection Law of the People’s Republic of China; the Regulations on the Administration of Commercial Cryptography; the Regulations on the Security Protection of Critical Information Infrastructure; the Regulations on Network Data Security Management; and other relevant laws and administrative regulations.
Article 2. These Provisions apply to the administration of commercial cryptography use in critical information infrastructure identified under the Cybersecurity Law of the People’s Republic of China, the Regulations on the Security Protection of Critical Information Infrastructure, and other relevant laws, administrative regulations and national requirements.
Article 3. The national cryptography administration department, together with the national cyberspace administration department and the State Council’s public security department, is responsible for planning, guiding and supervising the administration of commercial cryptography use in critical information infrastructure nationwide and establishing an information-sharing mechanism for this work.
Local cryptography administration departments at or above county level, together with cyberspace administration departments and public security organs, are responsible for guidance and supervision within their respective administrative areas.
Article 4. Departments responsible for protecting critical information infrastructure, referred to below as “protection departments,” shall supervise commercial cryptography use in the industries and sectors within their responsibilities. They shall prepare separate commercial cryptography use plans or incorporate such plans into their sector’s critical information infrastructure security plans, and organize implementation. They shall guide critical information infrastructure operators, referred to below as “operators,” in establishing supporting arrangements for policies, personnel and funding.
By March 31 each year, protection departments shall report to the national cryptography administration department, national cyberspace administration department and State Council’s public security department on the preceding year’s administration of commercial cryptography use in their industries and sectors.
When a major cybersecurity incident involving commercial cryptography occurs, or a major cybersecurity threat involving it is discovered, protection departments shall promptly report to those national departments and guide operators in emergency response. Where necessary, they shall conduct a commercial cryptography application security assessment.
Article 5. In accordance with relevant laws, administrative regulations and national requirements, operators shall use commercial cryptography to protect critical information infrastructure, following the systems for commercial cryptography administration, cybersecurity classified protection and critical information infrastructure security protection. Cryptographic protection systems shall be planned, constructed and operated in step with the infrastructure, and commercial cryptography application security assessments shall be conducted regularly.
By January 31 each year, operators shall report to their responsible protection department on commercial cryptography use and commercial cryptography application security assessments during the preceding year.
Article 6. Operators shall strengthen institutional safeguards for commercial cryptography use and establish management policies covering cryptography use, emergency response and reporting of major incidents.
The operator’s principal person in charge bears overall responsibility for the administration of commercial cryptography use, including its use in the infrastructure and the handling of major cybersecurity incidents involving commercial cryptography.
Article 7. Operators shall ensure appropriate staffing. Professionals with a cryptography-related academic qualification or a relevant nationally recognized occupational skill-level certificate shall perform roles such as key administrator and cryptographic operator. Personnel with professional security-auditing capabilities shall serve as cryptographic security auditors.
Operators shall conduct security background checks on cryptography professionals and arrange regular relevant skills training to improve their commercial cryptography capabilities.
Article 8. Operators shall ensure funding for commercial cryptography use and application security assessments, incorporating these costs into their cybersecurity and informatization funding arrangements.
Article 9. Commercial cryptography products and services used in critical information infrastructure shall have passed the required testing and certification. Commercial cryptographic technologies, including algorithms, protocols and key management mechanisms, shall have passed examination and appraisal by the national cryptography administration department.
When operators procure network products or services involving commercial cryptography that affect or may affect national security, they shall undergo cybersecurity review under the Measures for Cybersecurity Review.
Article 10. Critical information infrastructure shall use commercial cryptography to protect core data, important data and personal information that it stores, uses and transmits, in accordance with national requirements for data security and personal information protection.
Article 11. At the planning stage, operators shall prepare a commercial cryptography application plan based on their application requirements and relevant laws, administrative regulations, standards and specifications. They shall plan the cryptographic protection system and incorporate it into the overall critical information infrastructure security plan.
Operators shall assess the application plan’s commercial cryptography application security themselves or commission a commercial cryptography testing institution to do so. A plan that has not passed the assessment shall not serve as the basis for constructing the cryptographic protection system.
Article 12. During construction, operators shall implement the application plan that passed the security assessment, put cryptographic security safeguards in place and build the cryptographic protection system. If the application plan needs adjustment during construction, a new security assessment shall be conducted. Construction may proceed under the revised plan only after it passes that assessment.
Before the infrastructure begins operating, operators shall conduct a commercial cryptography application security assessment themselves or commission a commercial cryptography testing institution. If the infrastructure fails the assessment, operators shall carry out remediation, and it shall not be put into operation during remediation.
Article 13. After construction and commencement of operations, operators shall conduct a commercial cryptography application security assessment at least once a year, themselves or through a commissioned commercial cryptography testing institution, to ensure correct use of commercial cryptography and effective operation of the cryptographic protection system. If the infrastructure fails the assessment, operators shall carry out remediation and take necessary measures to maintain operational security during that period.
Article 14. For infrastructure already under construction before these Provisions take effect, operators shall strengthen the preparation and review of commercial cryptography application plans, build or improve cryptographic protection systems and conduct security assessments under Article 12.
