China Cybersecurity Law Smart home security standard evidence
How connected-device teams can scope and document GB/T 41387-2022.
GB/T 41387-2022 is a current recommended national standard implemented on 1 November 2022. It is separate from mandatory launch routes and from the voluntary China Cybersecurity Label scheme effective from 1 July 2026.
is the current titled Smart home general security specification. Use it as a documented technical reference. Any certification or product-approval duty must arise from a separate applicable requirement.
1
Section 1
Separate the standard from launch and label routes
Use as a smart-home security reference only after identifying the connected product, firmware, companion app, cloud service, operator, data flows, radio functions, suppliers, and China launch routes. The '/T' designation identifies a ; the source does not state that every smart-home product must obtain certification under it.
Obtain the applicable standard text before claiming clause-level implementation. Keep the standard mapping separate from mandatory telecom or network access, radio, app, privacy, and product-security records, and from network-operator records for an entity that owns or administers a network or provides network services.
The China measures effective from 1 July 2026 create a separate voluntary route for internet-connected products. The first , issued on 18 June 2026, covers consumer connected cameras and uses a category implementation rule plus TC260-PG-20265A as its security basis. Another smart-home appliance, hub, or service does not enter that route merely because it is internet-connected or mapped to . The label uses one, two, or three stars for basic, enhanced, or leading capability.
Standards owner: record why the standard is being used, such as a design benchmark, customer requirement, procurement criterion, risk control, or another documented basis.
Product-security owner: map the product, hardware, firmware, companion app, cloud services, interfaces, data flows, update path, supported life, and supplier boundaries before assigning evidence.
Regulatory owner: screen telecom, radio, app, privacy, network-operation, product-security, and routes separately and preserve each conclusion.
Do not describe the standard's 1 November 2022 implementation date as a recurring deadline or automatic certification obligation.
Use the complete applicable standard text to create a traceable mapping from relevant requirements to design evidence, test results, supplier inputs, exceptions, remediation, and product-security ownership.
Reassess the mapping when hardware, firmware, apps, cloud endpoints, authentication, update mechanisms, data flows, suppliers, or supported product life materially change.
Keep the product/system boundary and the documented reason for using .
Identify the edition of the standard, the clauses mapped, each applicability decision, and the responsible owner.
Link security architecture, authentication and authorisation, data protection, update, vulnerability, interface, cloud, supplier, test, exception, remediation, and retest evidence where the applicable clauses require them.
For the voluntary , check the current and before planning tests or filing. If participating, retain the capability-level decision, test report, label design, conformity declaration, producer and laboratory credentials, filing result, validity period, and any change or expiry refiling decision. The filing body performs a formal review within 10 working days after receiving complete materials; that timing does not replace testing or establish product approval under another regime.
Keep mandatory China launch decisions in their own records and cross-reference shared technical evidence.
Keep the standard mapping tied to the exact product family, hardware and firmware versions, companion app, cloud services, interfaces, suppliers, and supported life.
A reviewer should be able to trace each mapped requirement to design evidence, test results, an owner, any exception, remediation, and retesting.
Product and system boundary, model and version identifiers, intended use, interfaces, app and cloud dependencies, and supplier list.
Documented reason for applying and the exact edition and clauses mapped.
Security architecture, authentication and authorization design, update and vulnerability processes, test results, exceptions, remediation, and retest evidence.
Supported-life and security-maintenance period, end-of-support decision, user communications, and customer or supplier commitments.
product-directory and product-specific implementation-rule screen; if participating, retain test scope and report, capability level, filing materials, completed filing and label use, validity period, and change or expiry refiling decision.
Links to separate telecom, radio, app, privacy, network-operator, critical-information-infrastructure, or data-security decisions where they apply.
does not determine whether a product needs telecom network access approval, radio approval, app filing, personal-information measures, classified protection, cybersecurity review, or a . Assess each route under its own trigger.
Cross-reference shared facts such as the model number, firmware, app package, cloud endpoints, data flow, supplier, and release date, but keep each legal or standards conclusion separate.
Treating the standard's 1 November 2022 implementation date as an annual deadline.
Claiming certification or legal compliance when the source only establishes a recommended standard and its current status.
Calling the mandatory without checking the voluntary rule, current , and .
Mapping only the physical device while omitting firmware, companion apps, cloud services, interfaces, and suppliers.
Using the standard mapping as a substitute for separate telecom, radio, app, privacy, network, and data decisions.
Official June 2026 notice confirming that the first implemented category is consumer connected cameras and that TC260-PG-20265A is the category's security basis.