---
title: "GB/T 41387-2022 smart home security standard"
canonical_url: "https://www.sorena.io/artifacts/apac/china-cybersecurity-law/smart-home-security-standard"
source_url: "https://www.sorena.io/artifacts/apac/china-cybersecurity-law/smart-home-security-standard"
author: "Sorena AI"
description: "How connected-device teams can scope and document GB/T 41387-2022 without treating it as an automatic certification or product-approval duty."
published_at: "2026-07-05"
updated_at: "2026-07-25"
keywords:
  - "China Cybersecurity Law"
  - "Data Security Law"
  - "Cybersecurity Review Measures"
  - "Mobile app filing"
  - "MLPS"
---
**[SORENA](https://www.sorena.io/)** - AI-Powered GRC Platform

[Home](https://www.sorena.io/) | [Solutions](https://www.sorena.io/solutions) | [Artifacts](https://www.sorena.io/artifacts) | [About Us](https://www.sorena.io/about-us) | [Contact](https://www.sorena.io/contact) | [Portal](https://app.sorena.io)

---

# GB/T 41387-2022 smart home security standard

How connected-device teams can scope and document GB/T 41387-2022 without treating it as an automatic certification or product-approval duty.

*Cybersecurity* *China*

## China Cybersecurity Law Smart home security standard evidence

How connected-device teams can scope and document GB/T 41387-2022.

GB/T 41387-2022 is a current recommended national standard implemented on 1 November 2022. It is separate from mandatory launch routes and from the voluntary China Cybersecurity Label scheme effective from 1 July 2026.

GB/T 41387-2022 is the current recommended national standard titled Smart home general security specification. Use it as a documented technical reference. Any certification or product-approval duty must arise from a separate applicable requirement.

## Definitions

### GB/T 41387-2022 - Smart home general security specification

**Term:** GB/T 41387-2022

GB/T 41387-2022 is a current recommended Chinese national standard titled Information security technology - Smart home general security specification. The official standards record states that it was published on 15 April 2022 and implemented on 1 November 2022. That record does not expose the full clauses or establish that every connected product must be certified to the standard.

**Why it matters here:** Use the complete applicable standard text to map requirements to the exact device, firmware, companion app, cloud service, interfaces, and suppliers. Record why the organisation applies the standard and do not treat its implementation date as a recurring deadline.

Sources:

- [Official national standards record for GB/T 41387-2022](https://openstd.samr.gov.cn/bzgk/gb/newGbInfo?hcno=B1C14E854C0BA30D1C29FC376299761A&ref=sorena.io)

### Recommended Chinese national standard

**Term:** recommended national standard

A recommended national standard is identified by the GB/T designation and is listed separately from mandatory national standards in the official standards system. It is not itself a standalone statute and does not, by itself, require certification for every product. A contract, procurement specification, implementation rule, or another applicable instrument may still make conformance relevant to a particular launch or transaction.

**Why it matters here:** Record the specific basis for using GB/T 41387-2022. Keep voluntary design or procurement mappings separate from mandatory product, radio, telecom, app, privacy, and network-operation decisions.

Sources:

- [Official national standards record for GB/T 41387-2022](https://openstd.samr.gov.cn/bzgk/gb/newGbInfo?hcno=B1C14E854C0BA30D1C29FC376299761A&ref=sorena.io)

### China Cybersecurity Label

**Term:** cybersecurity label

The China Cybersecurity Label is the product label created by measures effective 1 July 2026 to show a product's cybersecurity capability level. Participation is voluntary. Product directories and product-specific implementation rules define the covered internet-connected products and detailed requirements. The three capability levels are basic, enhanced, and leading, shown as one, two, and three stars.

**Why it matters here:** The label route is separate from a GB/T 41387-2022 design mapping. Before using a label, the producer follows the applicable implementation rule, obtains the required test report, and files the specified materials. The producer must refile when a change may affect cybersecurity capability or the label expires.

Sources:

- [Cybersecurity Label Administrative Measures](https://www.cac.gov.cn/2026-04/10/c_1777558393316312.htm?ref=sorena.io)

### China Cybersecurity Label product directory

**Term:** product directory

The Cybersecurity Label measures apply to internet-connected products through batches of official product directories. The first directory, issued in June 2026, covers consumer connected cameras and uses the category's implementation rule and TC260-PG-20265A security requirements. The measures do not establish one generic label route for every connected product.

