Competition Concerns In Digital Certificate Issuance .

Introduction

Digital certificate issuance is a critical part of China's digital economy. It includes electronic authentication services, digital-signature certificates, enterprise identity certificates, SSL/TLS certificates, government e-certificates, platform authentication certificates, and certificates used in electronic procurement and e-government systems.

The competition issues are distinctive because the market combines technology, trust, accreditation, network effects, regulatory licensing and access to essential digital infrastructure. A certificate authority (CA) that becomes deeply embedded in government procurement, banking, e-commerce or enterprise software can potentially create substantial switching costs for users and competitors.

China's Anti-Monopoly Law (AML), as amended in 2022, prohibits monopoly agreements, abuse of dominant market position and anti-competitive concentrations. Article 22 specifically covers unjustified refusal to deal, exclusivity, tying, unreasonable trading conditions and discriminatory treatment, including conduct using data, algorithms, technology and platform rules.

At the same time, digital-certification markets are heavily regulated. Electronic-authentication service providers require regulatory authorization, while compulsory-certification systems operate through designated bodies and laboratories. Current Chinese certification rules expressly emphasize fair competition, non-discrimination and prevention of abusive dominance.

I. Relevant Market in Digital Certificate Issuance

A competition investigation would normally begin by defining the relevant market.

Possible product markets include:

  1. Electronic authentication services
  2. Digital-signature certificates
  3. Enterprise identity certificates
  4. Government electronic-certification services
  5. TLS/SSL certificates
  6. Specialized industry certificates
  7. Certificate validation and revocation services
  8. Certificate-management software and APIs
  9. Hardware-backed certificate/token services
  10. Certification-related testing and verification

The relevant geographic market could be:

  • China-wide;
  • a particular province or municipality;
  • a government-industry segment; or
  • potentially an international market for certain commercial certificates.

The market-definition exercise is particularly important because a CA may have only a modest share of the broad digital-security market while having considerable market power in a narrowly defined government-procurement, industry-specific or technically interoperable certificate market.

The Supreme People's Court's Qihoo v Tencent decision is particularly relevant because it emphasized that relevant-market definition is a tool for assessing market power and competitive effects rather than an end in itself. It also recognized that conventional price-based analysis may need modification for digital markets.

II. Major Competition Concerns

1. Regulatory Licensing and Barriers to Entry

Digital certificate issuance requires considerable compliance infrastructure.

China's electronic-authentication regime requires qualified providers to obtain the relevant authorization, while compulsory certification operates through designated certification bodies and laboratories. The regulatory framework therefore naturally creates entry barriers.

Such barriers are not automatically anti-competitive because authentication involves security, trust and public-interest considerations.

The competition concern arises if:

  • licensing requirements are unnecessarily restrictive;
  • incumbent CAs receive preferential regulatory treatment;
  • new CAs cannot obtain accreditation on equivalent terms;
  • technical requirements discriminate against particular providers;
  • government bodies effectively reserve markets for particular CAs; or
  • licensing requirements are used to exclude otherwise qualified competitors.

China's current compulsory-certification framework expressly provides for designation according to principles including fair competition, openness, impartiality and effectiveness.

III. Exclusive Government or Platform Designation

A major concern is the designation of one CA as the exclusive certificate provider for a platform, government procurement system or industry.

For example:

A government procurement platform requires all suppliers to obtain certificates exclusively from CA-A even though CA-B and CA-C possess equivalent regulatory qualifications.

The arrangement can produce:

  • foreclosure of competing CAs;
  • artificial switching costs;
  • reduced price competition;
  • dependence on one technological ecosystem;
  • higher certificate-renewal costs; and
  • exclusion of smaller authentication providers.

The 2022 AML specifically prohibits dominant undertakings from requiring trading counterparts to deal exclusively with themselves or designated undertakings without justification.

IV. Tying of Certificates With Other Services

A CA or dominant digital platform might require customers purchasing certificates to also purchase:

  • cybersecurity software;
  • cloud storage;
  • electronic-signature software;
  • identity-verification services;
  • document-management systems;
  • compliance services;
  • enterprise software; or
  • hardware tokens.

