Cryptography Law & 密评
China's commercial-cryptography regime rests on the Cryptography Law of the PRC (effective on 2020-01-01) and the mandatory 密评 (Commercial Cryptography Application Security Assessment). For enterprises in finance, power, and critical information infrastructure, these are compliance obligations — they require correct use of approved 商用密码 algorithms, but they are not post-quantum migration mandates.
The Cryptography Law of the PRC
The 《中华人民共和国密码法》 (Cryptography Law of the People's Republic of China) took effect on 1 January 2020. It is the top-level statute governing how cryptography is developed, used, and managed in China. The law classifies cryptography into three categories:
- 核心密码 (core cryptography) — protects information classified as state secrets at the highest levels.
- 普通密码 (common cryptography) — also protects state-secret information, at lower classification levels. Both 核心密码 and 普通密码 are reserved for state secrets and are not for general commercial use.
- 商用密码 (commercial cryptography, "SM"/国密) — for protecting information that is not a state secret. This is the layer that enterprises, banks, power utilities, and Web3 operators actually deploy.
The regime is administered by the State Cryptography Administration (SCA) — 国家密码管理局, formerly abbreviated OSCCA — which oversees algorithm standardization, product certification, and the conditions under which cryptography may be used. For the 商密 algorithm suite itself (SM2, SM3, SM4, SM9, ZUC), see china-overview.html and sm-algorithms.html.
密评 — Commercial Cryptography Application Security Assessment
密评 is shorthand for 商用密码应用安全性评估 (Commercial Cryptography Application Security Assessment). It is a formal evaluation that checks whether an information system uses approved commercial-cryptography algorithms correctly — covering key management, the cryptographic mechanisms protecting confidentiality, integrity, authenticity, and non-repudiation, and the operational controls around them.
密评 applies to the important networks and information systems that laws, administrative regulations, and relevant national rules require to be protected with 商用密码. In practice it typically covers:
- non-classified 关键信息基础设施 (critical information infrastructure, CII);
- important 网络安全等级保护 (等保) level-3-and-above systems;
- important government information systems, and the like.
The precise scope should follow the determinations of the competent authorities and the requirements of sector regulators. For systems within scope of 密评, an assessment must be carried out before operation — a system that does not pass may not be put into operation; once built and running, the operator must conduct 密评 at least once a year. In the CII context, the 《关键信息基础设施商用密码使用管理规定》 (Provisions on the Use of Commercial Cryptography in CII) set out the same kind of explicit requirement.
Key standards
The 密评 framework is operationalized through a set of national and industry standards:
- GB/T 39786-2021 — 《信息安全技术 信息系统密码应用基本要求》 ("Information security technology — Basic requirements for cryptography application of information systems"). Published 2021-03-09, effective 2021-10-01. This is the baseline against which a system's cryptographic design is judged. (As a GB/T national standard it is issued by SAMR and SAC, with the exact managing committee to be confirmed per the specific standard entry — distinct from the GM/T crypto-industry standards, which are managed by the Cryptography Industry Standardization Technical Committee, with the SCA as the typical competent authority.)
- GM/T 0115-2021 — 《信息系统密码应用测评要求》 (testing/assessment requirements for cryptography application of information systems).
- GM/T 0116-2021 — 《信息系统密码应用测评过程指南》 (guide to the assessment process).
- GM/T 0133-2024 — 《关键信息基础设施密码应用要求》 (cryptographic application requirements for CII), effective 1 July 2025, plus the 《关键信息基础设施商用密码使用管理规定》 (Provisions on the Use of Commercial Cryptography in CII; SCA/CAC/MPS Order No. 5), effective 1 August 2025.
- 《商用密码管理条例》 (Regulation on the Administration of Commercial Cryptography) — the key administrative regulation governing commercial-cryptography products, services, testing and certification, import/export, and supervision; together with the Cryptography Law and the 密评 regime it forms the 商密 compliance framework.
What it means for CN enterprises
For regulated sectors — finance, power, government, and other CII operators — 密评 turns "use good cryptography" into a documented, audited, recurring obligation. The practical implications:
- Use approved 商用密码 correctly. Deploying SM2/SM3/SM4/SM9/ZUC in the prescribed manner, with sound key management, is the substance of passing 密评.
- Plan around the annual cycle. Because re-assessment is required at least yearly, cryptographic changes must be tracked and re-validated, not set once and forgotten.
- Budget for pre-launch gating. No 密评, no go-live for in-scope systems.
