---
title: "How do smart home security standards fit with China cybersecurity law?"
canonical_url: "https://www.sorena.io/artifacts/apac/china-cybersecurity-law/faq/how-do-smart-home-security-standards-fit-with-china-cybersecurity-law"
source_url: "https://www.sorena.io/artifacts/apac/china-cybersecurity-law/faq/how-do-smart-home-security-standards-fit-with-china-cybersecurity-law"
author: "Sorena AI"
description: "GB/T 41387-2022 can organize smart-home security evidence, but it is a recommended standard, not a product approval. Check app, data, MLPS, telecom access, and radio requirements separately."
published_at: "2026-07-05"
updated_at: "2026-07-24"
keywords:
  - "China Cybersecurity Law"
  - "Data Security Law"
  - "Cybersecurity Review Measures"
  - "Mobile app filing"
  - "MLPS"
---
**[SORENA](https://www.sorena.io/)** - AI-Powered GRC Platform

[Home](https://www.sorena.io/) | [Solutions](https://www.sorena.io/solutions) | [Artifacts](https://www.sorena.io/artifacts) | [About Us](https://www.sorena.io/about-us) | [Contact](https://www.sorena.io/contact) | [Portal](https://app.sorena.io)

---

# How do smart home security standards fit with China cybersecurity law?

GB/T 41387-2022 can organize smart-home security evidence, but it is a recommended standard, not a product approval. Check app, data, MLPS, telecom access, and radio requirements separately.

*Question* *China*

## How do smart home security standards fit with China cybersecurity law? Direct answer

GB/T 41387-2022 can organize security evidence for a smart-home product, app, cloud service, and their interfaces. It is a recommended standard, not a product approval.

Run separate checks for app and privacy rules, network-operation and classified-protection duties, telecom network access, and radio type approval or station licensing.

GB/T 41387-2022 can organize smart-home security evidence across the device, app, cloud service, and interfaces. It is a recommended national standard, so using it does not by itself establish compliance with every law, filing, permit, or approval that may apply.

## Definitions

### Smart home general security specification

**Term:** GB/T 41387-2022

GB/T 41387-2022 is the current recommended national standard titled Information security technology - Smart home general security specification. It was published on 15 April 2022 and took effect on 1 November 2022.

**Why it matters here:** Use the standard to structure security evidence across the smart-home system. Its GB/T status does not create a product approval, filing, certificate, or legal safe harbour; a contract, procurement rule, certification scheme, or other binding instrument can separately make conformance a condition.

Sources:

- [GB/T 41387-2022 smart home general security specification](https://openstd.samr.gov.cn/bzgk/gb/newGbInfo?hcno=B1C14E854C0BA30D1C29FC376299761A&ref=sorena.io)

### Cybersecurity classified protection

**Term:** classified protection

Classified protection is China's graded cybersecurity system for networks. A network operator defines the protected network, determines its protection level, and applies management and technical safeguards appropriate to that level.

**Why it matters here:** A smart-home cloud, app backend, connected-product platform, or other China network can require a classified-protection analysis even when GB/T 41387-2022 is used for product-security evidence. The two control maps overlap but do not replace each other.

Sources:

- [PRC Cybersecurity Law, consolidated 2025 text](https://sdca.miit.gov.cn/zwgk/fgbz/art/2026/art_4815dd4ec11d454783b83a91502a3cc7.html?ref=sorena.io)
- [GB/T 22239-2019 classified protection baseline](https://openstd.samr.gov.cn/bzgk/gb/newGbInfo?hcno=BAFB47E8874764186BDB7865E8344DAF&ref=sorena.io)

### Ministry of Industry and Information Technology mobile app filing

**Term:** MIIT app filing

MIIT app filing is the internet-information-service record required for an app sponsor providing app-based internet information services within China. The sponsor files through a network access service provider or app distribution platform and displays the issued filing number.

**Why it matters here:** A smart-home companion app can need this filing even though the device uses GB/T 41387-2022. Filing does not replace a sector licence, CAC app duties, privacy compliance, or product and radio approvals.