**Why it matters here:** Before planning label testing or filing, confirm that the exact product category appears in the current directory and identify the corresponding implementation rule. A smart-home camera can be in the first batch, while another appliance or hub may not yet have a category route.

Sources:

- [Cybersecurity Label Administrative Measures, Articles 2 and 4](https://www.cac.gov.cn/2026-04/10/c_1777558393316312.htm?ref=sorena.io)
- [First Cybersecurity Label product directory and implementation rules](https://wap.miit.gov.cn/jgsj/waj/wjfb/art/2026/art_560972d39feb447e9187b9ee11b0654e.html?ref=sorena.io)

### Cybersecurity Label product-specific implementation rule

**Term:** product-specific implementation rule

For each product category in the Cybersecurity Label directory, the implementation rule supplies the detailed security requirements, applicable national standards or technical documents, label form, validity, and other category-specific procedures. The general measures do not supply those details for every product.

**Why it matters here:** Use the rule for the exact product category and version to set the test scope, capability level, filing materials, label design, validity period, and refiling decision. Do not substitute GB/T 41387-2022 unless the applicable rule or another documented basis calls for it.

Sources:

- [Cybersecurity Label Administrative Measures, Articles 4-10](https://www.cac.gov.cn/2026-04/10/c_1777558393316312.htm?ref=sorena.io)

## Separate the standard from launch and label routes

Use GB/T 41387-2022 as a smart-home security reference only after identifying the connected product, firmware, companion app, cloud service, operator, data flows, radio functions, suppliers, and China launch routes. The '/T' designation identifies a recommended national standard; the source does not state that every smart-home product must obtain certification under it.

Obtain the applicable standard text before claiming clause-level implementation. Keep the standard mapping separate from mandatory telecom or network access, radio, app, privacy, and product-security records, and from network-operator records for an entity that owns or administers a network or provides network services.

The China Cybersecurity Label measures effective from 1 July 2026 create a separate voluntary route for internet-connected products. The first product directory, issued on 18 June 2026, covers consumer connected cameras and uses a category implementation rule plus TC260-PG-20265A as its security basis. Another smart-home appliance, hub, or service does not enter that route merely because it is internet-connected or mapped to GB/T 41387-2022. The label uses one, two, or three stars for basic, enhanced, or leading capability.

- Standards owner: record why the standard is being used, such as a design benchmark, customer requirement, procurement criterion, risk control, or another documented basis.
- Product-security owner: map the product, hardware, firmware, companion app, cloud services, interfaces, data flows, update path, supported life, and supplier boundaries before assigning evidence.
- Regulatory owner: screen telecom, radio, app, privacy, network-operation, product-security, and cybersecurity label routes separately and preserve each conclusion.
- Do not describe the standard's 1 November 2022 implementation date as a recurring deadline or automatic certification obligation.

Sources for this answer:

- [GB/T smart home general security specification](https://openstd.samr.gov.cn/bzgk/gb/newGbInfo?hcno=B1C14E854C0BA30D1C29FC376299761A&ref=sorena.io) - Use as the smart-home security specification reference for connected appliance evidence mapping and the 1 November 2022 implementation date.
- [PRC Cybersecurity Law, current text](https://www.cac.gov.cn/2025-12/29/c_1768735112911946.htm?ref=sorena.io) - Use Articles 23, 24, 27, and 78 for separate network-operator, product-provider, incident, and actor duties.
- [Cybersecurity Label Administrative Measures](https://www.cac.gov.cn/2026-04/10/c_1777558393316312.htm?ref=sorena.io) - Use for voluntary participation, product directories and implementation rules, testing, filing, label levels and contents, validity, refiling, and the 1 July 2026 effective date.
- [First Cybersecurity Label product directory and implementation rules](https://wap.miit.gov.cn/jgsj/waj/wjfb/art/2026/art_560972d39feb447e9187b9ee11b0654e.html?ref=sorena.io) - Official June 2026 notice confirming that the first implemented category is consumer connected cameras and that TC260-PG-20265A is the category's security basis.

## Practical compliance steps

Use the complete applicable standard text to create a traceable mapping from relevant requirements to design evidence, test results, supplier inputs, exceptions, remediation, and product-security ownership.

Reassess the mapping when hardware, firmware, apps, cloud endpoints, authentication, update mechanisms, data flows, suppliers, or supported product life materially change.

