The automotive industry standards GB 44495 and GB 44496 are mandatory national standards. The publication date is 1 January 2026; combined with Amendment No.1, from 1 July 2026, all new type‑approval applications must meet both standards and submit complete compliance documentation.
·GB 44495: vehicle cybersecurity technical requirements.
·GB 44496: vehicle software upgrade general technical requirements.
The two standards do not issue separate certificates – compliance records are attached to the whole‑vehicle CCC certificate. Validity and annual surveillance rules all follow the CCC system.
Those working on whole‑vehicle compliance often confuse the surveillance requirements of the two standards – treating them as the same system. This article covers validity rules, annual CoP audits, key focus areas, and common non‑conformities.
GB 44495 and GB 44496 have no standalone certificates. Compliance is recorded as technical compliance filings under the whole‑vehicle CCC certificate – sharing the same lifecycle. When the CCC certificate is renewed, the corresponding compliance records are also renewed.
The whole‑vehicle CCC certificate has a statutory 5‑year validity – from the issue date. Companies must submit renewal applications within 90 days before expiry – the certification body conducts document review – and may arrange supplementary testing depending on the project.
If renewal is not completed before the 5‑year expiry – the certificate automatically expires – the vehicle model can no longer be legally produced or sold.
Within the 5‑year cycle, standard‑risk models generally have one CoP (Conformity of Production) surveillance audit per year – the industry calls it the annual audit. If the annual audit passes, the certificate remains valid.
Key distinction: annual surveillance and 5‑year renewal are two independent compliance obligations – they are not interchangeable – focusing on only one creates compliance gaps.
Supplementary: although there is no independent GB44495/44496 certificate, the company holds type‑test reports, cybersecurity compliance assessment reports, SUMS audit reports, etc., as supporting evidence for CCC filings – these must be retained long‑term.
2. Annual Audit – Overall Rhythm
The annual CoP audit is a whole‑vehicle package review – separate audits for information security and software upgrades are not arranged. Auditors on‑site check the factory's quality management system, production consistency, product change management – with information security and software upgrade management as key audit modules.
Surveillance frequency is not necessarily once per year. Certification bodies adjust based on factory credit rating, vehicle risk level, and past non‑conformity remediation. High‑risk models or companies with repeated issues may face more frequent audits. Audit plans are generally notified in advance – allowing preparation time.
Audit results fall into three categories: Pass, Conditional Pass, Fail. Conditional Pass requires remediation of all non‑conformities within a specified timeline. Audits are not just document reviews – auditors may randomly select vehicles for functional re‑testing. Even if documentation is complete – if on‑site functional verification fails – non‑conformities will be issued.
3. GB 44495 – Cybersecurity (CSMS) Audit Focus
Cybersecurity audits focus on the ongoing operation of the vehicle CSMS (Cybersecurity Management System). Key areas:
·Is the cybersecurity organisation and role allocation actually implemented?
·Are vehicle asset identification and risk assessments conducted periodically?
·Are security incident response processes closed‑loop?
·Are information‑security agreements with component suppliers still valid?
Security incident records for the past 12 months are mandatory. Whether or not actual security events occurred – complete records must be retained. If security vulnerabilities or network‑attack events occurred – records of response, remediation, and post‑incident review must be retained.
Regular security drills: plans, implementation records, and lesson‑learned conclusions must be retained. Random checks of penetration‑testing and security‑function validation records – ensure the full traceability chain from discovery to fix to retest.
4. GB 44496 – Software Upgrade (SUMS) Audit Focus
Software‑upgrade audits focus on the ongoing operation of the SUMS (Software Upgrade Management System). Key areas:
·Is the SUMS system continuously effective?
·Are all software upgrades executed according to system documentation?
·Do mass‑production vehicle software/hardware configurations match the type‑approval state?
·Are annual drills conducted as required?
Important: an organisation with UN R156 EU audit qualification does not automatically have domestic GB 44496 SUMS audit qualification. Domestic SUMS on‑site audits and witnessed tests must be conducted by labs and certification bodies listed in the vehicle certification alliance directory with appropriate qualifications.
Audit coverage includes the full software‑upgrade lifecycle: risk assessment, test verification, release approval, push execution, and post‑upgrade monitoring – each step's process documents and execution records must align.
