CybersecurityChina

China Cybersecurity Law Smart home security standard evidence

How connected-device teams can scope and document GB/T 41387-2022.

GB/T 41387-2022 is a current recommended national standard implemented on 1 November 2022. It is separate from mandatory launch routes and from the voluntary China Cybersecurity Label scheme effective from 1 July 2026.

Author
Sorena AI
Published
Jul 5, 2026
Updated
Jul 25, 2026
Sections
4

Structured answer sets in this page tree.

Primary sources
4

Cited legal and guidance references.

Publication metadata
Sorena AI
Published Jul 5, 2026
Updated Jul 25, 2026
Overview

is the current titled Smart home general security specification. Use it as a documented technical reference. Any certification or product-approval duty must arise from a separate applicable requirement.

Section 1

Separate the standard from launch and label routes

Use as a smart-home security reference only after identifying the connected product, firmware, companion app, cloud service, operator, data flows, radio functions, suppliers, and China launch routes. The '/T' designation identifies a ; the source does not state that every smart-home product must obtain certification under it.

Obtain the applicable standard text before claiming clause-level implementation. Keep the standard mapping separate from mandatory telecom or network access, radio, app, privacy, and product-security records, and from network-operator records for an entity that owns or administers a network or provides network services.

The China measures effective from 1 July 2026 create a separate voluntary route for internet-connected products. The first , issued on 18 June 2026, covers consumer connected cameras and uses a category implementation rule plus TC260-PG-20265A as its security basis. Another smart-home appliance, hub, or service does not enter that route merely because it is internet-connected or mapped to . The label uses one, two, or three stars for basic, enhanced, or leading capability.

  • Standards owner: record why the standard is being used, such as a design benchmark, customer requirement, procurement criterion, risk control, or another documented basis.
  • Product-security owner: map the product, hardware, firmware, companion app, cloud services, interfaces, data flows, update path, supported life, and supplier boundaries before assigning evidence.
  • Regulatory owner: screen telecom, radio, app, privacy, network-operation, product-security, and routes separately and preserve each conclusion.
  • Do not describe the standard's 1 November 2022 implementation date as a recurring deadline or automatic certification obligation.
Section 2

Practical compliance steps

Use the complete applicable standard text to create a traceable mapping from relevant requirements to design evidence, test results, supplier inputs, exceptions, remediation, and product-security ownership.

Reassess the mapping when hardware, firmware, apps, cloud endpoints, authentication, update mechanisms, data flows, suppliers, or supported product life materially change.

  • Keep the product/system boundary and the documented reason for using .
  • Identify the edition of the standard, the clauses mapped, each applicability decision, and the responsible owner.
  • Link security architecture, authentication and authorisation, data protection, update, vulnerability, interface, cloud, supplier, test, exception, remediation, and retest evidence where the applicable clauses require them.
  • For the voluntary , check the current and before planning tests or filing. If participating, retain the capability-level decision, test report, label design, conformity declaration, producer and laboratory credentials, filing result, validity period, and any change or expiry refiling decision. The filing body performs a formal review within 10 working days after receiving complete materials; that timing does not replace testing or establish product approval under another regime.
  • Keep mandatory China launch decisions in their own records and cross-reference shared technical evidence.
Section 3

Evidence to keep before launch or change approval

Keep the standard mapping tied to the exact product family, hardware and firmware versions, companion app, cloud services, interfaces, suppliers, and supported life.

A reviewer should be able to trace each mapped requirement to design evidence, test results, an owner, any exception, remediation, and retesting.

  • Product and system boundary, model and version identifiers, intended use, interfaces, app and cloud dependencies, and supplier list.
  • Documented reason for applying and the exact edition and clauses mapped.
  • Security architecture, authentication and authorization design, update and vulnerability processes, test results, exceptions, remediation, and retest evidence.
  • Supported-life and security-maintenance period, end-of-support decision, user communications, and customer or supplier commitments.
  • product-directory and product-specific implementation-rule screen; if participating, retain test scope and report, capability level, filing materials, completed filing and label use, validity period, and change or expiry refiling decision.
  • Links to separate telecom, radio, app, privacy, network-operator, critical-information-infrastructure, or data-security decisions where they apply.
Section 4

Boundary with nearby China regimes

does not determine whether a product needs telecom network access approval, radio approval, app filing, personal-information measures, classified protection, cybersecurity review, or a . Assess each route under its own trigger.

