What GB 44495 and GB 44496 Certification Really Cost — and Where the Money Goes

2026-09-01

Since these two national standards moved into real enforcement in 2026, most of the people who call us are not asking about the technology. They are asking about the budget. Online quotes run from just over 100,000 RMB to 600,000–700,000 RMB, and the spread is absurd. The stranger part is that most write-ups never explain which fee applies at which stage. BlueAsia sees this confusion every week, so this piece takes the cost structure apart without the runaround.

1. Three widely repeated claims to correct first

1.1 There is no such thing as a "GB 44495 certificate"

These two are mandatory national standards sitting under the vehicle type-approval (announcement) system. They are not a standalone certification scheme like CCC. If a model fails, the consequence is that it cannot obtain type approval, cannot enter mass production, and cannot be registered for the road. But the company never receives a document titled "GB 44495 certificate." When you hear someone say "information security is certified separately," that usually comes from someone who has not walked a full whole-vehicle programme.

1.2 Announcement review does not charge a separate administrative fee

The "application fee of 500, registration fee of 800, annual maintenance fee of 100" figures circulating online are CCC product-certification fee items. They have nothing to do with GB 44495 or GB 44496. At the announcement-review stage, MIIT does not set up a separate administrative charge for these two standards. 

What a company does pay are the real costs generated during certification — testing fees and laboratory service fees — and those make up 60% to 75% of the total budget. Translation fees are not the government's concern either; that is a company's own third-party arrangement.

1.3 Implementation date and mandatory node are two different things

On 16 December 2025, the State Administration for Market Regulation together with the Standardization Administration of China issued the No. 1 Amendment, with MIIT responsible for stewardship and rollout. The amendment changed the wording from "for models with a newly applied vehicle type approval, implementation starts from the date the amendment takes effect" to "implementation starts from the seventh month after the amendment takes effect."

The standard's own implementation date remains 1 January 2026, while the mandatory enforcement node for newly applied type-approval models was pushed back to 1 July 2026. Per the Equipment Industry Development Center's June 2026 notice "On Implementing and Rectifying Standards under the Announcement," both standards apply to newly applied type-approval models from 1 July 2026. Already-approved in-production models follow a separate rectification schedule, so confirm against the latest official notice when planning.

1.4 System requirements folded into whole-vehicle inspection

Another change in the No. 1 Amendment moves the standard's "system inspection" content into whole-vehicle inspection requirements. It no longer separately requires a CSMS (Cyber Security Management System) certification; the capability review is folded into the whole-vehicle announcement and factory audit. 

In other words, building a CSMS first is no longer a mandatory prerequisite before sending samples for testing. Putting your own system in place is a plus that helps you pass testing, but it is not an official front gate. This is real relief for small and medium manufacturers — stop reserving budget for a system audit under the old rule.

  2. The bulk of the money is testing fees

2.1 There is no official uniform price

State it plainly: these two standards have never had an industry-wide fixed price, and every "package quote" in circulation should be treated as folklore. The real spend depends on three things:

·How complex the model's electrical and electronic architecture is, and how many ECUs it carries.

·How many external interfaces it has, and whether it includes V2X.

·Whether it has OTA capability.

Each item maps to test modules, and as modules stack up, the price climbs.

2.2 Component reports cannot replace whole-vehicle testing

This is where budgets get miscalculated most often. The assumption that once the T-BOX or communication module has passed its own compliance, the whole-vehicle stage can just reuse the data — that does not work. Component test reports only serve as reference material for whole-vehicle testing. 

The whole-vehicle penetration testing and the end-to-cloud app full-chain verification still have to be done. What component-level compliance saves you is the re-test workload on component items, not the whole-vehicle test items. Only if the electrical and electronic architecture and security strategy are completely unchanged might individual component test items be accepted.

  3. How GB 44496 is counted on its own

3.1 Whether it applies depends on OTA

GB 44496 governs the general technical requirements for automotive software upgrades. If a model has no software-upgrade configuration, it usually needs only GB 44495 and does not need to be submitted for 44496 at the same time. Models with OTA generally submit both together.

3.2 Offline flashing alone does not mean exemption

A widely spread claim says that models doing only offline diagnostic flashing, with no remote OTA, get a full pass on 44496. That does not hold up. Basic items such as software identification-code reading and upgrade-package security safeguards are still tested. When submitted together, sharing the sample vehicle and merging test conditions saves a little, but the total budget is not a simple addition of the two items.

  4. Cost lines that get missed

4.1 Rectification re-testing

If the first submission shows high-risk vulnerabilities that are not closed, or the technical documentation is non-compliant, you rectify and re-test. Routine re-testing runs 30% to 50% of the initial test cost, and severe cases with a single supplementary round above 100,000 RMB have been seen. If you do not budget this up front, it becomes the biggest overrun later.

4.2 Document preparation

When the in-house technical team lacks the capability, outsourcing the risk-assessment report, security-protection plan, and compliance archiving can run anywhere from 10,000 to 30,000 RMB for the full set.

4.3 Schedule and manpower

The number of qualified inspection bodies is limited, and scheduling is tight. Lock your slot one week late and the whole project slips one week. The internal manpower and time cost is often harder to quantify than the testing fee on the books.

  5. How to pull the budget down

5.1 Use the same-platform, same-source determination to the full

The No. 1 Amendment added detailed rules for same-platform, same-source determination, corresponding to the standard's "same-type determination" clause. Series models whose whole-vehicle base architecture and information-security protection design stay consistent can share one valid test report, with no repeated physical testing. On platform projects with multiple models, this saves a considerable amount.

5.2 Push component compliance to the front

Individually testing core components like the T-BOX and communication modules cannot replace the whole-vehicle test, but it does compress the repeated testing at the whole-vehicle stage. Lay the groundwork early and you save later.

5.3 Get the security logic right during R&D

Fixing the design after the lab finds the problem costs an entirely different order of magnitude from fixing it during development.


Contact: King Email: king.guo@cblueasia.comAddress: Building C, Hongjingda Industrial Park, No. 107 Beihuan Road, Shiyan Street, Bao'an District, Shenzhen, China BlueAsia delivers more than service!