In China's intelligent-connected-vehicle compliance space, GB44495 and GB44496 are two core mandatory national standards that must be implemented. Simply: GB44495 governs vehicle cyber and information security, with a framework referencing overseas UN regulations. GB44496 specifically targets remote software upgrade, covering the full OTA upgrade compliance requirement.
Under the new No. 1 amendment, the mandatory compliance node for newly declared domestic models is pushed back to 1 July 2026. Although the authority gave a half-year grace, the compliance process and remediation standards are in no way reduced. Companies cannot adopt a wait-and-see attitude. The industry generally plans both standards together and lands them together; splitting them invites compliance gaps.
二、Process start: asset inventory
1. Map your vehicle compliance assets first
Many automakers trip on this: they jump straight to writing system documents and skip the core asset-mapping step. A compliance process that actually passes always starts by clarifying the vehicle's compliance assets. Fully tally every ECU, external communication interface, and OTA channel; map each component's connection logic, data-transmission content, and permission-modification method. This is the basis for all later risk assessment.
2. Manual plus tool verification, both directions
Relying only on manual drawing review easily misses obscure controllers and hidden communication ports. The industry's safe standard approach is professional-equipment scanning paired with manual cross-checking, completing full vehicle-network asset confirmation. This two-way verification guarantees a zero-omission asset list and satisfies the traceability checks during factory audit — avoiding later rework at the root.
三、Gap assessment and risk analysis
After asset inventory, strictly run a gap assessment against the full national-standard clauses. The "fourteen compliance requirements" often mentioned in the industry is just a practical consolidation — not a native standard division. Remediation must strictly target the official standard text to avoid mis-categorization and missed key items.
During remediation, focus on two China-specific mandatory requirements: the OTA three-channel status notification and the upgrade-block during driving scenarios. The "door mechanical unlock" requirement circulating in the market belongs to body-safety specs and is unrelated to these two standards — no need to include it in this remediation. Prioritize by risk level to lift compliance efficiency.
四、System build and remediation rollout
With the No. 1 amendment, the previous standalone front-end system certification is cancelled. All vehicle information-security and software-upgrade management requirements are consolidated into the whole-vehicle announcement factory-audit for unified checking. Companies do not need to copy overseas regulatory system models — just build a dedicated document system matching the domestic national standards.
Remediation rollout and document writing must proceed together, focusing on the real-vehicle core functions: full-channel upgrade-status notification and precise driving-upgrade blocking. The factory audit does not review paper — inspectors verify real-vehicle functions on site. Document packaging alone with a non-compliant vehicle gets rejected, and the cost of redoing it is extreme.
五、Announcement application and model review
Domestically, there is no standalone certificate for GB44495 and GB44496. Both compliance reviews are embedded in the whole-vehicle announcement and model type-approval process — not the overseas VTA model. After submitting the full technical file, the authority runs document review, on-site factory audit, and real-vehicle function sampling together.
Although these two standards' reference framework originates from UN regulations, the two sides cannot be mutually recognized as equivalent, and test reports are not directly interchangeable. China-specific security clauses and data-control rules need separate testing and remediation; only some process docs can be moderately referenced. Export and domestic models cannot simply share one documentation set.
六、Post-certification ongoing reporting obligations
Passing the announcement review does not end the compliance work — full-lifecycle routine control is the focus. Under GB44496, all related technical materials must be retained until ten years after the model stops production. Companies need a sound archiving mechanism to handle random official checks.
Every software upgrade and every safety-related event during the vehicle's lifecycle must be fully recorded and traceable. Clarify this: event data recording is a separate national-standard requirement, not within GB44495/44496 scope — do not blindly remediate and waste effort.
七、Process practical advice
Start the vehicle asset inventory at the model's project kickoff. If you discover architecture compliance defects only after the prototype is frozen, remediation difficulty and cost both climb sharply. Also clarify domestic-vs-overseas compliance differences and prepare materials specifically — do not directly apply overseas regulatory solutions.
Archive all process materials — remediation records, test reports, review ledgers — completely. That is the core content of the factory audit.
BlueAsia provides one-stop national-standard compliance services, coordinating document writing, pre-compliance testing, and factory-audit coaching to help you avoid compliance misconceptions and complete project landing efficiently.
Contact: King
Phone/Mob: (+86)13534225140
Email: king.guo@cblueasia.com
Address: Building C, Hongjingda Industrial Park, No. 107 Beihuan Road, Shiyan Street, Bao'an District, Shenzhen, China
BlueAsia delivers more than service!
Related News