GB 44495-2024 – full title Technical Requirements for Vehicle Cybersecurity – was officially published on 23 August 2024 and took effect on 1 January 2026. This is China's first mandatory national standard for whole‑vehicle cybersecurity. For connected vehicles sold in China, cybersecurity compliance is no longer optional – it's legally mandated.
Implementation is phased:
·From 1 January 2026: new models applying for type approval must comply directly.
·Existing type‑approved models: transition period – compliance deadline 1 January 2028.
Many companies over‑focus on the 2026 date – but existing models have a substantial buffer – remediation can be phased.
GB 44495 fills the gap where UN‑R155 is not legally binding in China. The two frameworks are broadly similar – but test cases, data localisation, national cryptographic algorithm requirements, and supply‑chain controls differ significantly – reports are not interchangeable. Common misconception: a company that has completed UN‑R155 assumes it can skip GB 44495 for the domestic market – many have fallen into this trap, delaying CCC submissions.
The standard covers M‑class passenger vehicles and N‑class freight vehicles. O‑class trailers – as long as they have at least one electronic control unit – are also covered – not just trailers with communication modules – even those with brake ECUs must comply. Purely mechanical trailers with no ECUs are exempt.
Compliance requires two assessments:
·CSMS (Cybersecurity Management System) review.
·VTA (Vehicle Type Approval) on‑vehicle cybersecurity testing.
Both must pass – results are integrated into the vehicle's CCC report.
Common misconception: there is no independent "GB 44495 certificate." CSMS and VTA results are integrated into the CCC documentation – you cannot obtain a standalone GB44495 certificate. Some third parties promote this – be cautious.
·CSMS: covers the vehicle's full cybersecurity lifecycle – from requirements, risk assessment, security design, to post‑sale vulnerability operations. Each stage must have auditable control documentation. Audit focus: supply‑chain management – T‑BOX, domain controllers, and in‑vehicle gateways are all on the checklist. Security responsibility allocation and vulnerability response coordination between OEMs and component suppliers must be documented in written agreements.
·VTA: on‑vehicle or bench testing – verifying the vehicle's information‑security protection capabilities. Test items include external network access protection, data‑transmission encryption, device authentication, security logging, OTA upgrade protection, and OBD diagnostic‑port security.
2. GB 44495, GB 44496, and CCC – How They Relate
GB 44495 covers vehicle cybersecurity. Its companion standard GB 44496 covers OTA software upgrades – the two are enforced together. Vehicles with remote upgrade capability must meet both. Under CCC, both sets of results are consolidated into the same CCC report.
Not all firmware changes trigger CCC changes: whether an OTA firmware upgrade, TCU module replacement, or SUMS system adjustment requires a vehicle‑type change notification depends on the scope of impact. If the change affects the security architecture or VTA test coverage → change process required. If it's only application‑layer fine‑tuning with no security‑architecture changes → internal risk assessment and filing are sufficient – no CCC change application needed. Each software/hardware change must be assessed individually – do not assume all firmware changes require full re‑certification.
Components cannot obtain standalone GB 44495 type approval – type approval is only issued at the whole‑vehicle level. T‑BOX, gateway, and domain‑controller manufacturers must cooperate with OEMs on security assessments – documentation is attached to the whole‑vehicle CCC system.
SUMS system audits must be conducted by CNCA‑designated bodies – only from the official list. Overseas bodies with UN‑R156 accreditation do not have domestic GB 44496 qualification – reports from overseas R156 bodies cannot be used for domestic compliance. This is a common blind spot for export‑oriented OEMs.
3. GB 44495 vs. UN‑R155 – Can They Be Cross‑Used?
Many OEMs with both domestic and international presence ask: "If we've already done UN‑R155, do we still need GB 44495?" The answer is yes. The two systems are not mutually recognised. UN‑R155 test reports cannot substitute for GB 44495 compliance materials. Many companies have been caught by this – submitting R155 reports for domestic type approval – only to be returned at the type‑test stage – having to re‑run VTA tests – extending project timelines.
Existing CSMS documentation can be reused to save document‑preparation time – but VTA test cases must be re‑adapted against GB 44495 requirements – UN‑R155 test reports cannot be directly submitted. The reverse also applies: GB 44495 compliance reports cannot be used for EU, Japan, or Korea market access.
Document retention: GB 44496 explicitly requires software‑upgrade records to be retained for at least 10 years after the vehicle model is discontinued. For example, if a model is discontinued in 2028 – records must be retained until 2038. The retention start date is the model discontinuation date – not when all vehicles are scrapped – don't over‑estimate the retention period.
4. 2026 Enforcement Tightening – Post‑Certification Surveillance Focus
Regulators are strengthening post‑certification surveillance – focusing on whether the CSMS is actually implemented and operational. Auditors will check:
·Are security risk assessment documents updated regularly?
·Are newly discovered cybersecurity threats incorporated into controls?
·Is supplier security management continuously effective?
Many non‑conformities arise because the system documentation is complete – but risk assessment documents haven't been updated in years – easily spotted during audits.
Imported vehicles are also subject to this standard. Parallel‑imported vehicles within GB 44495's scope – cybersecurity requirements are audited alongside the vehicle's CCC – importers are responsible for compliance. There is no standalone GB 44495 assessment channel – without a CCC certificate, customs clearance is impossible.
5. Impact on the Supply Chain
GB 44495 is not just about OEMs – the entire supply chain is affected.
5.1T‑BOX – as the core in‑vehicle communication node, most remote attack paths go through it. In‑vehicle gateways and domain controllers are also key assessment targets – do not assume audits only target the T‑BOX. Component suppliers must cooperate with OEMs on security interface definition, encryption scheme review, and remote‑command security verification. Security development documentation, vulnerability handling processes, and incident response plans are all subject to random audit.
5.2Software suppliers – cannot avoid the requirements. Operating systems, middleware, and application‑layer software – anything involving cybersecurity – must provide security design documentation and test reports. Teams using open‑source components must implement open‑source vulnerability management, code signing, and secure compilation options – previously optional controls are now mandatory audit items.
5.3The biggest change: security responsibility is flowing downstream. The standard requires OEMs to include cybersecurity clauses in supplier agreements – component suppliers must provide evidence that their products and development processes meet security requirements. Suppliers unable to provide valid evidence will likely lose their qualification to supply.
For GB 44495 vehicle cybersecurity compliance, contact BlueAsia at 13534225140 (King) or email king.guo@cblueasia.com.
Related News