China encryption policy

China's Order No. 24 Makes Encrypting 'Important Data' Trigger a Second, Separate Security Audit

A new CAC rule stacks a standalone commercial cryptography assessment atop the annual data-security review whenever important data is encrypted.

China's Double-Track Encryption Compliance People of Internet Research · China Aug 20, 2026 Order No. 24 effective date Jointly issued by CAC, MIIT and th… 20 working days Risk-assessment reporting deadline Important data handlers must submi… Annual since Aug 2025 CII crypto assessment cadence Critical infrastructure operators … peopleofinternet.com
China's Double-Track Encryption Compli… People of Internet Research · China Aug 20, 2026 Order No. 24 effective date 20 working days Risk-assessment reporting deadli… Annual since Aug 2025 CII crypto assessment caden… peopleofinternet.com

Key Takeaways

China's Cyberspace Administration (CAC), the Ministry of Industry and Information Technology, and the Ministry of Public Security jointly adopted the Measures for Network Data Security Risk Assessment — Order No. 24 — on June 1, 2026. The rule took effect August 20, 2026, and it does something narrow but consequential: it converts the general, catch-all obligation in the Data Security Law to periodically assess network data risk into a defined administrative process, with fixed deadlines, designated regulators, and — buried in Article 23 — a quiet but expensive trigger for anyone using encryption to protect "important data."

What Order No. 24 Actually Does

Important data handlers must now run a comprehensive risk assessment at least annually, plus targeted ad hoc assessments whenever a "significant change" could affect data security, and submit the resulting report to the competent regulator within 20 working days of completion, retained for at least three years (CAC, Order No. 24). That much tracks a fairly conventional risk-management cadence seen in data-protection regimes worldwide.

Article 23 adds a second track. Where a handler protects important data using "encryption or similar technical measures," it must additionally complete a commercial cryptography application security assessment under China's separate cryptography-law regime — a distinct process, historically run through licensed testing bodies, that evaluates whether the cryptographic implementation itself (key management, algorithm conformance, protocol design) actually holds up, rather than simply confirming a risk-assessment checkbox was ticked.

Stacking, Not Streamlining

This isn't a new concept in Chinese law — it's an extension of one. Since August 1, 2025, operators of critical information infrastructure (CII) have already been required to run commercial cryptography application security assessments at the planning, construction, and operational stages, including at least one every year once a system is live, under the CAC's Provisions on Commercial Cryptography Use for Critical Information Infrastructure (CAC, CII Provisions). Notably, those provisions instruct regulators to align the crypto assessment with other required security evaluations specifically "to avoid redundant evaluations."

Order No. 24 does the opposite for a much larger population. "Important data" handler is a broader, fuzzier category than CII operator — it can sweep in large platforms, logistics and mapping firms, healthcare and financial data processors, and multinationals running China operations that were never subject to CII-grade obligations. Article 23 now hands all of them a second, parallel audit track the moment they encrypt the data they're supposed to be protecting, without the redundancy-avoidance language that tempers the CII regime.

The Case for Verifying the Lock, Not Just the Door

There's a real security argument here, and it deserves to be stated plainly before it's dismissed. A generic annual "risk assessment" — often self-administered, often a paperwork exercise — can confirm a company says it encrypts important data without ever probing whether that encryption is implemented correctly. Weak key management, deprecated ciphers, or a certificate misconfiguration can render "encrypted" data effectively as exposed as plaintext. Regulators asking for an independent, standards-based cryptography assessment on top of a self-reported risk narrative is, in isolation, a defensible response to a genuine gap: declaring encryption and verifying it are different things, and China's Cryptography Law (effective January 1, 2020) already built the technical assessment infrastructure to do the latter for CII operators. Extending that scrutiny to a wider pool of important-data handlers is not, on its face, unreasonable.

The Compliance Paradox

Where the design breaks down is in what it makes rational for a company to do. Article 23's second assessment is triggered specifically by the use of encryption on important data — not by the existence of important data itself. A handler that skips encryption, or protects important data through access controls and network segmentation instead, does not trip the commercial cryptography assessment. One that does the more security-conscious thing faces a longer, costlier, more procedurally complex compliance path, layered on top of the annual review every important-data handler already owes.

That's a perverse incentive for a rule ostensibly about data security: it taxes the specific control — encryption — that regulators everywhere, including China's own cybersecurity establishment, generally want more of, not less. For resource-constrained handlers deciding how to protect a dataset that just crossed the "important data" threshold, the calculus now includes not just security value but which control avoids triggering a second licensed-assessor audit cycle within a 20-working-day reporting clock.

A Proportionate Fix Is Available

This arrives amid a broader 2026 tightening — the amended Cybersecurity Law took effect January 1 with sharply higher penalties, and the CAC's first formal PIPL enforcement action against a foreign company landed in September 2025 (China Briefing; Hunton). Compliance cost is compounding, not merely adding.

The fix isn't to abandon cryptographic verification — it's to fold it into the existing annual risk assessment as a module, the way the CII provisions already instruct regulators to align crypto checks with other required evaluations, rather than running two clocks, two reports, and potentially two assessor relationships for the same underlying dataset. Proportionate regulation means the rigor should scale with risk, not with how many separate legal regimes happen to touch the same control. As written, Order No. 24 asks companies to choose between encrypting important data properly and keeping their compliance overhead manageable — a choice a security-focused rule shouldn't be forcing anyone to make.

Sources & Citations

  1. CAC: Measures for Network Data Security Risk Assessment (Order No. 24)
  2. CAC: Provisions on Commercial Cryptography Use for Critical Information Infrastructure
  3. Hunton Privacy & Cybersecurity Law Blog
  4. China Briefing: China Data Compliance Trends