Cross-reference shared facts such as the model number, firmware, app package, cloud endpoints, data flow, supplier, and release date, but keep each legal or standards conclusion separate.

  • Treating the standard's 1 November 2022 implementation date as an annual deadline.
  • Claiming certification or legal compliance when the source only establishes a recommended standard and its current status.
  • Calling the mandatory without checking the voluntary rule, current , and .
  • Mapping only the physical device while omitting firmware, companion apps, cloud services, interfaces, and suppliers.
  • Using the standard mapping as a substitute for separate telecom, radio, app, privacy, network, and data decisions.
Primary sources

References and citations

Related guides

Explore more topics

China App Filing vs Personal Information Rules
Decide whether a China mobile app needs MIIT filing, personal-information controls, or both, with current triggers, duties, dates, and evidence.
China cybersecurity and data security requirements
China cybersecurity requirements by actor: network operators, data processors, CII operators, platforms, app providers, and distribution platforms.
China cybersecurity compliance checklist
A China cybersecurity checklist for scoping network duties, data security, CII procurement review, app rules, MIIT filing, and supporting standards.
China cybersecurity deadlines and compliance calendar
Separate China cybersecurity commencement dates from recurring duties, filing lead times, review periods, and event-driven response deadlines.
China Cybersecurity Law FAQ
Practical answers on China network-operator scope, MLPS evidence, important data, cybersecurity review, app filing and governance, and smart-home standards under the law in force from 1 January 2026.
China Cybersecurity Law vs EU Cyber Resilience Act
Compare China's network-operator rules with the EU CRA's product duties, including scope, actors, evidence, reporting dates, and launch decisions.
China Cybersecurity Law vs EU NIS2 Directive
Compare China's network-operator duties with NIS2 entity duties, including scope, management accountability, incident reporting, evidence, and enforcement.
China cybersecurity penalties and fines
Compare current China Cybersecurity Law and Data Security Law fines by actor, breach, severity, and enforcement consequence.
China Cybersecurity Review vs Data Export Assessment
Separate China's cybersecurity-review triggers from CAC data-export assessment triggers, thresholds, filings, evidence, timing, and reapplication rules.
China cybersecurity review workflow
Determine whether CII procurement, platform data processing, or a qualifying foreign listing triggers China's Cybersecurity Review Measures.
China mobile app filing and app governance
Identify the China app sponsor, complete MIIT filing before service, and separate provider, platform, privacy, content, and security duties.
China Smart-Home Security vs Telecom and Radio Approval
Separate GB/T 41387-2022 smart-home security evidence from China telecom network-access and radio approval decisions for connected products.
CII and network operator role triage
How to separate ordinary network operator duties from CII, procurement, and review-risk questions under China cybersecurity sources.
Does an app need MIIT filing and CAC app governance review?
An app sponsor providing internet information services through an app in China must complete MIIT filing. CAC rules separately govern app providers and distribution platforms without creating one routine CAC approval for every app.
GB/T 22239-2019 classified protection baseline
How to scope and document a GB/T 22239-2019 classified protection baseline without treating the recommended standard as a standalone law.
How do smart home security standards fit with China cybersecurity law?
GB/T 41387-2022 can organize smart-home security evidence, but it is a recommended standard, not a product approval. Check app, data, MLPS, telecom access, and radio requirements separately.
How does important data change China cybersecurity obligations?
Once data is officially identified as important data, the processor needs named governance, periodic risk assessments and reports, incident controls, and a separate export decision. An internal sensitivity label alone does not establish the legal category.
Is every company a network operator under China Cybersecurity Law?
No. Under China's Cybersecurity Law, a network operator is an owner or administrator of a network or a network service provider. Apply that definition to each China network or service, then test CII and other roles separately.
MLPS classified protection evidence map
Classify a China network under MLPS, complete level 2 or above filing, map controls, and retain assessment, remediation, and change evidence.
What is MLPS classified protection evidence?
MLPS evidence shows how a defined China network or system was graded and protected. Keep the scope, grading rationale, filing or assessment records where applicable, control mapping, test results, remediation, and reassessment history.
When does China cybersecurity review apply?
China cybersecurity review applies to CII procurement or network-platform data processing that affects or may affect national security, plus a mandatory pre-filing trigger for certain foreign listings involving more than one million users' personal information.