China Releases Draft Cybersecurity Labeling Rules for Consumer Network Cameras
Published 13 May 2026
Xia Yu
On 8 May 2026, the Cyberspace Administration of China (“CAC”) released the Draft Implementation Rules for the Cybersecurity Labeling of Consumer Network Cameras (“Implementation Rules”) and the Cybersecurity Labeling—Security Requirements for Consumer Network Cameras (“Security Requirements”), inviting public comments until 23 May 2026. It is the first product-specific implementation under the Administrative Measures for Cybersecurity Labeling (“Administrative Measures”), which will take effect on 1 July 2026. Targeting consumer network cameras as the pilot product category, the Implementation Rules and Security Requirements translate the voluntary labeling and tiered grading framework established by the Administrative Measures into operational technical specifications and procedural norms, signaling the formal transition of China’s cybersecurity labeling regime from framework legislation to product-level implementation.
Background: A Three-Tier Legal Architecture from the Cybersecurity Law to the Administrative Measures to the Implementation Rules
The Cybersecurity Law of the People’s Republic of China (“Cybersecurity Law”), amended on 28 October 2025, provides the foundational legal framework. Article 24 of the amended Cybersecurity Law establishes the baseline security obligations of network product and service providers—products must comply with the mandatory requirements of relevant national standards; providers shall not install malicious programs; upon discovery of security defects or vulnerabilities in their products or services, they shall immediately take remedial measures, inform users, and report to the competent authorities in accordance with applicable provisions, and shall continue to provide security maintenance for the prescribed or agreed period. Article 25 imposes a mandatory market access threshold—security certification or security testing—on critical network equipment and specialized cybersecurity products. The 2025 amendment substantially enhanced the penalties for breach of these obligations: a provider that violates Article 24 and refuses to rectify or causes harm to cybersecurity may be fined between RMB 50,000 (Equivalent to the US$ 7,500) and RMB 500,000 (Equivalent to the US$ 75,000); where the consequences are serious, such as causing large-scale data leakage, the maximum fine is raised to RMB 2 million (Equivalent to the US$ 0.3 million). The newly added Article 63 further stipulates that selling or offering for sale critical network equipment or specialized cybersecurity products without security certification or testing shall result in confiscation of unlawful gains and a fine of between one and five times the amount of unlawful gains—a significant escalation from the 2017 version of the law, under which the maximum fine was capped at RMB 100,000 (Equivalent to the US$ 15,000).
On 10 April 2026, the CAC released the Administrative Measures, which operationalize the principles-based obligations in Article 24 of the Cybersecurity Law and render them concrete and actionable in the context of products with internet connectivity capabilities. The Administrative Measures establish the core tenets of China’s cybersecurity labeling regime: voluntary participation, tiered grading, and record-filing management. They further specify the institutional architecture—joint oversight by the CAC, the Ministry of Industry and Information Technology, and the Ministry of Public Security—and the procedural framework comprising testing, record-filing, labeling, and supervision. The Administrative Measures apply only to products listed in the Catalogue of Products Subject to Cybersecurity Labeling (“Product Catalogue”), and designate the China Electronics Standardization Institute as the record-filing body. A product manufacturer must, upon completing the required security capability testing, submit seven categories of materials—including a testing report and a declaration of conformity—before it may use the cybersecurity label. The label must contain seven mandatory elements: the manufacturer’s name, product model, security capability grade (expressed in stars), label validity period, testing laboratory name, reference standard number, and a record-filing information code. The Administrative Measures also prescribe rigorous consequences for non-compliance: where a label has been counterfeited or misappropriated, or where record-filing materials have been falsified, the record-filing shall be revoked with public notice, and no further record-filing applications from that manufacturer shall be accepted for one year from the date of the notice; where a testing agency issues a fraudulent testing report, its testing results shall be excluded from reliance for one year. Article 17 of the Administrative Measures further clarifies that such conduct shall be subject to sanctions by the competent authorities under the Cybersecurity Law and the Measures for the Supervision and Administration of Inspection and Testing Institutions, thereby layering administrative penalties on top of the Administrative Measures’ own sanctions regime. The first batch of the Product Catalogue is limited to consumer network cameras, which are precisely the products governed by the Implementation Rules.
The Implementation Rules and Security Requirements convert the above framework provisions of the Administrative Measures into operational technical indicators and testing procedures specific to the consumer network camera product category, specifying in detail the technical requirements for each of the three security capability tiers, the testing and evaluation methodology, and the qualification criteria for testing bodies, thereby serving as the lex specialis of the Administrative Measures in the consumer network camera sector.
