How can we help you?

Are there other certification/license requirements for IT products?

Chinese laws and regulations require that, for certain IT/software products, several additional requirements and obligations may apply, including the obtainment of relevant certifications. These may include, for instance:

  • Certification for critical network equipment and network security product, if the product is included in China’s Catalogue of Critical Network Equipment and Network Security Products (网络关键设备和网络安全专用产品目录). The Catalogue currently includes 4 critical network equipment and 11 network security products such as web application firewalls, intrusion prevention and detection systems, information exchange products, security database systems, etc.)
  • Certification for information security products, for 13 types of information security products, largely matching those in for critical network equipment and network security products but with a stronger focus on security. In fact, in most cases the two certifications can be applied for and obtained at the same time.
  • Mandatory cybersecurity review, if a software is to be used by critical information infrastructure operators (CIIOs), entities operating networks with higher level of security, as well as network platform operators with 1+ million users and/or planning to list on foreign markets. The review is conducted based on the provisions of the Cybersecurity Review Measures.
  • Certification for commercial cryptography products, for products with encryption functions (even if encryption is not the core function of the product).