- Keep the product/system boundary and the documented reason for using GB/T 41387-2022.
- Identify the edition of the standard, the clauses mapped, each applicability decision, and the responsible owner.
- Link security architecture, authentication and authorisation, data protection, update, vulnerability, interface, cloud, supplier, test, exception, remediation, and retest evidence where the applicable clauses require them.
- For the voluntary cybersecurity label, check the current product directory and product-specific implementation rule before planning tests or filing. If participating, retain the capability-level decision, test report, label design, conformity declaration, producer and laboratory credentials, filing result, validity period, and any change or expiry refiling decision. The filing body performs a formal review within 10 working days after receiving complete materials; that timing does not replace testing or establish product approval under another regime.
- Keep mandatory China launch decisions in their own records and cross-reference shared technical evidence.

Sources for this answer:

- [GB/T smart home general security specification](https://openstd.samr.gov.cn/bzgk/gb/newGbInfo?hcno=B1C14E854C0BA30D1C29FC376299761A&ref=sorena.io) - Use as the smart-home security specification reference for connected appliance evidence mapping and the 1 November 2022 implementation date.
- [PRC Cybersecurity Law, current text](https://www.cac.gov.cn/2025-12/29/c_1768735112911946.htm?ref=sorena.io) - Use Article 24 for provider vulnerability, reporting, user-notice, and security-maintenance duties where the connected-product provider is in scope.
- [Cybersecurity Label Administrative Measures](https://www.cac.gov.cn/2026-04/10/c_1777558393316312.htm?ref=sorena.io) - Supports the separate voluntary label screen, product-specific implementation rules, testing, filing, validity, and refiling triggers.

## Evidence to keep before launch or change approval

Keep the standard mapping tied to the exact product family, hardware and firmware versions, companion app, cloud services, interfaces, suppliers, and supported life.

A reviewer should be able to trace each mapped requirement to design evidence, test results, an owner, any exception, remediation, and retesting.

- Product and system boundary, model and version identifiers, intended use, interfaces, app and cloud dependencies, and supplier list.
- Documented reason for applying GB/T 41387-2022 and the exact edition and clauses mapped.
- Security architecture, authentication and authorization design, update and vulnerability processes, test results, exceptions, remediation, and retest evidence.
- Supported-life and security-maintenance period, end-of-support decision, user communications, and customer or supplier commitments.
- Cybersecurity label product-directory and product-specific implementation-rule screen; if participating, retain test scope and report, capability level, filing materials, completed filing and label use, validity period, and change or expiry refiling decision.
- Links to separate telecom, radio, app, privacy, network-operator, critical-information-infrastructure, or data-security decisions where they apply.

Sources for this answer:

- [GB/T smart home general security specification](https://openstd.samr.gov.cn/bzgk/gb/newGbInfo?hcno=B1C14E854C0BA30D1C29FC376299761A&ref=sorena.io) - Use as the smart-home security specification reference for connected appliance evidence mapping and the 1 November 2022 implementation date.
- [PRC Cybersecurity Law, current text](https://www.cac.gov.cn/2025-12/29/c_1768735112911946.htm?ref=sorena.io) - Supports the separate evidence for network-operation, product-provider, vulnerability, reporting, and continuing security-maintenance duties.
- [Cybersecurity Label Administrative Measures](https://www.cac.gov.cn/2026-04/10/c_1777558393316312.htm?ref=sorena.io) - Supports the label participation decision and, where used, the testing, filing, label, validity, and refiling evidence.

## Boundary with nearby China regimes

GB/T 41387-2022 does not determine whether a product needs telecom network access approval, radio approval, app filing, personal-information measures, classified protection, cybersecurity review, or a cybersecurity label. Assess each route under its own trigger.

Cross-reference shared facts such as the model number, firmware, app package, cloud endpoints, data flow, supplier, and release date, but keep each legal or standards conclusion separate.

- Treating the standard's 1 November 2022 implementation date as an annual deadline.
- Claiming certification or legal compliance when the source only establishes a recommended standard and its current status.
- Calling the cybersecurity label mandatory without checking the voluntary rule, current product directory, and product-specific implementation rule.
- Mapping only the physical device while omitting firmware, companion apps, cloud services, interfaces, and suppliers.
- Using the standard mapping as a substitute for separate telecom, radio, app, privacy, network, and data decisions.