Rollback mechanisms are a high‑frequency audit point. Auditors verify the reliability of software rollback logic – and the emergency response plan for upgrade failures. For scenarios where upgrade failure could make the vehicle unusable – a mature handling plan and drill records must be in place.
5. Record Retention Requirements
Full software‑upgrade records – risk assessments, test verification reports, release approvals, push logs, post‑upgrade monitoring – and cybersecurity risk assessments, incident handling, and drill records – must be retained for at least 10 years from the date the vehicle model is officially discontinued – fully searchable and traceable.
T‑Box, gateway, and other ECU firmware version lists and change logs must align with whole‑vehicle software‑upgrade records. When a model is updated, old‑model records cannot be destroyed – discontinued‑model archives should be independently managed.
Records can be paper or electronic – but electronic archives cannot be stored only on a single local machine – reliable backup is required. Single‑point data loss = non‑conformity.
6. Change Management – Triggering Certification Reviews
When a vehicle model undergoes technical changes:
·First, conduct a same‑type determination.
·If not same‑type (major change) – submit a change application – arrange supplementary testing.
·If same‑type – internal change filing only – no re‑test application required.
Typical changes requiring assessment:
·TCU module replacement.
·Underlying firmware major upgrades.
·OTA rollback logic changes.
·Core ECU supplier changes.
Cybersecurity‑related changes are stricter: network‑architecture adjustments, remote‑communication‑port changes, security‑mechanism changes – all need assessment for major‑change classification. Major changes must not be simplified as internal changes – non‑reporting risks certificate compliance.
All change records must be archived: change description, risk assessment, test reports, internal approvals. Change logs are key audit items – missing or contradictory records trigger non‑conformities.
7. Proactive Reporting of Abnormal Events
For mass OTA push failures, software‑upgrade‑induced vehicle safety faults, or discovery of major cybersecurity vulnerabilities – companies must report in writing to the CCC certification body within 15 working days. For major incidents involving widespread safety risks – must also report to the market regulator.
Concealing incidents – upon discovery – the certification body may suspend the certificate.
Reports must clearly describe: incident timeline, affected vehicle range, current remediation measures, and long‑term improvement plans. Reporting is not the end – the certification body tracks remediation closure. Many companies prefer internal fixes – delaying reporting – turning small issues into major compliance risks.
8. Annual Audit – Pre‑Audit Checklist
Before formal audit, use this checklist:
·CSMS full operational records complete – organisation, risk register, security logs, drill records.
·SUMS system documentation current – aligned with factory implementation.
·Vehicle firmware version logs up‑to‑date – mass‑production config matches type‑approval sample.
·Component supplier information‑security agreements and upgrade agreements – all valid.
·Training records, drill records, and change logs for the past 12 months – fully archived.
If gaps are found – complete them before the audit. On audit day, have meeting rooms, document lists, and engineers ready – organised records improve audit efficiency.
9. Vehicle Exemptions
L‑class motorcycles – not subject to GB 44495/44496. Special‑purpose on‑site vehicles follow their own management rules.
Important: vehicles with only diagnostic‑port local flashing and no OTA – are not fully exempt from GB 44496. They can skip remote‑OTA tests – but software version traceability and local‑flash control still apply.
Component suppliers: no independent GB 44495/44496 type approval. T‑Box, gateways, etc., cannot obtain separate certificates – component test reports and firmware change logs are supporting evidence for whole‑vehicle CCC certification – they cannot substitute for whole‑vehicle testing and filing. Component suppliers should maintain version logs and deliver documentation to help OEMs pass annual audits.
10. Compliance Is an Ongoing State
Obtaining CCC filing is not the end. GB 44495/44496 compliance obligations are long‑term. Annual CoP surveillance, technical change reporting, security incident reporting, and record retention must be executed continuously. Gaps in management will be exposed in the next audit round.
BlueAsia can provide one‑stop compliance support for vehicle and component companies – covering CCC filing, annual audit preparation, product change assessment, and certificate renewal – plus CSMS and SUMS system‑building guidance. For annual audit preparation, system building, or project assessment – bring your project for a tailored consultation.
For GB44495/44496 certification, contact BlueAsia at 13534225140 (King) or email king.guo@cblueasia.com.
Related News