Viewed in this light, the three instruments form a three-tier hierarchical legal framework: the Cybersecurity Law is the foundational statute, setting out the baseline security obligations of network product providers and the mandatory certification framework; the Administrative Measures is the next-level implementing regulation, deploying a tiered labeling mechanism as its primary instrument to convert statutory duties into quantifiable, comparable, and enforceable technical standards and procedural rules in respect of connected products falling outside the scope of mandatory certification; and the Implementation Rules and Security Requirements constitute the product-specific rules addressing technical details and enforcement standards for consumer network cameras—serving both as the first operational vehicle for the Administrative Measures and as a reference template for the formulation of implementation rules for subsequent product categories.
The Implementation Rules: Procedural Provisions
The Implementation Rules serve as procedural provisions, addressing the procedural questions of how to apply for a label, how to use a label, and how labels are to be supervised and administered. They set forth the complete workflow for a product manufacturer to apply for and use a cybersecurity label, including the application conditions; testing modalities (for the Basic and Enhanced grades, manufacturers may use their own testing laboratories or engage a third-party testing agency; for the Advanced grade, they must engage a qualified third-party agency to conduct penetration testing); the list of record-filing materials; and label specifications. They further specify dynamic management requirements regarding the label’s validity period, re-filing upon a change in circumstances, and suspension and revocation of labels.
The Security Requirements: A Three-Tier Progressive Technical Baseline
The Security Requirements address the substantive question of what security level each tier must achieve and how compliance is determined. In the form of normative and informative annexes, they set out, across five dimensions—physical and hardware security, system and software security, network and communication security, data security and personal information protection, and security assurance—the specific technical indicators that must be satisfied at each of the Basic, Enhanced, and Advanced grades, together with the corresponding testing and evaluation methodology. These can be summarized as a three-tier progressive structure: baseline requirements, defense-in-depth, and adversarial validation.
1. Basic Grade (One Star)—Baseline Requirements: Focused on addressing market baseline deficiencies such as eliminating default weak passwords, establishing a vulnerability management mechanism, and implementing personal information protection. Every device must ship with a unique, randomly generated initial password; the use of universal or common default passwords is prohibited; and a vulnerability management mechanism must be in place to ensure that the product has no vulnerabilities at the high-risk level or above published in national vulnerability databases. This constitutes, in substance, the minimum cybersecurity baseline for a product to enter the market.
2. Enhanced Grade (Two Stars)—Defense-in-Depth: Introduces defense-in-depth requirements including hardware secure boot, firmware rollback prevention, least-privilege access control, communications encryption, and log auditing. It significantly strengthens protection of physical interfaces and the underlying system, requiring, among other things, that device binding be completed through interactive confirmation with the device (such as a physical button, Bluetooth pairing, acoustic waves, or QR code scanning), thereby preventing the device from being physically compromised or maliciously bound.
3. Advanced Grade (Three Stars)—Adversarial Validation: Further requires that the device root key be protected by a hardware security chip; that the product undergo third-party penetration testing lasting no fewer than 14 days with no fewer than five testers, as well as security crowd-testing with no fewer than 20 participants, to verify the absence of medium- or high-risk vulnerabilities under high-intensity adversarial conditions; and that the product manufacturer establish a full-lifecycle cybersecurity management mechanism covering design, development, testing, delivery, and operations and maintenance.
The Implementation Rules and the Security Requirements share a dual-layer complementary relationship of “procedural rules—technical baseline”. Together they constitute the complete compliance framework for a consumer network camera to apply for a cybersecurity label. A product manufacturer must deploy both instruments as an integrated compliance toolkit to complete the entire compliance workflow from security capability development and testing verification through to record-filing and public notice.
Comparison with Comparable Regimes in the European Union and the United States
The global governance of consumer IoT security is crystallizing along three parallel paths, with China, the United States, and the European Union representing three distinct regulatory choices.
The European Union has opted for a mandatory legislative path. The Cyber Resilience Act (“CRA”), which entered into force in December 2024, imposes full-lifecycle mandatory cybersecurity obligations on all “products with digital elements” placed on the EU market—requiring prevention of attack surfaces from the design phase, prohibiting the presence of known exploitable vulnerabilities at the time of placing on the market, and mandating post-market active reporting of exploited vulnerabilities and serious security incidents to the EU cybersecurity agency. The CRA directly ties compliance to the CE marking, such that a non-compliant digital product cannot bear the CE mark and is therefore excluded from the European single market. Violations may be sanctioned with fines of up to EUR 15 million or 2.5% of global annual turnover. This is, in essence, a baseline control model of “comply or exit the market”—the government draws the safety red line, and enterprises have no choice but to comply.