Sources:

- [MIIT notice on mobile app filing work](https://www.miit.gov.cn/zwgk/zcwj/wjfb/tz/art/2023/art_920db564162e4312916a01bed6540ad8.html?ref=sorena.io)

### Cyberspace Administration of China app-governance rules

**Term:** CAC app-governance

The Cyberspace Administration of China (CAC) app-governance rules are the 2022 Mobile Internet Application Information Service Management Provisions. They impose duties on app providers and separate duties on app distribution platforms for content, security, data, personal information, minors, complaints, verification, review, and records.

**Why it matters here:** These rules apply separately from MIIT app filing. They do not create one routine CAC product approval for every smart-home app, although regulated services and qualifying new functions can require a licence or security assessment.

Sources:

- [Mobile Internet Application Information Service Management Provisions](https://www.cac.gov.cn/2022-06/14/c_1656821626455324.htm?ref=sorena.io)

### Telecom equipment network-access licence

**Term:** telecom network access

Telecom network access is MIIT's administrative licence for covered telecom terminal equipment, radio communications equipment, and interconnection equipment that connects to a public telecommunications network. The current equipment category and product function control the decision.

**Why it matters here:** A Wi-Fi or Bluetooth feature alone does not prove that a smart-home product needs this licence. Check the current equipment catalogue and the product's intended public-network connection separately from radio approval.

Sources:

- [Telecom equipment network access licensing service guide](https://jwxkwap.miit.gov.cn/fwzn?ref=sorena.io)

### Radio-transmitting-equipment model approval

**Term:** radio type approval

Radio type approval, also called radio-transmitting-equipment model approval, is the approval required for covered transmitter models before they are produced or imported for domestic sale and use. A qualifying micro-power device can be exempt if it is listed in and meets the applicable catalogue conditions.

**Why it matters here:** Check the final transmitter, radio-frequency unit, antenna, band, power, firmware, and use conditions. A component certificate does not automatically show that a changed host configuration remains within an approval or exemption.

Sources:

- [MIIT notice on 2400 MHz, 5100 MHz and 5800 MHz radio management](https://wap.miit.gov.cn/zwgk/zcwj/wjfb/tz/art/2021/art_e4ae71252eab42928daf0ea620976e4e.html?ref=sorena.io)
- [MIIT Announcement No. 52 of 2019](https://wap.miit.gov.cn/jgsj/wgj/wjfb/art/2020/art_792ab84586c34b64bb391eb6496c0953.html?ref=sorena.io)

### Radio station licence

**Term:** station licence

A radio station licence authorizes the setting and use of a radio station under the applicable band and deployment rules. It is distinct from model approval, which applies to the transmitter model.

**Why it matters here:** For the cited 2400 MHz and 5800 MHz rules, an outdoor wireless LAN access point, broadband wireless-access center station, or point-to-point station needs a station licence when its equivalent isotropically radiated power exceeds the stated threshold. Ordinary indoor smart-home devices generally do not meet that specific station trigger, but their transmitters still need a separate model-approval or exemption decision.

Sources:

- [MIIT notice on 2400 MHz, 5100 MHz and 5800 MHz radio management](https://wap.miit.gov.cn/zwgk/zcwj/wjfb/tz/art/2021/art_e4ae71252eab42928daf0ea620976e4e.html?ref=sorena.io)

### Network operator under the PRC Cybersecurity Law

**Term:** network operator

A network operator is an owner or administrator of a network, or a provider of network services. The role must be applied to a defined network and responsible entity rather than inferred from the product category alone.

**Why it matters here:** A smart-home manufacturer, China affiliate, cloud provider, or app operator can have different roles for the device, app backend, cloud platform, or service. A network-operator finding leads to the Cybersecurity Law and classified-protection analysis.

Sources:

- [PRC Cybersecurity Law, consolidated 2025 text](https://sdca.miit.gov.cn/zwgk/fgbz/art/2026/art_4815dd4ec11d454783b83a91502a3cc7.html?ref=sorena.io)

## Short answer

GB/T 41387-2022, Information security technology - Smart home general security specification, is shown as current on the official standards page. It was published on 15 April 2022 and took effect on 1 November 2022. The '/T' designation identifies a recommended national standard; the implementation date is not an approval deadline or annual renewal date for every connected product.

