Connected vehicles have networking, OTA, and camera/positioning capabilities – data cybersecurity has become a hard requirement for vehicle launches. Domestic mandatory national standards apply – overseas exports face UN vehicle regulations – the two systems are not interchangeable – failing either blocks vehicle announcements or overseas market access.
Many companies mistakenly think that having a UN R155 report directly satisfies domestic announcement requirements – others assign data security entirely to IT departments. In reality, compliance work must be involved at the product‑definition stage – embedding security design into the vehicle architecture. Retrofitting late‑stage architecture changes is extremely costly.
GB 44495 and GB 44496 have been amended with Revision No.1 – adjusting implementation dates. GB 44497 maintains its original requirements – new‑application and existing‑production models have different schedules.
1.1 GB 44495-2024 – Vehicle cybersecurity (aligned with UN R155)
·Authentication, access control, communication protection, intrusion detection.
·China no longer has a separate pre‑CSMS certification process – security capability is reviewed together with the vehicle announcement materials.
·New type‑approval applications: mandatory from 1 July 2026.
1.2 GB 44496-2024 – Software update management (aligned with UN R156)
·Full OTA process – update notification, version rollback, exception tolerance, and upgrade‑record retention.
·New type‑approval applications: mandatory from 1 July 2026.
1.3 GB 44497-2024 – DSSAD event data recording
·Does not align with R155/R156.
·Applies only to vehicles with automated driving functions.
·Effective 1 January 2026 – data collection, storage duration, and access controls – for crash investigation.
·Existing announced models follow their own transition periods – no blanket cut‑off.
2. International UN WP.29 Regulations
Exported vehicles must align with UN WP.29 regulations – although some domestic test evidence may be reused, document details and audit focus differ – one set of materials cannot be submitted both ways.
·UN R155 (cybersecurity): adopted by 50+ contracting parties – mandatory for new vehicle types in the EU from 2022. Requires CSMS system certification first – then vehicle‑level VTA cybersecurity approval – a key threshold for many export markets.
·UN R156 (software‑update management): used with R155 – requires a SUMS (Software Update Management System). Similar to GB 44496 in concept – but document format and verification points differ – cannot be directly used for domestic submissions.
Different countries have different adoption statuses and transition periods – verify the latest requirements for your target markets before starting.
3. Data Privacy Compliance – An Independent Track
Passing vehicle‑level technical safety type approval does not mean privacy compliance is met. Privacy constraints mainly apply to head‑unit applications and cloud backends – easily overlooked by vehicle project teams – leading to audit penalties in overseas markets.
·China PIPL: face, voiceprint, location, and driving behaviour are all personal information. Consent, minimisation, and local storage must be implemented – separate from vehicle cybersecurity national standards.
·EU GDPR: for Europe‑bound products – key focus on cross‑border data transfer and user rights. Plan for both PIPL and GDPR at the design stage – late‑stage cloud data‑handling changes are extremely costly.
4. Industry Implementation Standards and Practical Approaches
T/CSAC series group standards are not mandatory – but they provide detailed implementation guidance on penetration testing, vulnerability management, and security deployment. Regulatory audits and supply‑chain client reviews often reference them – aligning early reduces later friction.
Security‑by‑design is not just a slogan – layered protection, intrusion detection, and full‑lifecycle vulnerability management are now project baselines. Waiting until the vehicle is finalised to add security – architecture‑change flexibility is limited – costs multiply.
5. BlueAsia's End‑to‑End Approach
BlueAsia can perform gap assessments between GB 44495/44496 and UN R155/R156 – identifying reusable test items – reducing duplicate testing. We also distinguish DSSAD and privacy‑compliance boundaries – supporting both domestic announcement and overseas export requirements.
6. Common Misconceptions and Practical Reminders
·UN R155 certificates cannot substitute for GB 44495 – localisation requirements and review processes differ.
·GB 44495 and GB 44496 new‑vehicle mandatory date is 1 July 2026 – not all national standards on 1 January 2026. GB 44497 only applies to vehicles with automated driving functions.
·DSSAD (GB 44497) does not align with R155/R156 – it is an independent event‑data recording requirement.
·OTA rollback and upgrade exception tolerance must be designed at the hardware‑architecture stage – late‑stage storage‑partition changes are costly.
·PIPL and GDPR privacy compliance are independent from vehicle type approval – they cannot be covered by cybersecurity national standards or UN regulations.
·Group standards are not mandatory – but supply‑chain audits often reference them – don't ignore them.
For connected vehicle data security compliance, contact BlueAsia at 13534225140 (King) or email king.guo@cblueasia.com.
相关新闻