Sources for this answer:

- [GB/T smart home general security specification](https://openstd.samr.gov.cn/bzgk/gb/newGbInfo?hcno=B1C14E854C0BA30D1C29FC376299761A&ref=sorena.io) - Use as the smart-home security specification reference for connected appliance evidence mapping and the 1 November 2022 implementation date.
- [PRC Cybersecurity Law, current text](https://www.cac.gov.cn/2025-12/29/c_1768735112911946.htm?ref=sorena.io) - Use for separate network-operator, product-provider, incident, CII, and personal-information duties.
- [Cybersecurity Label Administrative Measures](https://www.cac.gov.cn/2026-04/10/c_1777558393316312.htm?ref=sorena.io) - Use to distinguish the voluntary, directory-based label route from the smart-home standard mapping.

*Apply the requirement*

*Placement: Before primary sources*

## Build the China network security evidence file

Track the GB/T 41387-2022 scope and clauses separately from telecom, radio, app, privacy, network, and voluntary label decisions.

- [Map official sources to evidence](/solutions/research-copilot.md): Connect the product boundary and GB/T clauses to design evidence, tests, suppliers, exceptions, label records, and product changes.
- [Review the China route](/contact.md): Check the China Cybersecurity Law scope decision and unresolved launch questions with Sorena.

## Primary sources

- [GB/T smart home general security specification](https://openstd.samr.gov.cn/bzgk/gb/newGbInfo?hcno=B1C14E854C0BA30D1C29FC376299761A&ref=sorena.io) - Use as the smart-home security specification reference for connected appliance evidence mapping and the 1 November 2022 implementation date.
- [PRC Cybersecurity Law, current text](https://www.cac.gov.cn/2025-12/29/c_1768735112911946.htm?ref=sorena.io) - Use Articles 23, 24, 27, 33-40, and 78 to distinguish network, product, incident, CII, and actor duties from the recommended smart-home standard.
- [Cybersecurity Label Administrative Measures](https://www.cac.gov.cn/2026-04/10/c_1777558393316312.htm?ref=sorena.io) - Use for voluntary participation, product directories and implementation rules, testing and filing, label contents, validity, refiling, and the 1 July 2026 effective date.
- [First Cybersecurity Label product directory and implementation rules](https://wap.miit.gov.cn/jgsj/waj/wjfb/art/2026/art_560972d39feb447e9187b9ee11b0654e.html?ref=sorena.io) - Official current directory source for consumer connected cameras, the category implementation rule, and TC260-PG-20265A.

