China’s new cybersecurity labelling framework entered into force on 1 July 2026, introducing a one-to-three-star system intended to show buyers how well an internet-connected product can resist cyber threats.
The Cybersecurity Labelling Management Measures were jointly issued by the Cyberspace Administration of China, the Ministry of Industry and Information Technology and the Ministry of Public Security. They establish the official China Cybersecurity Label, a product-level mark displaying the assessed cybersecurity capability of eligible connected devices.
The development is strategically important because it moves cybersecurity information out of technical documentation and onto packaging, product interfaces and potentially online sales pages. Security becomes something buyers can see and compare at the point of purchase.
However, the scheme should not be interpreted as an immediate blanket requirement for every smart device sold in China. Participation is voluntary, and only product categories included in officially published catalogues can enter the programme. The authorities intend to release these catalogues and detailed implementation rules in stages.
Three levels of cybersecurity capability
The China Cybersecurity Label uses three levels.
A one-star product must meet the applicable basic security requirements. The national framework specifically identifies measures such as eliminating weak or universal default passwords, establishing a vulnerability-management process, correcting vulnerabilities as they emerge and maintaining the ability to provide software updates.
A two-star product must demonstrate an enhanced level of cybersecurity relative to comparable products.
A three-star product must reach the leading level within its product category and undergo penetration testing by an appropriately qualified independent laboratory to assess its ability to withstand more advanced attacks. The precise technical criteria will be defined separately for each product category.
The star system does more than indicate whether a product meets a minimum baseline. It creates a visible hierarchy through which manufacturers can compete on security.
That represents a different policy approach from rules that simply prohibit insecure products. Instead of dividing products only into compliant and non-compliant categories, the Chinese framework seeks to make different levels of cybersecurity capability understandable to purchasers.
More than a logo
Each label must identify the producer, product model, cybersecurity level, validity period, testing laboratory and the national standard or technical document used for the assessment.
It must also contain a registration code. Scanning it should allow a buyer to access information including the product’s test report, key security indicators and the producer’s declaration of conformity.
This digital component may prove more significant than the physical label itself. Conventional product marks often tell consumers only that a product has passed a particular assessment. China’s model is designed to connect the mark with a larger body of supporting evidence. In principle, procurement teams, distributors and customers will be able to verify what was assessed, who performed the testing and whether the label remains valid.
The framework therefore combines three functions: a consumer-facing rating, a technical evidence repository and a public registration mechanism.
Testing remains partly under manufacturer control
The assurance model differs according to the rating sought. For one- and two-star labels, a producer may use its own testing laboratory or an eligible third-party organisation, subject to the applicable product rules. Three-star status requires additional penetration testing by a qualified external laboratory.
After testing, the producer must submit the assessment report, proposed label, conformity declaration, business documentation and evidence of laboratory capability to the registration platform operated by the China Electronics Standardization Institute. The institute then has ten working days after receiving a complete submission to perform a formal review and publish the registration information.
This distinction matters. The label is supported by testing, but the central registration stage is described as a formal review of the submitted documentation. It should not automatically be understood as a new government laboratory independently repeating every product assessment.
For buyers, the star rating, identity of the laboratory, scope of testing and linked technical evidence will therefore all be relevant when deciding how much assurance a particular label provides.
Consumer cameras are the first practical test
Consumer connected cameras have emerged as the first product category for which detailed implementation material has been published. In May, the Cyberspace Administration of China released draft rules for cameras purchased by individuals or organisations for audio and video collection and processing. Cameras used in the public-security field were excluded from that draft category. The consultation closed on 23 May.
The proposed camera rules provide an indication of how the broader framework may work in practice. They would assess security across physical and hardware controls, system and software security, network communications, data and personal-information protection, and the producer’s wider security-assurance processes. A product would have to meet all requirements at a given level to receive the corresponding star rating.
The draft also proposes grouping related product models into testing units only where important components and configurations remain equivalent. These include the chip generation, firmware, communications module, management method and security-relevant interfaces, protocols, authentication mechanisms, access controls and encryption design.
Testing organisations would examine a representative product and randomly select additional models corresponding to 10% of the models in the group, rounded upwards, to verify consistency. The proposed label validity period for cameras is three years.
