After years of working on in-vehicle certification, the question we hear most is still the simplest one: what on earth do GB 44495 and GB 44496 actually govern? The moment a new model is kicked off, procurement, R&D and project management take turns asking. BlueAsia fields these from three different teams on the same vehicle programme, so here is a straight walk-through in plain language, with a few walls we have personally hit.
1.1 Publication and implementation dates
Pin the dates down first. On 23 August 2024, the State Administration for Market Regulation and the Standardization Administration of China released three mandatory intelligent-vehicle standards; GB 44495 and GB 44496 took effect on 1 January 2026.
The No. 1 Amendment has a slightly twisty timeline: it went to public comment in September 2025, the draft for approval was published on 16 December 2025, and it entered into force on 28 January 2026.
1.2 What the amendment actually changed
Two phrases shifted. "Information security management system" became "information security assurance requirements," and "inspection" became "examination." The system was not scrapped — the framing changed. Clause 8.1 is now called document examination; it reviews the materials and runs on a separate track from the factory audit.
1.3 Three standards, one batch, three jobs
GB 44495 covers whole-vehicle information security; GB 44496 covers software upgrades; GB 44497 covers the automated-driving data recorder. Match them to function. Whether you touch 44497 depends on whether the vehicle has automated driving. It has no amendment and is not synchronised with the other two.
1.4 Relationship to international regulation
When drafted, they were closely coordinated with UN R155 and R156, so the broad framework is aligned. The domestic version adds a few extras: vehicle-cloud interaction, cross-border data transfer, identity marking and cryptography compliance.
2. What GB 44495 covers
2.1 Which vehicles it applies to
The GB 44495-2024 formal edition applies to M-class and N-class vehicles, plus O-class vehicles fitted with at least one electronic control unit. The No. 1 Amendment narrows this to M-class and N-class only; trailers are no longer mandatory. If you make trailer parts, confirm first which edition you are declaring against.
2.2 Information security assurance requirements
The check is whether the risk-management mechanism actually runs — covering the full lifecycle from R&D and production through operation and end-of-life. China does not issue a standalone CSMS certificate; the materials go through document examination at the type-approval stage, on a separate track from the factory audit.
2.3 External connection security
OBD, USB, Bluetooth, Wi-Fi, cellular — each is examined one by one. The focus is interface identity authentication, protection against unauthorised access, and how the production debug port is closed off. The debug port sparks the most debate. Any port exposed to the outside must be tightened; adding authentication and assuming you can keep it open still leaves the risk. Built-in ports need access control too. On a recent project, hardware wanted to keep the port in the glove box for production testing; it got pulled out and reworked at the rating stage.
2.4 Communication, upgrade and data security
Inside the vehicle, check CAN and automotive-Ethernet message authentication and integrity. Vehicle-to-cloud checks encryption and identity verification; V2X requires an assessment of external communication protection. Upgrade-package signature verification and anti-rollback tie directly into GB 44496. Data security watches for data minimisation and deletion.
3. What GB 44496 covers
3.1 Which vehicles it applies to
Any M-, N- or O-class vehicle with a software-upgrade function falls inside. It only looks at whether OTA is possible — nothing to do with whether it is new-energy. A fuel vehicle with OTA still has to pass.
3.2 Upgrade management system and notification
The process, roles and responsibilities, version control and rollback plan must be written down, with traceable records kept. The standard sets requirements for what the notification says and how it is presented; a forced upgrade must state its reason. The version number must be readable from outside — this is the item most often missed.
3.3 Preconditions and failure handling
Upgrade must not start if vehicle speed, gear or battery level is not met. A power loss or interrupted transfer must be able to roll back, with evidence of functional consistency. Cryptography is assessed under commercial-cryptography rules, with domestic algorithms preferred; others go through the formal procedure. The user manual is also required by the standard and is often missing at sample submission.
4. Pitfalls that bite at implementation
4.1 There is no standalone "GB 44495 certificate"
Right now there is no independent certificate; the report folds into the whole-vehicle type approval. The TC11 technical resolution from the certification accreditation body has already listed these two as candidate standards to be brought under CCC; once the announcement lands, they bind even tighter to CCC. If you accept a project on a "get a certificate" basis, disputes tend to follow.
4.2 How to use component reports
Module and component reports are useful — they can support the TARA document. But the whole-vehicle type test is the one the component material cannot replace; it needs whole-vehicle testing. Handing the lab a patchwork of supplier materials gets rejected.
4.3 Use the same-type determination to the full
The standard has a same-type determination clause, and the amendment refines the same-platform, same-source rules. Series models with consistent architecture and protection design share one report. The premise is that the testing body confirms the conditions are met; if you self-determine and use it directly, the report is void.
4.4 How to prepare the documentation
Documentation splits into three blocks, checked item by item:
(1) Information security: system documents, TARA report, incident-response plan, vulnerability-management process, clause-by-clause self-declaration. (2) Software upgrade: upgrade-process documents, version-control records, rollback plan, notification template. (3) Sample-vehicle testing: the sample vehicle, the product user manual, and test-support personnel.
① The TARA report gets bounced back most often — do not write only conclusions without the derivation. ② Missing items do not always trigger an immediate rejection, but the report will not come out and the schedule slips.
5. A few frequently asked questions
5.1 What about in-production models
In-production models that already hold type approval get a rectification window, but it is not open-ended; there is a cutoff node later, confirmed against the competent authority's notice. Do not back-calculate from the new-model timeline, and do not assume you never have to deal with it.
5.2 Do export vehicles need it
This is a domestic market-access requirement, a separate system from the EU's R155 and R156, planned per target-market regulation. The frameworks align, so a system built once can be reused for most of it; the domestic items are added on top.
Contact: King Email: king.guo@cblueasia.comAddress: Building C, Hongjingda Industrial Park, No. 107 Beihuan Road, Shiyan Street, Bao'an District, Shenzhen, China BlueAsia delivers more than service!
Related News