GB/T 41387-2022 is a recommended smart-home cybersecurity standard. Telecom network-access licensing and radio approvals are separate market-entry decisions.
A connected appliance can need security evidence, radio type approval, and telecom network-access permission, but no single test report or certificate completes every track.
Use to structure smart-home cybersecurity evidence; it is a recommended national standard, not a product approval or a substitute for binding law. Separately check whether the product appears in the telecom-equipment network-access catalogue and whether each radio transmitter needs or qualifies for a . A Wi-Fi appliance does not automatically need every permit, and using a pre-approved radio module does not by itself settle approval for the final host product.
Comparison
Smart-home security evidence vs Telecom and wireless launch
Use the security track to map and test smart-home cybersecurity controls. Use the market-access track to decide whether the exact product needs licensing, radio , or a documented exemption.
addresses security for smart-home systems and provides a recommended control reference. Its GB/T status does not itself create a government product approval.
licensing applies to covered equipment in the applicable catalogue that connects to public telecom networks. Radio applies to transmitters unless a rule such as the micro-power catalogue provides an exemption subject to conditions.
Determine the standard, network-access, and radio scopes independently for the exact product configuration. Do not infer a permit from the presence of Wi-Fi or Bluetooth alone.
The producer or applicant coordinates the network-access application and radio classification with accredited testing, certification, import, labeling, and sales teams.
Name a security evidence owner and a market-access applicant. A module vendor's certificate can be an input, but the final-product owner must confirm its permitted use.
Repeat the radio and security reviews after changes to a module, antenna, frequency, output power, enclosure, firmware, cloud endpoint, or network function.
Map the applicable GB/T requirements to the smart-home architecture, implement the controls, test the released configuration, manage vulnerabilities and updates, and record deviations and remediation.
For covered telecom equipment, obtain the required network-access licence or trial approval and maintain the approved configuration. For radio equipment, obtain or document the exact exemption and comply with the applicable technical, labeling, interference, and use conditions.
Retain the system and trust-boundary diagram, asset and interface inventory, GB/T clause map, risk analysis, security design, test plan and results, defect decisions, vulnerability process, update support plan, and released versions.
Retain the current telecom-catalogue rationale, application and licence where required, transmitter and module inventory, radio test reports, model-approval certificate or micro-power analysis, approved technical parameters, labels, import and sales records, and change assessment.
Tie every record to hardware, firmware, radio module, antenna, and regional variant. Similar model names are not evidence that approval scope is identical.
was published on 15 April 2022 and implemented on 1 November 2022. That implementation date is not a recurring renewal or a government approval deadline.
Complete required testing and applications before the regulated production, import, sale, or network connection. MIIT's 2023 reform commits, except for a statutory reason, to decide a network-access application within 15 working days after acceptance. The cited 2400 MHz, 5100 MHz, and 5800 MHz model-approval technical requirements have applied to applications since 15 October 2023; confirm the current rule for every band and product.
Plan market-access lead time from the exact approval route, including testing and any application cure period, and maintain security evidence through the support lifecycle.
Failure to follow a recommended GB/T standard is not automatically the same as violating a mandatory rule. Exposure depends on any binding law, contract, certification claim, procurement condition, or representation that makes the standard relevant.
Equipment that requires network-access or radio approval must not be treated as approved merely because a component was tested. Consequences depend on the missing licence, approval, filing, label, technical condition, or other breached rule.
State exactly what was assessed, what approval or exemption applies, and which configuration it covers. Avoid a broad claim that the whole product is 'China certified.'
Security and market-access teams can share the bill of materials, architecture, module list, interfaces, firmware identifiers, test samples, suppliers, and change history.
Only the market-access record decides whether network-access licensing or radio is required and whether an exemption covers the released configuration.
addresses security for smart-home systems and provides a recommended control reference. Its GB/T status does not itself create a government product approval.
licensing applies to covered equipment in the applicable catalogue that connects to public telecom networks. Radio applies to transmitters unless a rule such as the micro-power catalogue provides an exemption subject to conditions.
Determine the standard, network-access, and radio scopes independently for the exact product configuration. Do not infer a permit from the presence of Wi-Fi or Bluetooth alone.
The producer or applicant coordinates the network-access application and radio classification with accredited testing, certification, import, labeling, and sales teams.
Name a security evidence owner and a market-access applicant. A module vendor's certificate can be an input, but the final-product owner must confirm its permitted use.
Repeat the radio and security reviews after changes to a module, antenna, frequency, output power, enclosure, firmware, cloud endpoint, or network function.