This creates a classic tying/bundling concern.

Under Article 22 of the AML, a dominant undertaking cannot engage in tied selling or impose unreasonable trading conditions without justification.

Example

CA-A controls certificates used on a major electronic-procurement platform.

It tells users:

"You may obtain the required certificate only if you also purchase our electronic-signature software."

If CA-A possesses dominance in the certificate market, the arrangement could potentially leverage that position into the software market.

V. Discriminatory Access to Certificate Validation

Certificate issuance is only one component of the ecosystem.

Other competitors may need access to:

  • certificate-validation systems;
  • OCSP services;
  • certificate revocation lists;
  • APIs;
  • identity-verification infrastructure;
  • trust stores;
  • interoperability protocols; and
  • authentication databases.

A dominant provider could potentially disadvantage rivals by:

  • delaying API access;
  • charging discriminatory fees;
  • imposing technically unnecessary requirements;
  • limiting validation frequency;
  • providing better service to affiliated businesses; or
  • refusing interoperability.

Article 22 prohibits unjustified discriminatory treatment among trading counterparts with equivalent conditions.

VI. Refusal to Deal

A dominant CA could potentially refuse to:

  • issue certificates to a competing platform;
  • provide certificate-validation access;
  • renew certificates;
  • provide migration information;
  • supply necessary technical interfaces; or
  • recognize certificates issued by competing providers.

Article 22 expressly addresses unjustified refusal to deal.

However, not every refusal is unlawful.

A CA can have legitimate security reasons for refusing issuance, such as:

  • inadequate identity verification;
  • fraud;
  • compromised credentials;
  • failure to satisfy technical requirements;
  • cybersecurity threats; or
  • statutory restrictions.

The competition question is whether the refusal is objectively justified or is being used as a means of excluding competitors.

VII. Certificate Portability and Switching Costs

Digital certificates can generate significant switching costs.

Businesses may have to:

  • re-register certificates;
  • modify APIs;
  • change software configurations;
  • replace hardware tokens;
  • retrain employees;
  • update trust chains;
  • modify procurement-platform settings; and
  • reconfigure authentication infrastructure.

If a dominant CA deliberately makes migration difficult, competition may be weakened even where competitors technically exist.

This is analogous to the broader digital-platform concern identified by the Supreme People's Court in Qihoo v Tencent, where technological architecture and user dependence were relevant to the assessment of competitive conditions.

VIII. Self-Preferencing

A CA integrated into a broader digital ecosystem could potentially favor its own affiliated products.

For example:

CA → certificate issuance → authentication platform → e-signature platform → cloud service

If the CA gives its affiliated e-signature service:

  • faster authentication;
  • preferential APIs;
  • lower validation fees;
  • greater certificate compatibility; or
  • preferential technical access,

competing e-signature providers may be disadvantaged.

This becomes especially important where the certificate authority is also a platform operator.

IX. Algorithmic and Data-Based Discrimination

Modern certification systems increasingly use automated identity verification, fraud detection and risk scoring.

Potential competition problems include:

  • algorithms rejecting competitors' customers;
  • discriminatory risk thresholds;
  • preferential treatment of affiliated enterprises;
  • use of customer data to disadvantage competing CAs;
  • algorithmically differentiated pricing; and
  • withholding data necessary for interoperability.

The 2022 AML expressly recognizes that abuse of dominance can occur through data, algorithms, technologies and platform rules.

X. Excessive or Discriminatory Pricing

A dominant CA could potentially charge:

  • excessive certificate-renewal fees;
  • discriminatory validation charges;
  • different prices for equivalent customers;
  • high API-access fees;
  • excessive revocation fees; or
  • unreasonable migration charges.

Price discrimination becomes particularly problematic where comparable customers receive materially different commercial terms without objective justification.

XI. Collective Conduct Among Certification Authorities

Several CAs or certification-related service providers could potentially coordinate on:

  • certificate prices;
  • renewal charges;
  • customer allocation;
  • technical standards;
  • market territories;
  • procurement bids;
  • customer restrictions; or
  • exclusion of new entrants.