Use the standard only after defining the product boundary: device hardware and firmware, local hub, mobile app, cloud services, accounts, data flows, interfaces, update path, and third-party components. Record which clauses apply, the design or test evidence for each clause, exceptions, remediation, and retest results. If a contract, procurement rule, certification scheme, or sector rule incorporates the standard, document that separate source and its legal or contractual effect.

Then run the independent legal routes. A network operator for a China network may have classified protection and incident duties under Articles 23 and 27 of the consolidated 2025 Cybersecurity Law. A companion app may need MIIT app filing and must meet CAC app-governance and personal-information rules. Radio transmitters may need radio type approval unless an exemption applies. Under the cited band rules, certain outdoor access points, center stations, and point-to-point stations in the 2400 MHz or 5800 MHz bands need a station licence when they exceed the applicable power threshold. Covered telecom equipment connected to a public telecommunications network may require telecom network access under the current equipment catalogue.

For example, a smart camera sold with a China-facing companion app and cloud account needs separate decisions for the device boundary under GB/T 41387-2022, the app sponsor and app provider, the cloud or backend network operator, personal-information processing, and the radio configuration. A local-only sensor with no app, cloud service, or public-network connection can follow a different route, but its transmitter and any incorporated contractual standard still need their own checks. These are examples; the final result depends on the released functions, architecture, responsible entities, and current catalogues.

Sources for this answer:

- [GB/T smart home general security specification](https://openstd.samr.gov.cn/bzgk/gb/newGbInfo?hcno=B1C14E854C0BA30D1C29FC376299761A&ref=sorena.io) - Confirms the standard number, recommended GB/T status, current status, title, publication date, 1 November 2022 implementation date, and standards authority.
- [PRC Cybersecurity Law](https://sdca.miit.gov.cn/zwgk/fgbz/art/2026/art_4815dd4ec11d454783b83a91502a3cc7.html?ref=sorena.io) - Articles 23, 24 and 27 support the separate network-operation, classified-protection, network-product security, and incident analysis in the consolidated 2025 text.
- [MIIT notice on 2400 MHz, 5100 MHz and 5800 MHz radio management](https://wap.miit.gov.cn/zwgk/zcwj/wjfb/tz/art/2021/art_e4ae71252eab42928daf0ea620976e4e.html?ref=sorena.io) - Sets model-approval, antenna, technical, band-use, and outdoor station-licensing requirements and identifies the cited power thresholds.

## What to keep as evidence

The official metadata page confirms the standard's identity and status but does not supply enough text for clause-level claims. Obtain the applicable edition before building the control map.

- Architecture and data-flow record covering hardware, firmware, hub, app, cloud, accounts, interfaces, updates, data, and suppliers.
- Applicability record for GB/T 41387-2022: why it is used, who incorporated it, edition, clauses, exclusions, and whether the effect is legal, contractual, procurement-based, or voluntary.
- Clause-level control map with owner, design evidence, configuration, test method and result, exception, remediation, retest, and release decision.
- Separate MIIT app-filing, CAC app-governance, personal-information, network-operator, classified-protection, telecom network-access, radio type-approval, and station-licensing decisions.
- Change triggers for hardware, radio module, firmware, app permissions, cloud location, data use, interfaces, suppliers, standards editions, or incorporated requirements.

Sources for this answer:

- [GB/T smart home general security specification](https://openstd.samr.gov.cn/bzgk/gb/newGbInfo?hcno=B1C14E854C0BA30D1C29FC376299761A&ref=sorena.io) - Supports the standard identity, recommended status, current status, and edition date used in the applicability record.
- [PRC Cybersecurity Law](https://sdca.miit.gov.cn/zwgk/fgbz/art/2026/art_4815dd4ec11d454783b83a91502a3cc7.html?ref=sorena.io) - Supports the separate classified-protection and secure network-product analysis; it does not make the GB/T smart-home standard an approval.
- [MIIT notice on 2400 MHz, 5100 MHz and 5800 MHz radio management](https://wap.miit.gov.cn/zwgk/zcwj/wjfb/tz/art/2021/art_e4ae71252eab42928daf0ea620976e4e.html?ref=sorena.io) - Supports the radio type-approval exemptions and requirements and the station-licensing distinction for these common smart-home bands.