Map the applicable GB/T requirements to the smart-home architecture, implement the controls, test the released configuration, manage vulnerabilities and updates, and record deviations and remediation.
For covered telecom equipment, obtain the required network-access licence or trial approval and maintain the approved configuration. For radio equipment, obtain or document the exact exemption and comply with the applicable technical, labeling, interference, and use conditions.
Retain the system and trust-boundary diagram, asset and interface inventory, GB/T clause map, risk analysis, security design, test plan and results, defect decisions, vulnerability process, update support plan, and released versions.
Retain the current telecom-catalogue rationale, application and licence where required, transmitter and module inventory, radio test reports, model-approval certificate or micro-power analysis, approved technical parameters, labels, import and sales records, and change assessment.
Tie every record to hardware, firmware, radio module, antenna, and regional variant. Similar model names are not evidence that approval scope is identical.
was published on 15 April 2022 and implemented on 1 November 2022. That implementation date is not a recurring renewal or a government approval deadline.
Complete required testing and applications before the regulated production, import, sale, or network connection. MIIT's 2023 reform commits, except for a statutory reason, to decide a network-access application within 15 working days after acceptance. The cited 2400 MHz, 5100 MHz, and 5800 MHz model-approval technical requirements have applied to applications since 15 October 2023; confirm the current rule for every band and product.
Plan market-access lead time from the exact approval route, including testing and any application cure period, and maintain security evidence through the support lifecycle.
Failure to follow a recommended GB/T standard is not automatically the same as violating a mandatory rule. Exposure depends on any binding law, contract, certification claim, procurement condition, or representation that makes the standard relevant.
Equipment that requires network-access or radio approval must not be treated as approved merely because a component was tested. Consequences depend on the missing licence, approval, filing, label, technical condition, or other breached rule.
State exactly what was assessed, what approval or exemption applies, and which configuration it covers. Avoid a broad claim that the whole product is 'China certified.'
Security and market-access teams can share the bill of materials, architecture, module list, interfaces, firmware identifiers, test samples, suppliers, and change history.
Only the market-access record decides whether network-access licensing or radio is required and whether an exemption covers the released configuration.
Use to map and test smart-home cybersecurity controls, while recording that GB/T is a recommended standard unless another instrument makes it binding.
Check the current telecom-equipment catalogue and each transmitter's radio classification before production, import, sale, or public-network connection; obtain the required approval or document the exemption.
Release only the hardware, firmware, module, antenna, frequency, power, label, and network configuration covered by the retained evidence.
First define the product: appliance functions, controller, cloud service, mobile app, network interfaces, radio bands, modules, intended public-network connection, and China sales model. Use that architecture for every track.
, Information security technology - Smart home general security specification, was issued on 15 April 2022 and implemented on 1 November 2022. The official standards catalogue marks it GB/T, a recommended national standard. Use it as a control and evidence reference unless a contract, certification scheme, procurement rule, or other binding instrument makes compliance a condition.
For market access, check the current telecom-equipment catalogue before assuming a network-access licence is required. Separately classify every transmitter under the radio rules. Covered radio-transmitting equipment needs before production or import for domestic sale or use unless an exemption applies. Equipment claimed as micro-power must appear in and meet the catalogue's frequency, power, antenna, use-scenario, interference, and instruction conditions.
Also screen the voluntary China Cybersecurity Label separately. The first product directory, issued in June 2026, covers consumer connected cameras and uses its own implementation rule and TC260-PG-20265A security requirements. A camera may therefore have a label route as well as radio and, if catalogued, telecom work; the label does not replace either approval.
Security owner: retain the GB/T clause map, architecture, threat and risk analysis, design controls, security tests, vulnerability handling, update plan, and remediation.
Market-access owner: retain the current catalogue decision, device category, network-access application and result where required, transmitter inventory, radio classification, model-approval or exemption evidence, labels, and sales records.
Product owner: link every decision to the exact hardware, firmware, module, antenna, frequency, power, and released configuration.
Official source for the first voluntary label category, consumer connected cameras, its implementation rule, and TC260-PG-20265A security requirements.
Use for 2400 MHz, 5100 MHz, and 5800 MHz radio transmitting equipment requirements, model-approval evidence, station-license distinctions, interference controls, transition handling, and 15 October 2023 technical requirement start date.
Use for PIPL scope, processing bases, notice and consent, individual rights, processor duties, PIPIA, cross-border transfer duties, penalties, and effective date.