China's AML prohibits monopoly agreements between competing undertakings, including agreements concerning prices, market allocation, restriction of technology and joint boycotts.

Therefore, a trade association of certification providers should be cautious about coordinating commercial terms under the guise of technical standardization.

XII. Standard-Setting and Certification

Standards can create both pro-competitive interoperability and anti-competitive exclusion.

A dominant participant may attempt to ensure that:

  • only its certificate format is recognized;
  • competing certificates cannot be technically validated;
  • alternative security technologies are excluded;
  • rivals cannot participate in standard-setting; or
  • certification testing is available only through affiliated organizations.

Chinese antitrust policy concerning standard-essential patents recognizes competition concerns where firms are excluded from standard-setting or from standard-related testing and certification activities without adequate justification.

This principle can be relevant by analogy to digital certificate standards.

XIII. Administrative Monopoly and Government Procurement

This is particularly important in China.

Competition problems can arise not only from private CA conduct but also from administrative measures favouring particular certification providers.

The AML prohibits administrative organs from:

  • requiring businesses to purchase from designated undertakings;
  • excluding non-local undertakings;
  • imposing discriminatory qualification requirements;
  • restricting participation in bidding; or
  • adopting regulatory measures that eliminate or restrict competition. 

Therefore, a government procurement specification stating:

"Only certificates issued by CA-X will be accepted"

could raise competition concerns if there is no objective technical or security justification.

XIV. Six Important Case Laws

A significant qualification is necessary: Chinese reported case law specifically concerning antitrust abuse in digital-certificate issuance is still limited. Accordingly, the following cases are the most useful Chinese authorities by direct relevance or close analogy, rather than six cases all involving CA issuance itself.

1. Qihoo 360 v Tencent — Guiding Case No. 78

Beijing Qihoo Technology Co., Ltd. v Tencent Technology (Shenzhen) Co., Ltd. & Shenzhen Tencent Computer System Co., Ltd.

Principle

The Supreme People's Court dealt with dominance and relevant-market definition in a digital environment.

The Court emphasized:

  • relevant-market definition is a tool rather than an end;
  • digital markets may require approaches different from traditional markets;
  • market share alone is insufficient;
  • entry conditions and competitive constraints matter; and
  • direct evidence of competitive effects can be important.

 

Relevance to digital certificates

A CA's market power should not necessarily be assessed by looking only at its overall cybersecurity-market share.

A narrowly defined market—such as certificates accepted by a particular government platform—may need separate analysis.

2. Wu Xiaoqin v Shaanxi Radio & Television Network

Guiding Case No. 79

This case concerned alleged tying/bundling by a dominant cable-television operator.

The Supreme People's Court's Guiding Case database identifies the case as involving bundled transactions, dominance and tied sales.

Relevance

The principle can be applied to a digital-certification scenario:

Certificate + mandatory e-signature software
Certificate + mandatory cloud service
Certificate + mandatory cybersecurity product

The critical question would be whether the additional product is genuinely necessary or is being imposed through market power.

3. Alibaba Group — SAMR Antitrust Decision, 2021

SAMR found Alibaba responsible for an abuse involving the requirement that merchants choose between Alibaba and competing platforms, commonly described as "choose one from two."

The decision resulted in an RMB 18.228 billion penalty.

Relevance

The case demonstrates China's willingness to examine exclusivity imposed through a powerful digital platform.

In certificate markets, an analogous concern could arise where:

"If you use our certificate, you cannot use another CA."

The legality would depend on dominance, competitive effects and justification.

4. Meituan — SAMR Antitrust Enforcement, 2021

Meituan's conduct was examined in China's broader digital-platform antitrust enforcement, particularly concerning restrictions on merchants and platform competition.

Relevance to certification

The case is useful for understanding how platform ecosystems can create lock-in and exclusionary effects.

A digital certificate provider embedded in:

  • payment systems,
  • e-commerce,
  • enterprise software,
  • electronic signatures, and
  • procurement platforms

could potentially use ecosystem power to disadvantage competing authentication providers.

The broader Chinese digital-economy enforcement framework expressly targets exclusionary practices involving platform rules, data and technology.

