The Technical Requirements for Vehicle Cybersecurity (GB 44495) and the General Technical Requirements for Vehicle Software Update (GB 44496) are China's mandatory national standards for vehicles – aligned with UN R155 and R156 respectively. These two standards do not issue separate certificates – compliance capability is reviewed alongside the whole‑vehicle announcement.
GB 44497 (event data recording) took effect on 1 January 2026 – applying only to vehicles with automated driving features. It is not aligned with GB 44495/44496 – compliance materials must be prepared separately.
2. 2026 – The Most Critical Implementation Dates
Due to Amendment No.1, the mandatory date for new type‑approval applications has been moved to 1 July 2026 – the original 1 January 2026 date no longer applies to new vehicles. Existing announced models have a transition period – no blanket cut‑off. When scheduling projects, always refer to the official Amendment text – using old dates risks delaying announcement submissions.
China has abolished the separate pre‑CSMS certificate – security capability is now reviewed together with the whole‑vehicle announcement materials. Companies must prepare complete system documentation and supporting evidence – a single certificate is not sufficient. This logic differs from overseas (system certification first, then model approval) – do not directly copy overseas project experience.
3. Software Update Standard – Six Main Parts
3.1 Management system and process
Companies must establish a software‑update management system – covering the full lifecycle: version generation, verification, release, monitoring, and rollback – with regular internal audits.
Amendment No.1 is still in draft consultation – terminology changes are not yet effective. Use current standard wording in applications – do not pre‑apply draft content – otherwise documents will be rejected.
3.2 Vehicle and OTA upgrade requirements
Whole‑vehicle verification includes 14 test items – 8 for local upgrades and 6 additional for OTA. In‑vehicle upgrades are prohibited while the vehicle is in motion – a hard requirement.
Door mechanical unlocking during upgrades follows body‑safety national standards – not within GB 44496 scope. The standard only requires effective user notification – there is no mandatory requirement for simultaneous head‑unit, mobile‑app, and SMS notifications – choose a viable notification channel.
3.3 Processes must be auditable
Every step – from upgrade initiation to rollback – must have retained records – fully traceable. Auditors may randomly request the complete records of a single upgrade. Verbal process descriptions are insufficient – system logs and approval records are both required – missing records = non‑compliance.
4. Security Protection and Records
Upgrade packages must include digital signatures – flashing is only permitted after vehicle‑side verification. Data transmission must be encrypted – plain‑text is prohibited. Deploy anti‑rollback mechanisms to prevent downgrade attacks. On upgrade failure, automatic rollback is required – with complete vehicle self‑check – and user notification of the result.
Software‑upgrade records must be retained for 10 years after the model is discontinued – archived backups must be complete and verifiable. After server migration, archived files must be re‑verified – otherwise audit findings will be issued.
5. Imported Vehicles – Equivalent Path
If an overseas model already has SUMS or equivalent foreign system certification – difference assessment may be used – reducing duplicate system building. Whole‑vehicle testing is not fully exempt – some equivalent data may be accepted under certain conditions – but overseas documentation cannot be directly submitted for domestic applications.
System documents, process files, and user manuals submitted for domestic approval must be in Simplified Chinese – English is for internal reference only. We recommend producing bilingual documentation during R&D – avoiding last‑minute translation bottlenecks.
6. Common Misconceptions
·Overseas cybersecurity test reports cannot substitute for domestic standard reviews.
·OTA capability alone is not sufficient – in‑motion upgrade blocking must be implemented.
·Before submission, check the standard number version – incorrect numbering is a frequent low‑level rejection reason.
7. Practical Recommendations
For vehicles with automated driving features – do not overlook GB 44497 – separate evidence chains are required. Many OEMs focus only on 44495/44496 – only preparing GB 44497 materials close to audit.
Security systems are not a one‑time task – they are continuously reviewed with the vehicle announcement – internal audit and verification records must be maintained. Build system processes, OTA security design, and version management into the R&D workflow at the project‑definition stage – don't wait until announcement submission.
BlueAsia can support connected‑vehicle and multi‑country compliance work – early involvement reduces later remediation pressure.
For 2026 GB 44495/44496 certification, contact BlueAsia at 13534225140 (King) or email king.guo@cblueasia.com.
Related News