Since GB44495 and GB44496 took effect on 1 July 2026, I've been answering the same question daily: "How long is the test report valid? Do we need annual audits?"
First, clarify a widely confused concept: GB44495 and GB44496 are mandatory national standard test items – they are not independent certification systems. What you receive are test reports plus information security management system verification results – these are submitted as part of the whole-vehicle Road Motor Vehicle Manufacturer and Product Announcement access materials. The widely used terms "GB44495 certificate" and "GB44496 certificate" – strictly speaking, no such independent certificates exist.
So validity breaks into three layers: the supporting validity of the test report itself, the maintenance of the vehicle announcement status, and ongoing compliance obligations.
After the type-approval test reports pass, the manufacturer submits them for announcement申报. The announcement is reviewed by MIIT's Department of Equipment Industry (first department) and executed by the Equipment Industry Development Centre. After approval, the vehicle type is included in the announcement catalogue.
The announcement status has no fixed expiry date. As long as the manufacturer does not voluntarily withdraw it, it is not suspended/revoked by regulators, and the product meets current regulations – the announcement remains valid. But "valid" does not mean the job is done after obtaining the announcement. The real pressure comes from two things: new-regulatory mandatory implementation dates and ongoing surveillance.
2. GB44495/44696 – Mandatory Timeline for New vs. Existing Vehicles
This is the most frequently misread area: GB44495/GB44496 are first-time implementations – there is no "transition period between old and new versions". There is a phased mandatory schedule.
·Newly declared vehicle types – mandatory from 1 July 2026. From this date, new announcement applications must complete testing and system verification against both standards.
·Existing announced vehicle types – compliance deadline: 1 January 2028. Existing vehicles must complete validation, supplementary testing, and filing by this date. Failure to comply means the vehicle announcement cannot be maintained.
Critical distinction: many companies panicked assuming all vehicle types would be invalid immediately on 1 July 2026. In reality, new vehicles are mandatory first – existing vehicles have a buffer. But once the buffer expires without remediation – the announcement is invalid.
3. OTA Upgrade Compliance Obligations
GB44496 governs software upgrades – OTA compliance is the most frequently asked topic.
MIIT's current rules divide OTA into two categories:
·Category 1: Changes that do not affect major technical parameters in the announcement – only routine functional optimisation and security hotfixes – require OTA activity filing – no announcement change process. Most minor security policy adjustments and minor version upgrades fall here.
·Category 2: OTA changes that affect major technical parameters, information security architecture, or the SUMS (Software Upgrade Management System) core mechanism – require announcement change approval before the upgrade and subsequent filing.
Many companies still do not distinguish between filing and announcement change – hearing "information security related change" makes them assume a full announcement re-application – when in fact most changes only require filing.
4. GB44495/44496 Ongoing Surveillance Mechanisms
Announcement surveillance is not limited to random sampling. Under MIIT's system, standardised surveillance for GB44495/GB44496 has two main directions:
·Market sampling of mass-production vehicles: vehicles are randomly purchased from the market for information security conformance verification – without prior notification.
·System verification: on-site inspections of the manufacturer's information security management system and SUMS operation status.
These are not equivalent to KC's annual fixed factory audits. If non-conformities are found, the consequences go far beyond announcement suspension – including defect recalls and production-access re-verification – impacting the entire enterprise, not just a single vehicle announcement.
5. Change Determination Rules
This is the most frequently overlooked core content. Change determination is not only about OTA.
If the vehicle changes the in-vehicle security controller hardware, operating system the lower stratum, firewall policies, or OTA upgrade mechanisms – even if no OTA has ever been pushed – these changes themselves are vehicle design changes and must be assessed for whether information security difference testing or announcement changes are required. Focusing only on OTA push windows while ignoring static hardware and firmware changes is the most common compliance blind spot today.
Derivative model trap: a test report for one vehicle type only supports that specific configuration. If a derivative model changes the network topology, controller list, or SUMS execution flow – you cannot directly reuse the original report – a same-type determination assessment is required.
6. GB44495/44696 – Practical Points
·Standard version tracking and announcement expiry are two separate things: there is currently no draft replacement for GB44495/GB44496 – focus first on the 1 January 2028 existing-vehicle compliance deadline.
·OTA filing process and record retention must be internally established – even after vehicle production ends, OTA record retention obligations continue – most companies' process management does not yet cover this.
·Test reports and announcement status must be maintained in sync: if vehicle configuration changes, controller hardware changes, or SUMS processes are adjusted – assess whether the original test report still supports the current state – do not assume that because the announcement has not expired, the report can still be used.
For GB44495/44496 access testing validity and compliance, contact BlueAsia at 13534225140 (King) or king.guo@cblueasia.com.
相关新闻