5. Qualcomm — China NDRC Antitrust Decision, 2015

The Qualcomm case involved alleged abuse of dominance in relation to licensing of standard-essential patents and related commercial conditions.

The case is important to Chinese competition-law analysis because it illustrates how technology, standards, licensing and market power can intersect.

Relevance

Digital certificate systems similarly depend upon technical standards and trusted infrastructure.

A dominant certification provider could potentially use control over:

  • proprietary technology;
  • technical standards;
  • validation infrastructure; or
  • essential interfaces

to impose unreasonable conditions on downstream competitors.

Chinese scholarship identifies Qualcomm and Huawei-related disputes among the important Chinese experiences at the intersection of antitrust and technology/IP.

6. Huawei v IDC

Huawei Technologies Co. Ltd. v InterDigital (IDC)

This dispute concerned standard-essential patents and allegations involving licensing conditions.

Relevance

The broader principle concerns the interaction between technology standards, access and discriminatory licensing conditions.

That is relevant where digital-certification infrastructure becomes standardized and one provider controls an indispensable technological interface.

The Huawei/IDC experience is commonly discussed in the Chinese literature concerning antitrust regulation of standard-essential technology.

XV. Additional Relevant Digital-Certificate Judicial Material

There is also an important Chinese judicial decision directly concerning digital certificate issuance, although it is not an antitrust case.

Wang v Ministry of Industry and Information Technology — Beijing High People's Court

The Beijing High People's Court considered a dispute concerning the issuance of a digital certificate and the regulatory investigation of an electronic-authentication service provider.

The Court noted that the provider had used intermediaries in the certificate-application process and that regulatory authorities had identified deficiencies concerning:

  • application procedures;
  • notification of applicants;
  • contractual arrangements; and
  • certificate issuance processes.

The court upheld the regulatory response.

Competition significance

Although this is not an AML case, it demonstrates that certificate issuance is a regulated market in which:

  • access procedures,
  • contractual relationships,
  • verification processes,
  • intermediary arrangements, and
  • regulatory compliance

can materially affect the competitive environment.

XVI. Competition Analysis Matrix

ConductPotential Competition ConcernRelevant Chinese Legal Principle
Exclusive CA appointmentForeclosureAbuse of dominance / administrative monopoly
Mandatory CA selectionCustomer lock-inArticle 22 / administrative-power provisions
Certificate + software bundleTyingArticle 22
Refusal to issue certificatesForeclosureRefusal to deal
Refusal of validation APIEssential-access concernRefusal to deal
Discriminatory API feesRival disadvantageDiscriminatory treatment
Excessive renewal feesExploitative conductUnfair pricing
Local-only certificate acceptanceGeographic foreclosureAdministrative monopoly
Exclusive procurement contractsMarket foreclosureMonopoly agreement / dominance
CA mergerIncreased concentrationMerger control
Algorithmic customer discriminationDigital exclusionArticle 22
Exclusive technical standardsInteroperability restrictionAML + standards/IP principles
Restrictive certificate migrationSwitching-cost exploitationAbuse of dominance
Joint CA pricingCartel riskMonopoly agreement
Customer allocation among CAsMarket sharingMonopoly agreement
Affiliated-service preferential accessSelf-preferencingAbuse of dominance

XVII. Role of Certification Regulation

Competition law cannot be considered separately from certification regulation.

China's compulsory-certification framework provides for designated certification bodies and laboratories, and the current rules expressly require fair competition and prohibit discrimination against applicants.

The 2026 implementation rules are particularly significant because they expressly state that designated certification bodies must not abuse a dominant position by:

  • limiting testing to specific designated laboratories;
  • imposing unreasonable additional conditions;
  • applying differential treatment; or
  • bundling voluntary certification or other services with compulsory certification.

They also require certification fees to be calculated and publicly disclosed in accordance with fair-competition requirements.

These provisions are highly relevant to digital-certification competition because they show an explicit regulatory concern with bundling, discrimination, laboratory access and dominance within certification ecosystems.

XVIII. Competition Issues in Government Digital Certificates

Government digital certificates deserve separate treatment.

