Three National Standards for Automotive Cybersecurity and Data Protection Proposed

On July 24, 2026, the Department of Science and Technology of China’s Ministry of Industry and Information Technology (MIIT) released for public comment three voluntary national standard drafts for approval targeting critical areas of automotive cybersecurity and data governance. These documents include:

  • 20243206-T-339 Evaluation for categorization and classification of vehicle security vulnerability
  • 20243203-T-339 Requirements for vehicle data security assurance
  • 20250941-T-339 Technical specifications of cybersecurity for vehicle chip

All three standard drafts were developed and managed by the National Technical Committee of Auto Standardization (SAC/TC114). The public comment period ran from July 25 to July 31, 2026, and has now concluded. With final ratification now pending, the following outlines the core focus of each standard.

20243206-T-339 establishes overarching principles and an evaluation indicator system for classifying and grading automotive security vulnerabilities. It details classification rules, evaluation content, and assessment methodologies, while also specifying the rules for determining evaluation indicator values and the procedures for forming evaluation results. This standard is applicable to organizations conducting vulnerability classification and grading evaluations across activities such as vulnerability management, technology R&D, product manufacturing, and security operations.

Moreover, 20243203-T-339 sets forth comprehensive requirements for organizational data security management, data security management involving relevant parties, full lifecycle data protection, data security monitoring and incident response, data security engineering, and data security risk assessment. Applicable to all automotive data processors, it also provides corresponding inspection methods to verify compliance with each of these requirements.

20250941-T-339 is applicable to automotive chips equipped with hardware-based security protection mechanisms. It specifies technical requirements and test methods for such chips, and provides an analytical methodology for deriving automotive chip information security requirements. This is achieved by decomposing and refining the information security requirements of vehicle components, and subsequently mapping the resulting chip-level security requirements onto multiple information security functions, thereby ensuring that the security functions embedded in the chip effectively fulfill the corresponding security requirements.

For European stakeholders, while these three recommended standards do not constitute mandatory market access barriers, they signal that China’s automotive safety regulations are rapidly evolving. European chip suppliers and vehicle manufacturers would benefit from proactively understanding and referencing these standards in their compliance preparations, which may help reduce future technical adaptation costs. Relevant industry bodies are also advised to monitor their further developments.

 

Source: https://std.miit.gov.cn/#/ShowGbNoticeBPDetailsXd/3

https://mp.weixin.qq.com/s/bfwxrHk9KbLDqNtYmcO_Ew

Please email us with any comments or feedback.

Related Posts

You would like to go:

Tags: