Skip to main content

Which websites must enable HTTPS encryption?

In today's era where cybersecurity is highly valued, deploying an SSL certificate on a website is a critical step to improve website security. It enables HTTPS encryption and trusted identity authentication, prevents the leakage or tampering of transmitted data, and effectively ensures the security of data in transit. The following are websites that must enable HTTPS encryption:

1. E-government portal websites

According to the Provisions on the Security Management of Internet Government Applications, portal websites established by government institutions and public institutions on the internet shall be accessed via secure connection methods.

2. E-commerce platforms and their payment system websites

E-commerce platforms and their payment systems involve a large amount of sensitive information, including user information, order information, payment information, etc. In accordance with the Cybersecurity Law, the Data Security Law, and the PCI/DSS data security standard for the third-party payment industry, data encryption must be implemented on the platforms to prevent data tampering or leakage.

3. Banking institutions and financial websites of all sizes

Banking institutions and financial websites of all sizes involve large volumes of personal information, financial information and financial data. Pursuant to the Notice on Strengthening the Management of Mobile Internet Applications in the Banking and Insurance Industries, financial institutions must adopt encryption methods for data transmission to prevent security risks such as data leakage and data tampering.

4. Education and training websites

Education and training websites involve a large amount of sensitive student information and educational data resources. In accordance with the Measures for the Management of Educational Data of the Ministry of Education Organs and Directly Affiliated Public Institutions and the Notice on Effectively Completing the Conversion of Existing Online Discipline Training Institutions from Filing to Approval, data guarantee mechanisms for links such as data transmission and use must be established.

5. Academic and technology service platforms

Academic and technology service platforms involve large volumes of data such as academic literature, research data, scholar information, scientific research institution information, and user information. In accordance with the Cybersecurity Law, the Data Security Law, the Personal Information Protection Law, and the data security requirements for academic and technology service platforms, such platforms must fulfill data security obligations, adopt technical measures to protect the integrity and confidentiality of data transmission, and prevent data tampering and leakage.

6. Medical and health websites

The medical and health field involves sensitive data such as patient information and clinical research data. In accordance with the HIPAA Act, China's Measures for the Cybersecurity Management of Medical and Health Institutions, and the Information Security Technology - Guide for Health and Medical Data Security, secure transmission methods must be adopted to ensure the confidentiality and integrity of data transmission and prevent data from being stolen or tampered with.

7. Enterprise websites across all industries

In accordance with relevant laws and regulations such as the Cybersecurity Law and the Data Security Law, enterprises must fulfill their data security protection obligations, take corresponding technical measures and other necessary measures to safeguard data security, and prevent data leakage or tampering.

8. Community and forum websites

Community and forum websites involve the transmission of sensitive information such as personal information. In accordance with the Cybersecurity Law, the Data Security Law, and the Personal Information Protection Law, necessary measures must be taken to protect personal information security and prevent data leakage or tampering.