When GB 44495-2024 was published, the industry discussion was lively – but the practical failures have been far more common than expected. It's not that the standard is hard to understand – it's that many people confuse the key elements. Timelines, scope, and certification systems – all tangled up.
One OEM spent nearly a year preparing – thought their team fully understood it – only to find one month before submission that they had the wrong mandatory date – the whole schedule slipped by a full quarter. This isn't rare in our circles.
Full title: Technical Requirements for Vehicle Cybersecurity – mandatory national standard – embedded in whole‑vehicle CCC certification. The core requirement: the vehicle's cybersecurity protection capability must meet the standard.
Scope: M‑class passenger vehicles, N‑class freight vehicles, and O‑class trailers equipped with at least one ECU.
The trigger is not "having wireless connectivity". Traditional fuel vehicles without 4G/5G/Wi‑Fi but with ECUs – still covered. Vehicles without connectivity can have test items pruned – but they are not automatically exempt. The argument "my vehicle isn't connected" doesn't work.
Certificate confusion: the GB 44495 vehicle‑level security requirement is embedded in the whole‑vehicle CCC certificate – there is no standalone "GB 44495 certificate." However, there are independent CSMS system audit certificates – companies use these as internal capability evidence – they do not substitute for whole‑vehicle CCC compliance. They are two completely different things.
Can component suppliers do the full certification on their own? No – not at the whole‑vehicle level. But component suppliers can complete their own cybersecurity testing and system‑building – issue reports to the OEM – it's more than just handing over a configuration table.
二、Mandatory Timeline
·New type‑approval applications: mandatory from 1 July 2026 – not 1 January. 1 January is the standard publication date – 1 July is the new‑vehicle mandatory date.
·Existing production models: mandatory from 1 January 2028.
三、Gap Analysis and System Building
First, do a gap analysis – check item by item against the standard. Having an experienced partner helps – doing it alone, you're likely to mistake "I think it's fine" for "the standard thinks it's fine."
Simultaneously, build the CSMS (Cybersecurity Management System): organisational structure, security policy documentation, risk assessment, vulnerability management, incident response, supplier security management – all must be established.
The full‑lifecycle risk‑assessment report is a mandatory application threshold – no way around it. Key attack entry points: T‑BOX, remote communication modules, IVI head unit, OBD port, USB port, Bluetooth and Wi‑Fi wireless interfaces. Each threat scenario must be assessed for attack feasibility and impact. If you skip this – penetration testing later will fail.
四、GB 44495 – Technical Testing and Factory Audit
·VTA (Vehicle Type Approval) technical testing – including penetration testing – is performed at the lab.
·System audit – factory‑based – not at the lab.
Penetration testing is mandatory. The three highest‑failure areas:
·National cryptographic algorithm performance.
·OTA upgrade‑package signature verification.
·Communication encryption implementation.
First‑round pass vs. three rounds of remediation – the timeline difference is 1–2 months.
Real‑vehicle testing: with conditions met and lab approval, some scenarios can be tested on‑site at the manufacturer's facility – you don't always have to tow the vehicle to the lab.
Submission peak: from the second half of 2026 to the July 2027 deadline – top labs will be increasingly busy. Important: designated labs do not offer paid expedite/jump‑the‑queue services – statutory type testing is not commercial pre‑testing.
Factory audit: auditors check three things on‑site:
·Information‑security management system – records of actual implementation.
·Supplier security agreements – all signed and filed.
·Production‑line security‑critical component control – properly managed.
The factory audit is a CoP (Conformity of Production) audit with information‑security content – it's not a separate dedicated information‑security factory audit.
五、GB 44495 – Document Submission and Application Acceptance
Submit product certification applications to CQC or other certification bodies. Four items are mandatory – missing any one and you're rejected:
·Full‑lifecycle risk‑assessment report.
·Complete set of supply‑chain security agreements.
·Chinese translations of foreign‑language documents (with translation company stamp).
Vehicle configuration in application materials must match the submitted vehicle – software version numbers, ECU part numbers, T‑BOX model numbers – all must align. If the application says "A" and you submit "B" – rejected – re‑queue.
Imported vehicles: China's CCC and vehicle‑announcement systems test directly against GB 44495 – UN‑R155 equivalent assessment reports are not mandatory. R155 is the EU framework – can be used as reference – not a mandatory prerequisite.
六、GB 44495 – Certificate Issuance and Ongoing Maintenance
After passing test reports and factory audit – CQC integrates the information‑security compliance record into the whole‑vehicle CCC certificate – issued together.
CCC certificate validity: 5 years – not 3. The 3‑year figure is for standalone CSMS system certificates – two different things.
Annual CoP surveillance: certification rules require that information‑security controls be added to the CoP scope.
Change notifications – easily overlooked:
·T‑BOX supplier changed.
·Communication module model changed.
·National cryptographic algorithm changed.
·Head‑unit software architecture major version upgraded.
These require assessment under CQC change‑evaluation rules. Some items only need document review – not every change requires retesting. Appearance/interior changes with no ECU changes – no need to report.
Vulnerability monitoring and incident response: a manufacturer's full‑lifecycle obligation – it does not end after VTA testing. OEMs must establish monitoring mechanisms covering the vehicle's full lifecycle – and keep them running.
七、GB 44495 – Timeline Recommendations
For companies starting from scratch – allow 6–8 months lead time. Gap analysis, system building, and functional remediation can run in parallel – don't serialise them. The timeline is long not because any single step is slow – but because remediation piles on remediation. Getting the gap analysis right and thoroughly pre‑testing functionality upfront saves enormous time later.
For GB 44495 certification, contact BlueAsia at 13534225140 (King) or email king.guo@cblueasia.com.
Related News