New measures entered into force
What changed on 1 July 2026
China's Measures for the Administration of the Use of Cryptography in Electronic Certification Services (Order No. 6 of the State Cryptography Administration) took effect on 1 July 2026. The measures replace the earlier cryptography-management rules for electronic certification services. They apply to the use of commercial cryptography by electronic certification service providers in mainland China. They do not amend China's Electronic Signature Law, invalidate electronic contracts signed before July 2026, or require every company that buys eSignature software to obtain a CA licence.
Existing licensees must submit their compliance assessment
Validity period of the cryptography-use licence
Minimum frequency for cryptography compliance assessment
The six controls introduced or clarified by the new measures
The regulation focuses on the security and governance of cryptography inside electronic certification services.
Providers using commercial cryptography for electronic certification must obtain an Electronic Certification Service Cryptography Use Licence from the State Cryptography Administration.
Electronic certification systems and other relevant facilities must be located in China and comply with applicable national cryptography standards.
Applicants must demonstrate suitable premises, facilities, qualified personnel, professional capability, and a documented management system.
Material changes to the licensed entity or certification system can trigger a licence-change procedure and further review.
Licensees must complete a cryptography compliance assessment at least once a year, remediate findings, and report to the relevant provincial authority.
Technical and security personnel must receive at least 20 hours of cryptography security and role-specific training each year.
China's two related licences answer different questions
Electronic certification service licensing and cryptography-use licensing are connected, but they are not interchangeable.
Electronic Certification Service Licence
Issued under the electronic certification service regime supervised by the Ministry of Industry and Information Technology (MIIT). It authorises a named legal entity to provide third-party electronic certification services to the public.
Electronic Certification Service Cryptography Use Licence
Issued by the State Cryptography Administration. It addresses whether the named provider's certification system, cryptographic facilities, personnel, operating controls, and management framework meet the requirements for using commercial cryptography.
What enterprises should take from this
Do not accept a generic claim that a platform is 'CA compliant'. Ask which legal entity issues the certificate, which licences it holds, whether they are current, and how that entity appears in the signer agreement and evidence package.
Do not collapse the regulation and the business-rule standard into one document
Two related 2026 developments are often described together in vendor materials, but they have different legal status and deadlines.
State Cryptography Administration Order No. 6
This is the national regulation that took effect on 1 July 2026. It governs the use of commercial cryptography in electronic certification services. Its official implementation notice gives pre-existing cryptography-use licensees until 30 September 2026 to submit a compliance assessment.
T/CQAE 11034-2025
This is an industry association standard for electronic certification business rules, not the text of Order No. 6 and not an amendment to the Electronic Signature Law. It provides more operational detail around certification-service processes and is used in 2026 vendor compliance reviews.
Why the distinction matters
A June or July operational-remediation date cited in a vendor campaign should not replace the 30 September deadline stated in the State Cryptography Administration's official implementation notice. Legal teams should record the source, issuing body, legal status, and affected entity for every requirement.
Four workflow controls to test in an electronic certification review
e签宝's 2026 compliance materials use these four checkpoints to translate certification-business rules into an enterprise workflow review. They are useful procurement questions, but should be mapped to the relevant regulation, standard, certificate level, and service design.
CA-direct identity review: establish whether the licensed certification entity performs the required identity and certificate-application checks, and whether any delegated role is permitted and documented.
CA-direct subscriber agreement: confirm that the certificate subscriber receives and accepts the certification-service terms from the responsible CA, with clear rights, responsibilities, risks, and service information.
Evidence of intent: retain proof that the signer knowingly requested or used the certificate and intended the relevant signing action, using controls appropriate to the assurance level and transaction risk.
Private-key control: document where signing keys are generated and managed, who can invoke them, what authorisation applies to hosted signing, and which event records can be exported for audit or dispute resolution.
The 2026 implementation timeline
The transition obligations fall mainly on electronic certification service providers, while enterprise customers should use the period to validate their trust chain.
30 May 2026: Order No. 6 was issued
The State Cryptography Administration published the revised measures after their approval on 13 April 2026.
