2026 GB 44495 and GB 44496 Certification – Key New Changes

2026-08-21

1. What Are the Two Mandatory Standards?

The Technical Requirements for Vehicle Cybersecurity (GB 44495) and the General Technical Requirements for Vehicle Software Update (GB 44496) are China's mandatory national standards for vehicles – aligned with UN R155 and R156 respectively. These two standards do not issue separate certificates – compliance capability is reviewed alongside the whole‑vehicle announcement.

GB 44497 (event data recording) took effect on 1 January 2026 – applying only to vehicles with automated driving features. It is not aligned with GB 44495/44496 – compliance materials must be prepared separately.


  2. 2026 – The Most Critical Implementation Dates

Due to Amendment No.1, the mandatory date for new type‑approval applications has been moved to 1 July 2026 – the original 1 January 2026 date no longer applies to new vehicles. Existing announced models have a transition period – no blanket cut‑off. When scheduling projects, always refer to the official Amendment text – using old dates risks delaying announcement submissions.

China has abolished the separate pre‑CSMS certificate – security capability is now reviewed together with the whole‑vehicle announcement materials. Companies must prepare complete system documentation and supporting evidence – a single certificate is not sufficient. This logic differs from overseas (system certification first, then model approval) – do not directly copy overseas project experience.


  3. Software Update Standard – Six Main Parts

3.1 Management system and process

Companies must establish a software‑update management system – covering the full lifecycle: version generation, verification, release, monitoring, and rollback – with regular internal audits.

Amendment No.1 is still in draft consultation – terminology changes are not yet effective. Use current standard wording in applications – do not pre‑apply draft content – otherwise documents will be rejected.

3.2 Vehicle and OTA upgrade requirements

Whole‑vehicle verification includes 14 test items – 8 for local upgrades and 6 additional for OTA. In‑vehicle upgrades are prohibited while the vehicle is in motion – a hard requirement.

Door mechanical unlocking during upgrades follows body‑safety national standards – not within GB 44496 scope. The standard only requires effective user notification – there is no mandatory requirement for simultaneous head‑unit, mobile‑app, and SMS notifications – choose a viable notification channel.

3.3 Processes must be auditable

Every step – from upgrade initiation to rollback – must have retained records – fully traceable. Auditors may randomly request the complete records of a single upgrade. Verbal process descriptions are insufficient – system logs and approval records are both required – missing records = non‑compliance.


  4. Security Protection and Records

Upgrade packages must include digital signatures – flashing is only permitted after vehicle‑side verification. Data transmission must be encrypted – plain‑text is prohibited. Deploy anti‑rollback mechanisms to prevent downgrade attacks. On upgrade failure, automatic rollback is required – with complete vehicle self‑check – and user notification of the result.

Software‑upgrade records must be retained for 10 years after the model is discontinued – archived backups must be complete and verifiable. After server migration, archived files must be re‑verified – otherwise audit findings will be issued.


  5. Imported Vehicles – Equivalent Path

If an overseas model already has SUMS or equivalent foreign system certification – difference assessment may be used – reducing duplicate system building. Whole‑vehicle testing is not fully exempt – some equivalent data may be accepted under certain conditions – but overseas documentation cannot be directly submitted for domestic applications.

System documents, process files, and user manuals submitted for domestic approval must be in Simplified Chinese – English is for internal reference only. We recommend producing bilingual documentation during R&D – avoiding last‑minute translation bottlenecks.


  6. Common Misconceptions

·Overseas cybersecurity test reports cannot substitute for domestic standard reviews.

·OTA capability alone is not sufficient – in‑motion upgrade blocking must be implemented.

·Before submission, check the standard number version – incorrect numbering is a frequent low‑level rejection reason.


  7. Practical Recommendations

For vehicles with automated driving features – do not overlook GB 44497 – separate evidence chains are required. Many OEMs focus only on 44495/44496 – only preparing GB 44497 materials close to audit.

Security systems are not a one‑time task – they are continuously reviewed with the vehicle announcement – internal audit and verification records must be maintained. Build system processes, OTA security design, and version management into the R&D workflow at the project‑definition stage – don't wait until announcement submission.

BlueAsia can support connected‑vehicle and multi‑country compliance work – early involvement reduces later remediation pressure.


For 2026 GB 44495/44496 certification, contact BlueAsia at 13534225140 (King) or email king.guo@cblueasia.com.