CybersecurityChina

Smart-home security vs telecom and radio approval

GB/T 41387-2022 is a recommended smart-home cybersecurity standard. Telecom network-access licensing and radio approvals are separate market-entry decisions.

A connected appliance can need security evidence, radio type approval, and telecom network-access permission, but no single test report or certificate completes every track.

Author
Sorena AI
Published
Jul 5, 2026
Updated
Jul 25, 2026
Sections
1

Structured answer sets in this page tree.

Primary sources
9

Cited legal and guidance references.

Publication metadata
Sorena AI
Published Jul 5, 2026
Updated Jul 25, 2026
Overview

Use to structure smart-home cybersecurity evidence; it is a recommended national standard, not a product approval or a substitute for binding law. Separately check whether the product appears in the telecom-equipment network-access catalogue and whether each radio transmitter needs or qualifies for a . A Wi-Fi appliance does not automatically need every permit, and using a pre-approved radio module does not by itself settle approval for the final host product.

Comparison

Smart-home security evidence vs Telecom and wireless launch

Use the security track to map and test smart-home cybersecurity controls. Use the market-access track to decide whether the exact product needs licensing, radio , or a documented exemption.

Review all sources
First framework
Smart-home security evidence

Use as a recommended control map for the smart-home system, including devices, communications, applications, platforms, and security management.

Second framework
Telecom and wireless launch

Use for product-specific licensing and radio classification, , micro-power conditions, labeling, and sales evidence.

Comparison row 1

Scope boundary

Smart-home security evidence

addresses security for smart-home systems and provides a recommended control reference. Its GB/T status does not itself create a government product approval.

Telecom and wireless launch

licensing applies to covered equipment in the applicable catalogue that connects to public telecom networks. Radio applies to transmitters unless a rule such as the micro-power catalogue provides an exemption subject to conditions.

Operational implication

Determine the standard, network-access, and radio scopes independently for the exact product configuration. Do not infer a permit from the presence of Wi-Fi or Bluetooth alone.

Comparison row 2

Covered actors

Smart-home security evidence

The manufacturer or system provider assigns product security, firmware, cloud, app, testing, and vulnerability owners for the GB/T evidence map.

Telecom and wireless launch

The producer or applicant coordinates the network-access application and radio classification with accredited testing, certification, import, labeling, and sales teams.

Operational implication

Name a security evidence owner and a market-access applicant. A module vendor's certificate can be an input, but the final-product owner must confirm its permitted use.

Comparison row 3

Trigger event

Smart-home security evidence

Screen when a product participates in a smart-home system or when a customer, certification scheme, or procurement requirement calls for evidence.

Telecom and wireless launch

Screen before China production, import, sale, or public-network connection when the product contains a transmitter or may fall in the catalogue.

Operational implication

Repeat the radio and security reviews after changes to a module, antenna, frequency, output power, enclosure, firmware, cloud endpoint, or network function.

Comparison row 4

Core obligations

Smart-home security evidence

Map the applicable GB/T requirements to the smart-home architecture, implement the controls, test the released configuration, manage vulnerabilities and updates, and record deviations and remediation.

Telecom and wireless launch

For covered telecom equipment, obtain the required network-access licence or trial approval and maintain the approved configuration. For radio equipment, obtain or document the exact exemption and comply with the applicable technical, labeling, interference, and use conditions.

Operational implication

A penetration test does not grant market access, and a network-access or radio certificate does not establish the product's cybersecurity posture.

Comparison row 5

Evidence package

Smart-home security evidence

Retain the system and trust-boundary diagram, asset and interface inventory, GB/T clause map, risk analysis, security design, test plan and results, defect decisions, vulnerability process, update support plan, and released versions.

Telecom and wireless launch

Retain the current telecom-catalogue rationale, application and licence where required, transmitter and module inventory, radio test reports, model-approval certificate or micro-power analysis, approved technical parameters, labels, import and sales records, and change assessment.

Operational implication

Tie every record to hardware, firmware, radio module, antenna, and regional variant. Similar model names are not evidence that approval scope is identical.

