Skip to content
Crypto2026-10-03Begin3 min read

Chinese Cryptographic Assessment (Miping) Self-Check Checklist: GB/T 39786, Layer by Layer

What miping actually is

Commercial cryptography application security assessment (商用密码应用安全性评估, "miping"), governed by GB/T 39786-2021, evaluates whether an information system uses cryptography compliantly, correctly and effectively. For MLPS level-3+ systems and critical information infrastructure it is becoming mandatory — running parallel to MLPS evaluation, but focused on "is cryptography used, and used right."

The verdict has four grades: compliant, basically compliant, non-compliant. Even "basically compliant" requires an overall score threshold with zero high-risk findings — and most systems fall short on a handful of quantitative items you can self-check before submitting.

The framework: 4+1 layers

GB/T 39786 splits requirements into four technical layers plus one management layer. Walk them one by one:

1. Physical and environmental security

  • Machine-room access uses cryptographic identity authentication (door access)
  • Video surveillance records cryptographically protected (integrity/confidentiality)
  • Authentication data encrypted in storage and transit

Common finding: legacy IC-card door systems without crypto modules — low weight; most assessors accept explanatory documentation.

2. Network and communication security

  • Communication confidentiality: SM-algorithm encrypted channels (TLCP/guomi HTTPS)
  • Communication integrity: MAC/signature protection
  • Mutual authentication between communicating parties (certificates)
  • Channel built on certified cryptographic products

Common finding: this layer is the disaster zone — plain TLS 1.2 with international certificates does not count; you need SM2 dual certificates with TLCP or RFC 8998. See the guomi HTTPS deployment guide.

3. Device and computing security

  • Remote administration channel encrypted (SSH versions / guomi retrofit)
  • Integrity protection for access-control information (e.g. config files)
  • Log record integrity (tamper-evident)
  • Integrity verification of critical executables

Common finding: log tamper-proofing is broadly missing — an SM3 digest chain works (the SM3 digest tool is handy for PoCs).

4. Application and data security (highest weight)

  • User authentication: passwords salted and hashed (no plaintext/reversible encryption; salted SM3)
  • Critical data confidentiality in transit: credentials, business payloads
  • Critical data confidentiality at rest: sensitive database fields
  • Critical data integrity at rest/transit: SM3/HMAC-SM3
  • Non-repudiation for declared critical operations: digital signatures (SM2 sign/verify)
  • Automated detection of unauthorized modification

Common finding: passwords still unsalted MD5 (an instant high-risk item); sensitive fields in plaintext; signatures enabled on only some interfaces.

5. Management layer (the paperwork four)

  • Cryptography management system (documented and actually followed)
  • Personnel: separation of duties for key management
  • Implementation: planning/construction/operation phase documents
  • Contingency: crypto incident response plan plus drill records

Management points are cheap: documents and records, far less costly than technical retrofit.

Three quantitative red lines (instant-veto territory)

  1. Algorithm compliance: SM2/SM3/SM4 (or approved international-algorithm scenarios) — DES/MD5 in new systems loses heavy points
  2. Product compliance: cryptographic products (HSMs/gateways/USB keys) must carry commercial-cryptography product certification
  3. Key management compliance: full lifecycle — generation, distribution, storage, rotation, destruction. Hardcoded keys are the classic high-risk finding

Suggested remediation order before submitting

Ranked by points-per-effort: application-layer crypto retrofit > network-layer guomi channel > log integrity > management documents > physical environment. Application-layer work (password hashing, field encryption, interface signatures) typically takes days to two weeks; network-layer guomi HTTPS follows the Tongsuo guide; physical environment usually passes with explanatory materials.

Implementer's note

Cross-checking the on-site guomi toolchain while writing this: the structural comparison of SM3 versus SHA-256 (Merkle–Damgård construction, 256-bit output) is expanded in a separate article; SM2 sign/verify runs in the browser via sm-crypto, so verifying ciphertext ordering (C1C3C2) during retrofit integration needs no backend environment — the PoC phase can run entirely on the tool page. The mapping of standard numbers (GM/T vs GB/T vs ISO/IEC) is the easiest thing to get wrong when citing standards in assessment paperwork.