For infrastructure already in operation before these Provisions take effect, operators shall conduct security assessments under Article 13.
Article 15. Commercial cryptography application security assessments of critical information infrastructure shall comply with the relevant provisions of the Measures for the Administration of Commercial Cryptography Application Security Assessments.
These assessments shall be coordinated with critical information infrastructure security testing and assessment and cybersecurity classified-protection evaluations to avoid duplicate assessments and evaluations.
Article 16. The national cryptography administration department is responsible for building and managing national infrastructure for the operational security management of commercial cryptography in critical information infrastructure. It shall coordinate the corresponding work of protection departments in their industries and sectors. Together with the national cyberspace administration department and State Council’s public security department, it shall analyze operational security conditions and coordinate responses to major threats to commercial cryptography operational security.
Article 17. Cryptography administration departments shall regularly organize supervision and inspections of commercial cryptography use in critical information infrastructure. Protection departments shall regularly inspect use within their industries and sectors and propose improvements. Where necessary, they may conduct application security assessments themselves or commission commercial cryptography testing institutions or other professional institutions.
Operators shall cooperate with supervision and inspections by cryptography administration and protection departments, promptly implement rectification based on the findings, and report the results to the protection departments. Protection departments shall report rectification results to the national cryptography administration department.
Supervision and inspections shall strengthen coordination and information-sharing to avoid unnecessary or overlapping duplicate inspections. No inspection fees may be charged. Inspected entities may not be required to purchase or use commercial cryptography products or services from designated suppliers or brands.
Article 18. Cryptography administration departments, relevant departments, commercial cryptography testing institutions and their staff shall maintain the confidentiality of state secrets, trade secrets and personal privacy learned in the performance of their duties. They shall not disclose such information or unlawfully provide it to others.
Article 19. Where an operator violates the Cryptography Law, Cybersecurity Law, Regulations on the Administration of Commercial Cryptography, Regulations on the Security Protection of Critical Information Infrastructure or relevant provisions herein in any of the following ways, the cryptography administration department shall order rectification and issue a warning. If the operator refuses to rectify the violation or other serious circumstances exist, a fine of RMB 100,000 to RMB 1,000,000 shall be imposed, and the directly responsible person in charge shall be fined RMB 10,000 to RMB 100,000:
- Failing to use commercial cryptography to protect critical information infrastructure as required, or failing to plan, construct and operate the cryptographic protection system in step with the infrastructure.
- Using commercial cryptography products or services that have not passed the required testing and certification.
- Using cryptographic technologies, including algorithms, protocols or key management mechanisms, that have not passed examination and appraisal by the national cryptography administration department.
- At the planning stage, failing to prepare a commercial cryptography application plan or failing to assess that plan’s application security.
- During construction, failing to build the cryptographic protection system according to the application plan that passed the security assessment.
- Before operations begin, failing to conduct a security assessment, or failing the assessment without carrying out remediation.
- After operations begin, failing to conduct regular security assessments, or failing such an assessment without carrying out remediation.
Article 20. Where an operator violates the laws and regulations listed in Article 19 and Article 9 of these Provisions by using network products or services involving commercial cryptography that have not undergone or have failed the required security review, the competent authorities shall order their use to cease and impose a fine of one to ten times the procurement amount. The directly responsible person in charge and other directly responsible personnel shall each be fined RMB 10,000 to RMB 100,000.
Article 21. Where an operator violates the laws and regulations listed in Article 19 and Article 17 of these Provisions by refusing without proper reason to accept or cooperate with, or by interfering with or obstructing, commercial cryptography supervision and administration by cryptography administration or relevant departments, those departments shall order rectification and issue a warning. If the operator refuses to rectify the violation or other serious circumstances exist, a fine of RMB 50,000 to RMB 500,000 shall be imposed, and the directly responsible person in charge and other directly responsible personnel shall each be fined RMB 10,000 to RMB 100,000. In particularly serious cases, suspension of business for rectification shall be ordered.
Article 22. Where an operator violates these Provisions in any of the following ways, cryptography administration and relevant departments shall order rectification within their respective responsibilities:
- Failing to report the preceding year’s commercial cryptography use and application security assessments as required.
- Failing to establish management policies for commercial cryptography use.
- Failing to appoint key administrators, cryptographic operators or cryptographic security auditors as required.
- Failing to ensure funding for commercial cryptography use and application security assessments.
Article 23. Personnel supervising and administering commercial cryptography use in critical information infrastructure who abuse their powers, neglect their duties, engage in favoritism or malpractice, or disclose or unlawfully provide to others trade secrets, personal privacy or whistleblower information learned in the performance of their duties shall be disciplined according to law.
Article 24. In addition to these Provisions, the administration of commercial cryptography use in critical information infrastructure that forms part of national government information systems shall comply with the Measures for the Administration of National Government Informatization Project Construction, State Council General Office Document No. 57 of 2019, and other relevant requirements.
Article 25. These Provisions take effect on August 1, 2025.
Source attribution in the original article: the Cyberspace Administration of China website. Chinese titles and legal text take precedence over this unofficial translation.