This is the most-asked question, and getting it wrong derails everything after. GB 44495-2024 governs whole-vehicle information security; GB 44496-2024 governs software upgrades. The two are parallel, not superior-subordinate, with separately prepared and submitted materials. But neither has an independent certificate. Compliance follows the whole vehicle: it is both a mandatory inspection item in the MIIT vehicle announcement and content that CCC certification must cover. Both the announcement and CCC access paths must be satisfied — do not stare only at the CCC side.
So when we talk about validity, we are not talking about "how many years between renewals of these two standards", but how the thing they hang on proceeds. Separate these two layers and the scheduler stops conflating two matters into one.
The whole-vehicle CCC certificate is statutory five years, with renewal applications possible 90 days before expiry. Fail to renew and the certificate is no longer valid; the model cannot be produced or sold. But a valid certificate does not mean information-security compliance auto-maintains — once the model's software or hardware changes, re-evaluation is still required where due.
The vehicle announcement is another matter. The announcement itself has no preset expiry, but it moves with the CCC certificate status, model discontinuation and regulatory action — it is not "valid forever if not revoked". Existing models must also meet the 2028-01-01 remediation node. Both announcement and certificate timelines must be watched, just do not paste the CCC five years onto the announcement.
Taken together: the number five years only means something for the certificate. Do not treat it as the standard's re-test cycle. This side watches change and regulatory requirements, not the calendar.
The vehicle itself changed. Adjustments to hardware or software architecture that affect information security or software upgrade must be re-evaluated, and serious cases require re-inspection and re-filing. Changing the main controller, swapping the communication module, or touching the OTA channel all fall in the re-review category. Keep the evaluation conclusion on file; that is what regulators check in spot inspections.
Standard revision or a modification order. Modification No. 1 is an example: it pushed the mandatory node for newly declared models to 2026-07-01 and removed O-category trailers from the mandatory scope. Such changes are not "wait five years"; the modification order has a specified implementation date — respond by that date, not from the publication day.
Market-supervision problems. Production consistency failing to match the filed state, caught in inspection, is more serious than expiry; the remediation period may directly suspend the model.
Already-announced existing models have a two-year transition; compliance remediation is due by 2028-01-01. But this is for in-production models; old models already discontinued need not do this remediation. Schedule old-model projects on this separate line; do not crowd them with newly declared models.
This modification order is already implemented, not a draft for comment. Many online articles write the public-comment draft date as the publication date; the two do not match, and scheduling by them goes wrong. When statements conflict, follow the current competent-authority notice.
The GB 44496 line governs software upgrades; the core is an upgrade-management system. Building it is only the start; it must keep running and produce records. The audit checks whether the system truly turns, not how pretty the documents are.
On system audit: Modification No. 1 cancelled the independent CSMS system certification and changed it to a documentation examination of the information-security assurance requirements, dropping the old independent audit of one to two weeks document review plus two to three days on-site. Across the text, the term for field inspection was uniformly changed to laboratory examination — write reports and system documents accordingly; do not carry the old "rectification" vocabulary in.
These projects are best handled by managing three separate tables — certificate renewal, change filing and system maintenance — each noted on its own, avoiding pasting one five-year cycle onto everything.
For vehicle projects doing both export and domestic, BlueAsia's one-stop testing and certification views domestic information-security requirements and export-market cybersecurity access on one timeline, aligning test schedule and document preparation in one pass.
These two standards are already on the list of standards proposed for inclusion in the CCC basis (pending official confirmation by the certification authority). Do not plan on the assumption that "they are not in the catalogue". Once truly included, how and how often they are checked must be recalculated under the new rules.
Contact: King Email: king.guo@cblueasia.comAddress: Building C, Hongjingda Industrial Park, No. 107 Beihuan Road, Shiyan Street, Bao'an District, Shenzhen, China BlueAsia delivers more than service!
Related News