China encryption policy

China's Open NGCC Cryptography Contest Is Sound Process, and Its Real Test Is Whether Standards Stay Interoperable

China's 119 post-quantum candidates drew 191 public findings in a week. The open process is a strength, but a separate Chinese standard raises interoperability costs.

China's NGCC Round One in Numbers People of Internet Research · China 119 Round-one candidates 34 signatures, 41 KEMs, 9 key exch… 191 Active findings, week one Spread across 89 candidates. 78 Findings rated Critical Includes forgeries, key recovery a… 3 NIST PQC standards published FIPS 203, 204 and 205 appeared on … peopleofinternet.com
China's NGCC Round One in Numbers People of Internet Research · China 119 Round-one candidates 191 Active findings, week one 78 Findings rated Critical 3 NIST PQC standards publis… peopleofinternet.com

Key Takeaways

On September 20, 2026, China's Institute of Commercial Cryptography Standards (ICCS) published 119 round-one candidates for its Next-generation Commercial Cryptographic Algorithms (NGCC) programme: 34 signature schemes, 41 key encapsulation mechanisms (KEMs), 9 key exchanges and 35 hash functions. None is a standard yet, and no migration deadline has been announced. The programme invites the world's cryptographers to attack the candidates in public, and they did so within days.

The case for a national standard

The strongest argument for Beijing's approach is sovereignty. Cryptographic standards are trust anchors. A country that adopts another state's primitives has to trust that state's process, its funding and its intelligence agencies. NIST itself is a US government body, and its post-quantum standards, FIPS 203, 204 and 205, were published on August 13, 2024. China's Cryptography Law, adopted on October 26, 2019 and in force since January 1, 2020, already assigns the development of commercial cryptography standards to the State Council's standardization authority and the national cryptography administration (Article 22). A China-specific suite follows from that statute. Many governments, including some US allies, have asked whether they should depend on a single foreign standards pipeline. Seen that way, running a competition is a reasonable response.

The process is the interesting part

What distinguishes NGCC from earlier Chinese cryptography is how open it is. The SM2, SM3 and SM4 family was developed with far less public scrutiny. NGCC copies the template NIST used for AES, SHA-3 and its post-quantum project, which began with a call for proposals in 2016-2017. ICCS opened a global call for proposals in February 2025 and welcomed submissions from researchers worldwide. The official NICCS site carries algorithm proposal and evaluation sections. We could not confirm the full candidate list there, so the 119-candidate breakdown rests on secondary reporting and the independent tracker described below.

Public cryptanalysis arrived almost at once. An independent tracker, ngcc.dev, run by Markku-Juhani O. Saarinen of Tampere University and not affiliated with NICCS, logs findings against the candidates. His ePrint paper reports that in the first seven days researchers documented 191 active findings across 89 candidates, and that 78 were rated Critical. Many of the Critical findings are universal forgeries, key recovery attacks and hash collisions. The same paper says an AI-assisted workflow discovered, verified and disclosed 110 of the issues. Counts differ between snapshots, because findings are added and revised as the tracker updates, so we use the paper's figures.

This is how an open competition is supposed to work. A candidate that fails in week one is eliminated cheaply, before anyone deploys it. Open attack is the best available quality control for cryptography, and the volume of breaks tells us the process is being taken seriously by outside researchers. It does not show that the candidates are weak as a class. Round one is meant to be noisy, and many findings are implementation bugs in submitted code. Neither the tracker nor the paper reports how many of the 191 findings are design flaws versus code bugs, so we cannot say how much of the break rate is fatal to the underlying schemes.

Where the real policy risk lies

A transparent contest does not remove the main cost, which is fragmentation. If China standardises its own KEMs and signatures while the rest of the world deploys NIST's, multinational firms face dual implementations, dual certification and larger attack surface. The Cryptography Law says commercial cryptography products affecting national welfare or public interest must pass testing and certification, and that those used to protect critical information are subject to security assessments under the Cybersecurity Law. If Chinese certification eventually requires NGCC algorithms, foreign vendors would need to ship them. Chinese vendors could face the mirror-image problem abroad.

The law does contain pro-market language. Article 21 calls for equal treatment of commercial cryptography entities, including foreign-invested firms, in an open, competitive and orderly market, and says import and export must not endanger national security. Whether those commitments survive contact with a mandatory national algorithm list is the thing to watch. Nothing in the current announcement sets a mandate. No candidate is a standard and no deadline exists.

What proportionate policy looks like

The sensible response from governments and firms is neither alarm nor dismissal.

The pro-innovation reading is that more competing, publicly attacked designs make cryptography stronger. Rivals have already shown that the NGCC pool contains weak candidates, which is a feature of the contest. The danger would be a mandate that locks hardware and software into a single national suite before the cryptanalysis has settled, and that has not happened yet.

The opposing view deserves a fair hearing as well. Sceptics say a state-run process cannot be fully trusted regardless of how open its first round is, because the final selection and the certification regime stay in government hands. That concern is legitimate and cannot be resolved today. It can be tested over the coming rounds: do the published attacks change which candidates advance, and are the evaluation reports public?

Sources & Citations

  1. NIST Post-Quantum Cryptography Standardization
  2. Cryptography Law of the PRC (NPC, 2019)
  3. NICCS (China commercial cryptography standards site)
  4. Saarinen, Chinese NGCC Algorithms: The First Week of AI Cryptanalysis (IACR ePrint 2026/2266)
  5. ngcc.dev independent tracker
  6. The Quantum Insider: China launches its own quantum-resistant encryption standards