## Primary sources

- [GB/T smart home general security specification](https://openstd.samr.gov.cn/bzgk/gb/newGbInfo?hcno=B1C14E854C0BA30D1C29FC376299761A&ref=sorena.io) - Confirms that GB/T 41387-2022 is a current recommended national standard published on 15 April 2022 and implemented on 1 November 2022.
- [PRC Cybersecurity Law](https://sdca.miit.gov.cn/zwgk/fgbz/art/2026/art_4815dd4ec11d454783b83a91502a3cc7.html?ref=sorena.io) - Use Articles 23, 24 and 27 of the consolidated 2025 text for classified-protection, network-product security, and incident duties.
- [MIIT notice on 2400 MHz, 5100 MHz and 5800 MHz radio management](https://wap.miit.gov.cn/zwgk/zcwj/wjfb/tz/art/2021/art_e4ae71252eab42928daf0ea620976e4e.html?ref=sorena.io) - Use for radio type-approval and station-licensing requirements and exemptions for common wireless bands.

## Topic Guides

- [China App Filing vs Personal Information Rules](/artifacts/apac/china-cybersecurity-law/mobile-app-filing-vs-app-personal-information-rules.md): Decide whether a China mobile app needs MIIT filing, personal-information controls, or both, with current triggers, duties, dates, and evidence.
- [China cybersecurity and data security requirements](/artifacts/apac/china-cybersecurity-law/requirements.md): China cybersecurity requirements by actor: network operators, data processors, CII operators, platforms, app providers, and distribution platforms.
- [China cybersecurity compliance checklist](/artifacts/apac/china-cybersecurity-law/checklist.md): A China cybersecurity checklist for scoping network duties, data security, CII procurement review, app rules, MIIT filing, and supporting standards.
- [China cybersecurity deadlines and compliance calendar](/artifacts/apac/china-cybersecurity-law/deadlines-and-compliance-calendar.md): Separate China cybersecurity commencement dates from recurring duties, filing lead times, review periods, and event-driven response deadlines.
- [China Cybersecurity Law FAQ](/artifacts/apac/china-cybersecurity-law/faq.md): Practical answers on China network-operator scope, MLPS evidence, important data, cybersecurity review, app filing and governance, and smart-home standards under the law in force from 1 January 2026.
- [China Cybersecurity Law vs EU Cyber Resilience Act](/artifacts/apac/china-cybersecurity-law/china-cybersecurity-law-vs-eu-cyber-resilience-act.md): Compare China's network-operator rules with the EU CRA's product duties, including scope, actors, evidence, reporting dates, and launch decisions.
- [China Cybersecurity Law vs EU NIS2 Directive](/artifacts/apac/china-cybersecurity-law/china-cybersecurity-law-vs-nis2.md): Compare China's network-operator duties with NIS2 entity duties, including scope, management accountability, incident reporting, evidence, and enforcement.
- [China cybersecurity penalties and fines](/artifacts/apac/china-cybersecurity-law/penalties-and-fines.md): Compare current China Cybersecurity Law and Data Security Law fines by actor, breach, severity, and enforcement consequence.
- [China Cybersecurity Review vs Data Export Assessment](/artifacts/apac/china-cybersecurity-law/cybersecurity-review-vs-data-export-security-assessment.md): Separate China's cybersecurity-review triggers from CAC data-export assessment triggers, thresholds, filings, evidence, timing, and reapplication rules.
- [China cybersecurity review workflow](/artifacts/apac/china-cybersecurity-law/cybersecurity-review-workflow.md): Determine whether CII procurement, platform data processing, or a qualifying foreign listing triggers China's Cybersecurity Review Measures.
- [China mobile app filing and app governance](/artifacts/apac/china-cybersecurity-law/mobile-app-filing-and-app-governance.md): Identify the China app sponsor, complete MIIT filing before service, and separate provider, platform, privacy, content, and security duties.
- [China Smart-Home Security vs Telecom and Radio Approval](/artifacts/apac/china-cybersecurity-law/smart-home-security-vs-telecom-wireless-launch.md): Separate GB/T 41387-2022 smart-home security evidence from China telecom network-access and radio approval decisions for connected products.
