On August 21, 2026, the Ministry of Industry and Information Technology (MIIT) released a draft mandatory national standard titled Technical requirements for vehicle cryptography application for public comment. The consultation, organized by the Equipment Industry Division I under the MIIT and coordinated by the National Technical Committee of Auto Standardization (SAC/TC114), runs from August 21 to October 20, 2026.
The draft standard, numbered 20243883-Q-339, is jointly administered by MIIT and the National Cryptography Administration and executed by TC114 SC34, the Intelligent Connected Vehicle Subcommittee. It applies to Category M and N vehicles, with relevant components implementing cryptographic functions also encouraged to comply. The standard specifies technical requirements and test methods for automotive cryptography across four key areas: general requirements, system security, communication security, and data security.
The security boundary of intelligent connected vehicles is extending from physical space to cyberspace, and cryptography serves as the strategic cornerstone for building an intrinsic security defense system. To implement the Cryptography Law and other relevant laws and regulations, MIIT and the National Cryptography Administration are jointly advancing the development of the above-mentioned mandatory standard. Meanwhile, automotive cryptography application faces three prominent contradictions: inconsistent selection of algorithms and modules, incomplete scenario coverage, and weak full-lifecycle key management.
Against this background, the standard aims to define the overall framework and security requirements for automotive cryptography application, covering the entire process of design, development, testing, and validation. It will provide an authoritative basis for compliant cryptography application in the industry, guide the standardized, systematic, and industrialized development of automotive cryptography security technology, and support the secure, controllable, high-quality, and sustainable development of China’s intelligent connected vehicle industry.
According to the drafting notes, it is proposed to take effect on January 1, 2029, with new type approvals required to comply from the implementation date and already-approved models given a 25-month transition period. For European automotive stakeholders, the introduction of this standard marks the establishment of an independent compliance framework for cryptography application in intelligent connected vehicles in China. Companies are advised to monitor the finalization of the standard and subsequent testing and certification requirements, and to assess the potential impact on product design and supply chains in light of their own market strategies.
Source: https://wap.miit.gov.cn/gzcy/yjzj/art/2026/art_86c17feda8e0436798049b8eb3694658.html