Comparison row 6

Timing and refresh points

Smart-home security evidence

was published on 15 April 2022 and implemented on 1 November 2022. That implementation date is not a recurring renewal or a government approval deadline.

Telecom and wireless launch

Complete required testing and applications before the regulated production, import, sale, or network connection. MIIT's 2023 reform commits, except for a statutory reason, to decide a network-access application within 15 working days after acceptance. The cited 2400 MHz, 5100 MHz, and 5800 MHz model-approval technical requirements have applied to applications since 15 October 2023; confirm the current rule for every band and product.

Operational implication

Plan market-access lead time from the exact approval route, including testing and any application cure period, and maintain security evidence through the support lifecycle.

Comparison row 7

Enforcement exposure

Smart-home security evidence

Failure to follow a recommended GB/T standard is not automatically the same as violating a mandatory rule. Exposure depends on any binding law, contract, certification claim, procurement condition, or representation that makes the standard relevant.

Telecom and wireless launch

Equipment that requires network-access or radio approval must not be treated as approved merely because a component was tested. Consequences depend on the missing licence, approval, filing, label, technical condition, or other breached rule.

Operational implication

State exactly what was assessed, what approval or exemption applies, and which configuration it covers. Avoid a broad claim that the whole product is 'China certified.'

Comparison row 8

Overlap and routing

Smart-home security evidence

Security and market-access teams can share the bill of materials, architecture, module list, interfaces, firmware identifiers, test samples, suppliers, and change history.

Telecom and wireless launch

Only the market-access record decides whether network-access licensing or radio is required and whether an exemption covers the released configuration.

Operational implication

Link shared evidence, but keep the GB/T control conclusion, network-access decision, and radio decision as separate records.

Comparison row 9

Practical decision rule

Smart-home security evidence

Run the GB/T track when the product or smart-home system needs structured cybersecurity evidence under .

Telecom and wireless launch

Run the market-access track when the product connects to a public telecom network, contains radio-transmitting equipment, or relies on a claimed .

Operational implication

Most connected-appliance launches should at least screen both tracks. Complete only the approvals that the exact product and route require.

Practical decision rule

When to run one track or both

  • Use to map and test smart-home cybersecurity controls, while recording that GB/T is a recommended standard unless another instrument makes it binding.
  • Check the current telecom-equipment catalogue and each transmitter's radio classification before production, import, sale, or public-network connection; obtain the required approval or document the exemption.
  • Release only the hardware, firmware, module, antenna, frequency, power, label, and network configuration covered by the retained evidence.
Section 1

How to use this comparison

First define the product: appliance functions, controller, cloud service, mobile app, network interfaces, radio bands, modules, intended public-network connection, and China sales model. Use that architecture for every track.

, Information security technology - Smart home general security specification, was issued on 15 April 2022 and implemented on 1 November 2022. The official standards catalogue marks it GB/T, a recommended national standard. Use it as a control and evidence reference unless a contract, certification scheme, procurement rule, or other binding instrument makes compliance a condition.

For market access, check the current telecom-equipment catalogue before assuming a network-access licence is required. Separately classify every transmitter under the radio rules. Covered radio-transmitting equipment needs before production or import for domestic sale or use unless an exemption applies. Equipment claimed as micro-power must appear in and meet the catalogue's frequency, power, antenna, use-scenario, interference, and instruction conditions.

Also screen the voluntary China Cybersecurity Label separately. The first product directory, issued in June 2026, covers consumer connected cameras and uses its own implementation rule and TC260-PG-20265A security requirements. A camera may therefore have a label route as well as radio and, if catalogued, telecom work; the label does not replace either approval.