Labels could be placed on the device, packaging or instructions, or displayed in the startup screen, management application and online product listing.
Nevertheless, the material located for this category remains identified as a consultation draft. The entry into force of the national Measures on 1 July should therefore be distinguished from the final operational rollout of individual product categories.
Voluntary does not mean consequence-free
Manufacturers are not generally required to seek the label. Once they choose to use it, however, they enter a supervised regime. Registrations may be withdrawn if submitted information is false, the displayed rating does not correspond to the product’s actual cybersecurity capability, the label is incorrectly presented or the producer stops providing technical support for the product.
A producer found to have forged or misused the label, or used it for misleading promotion, can lose the registration, have the violation publicly announced and be prevented from submitting another product for one year.
Testing organisations that fabricate results can similarly have their reports rejected for a year. More serious cases may also be handled under China’s Cybersecurity Law and testing-sector regulations. Violations are to be recorded in China’s national credit-information system.
The framework also connects product labelling with continuing vulnerability management. Vulnerabilities discovered during testing or later operation must be reported, corrected and disclosed under China’s existing rules for network-product security vulnerabilities.
A label is therefore not intended to be a permanent statement based only on the product’s condition on one testing date. Significant technical changes that could affect cybersecurity, or expiry of the label, require a new registration.
Why foreign manufacturers should pay attention
The legal framework does not make the label mandatory simply because a manufacturer is foreign. The more immediate issue is commercial rather than purely regulatory.
A recognised security rating may gradually become relevant to distributors, online platforms, enterprise purchasers and government-linked procurement. A voluntary mark can become difficult to ignore when competing products display one and major buyers begin using it as a selection criterion.
Foreign brands using Chinese manufacturers will also need to determine who is treated as the responsible product producer, who controls the technical evidence and who accepts responsibility for the registration. The draft camera rules define the producer as the brand owner or user legally responsible for product quality, illustrating why cybersecurity obligations cannot always be delegated entirely to an original equipment manufacturer.
Companies should therefore review contracts with manufacturers, importers and distributors, particularly where one organisation controls the brand while another develops the firmware, manages vulnerabilities or provides updates.
Part of a wider international movement
China is not acting in isolation. The United States is developing the voluntary US Cyber Trust Mark for consumer wireless Internet of Things products. Singapore operates a four-level Cybersecurity Labelling Scheme, while Japan’s JC-STAR programme is intended to make IoT product security easier for consumers and procurement organisations to evaluate.
Japan and Singapore have already agreed to streamline recognition between their respective schemes, while Japan has also established cooperation arrangements with other countries. These initiatives suggest that cybersecurity labels may increasingly form part of international product trade and assurance mechanisms.
The European Union is following a different legal model through the Cyber Resilience Act. Its principal requirements will become applicable in December 2027, with vulnerability-reporting obligations beginning earlier. Products covered by the regulation will use the CE marking to indicate conformity rather than a consumer-facing cybersecurity star rating.
For multinational manufacturers, the result is not one global cybersecurity mark but an expanding set of national and regional assurance systems.
Existing security evidence may be reusable across jurisdictions, but companies should not assume that an assessment performed for one scheme will automatically satisfy another. Product scope, testing depth, responsible parties, reporting obligations and recognition arrangements remain different.
Cybersecurity becomes part of product competition
The long-term significance of the China Cybersecurity Label lies in how it may change purchasing behaviour. Until now, many connected-device buyers have had little practical ability to compare the security of two similar products. Marketing materials rarely reveal the quality of vulnerability management, the duration of software support or the depth of security testing.
A visible rating, combined with a QR code leading to supporting evidence, begins to reduce that information gap.
It may also change internal business decisions. Product-security teams will have a stronger argument for secure development funding when security performance influences ratings, customer confidence and sales. Procurement departments will gain another factor for supplier comparison. Boards will need to consider whether a lower rating, an expired label or a publicly withdrawn registration creates reputational and market risk.
The Chinese framework is still at an early stage. Its practical importance will depend on the product categories added, the quality and independence of testing, the transparency of published evidence and whether buyers begin demanding labelled products.
But the policy direction is already clear: cybersecurity is moving from an invisible technical characteristic to a visible and potentially competitive product attribute.