- [CII and network operator role triage](/artifacts/apac/china-cybersecurity-law/critical-information-infrastructure-and-network-operators.md): How to separate ordinary network operator duties from CII, procurement, and review-risk questions under China cybersecurity sources.
- [Does an app need MIIT filing and CAC app governance review?](/artifacts/apac/china-cybersecurity-law/faq/does-an-app-need-miit-filing-and-cac-app-governance-review.md): An app sponsor providing internet information services through an app in China must complete MIIT filing. CAC rules separately govern app providers and distribution platforms without creating one routine CAC approval for every app.
- [GB/T 22239-2019 classified protection baseline](/artifacts/apac/china-cybersecurity-law/classified-protection-baseline.md): How to scope and document a GB/T 22239-2019 classified protection baseline without treating the recommended standard as a standalone law.
- [GB/T 41387-2022 smart home security standard](/artifacts/apac/china-cybersecurity-law/smart-home-security-standard.md): How connected-device teams can scope and document GB/T 41387-2022 without treating it as an automatic certification or product-approval duty.
- [How does important data change China cybersecurity obligations?](/artifacts/apac/china-cybersecurity-law/faq/how-does-important-data-change-cybersecurity-obligations.md): Once data is officially identified as important data, the processor needs named governance, periodic risk assessments and reports, incident controls, and a separate export decision. An internal sensitivity label alone does not establish the legal category.
- [Is every company a network operator under China Cybersecurity Law?](/artifacts/apac/china-cybersecurity-law/faq/is-every-company-a-network-operator-under-china-cybersecurity-law.md): No. Under China's Cybersecurity Law, a network operator is an owner or administrator of a network or a network service provider. Apply that definition to each China network or service, then test CII and other roles separately.
- [MLPS classified protection evidence map](/artifacts/apac/china-cybersecurity-law/mlps-classified-protection-evidence-map.md): Classify a China network under MLPS, complete level 2 or above filing, map controls, and retain assessment, remediation, and change evidence.
- [What is MLPS classified protection evidence?](/artifacts/apac/china-cybersecurity-law/faq/what-is-mlps-classified-protection-evidence.md): MLPS evidence shows how a defined China network or system was graded and protected. Keep the scope, grading rationale, filing or assessment records where applicable, control mapping, test results, remediation, and reassessment history.
- [When does China cybersecurity review apply?](/artifacts/apac/china-cybersecurity-law/faq/when-does-china-cybersecurity-review-apply.md): China cybersecurity review applies to CII procurement or network-platform data processing that affects or may affect national security, plus a mandatory pre-filing trigger for certain foreign listings involving more than one million users' personal information.

*Operationalize the requirement*

*Placement: Before primary sources*

## Build the China network security evidence file

Sorena AI helps turn the answer to "How do smart home security standards fit with China cybersecurity law?" into assigned controls and retained evidence.

- [Map official sources to evidence](/solutions/research-copilot.md): Research Copilot connects the official citation, decision, owner, retained evidence, and change history.
- [Review the China route](/contact.md): Check the China Cybersecurity Law scope decision and unresolved launch questions with Sorena.


---

[Privacy Policy](https://www.sorena.io/privacy.md) | [Terms of Use](https://www.sorena.io/terms-of-use.md) | [DMCA](https://www.sorena.io/dmca.md) | [About Us](https://www.sorena.io/about-us.md)

(c) 2026 Sorena AB (559573-7338). All rights reserved.

Source: https://www.sorena.io/artifacts/apac/china-cybersecurity-law/faq/how-do-smart-home-security-standards-fit-with-china-cybersecurity-law.md