1 July 2026: the new measures took effect
New applications follow the revised requirements, and the earlier 2009 measures, as amended in 2017, were repealed.
By 30 September 2026: existing licensees report
Entities licensed before 1 July must assess their compliance against the new measures, remediate identified issues, and submit the assessment report to the relevant provincial cryptography authority.
Ongoing: annual assessment and operational controls
Licensees must maintain secure operations, complete at least one compliance assessment each year, address findings, and keep personnel training current.
What contract, procurement, and security teams should verify
Identify the certificate issuer
Record the full legal name of the CA that issues certificates for each signing method. The vendor brand, software platform, registration authority, and licensed CA may be different entities.
Check both licensing layers
Verify the CA's MIIT electronic certification service licence and its State Cryptography Administration cryptography-use licence, including validity and the certification system covered.
Inspect the signer and certificate journey
Confirm how identity is verified, how certificate terms are presented and accepted, where keys are generated or controlled, and what proof is retained for each step.
Export the complete evidence package
A completed workflow should preserve the signed file, certificate information, signer authentication events, consent and intent evidence, timestamps, delivery records, and tamper-evident audit history.
Separate document validity from provider compliance
A provider's licensing obligation and the enforceability of a particular electronic contract are related but not identical questions. Contract validity still depends on the document type, the parties' intent, the reliability of the signature method, and the available evidence.
Licensed CA capability inside the e签宝 China ecosystem
eSign.AI's mainland China capability is supported by e签宝's domestic electronic-signature infrastructure. First Financial (Yicai) reported that e签宝 obtained an Electronic Certification Service Licence from MIIT in October 2024 and an electronic-government CA qualification from the State Cryptography Administration in December 2025. Earlier MIIT-published material also lists Hangzhou Tiangu Information Technology Co., Ltd. (杭州天谷信息科技有限公司), a CA entity in the e签宝 China ecosystem, among licensed CA institutions. In procurement and legal documentation, the licence number, current holder, covered system, and validity period should be verified against the certificate rather than inferred from the brand name alone.
China-native electronic signature services
The e签宝 platform supports identity verification, digital certificate application, electronic seals, online signing, contract management, and signing evidence for mainland China workflows.
A connected certification and signing chain
The China operation can bring CA capability, identity checks, certificate services, electronic seals, signing controls, timestamps, evidence retention, and verification records into one documented operating chain instead of treating the signing screen as the whole service.
Deployment and integration choices
The China offering supports SaaS, API integration, dedicated-cloud arrangements, and local deployment patterns for organisations with different data-location, system-integration, and document-storage requirements.
Compliance review and migration support
e签宝's 2026 China programme covers current-state diagnosis, review of provider and evidence-chain risks, remediation priorities, signing-system upgrades, historical-data migration, and workflow training. The scope should be agreed against the customer's actual certificate issuer, deployment model, and document types.
Cross-border workflow continuity
eSign.AI can connect China-compliant signing methods with cross-border agreement workflows, while preserving the jurisdiction-specific certificate and evidence trail used by each signer.
China eSignature regulation: specific articles and thresholds
Article-level citations for compliance verification.
Electronic Signature Law key articles
Article 13: reliability standard (four conditions). Article 14: reliable electronic signatures have the same legal effect as handwritten signatures. Article 15: electronic certification service providers must obtain a licence from the SCA. Article 21: certificate content requirements (holder name, serial number, validity period, public key). Article 27: liability of CA for failure to verify identity.
2026 SCA Implementation Measures timeline
Effective 1 July 2026. Key deadlines: 1 July 2026 - new CA licence applications must meet updated capital ($14M minimum) and personnel requirements. 1 January 2027 - all existing CA systems must pass updated security audit (GB/T 37092 Level 3). 1 July 2027 - cross-border signing data must be stored in mainland China for at least 6 months.
Common questions about the 2026 rules
No. The new measures directly regulate entities that use commercial cryptography to provide electronic certification services. A workflow platform may integrate with a separately licensed CA. Buyers should establish which entity performs each regulated function and how the relationship is disclosed to signers.