  • Security owner: retain the GB/T clause map, architecture, threat and risk analysis, design controls, security tests, vulnerability handling, update plan, and remediation.
  • Market-access owner: retain the current catalogue decision, device category, network-access application and result where required, transmitter inventory, radio classification, model-approval or exemption evidence, labels, and sales records.
  • Product owner: link every decision to the exact hardware, firmware, module, antenna, frequency, power, and released configuration.
Primary sources

References and citations

wap.miit.gov.cn
Referenced sections
  • Use for 2400 MHz, 5100 MHz, and 5800 MHz radio transmitting equipment requirements, model-approval evidence, station-license distinctions, interference controls, transition handling, and 15 October 2023 technical requirement start date.
sdca.miit.gov.cn
Referenced sections
  • Use the consolidated 2025 text for current network-operator, network-product, CII, personal-information security, incident, and penalty provisions.
cac.gov.cn
Referenced sections
  • Use for PIPL scope, processing bases, notice and consent, individual rights, processor duties, PIPIA, cross-border transfer duties, penalties, and effective date.
Related guides

Explore more topics

China App Filing vs Personal Information Rules
Decide whether a China mobile app needs MIIT filing, personal-information controls, or both, with current triggers, duties, dates, and evidence.
China cybersecurity and data security requirements
China cybersecurity requirements by actor: network operators, data processors, CII operators, platforms, app providers, and distribution platforms.
China cybersecurity compliance checklist
A China cybersecurity checklist for scoping network duties, data security, CII procurement review, app rules, MIIT filing, and supporting standards.
China cybersecurity deadlines and compliance calendar
Separate China cybersecurity commencement dates from recurring duties, filing lead times, review periods, and event-driven response deadlines.
China Cybersecurity Law FAQ
Practical answers on China network-operator scope, MLPS evidence, important data, cybersecurity review, app filing and governance, and smart-home standards under the law in force from 1 January 2026.
China Cybersecurity Law vs EU Cyber Resilience Act
Compare China's network-operator rules with the EU CRA's product duties, including scope, actors, evidence, reporting dates, and launch decisions.
China Cybersecurity Law vs EU NIS2 Directive
Compare China's network-operator duties with NIS2 entity duties, including scope, management accountability, incident reporting, evidence, and enforcement.
China cybersecurity penalties and fines
Compare current China Cybersecurity Law and Data Security Law fines by actor, breach, severity, and enforcement consequence.
China Cybersecurity Review vs Data Export Assessment
Separate China's cybersecurity-review triggers from CAC data-export assessment triggers, thresholds, filings, evidence, timing, and reapplication rules.
China cybersecurity review workflow
Determine whether CII procurement, platform data processing, or a qualifying foreign listing triggers China's Cybersecurity Review Measures.
China mobile app filing and app governance
Identify the China app sponsor, complete MIIT filing before service, and separate provider, platform, privacy, content, and security duties.
CII and network operator role triage
How to separate ordinary network operator duties from CII, procurement, and review-risk questions under China cybersecurity sources.
Does an app need MIIT filing and CAC app governance review?
An app sponsor providing internet information services through an app in China must complete MIIT filing. CAC rules separately govern app providers and distribution platforms without creating one routine CAC approval for every app.
GB/T 22239-2019 classified protection baseline
How to scope and document a GB/T 22239-2019 classified protection baseline without treating the recommended standard as a standalone law.
GB/T 41387-2022 smart home security standard
How connected-device teams can scope and document GB/T 41387-2022 without treating it as an automatic certification or product-approval duty.
How do smart home security standards fit with China cybersecurity law?
GB/T 41387-2022 can organize smart-home security evidence, but it is a recommended standard, not a product approval. Check app, data, MLPS, telecom access, and radio requirements separately.
How does important data change China cybersecurity obligations?
Once data is officially identified as important data, the processor needs named governance, periodic risk assessments and reports, incident controls, and a separate export decision. An internal sensitivity label alone does not establish the legal category.
Is every company a network operator under China Cybersecurity Law?
No. Under China's Cybersecurity Law, a network operator is an owner or administrator of a network or a network service provider. Apply that definition to each China network or service, then test CII and other roles separately.
MLPS classified protection evidence map
Classify a China network under MLPS, complete level 2 or above filing, map controls, and retain assessment, remediation, and change evidence.
What is MLPS classified protection evidence?
MLPS evidence shows how a defined China network or system was graded and protected. Keep the scope, grading rationale, filing or assessment records where applicable, control mapping, test results, remediation, and reassessment history.
When does China cybersecurity review apply?
China cybersecurity review applies to CII procurement or network-platform data processing that affects or may affect national security, plus a mandatory pre-filing trigger for certain foreign listings involving more than one million users' personal information.