Standards & references
- 国家标准全文公开 — GB/T 39786-2021 full text: openstd.samr.gov.cn — GB/T 39786
- 全国标准信息公共服务平台: std.samr.gov.cn
- SCA (国家密码管理局): www.oscca.gov.cn
- GM-Standards (community archive of GM/T texts): github.com/guanzhi/GM-Standards
- Resources — full standards register
商用密码合规与密评
中国商用密码体系以《中华人民共和国密码法》(2020-01-01 施行)和强制性的密评(商用密码应用安全性评估)为根基。对于金融、电力以及关键信息基础设施领域的企业而言,这些是合规义务——要求正确使用经批准的商用密码算法,但它们并非后量子迁移的强制要求。
中华人民共和国密码法
《中华人民共和国密码法》于 2020 年 1 月 1 日起施行,是规范中国密码研发、使用与管理的顶层法律。该法将密码分为三类:
- 核心密码——用于保护最高密级的国家秘密信息。
- 普通密码——同样用于保护国家秘密信息,密级较低。核心密码与普通密码均专用于国家秘密,不用于一般商业用途。
- 商用密码(SM、国密)——用于保护不属于国家秘密的信息。这正是企业、银行、电力企业以及 Web3 运营方实际部署的那一层。
整个体系由国家密码管理局(SCA 旧称 OSCCA)主管,负责算法标准化、产品认证以及密码使用条件的监管。关于商密算法套件本身(SM2、SM3、SM4、SM9、ZUC),详见 china-overview.html 与 sm-algorithms.html。
密评 商用密码应用安全性评估
密评是商用密码应用安全性评估的简称。它是一项正式评估,用于检验信息系统是否正确使用了经批准的商用密码算法——涵盖密钥管理,保障机密性、完整性、真实性、不可否认性的密码机制,以及相关运行管理措施。
密评适用于法律、行政法规和国家有关规定要求使用商用密码保护的重要网络与信息系统。实务中通常覆盖:
- 非涉密的关键信息基础设施(CII);
- 网络安全等级保护(等保)第三级及以上的重要系统;
- 重要的政务信息系统等。
具体范围应以主管部门认定和行业监管要求为准。对纳入密评范围的重要网络与信息系统,运行前应开展密评,未通过的不得投入运行;建成运行后,运营者应每年至少开展一次密评。CII 场景下,《关键信息基础设施商用密码使用管理规定》也作了同类明确要求。
关键标准
密评框架通过一系列国家标准与行业标准落地实施:
- GB/T 39786-2021——《信息安全技术 信息系统密码应用基本要求》。2021-03-09 发布,2021-10-01 施行。这是衡量系统密码应用设计的基线(GB/T 国家标准由国家市场监督管理总局、国家标准化管理委员会发布,具体归口部门需按标准条目确认;与 GM/T 行业标准不同——GM/T 是密码行业标准,由密码行业标准化技术委员会归口,主管部门通常为国家密码管理局)。
- GM/T 0115-2021——《信息系统密码应用测评要求》。
- GM/T 0116-2021——《信息系统密码应用测评过程指南》。
- GM/T 0133-2024——《关键信息基础设施密码应用要求》,2025 年 7 月 1 日起施行;另有《关键信息基础设施商用密码使用管理规定》(国家密码管理局 国家互联网信息办公室 公安部令第 5 号),2025 年 8 月 1 日起施行。
- 《商用密码管理条例》——商用密码产品、服务、检测认证、进出口和监督管理的重要行政法规;与《密码法》和密评制度共同构成商密合规框架。
对中国企业意味着什么
对于金融、电力、政务等受监管行业以及其他关键信息基础设施运营者而言,密评把"使用合格密码"变成了一项有据可查、可审计、周期性重复的义务。实务含义如下:
- 正确使用经批准的商用密码。按规范部署 SM2/SM3/SM4/SM9/ZUC 并做好密钥管理,正是通过密评的实质所在。
- 围绕年度周期规划。由于至少每年要复评一次,密码变更必须持续跟踪并重新验证,不能一劳永逸。
- 为上线前的门禁预留预算。对纳入范围的系统而言,没有密评就不能上线。
标准与参考
- 国家标准全文公开 —— GB/T 39786-2021 全文:openstd.samr.gov.cn — GB/T 39786
- 全国标准信息公共服务平台:std.samr.gov.cn
- 国家密码管理局(SCA):www.oscca.gov.cn
- GM-Standards(GM/T 文本社区存档):github.com/guanzhi/GM-Standards
- 资源链接 — 完整标准登记册