Potential concerns include:

A. Exclusive government CA

One provider receives exclusive access to an entire government system.

B. Discriminatory recognition

Certificates from competing providers are technically valid but not accepted by government platforms.

C. Local protectionism

A provincial authority accepts only certificates issued by a local provider.

D. Procurement discrimination

Tender requirements are designed around a particular CA's proprietary technology.

E. Interoperability restrictions

A government platform refuses to implement common standards that would allow alternative certificates.

F. Renewal lock-in

Businesses must repeatedly purchase certificates from the original provider even though equivalent providers are available.

These issues can potentially engage both Article 22 abuse-of-dominance rules and Chapter V rules concerning administrative power.

XIX. Merger-Control Concerns

Consolidation among CAs can create additional risks.

Suppose:

CA-A + CA-B → 70% of certificates used by Chinese financial institutions

The transaction could potentially increase:

  • certificate prices;
  • switching costs;
  • dependency on one trust infrastructure;
  • barriers to entry;
  • access restrictions; and
  • interoperability problems.

China's AML permits merger review where a concentration may eliminate or restrict competition, including consideration of market shares, concentration, entry barriers, technological development and effects on consumers and other undertakings.

The digital nature of certificate markets also means that data and network effects may matter even where current revenue-based market shares appear modest.

XX. Defences and Legitimate Business Justifications

Not every restrictive practice by a CA violates competition law.

Possible legitimate justifications include:

  1. Cybersecurity requirements
  2. Fraud prevention
  3. Identity-verification requirements
  4. Protection of private keys
  5. National-security requirements
  6. Regulatory licensing
  7. Technical interoperability
  8. Protection against compromised certificates
  9. Data-security requirements
  10. Prevention of certificate misuse

For example, refusing to issue a certificate because the applicant failed mandatory identity verification is fundamentally different from refusing to issue certificates because the applicant also uses a competing CA.

The competition assessment must therefore distinguish security-driven restrictions from exclusionary restrictions.

XXI. Compliance Measures for Digital Certificate Providers

A CA operating in China should consider:

1. Non-discrimination policy

Equivalent customers should receive equivalent commercial and technical treatment.

2. Interoperability

Use recognized standards wherever reasonably possible.

3. Transparent pricing

Certificate, renewal, revocation and API charges should be objectively explainable.

4. No unjustified exclusivity

Avoid unnecessarily restricting customers from using competing authentication services.

5. Separate bundled services

Do not make unrelated products compulsory merely because the CA controls certificate issuance.

6. API-access policy

Maintain transparent and objective access criteria.

7. Procurement compliance

Government tender requirements should not artificially favour one CA.

8. Competition review of standards

Technical committees should avoid exclusionary standard-setting.

9. Algorithmic neutrality

Automated authentication and risk systems should not improperly discriminate against competitors.

10. Merger review

Potential acquisitions of competing CAs or complementary identity platforms should receive antitrust review.

XXII. Conclusion

Digital certificate issuance in China occupies a particularly sensitive position at the intersection of competition law, cybersecurity, electronic signatures, digital identity, accreditation and government regulation.

The principal competition concerns are:

  • exclusive CA arrangements;
  • regulatory barriers to entry;
  • refusal to deal;
  • discriminatory access;
  • certificate-validation API restrictions;
  • tying and bundling;
  • excessive or discriminatory fees;
  • technical lock-in;
  • self-preferencing;
  • anti-competitive standard-setting;
  • government procurement discrimination;
  • administrative monopoly; and
  • anti-competitive consolidation of certification providers.

The most important Chinese authorities for constructing the legal analysis are Qihoo v Tencent (Guiding Case No. 78), Wu Xiaoqin v Shaanxi Radio & Television Network (Guiding Case No. 79), Alibaba, Meituan, Qualcomm, and Huawei v IDC, supplemented by the Chinese judicial material specifically concerning digital-certificate issuance. The first two are especially useful for market definition and tying, while the platform and technology cases provide analogies for exclusivity, ecosystem leverage, standards and technology-based exclusion.

LEAVE A COMMENT