## Related Topic Guides

- [China App Filing vs Personal Information Rules](/artifacts/apac/china-cybersecurity-law/mobile-app-filing-vs-app-personal-information-rules.md): Decide whether a China mobile app needs MIIT filing, personal-information controls, or both, with current triggers, duties, dates, and evidence.
- [China cybersecurity and data security requirements](/artifacts/apac/china-cybersecurity-law/requirements.md): China cybersecurity requirements by actor: network operators, data processors, CII operators, platforms, app providers, and distribution platforms.
- [China cybersecurity compliance checklist](/artifacts/apac/china-cybersecurity-law/checklist.md): A China cybersecurity checklist for scoping network duties, data security, CII procurement review, app rules, MIIT filing, and supporting standards.
- [China cybersecurity deadlines and compliance calendar](/artifacts/apac/china-cybersecurity-law/deadlines-and-compliance-calendar.md): Separate China cybersecurity commencement dates from recurring duties, filing lead times, review periods, and event-driven response deadlines.
- [China Cybersecurity Law FAQ](/artifacts/apac/china-cybersecurity-law/faq.md): Practical answers on China network-operator scope, MLPS evidence, important data, cybersecurity review, app filing and governance, and smart-home standards under the law in force from 1 January 2026.
- [China Cybersecurity Law vs EU Cyber Resilience Act](/artifacts/apac/china-cybersecurity-law/china-cybersecurity-law-vs-eu-cyber-resilience-act.md): Compare China's network-operator rules with the EU CRA's product duties, including scope, actors, evidence, reporting dates, and launch decisions.
- [China Cybersecurity Law vs EU NIS2 Directive](/artifacts/apac/china-cybersecurity-law/china-cybersecurity-law-vs-nis2.md): Compare China's network-operator duties with NIS2 entity duties, including scope, management accountability, incident reporting, evidence, and enforcement.
- [China cybersecurity penalties and fines](/artifacts/apac/china-cybersecurity-law/penalties-and-fines.md): Compare current China Cybersecurity Law and Data Security Law fines by actor, breach, severity, and enforcement consequence.
- [China Cybersecurity Review vs Data Export Assessment](/artifacts/apac/china-cybersecurity-law/cybersecurity-review-vs-data-export-security-assessment.md): Separate China's cybersecurity-review triggers from CAC data-export assessment triggers, thresholds, filings, evidence, timing, and reapplication rules.
- [China cybersecurity review workflow](/artifacts/apac/china-cybersecurity-law/cybersecurity-review-workflow.md): Determine whether CII procurement, platform data processing, or a qualifying foreign listing triggers China's Cybersecurity Review Measures.
- [China mobile app filing and app governance](/artifacts/apac/china-cybersecurity-law/mobile-app-filing-and-app-governance.md): Identify the China app sponsor, complete MIIT filing before service, and separate provider, platform, privacy, content, and security duties.
- [China Smart-Home Security vs Telecom and Radio Approval](/artifacts/apac/china-cybersecurity-law/smart-home-security-vs-telecom-wireless-launch.md): Separate GB/T 41387-2022 smart-home security evidence from China telecom network-access and radio approval decisions for connected products.
- [CII and network operator role triage](/artifacts/apac/china-cybersecurity-law/critical-information-infrastructure-and-network-operators.md): How to separate ordinary network operator duties from CII, procurement, and review-risk questions under China cybersecurity sources.
- [Does an app need MIIT filing and CAC app governance review?](/artifacts/apac/china-cybersecurity-law/faq/does-an-app-need-miit-filing-and-cac-app-governance-review.md): An app sponsor providing internet information services through an app in China must complete MIIT filing. CAC rules separately govern app providers and distribution platforms without creating one routine CAC approval for every app.
- [GB/T 22239-2019 classified protection baseline](/artifacts/apac/china-cybersecurity-law/classified-protection-baseline.md): How to scope and document a GB/T 22239-2019 classified protection baseline without treating the recommended standard as a standalone law.
- [How do smart home security standards fit with China cybersecurity law?](/artifacts/apac/china-cybersecurity-law/faq/how-do-smart-home-security-standards-fit-with-china-cybersecurity-law.md): GB/T 41387-2022 can organize smart-home security evidence, but it is a recommended standard, not a product approval. Check app, data, MLPS, telecom access, and radio requirements separately.
- [How does important data change China cybersecurity obligations?](/artifacts/apac/china-cybersecurity-law/faq/how-does-important-data-change-cybersecurity-obligations.md): Once data is officially identified as important data, the processor needs named governance, periodic risk assessments and reports, incident controls, and a separate export decision. An internal sensitivity label alone does not establish the legal category.
- [Is every company a network operator under China Cybersecurity Law?](/artifacts/apac/china-cybersecurity-law/faq/is-every-company-a-network-operator-under-china-cybersecurity-law.md): No. Under China's Cybersecurity Law, a network operator is an owner or administrator of a network or a network service provider. Apply that definition to each China network or service, then test CII and other roles separately.
- [MLPS classified protection evidence map](/artifacts/apac/china-cybersecurity-law/mlps-classified-protection-evidence-map.md): Classify a China network under MLPS, complete level 2 or above filing, map controls, and retain assessment, remediation, and change evidence.
- [What is MLPS classified protection evidence?](/artifacts/apac/china-cybersecurity-law/faq/what-is-mlps-classified-protection-evidence.md): MLPS evidence shows how a defined China network or system was graded and protected. Keep the scope, grading rationale, filing or assessment records where applicable, control mapping, test results, remediation, and reassessment history.
- [When does China cybersecurity review apply?](/artifacts/apac/china-cybersecurity-law/faq/when-does-china-cybersecurity-review-apply.md): China cybersecurity review applies to CII procurement or network-platform data processing that affects or may affect national security, plus a mandatory pre-filing trigger for certain foreign listings involving more than one million users' personal information.


---

[Privacy Policy](https://www.sorena.io/privacy.md) | [Terms of Use](https://www.sorena.io/terms-of-use.md) | [DMCA](https://www.sorena.io/dmca.md) | [About Us](https://www.sorena.io/about-us.md)

(c) 2026 Sorena AB (559573-7338). All rights reserved.

Source: https://www.sorena.io/artifacts/apac/china-cybersecurity-law/smart-home-security-standard.md
