China’s Cybersecurity Label Takes Effect with First Product Catalogue

On 15 June 2026, the Cyberspace Administration of China(CAC), together with the Ministry of Industry and Information Technology (MIIT) and the Ministry of Public Security (MPS), jointly issued the first product catalogue and the supporting implementation rules under the Measure for the Administration of the China Cybersecurity Labeling (hereinafter referred to the Measures).  Released in April 2026, the Measure took effect on 1 July 2026. The first catalogue covers only one category which is consumer-grade internet-connected cameras, while cameras used in the public security domains are excluded.

The Measures target products with internet connectivity – a feature common to what the EU Cyber Resilience Acts calls “product with digital elements”. Unlike CRA’ s mandatory market-access regime, however, the Chinese scheme operates on the principle of voluntary participation. Products such as Wi-Fi router, servers, and Virtual Private Network (VPN) are not covered, as they are already regulated as Key Network Equipment and Exclusive Cybersecurity Products under a separate catalogue issued and maintained by CAC since 2017.

The Labeling scheme mainly seeks to raise public awareness of cybersecurity and to phase out products with inadequate or outdated security capabilities through market-driven choices rather than mandates.

The implementation rules set out the full procedure for testing, filing and use of the label, and apply primarily to manufacturers and testing laboratories. Products are tested against the TC260 practice guide: TC260-PG-20265A Cybersecurity Labeling: Security Requirements for Consumer Connected Cameras. After passing the tests, manufacturers submit the required documents (including the filing form, test report, label design and declaration of conformity) via the online filing platform operated by the designated filing body, the China Electronics Standardization Institute (CESI). The filing body completes a formal review within 10 working days and publicly announces the filing. The label is valid for 3 years from the date of the announcement; re-testing and re-filing are required if key technical parameters change or the label expires.

One- and two-star products may be tested by the manufacturer’s own lab or a qualified third party, with CNAS accreditation required for self-owned labs at the two-star level; three-star products must additionally pass a third-party penetration test.

The TC260 Practice Guide referenced above was released by the National Technical Committee 260 on Cybersecurity (SAC/TC260). It sets out security technical requirements for each of the three levels across five different capability dimensions:

  • Physical and hardware security: device identification and information, physical interface security, and secure boot.
  • System and software security: password security, identity authentication, critical security parameter protection, cryptographic application, access control, log auditing, firmware security, input validation, and security configuration.
  • Network and communication security: network ports and communication security.
  • Data security and personal information protection: data security and personal information protection.
  • Security assurance: vulnerability management, product lifecycle management, code testing, and penetration testing.

A product must satisfy all individual requirements at a given level to qualify for the corresponding star rating.

The Practice Guide builds its security requirements on 6 national standards developed under SAC/TC260, which are listed below in the order they appear in the document.

  • GB 46864-2025 Data security technology – Technical requirements for information sanitization of electronic products
  • GB/T 25069-2022 Information security techniques – Terminology
  • GB/T 35273-2020 Information security technology – Personal information security specification
  • GB/T 38674-2020 Information security technology – Guideline on secure coding of application software
  • GB/T 39276-2020 Information security technology – General security requirements of network products and services
  • GB/T 45574-2025 Data security technology – Security requirements for processing of sensitive personal information

For European stakeholders, the labeling scheme is best understood as an effort to fill regulatory gaps and mature China’s existing cybersecurity management framework. It targets consumer products and relies on market forces, rather than mandates, to phase out products with inadequate security and raise the baseline of connected devices. Being voluntary, it currently creates no uncertainty for market access.

However, it would be premature to dismiss it as unimportant. The scheme could be designed to scale, with the camera catalogue likely only the first step of an experimentation phase. Tracking its implementation and expansion will therefore be essential to judging its future impact.

SESEC strongly recommends that affected stakeholders study the Practice Guide and the national standards it references, assess whether their products meet the security capability requirements, and prepare early to stay competitive in the Chinese market.

SESEC has prepared an unofficial translation of the Implementation Rules and Practice Guide.

Download them here: SESEC VI Translation – CN CYBER Label Rules and Practice Guide – Consumer Camera

Please email us with any comments or feedback.

Related Posts

You would like to go:

Tags: