Chinese Cryptographic Assessment (Miping) Self-Check Checklist: GB/T 39786, Layer by Layer
What miping actually is
Commercial cryptography application security assessment (商用密码应用安全性评估, "miping"), governed by GB/T 39786-2021, evaluates whether an information system uses cryptography compliantly, correctly and effectively. For MLPS level-3+ systems and critical information infrastructure it is becoming mandatory — running parallel to MLPS evaluation, but focused on "is cryptography used, and used right."
The verdict has four grades: compliant, basically compliant, non-compliant. Even "basically compliant" requires an overall score threshold with zero high-risk findings — and most systems fall short on a handful of quantitative items you can self-check before submitting.
The framework: 4+1 layers
GB/T 39786 splits requirements into four technical layers plus one management layer. Walk them one by one:
1. Physical and environmental security
- Machine-room access uses cryptographic identity authentication (door access)
- Video surveillance records cryptographically protected (integrity/confidentiality)
- Authentication data encrypted in storage and transit
Common finding: legacy IC-card door systems without crypto modules — low weight; most assessors accept explanatory documentation.
2. Network and communication security
- Communication confidentiality: SM-algorithm encrypted channels (TLCP/guomi HTTPS)
- Communication integrity: MAC/signature protection
- Mutual authentication between communicating parties (certificates)
- Channel built on certified cryptographic products
Common finding: this layer is the disaster zone — plain TLS 1.2 with international certificates does not count; you need SM2 dual certificates with TLCP or RFC 8998. See the guomi HTTPS deployment guide.
3. Device and computing security
- Remote administration channel encrypted (SSH versions / guomi retrofit)
- Integrity protection for access-control information (e.g. config files)
- Log record integrity (tamper-evident)
- Integrity verification of critical executables
Common finding: log tamper-proofing is broadly missing — an SM3 digest chain works (the SM3 digest tool is handy for PoCs).
4. Application and data security (highest weight)
- User authentication: passwords salted and hashed (no plaintext/reversible encryption; salted SM3)
- Critical data confidentiality in transit: credentials, business payloads
- Critical data confidentiality at rest: sensitive database fields
- Critical data integrity at rest/transit: SM3/HMAC-SM3
- Non-repudiation for declared critical operations: digital signatures (SM2 sign/verify)
- Automated detection of unauthorized modification
Common finding: passwords still unsalted MD5 (an instant high-risk item); sensitive fields in plaintext; signatures enabled on only some interfaces.
5. Management layer (the paperwork four)
- Cryptography management system (documented and actually followed)
- Personnel: separation of duties for key management
- Implementation: planning/construction/operation phase documents
- Contingency: crypto incident response plan plus drill records
Management points are cheap: documents and records, far less costly than technical retrofit.
Three quantitative red lines (instant-veto territory)
- Algorithm compliance: SM2/SM3/SM4 (or approved international-algorithm scenarios) — DES/MD5 in new systems loses heavy points
- Product compliance: cryptographic products (HSMs/gateways/USB keys) must carry commercial-cryptography product certification
- Key management compliance: full lifecycle — generation, distribution, storage, rotation, destruction. Hardcoded keys are the classic high-risk finding
Suggested remediation order before submitting
Ranked by points-per-effort: application-layer crypto retrofit > network-layer guomi channel > log integrity > management documents > physical environment. Application-layer work (password hashing, field encryption, interface signatures) typically takes days to two weeks; network-layer guomi HTTPS follows the Tongsuo guide; physical environment usually passes with explanatory materials.
Implementer's note
Cross-checking the on-site guomi toolchain while writing this: the structural comparison of SM3 versus SHA-256 (Merkle–Damgård construction, 256-bit output) is expanded in a separate article; SM2 sign/verify runs in the browser via sm-crypto, so verifying ciphertext ordering (C1C3C2) during retrofit integration needs no backend environment — the PoC phase can run entirely on the tool page. The mapping of standard numbers (GM/T vs GB/T vs ISO/IEC) is the easiest thing to get wrong when citing standards in assessment paperwork.
Related Tools
Related Articles
Guomi HTTPS Deployment Guide: TLCP Protocol, SM2 Dual Certificates, and nginx with Tongsuo
The full picture of cryptographic-compliance HTTPS: why TLCP (GB/T 38636) needs two SM2 certificates, the mainline steps to build nginx with Tongsuo, dual-stack coexistence with regular Chrome, and the three failure modes assessors hit most.
GB/T 32907, GM/T 0004, RFC 8998: Decoding the Standard Numbers Behind SM2/SM3/SM4
A decoder ring for the standard numbers that come with every Chinese national crypto requirement: which GM/T number became which GB/T standard, where ISO/IEC and RFC 8998 fit in, and what each document actually specifies for SM2, SM3 and SM4.
SM2/SM3/SM4 in Practice: Choosing, Integrating, and Debugging Chinese National Cryptography
A field guide to Chinese national crypto algorithms: when SM4 vs SM3 vs SM2 applies, why ciphertext mismatches happen in integration, the debug order that resolves 90% of SM4 failures, and the key-management line you must never cross.