The United States has, like China, chosen a voluntary labeling path, but there are marked divergences in design. The Rules for IoT Cybersecurity Labeling Program established by the Federal Communications Commission (FCC) in March 2024 likewise follows the principle of “voluntary participation, market-driven”, using NIST IR 8425 as its technical baseline and relying on a third-party administrator to assess product compliance. It differs from the Chinese regime in two core respects. First, the U.S. adopts a single-tier standard rather than a tiered grading system: a product either meets the standard and receives the mark, or it does not, depriving consumers of the ability to intuitively compare the relative security capabilities of different products in the way one might compare star-rated hotels. Second, the United States issued a rule in November 2025 expressly prohibiting IoT products manufactured by enterprises on designated source lists from using the FCC cybersecurity label, thereby embedding a supply chain security screening dimension into the labeling regime.
China’s cybersecurity labeling regime has charted a third path between the above two approaches. Compared with the EU model, it is voluntary rather than mandatory—an enterprise may decide on its own whether to apply for a label and for which tier, affording greater flexibility at the market access threshold. Yet compared with the U.S. model, its three-star progressive grading system provides consumers with a more granular information structure—not a binary “compliant/non-compliant” signal, but a vertical comparative dimension of “adequate”, “good” and “excellent”. China further distinguishes its approach by adopting a batch-based catalogue management system rather than an omnibus roll-out, using consumer network cameras as the pilot to accumulate experience and reserving policy calibration space for the progressive inclusion of additional product categories.
Conclusion
The draft Implementation Rules and Security Requirements signal the extension of China’s cyberspace governance from platform regulation to end-device regulation. By constructing a transparent security market through tiered labeling, they present significant legal compliance challenges for camera manufacturers both domestically and internationally. Subsequent batches of the Product Catalogue may cover high-frequency consumer IoT categories such as smart door locks, smart speakers, and home routers.
Background: A Three-Tier Legal Architecture from the Cybersecurity Law to the Administrative Measures to the Implementation Rules
The Cybersecurity Law of the People’s Republic of China (“Cybersecurity Law”), amended on 28 October 2025, provides the foundational legal framework. Article 24 of the amended Cybersecurity Law establishes the baseline security obligations of network product and service providers—products must comply with the mandatory requirements of relevant national standards; providers shall not install malicious programs; upon discovery of security defects or vulnerabilities in their products or services, they shall immediately take remedial measures, inform users, and report to the competent authorities in accordance with applicable provisions, and shall continue to provide security maintenance for the prescribed or agreed period. Article 25 imposes a mandatory market access threshold—security certification or security testing—on critical network equipment and specialized cybersecurity products. The 2025 amendment substantially enhanced the penalties for breach of these obligations: a provider that violates Article 24 and refuses to rectify or causes harm to cybersecurity may be fined between RMB 50,000 (Equivalent to the US$ 7,500) and RMB 500,000 (Equivalent to the US$ 75,000); where the consequences are serious, such as causing large-scale data leakage, the maximum fine is raised to RMB 2 million (Equivalent to the US$ 0.3 million). The newly added Article 63 further stipulates that selling or offering for sale critical network equipment or specialized cybersecurity products without security certification or testing shall result in confiscation of unlawful gains and a fine of between one and five times the amount of unlawful gains—a significant escalation from the 2017 version of the law, under which the maximum fine was capped at RMB 100,000 (Equivalent to the US$ 15,000).
On 10 April 2026, the CAC released the Administrative Measures, which operationalize the principles-based obligations in Article 24 of the Cybersecurity Law and render them concrete and actionable in the context of products with internet connectivity capabilities. The Administrative Measures establish the core tenets of China’s cybersecurity labeling regime: voluntary participation, tiered grading, and record-filing management. They further specify the institutional architecture—joint oversight by the CAC, the Ministry of Industry and Information Technology, and the Ministry of Public Security—and the procedural framework comprising testing, record-filing, labeling, and supervision. The Administrative Measures apply only to products listed in the Catalogue of Products Subject to Cybersecurity Labeling (“Product Catalogue”), and designate the China Electronics Standardization Institute as the record-filing body. A product manufacturer must, upon completing the required security capability testing, submit seven categories of materials—including a testing report and a declaration of conformity—before it may use the cybersecurity label. The label must contain seven mandatory elements: the manufacturer’s name, product model, security capability grade (expressed in stars), label validity period, testing laboratory name, reference standard number, and a record-filing information code. The Administrative Measures also prescribe rigorous consequences for non-compliance: where a label has been counterfeited or misappropriated, or where record-filing materials have been falsified, the record-filing shall be revoked with public notice, and no further record-filing applications from that manufacturer shall be accepted for one year from the date of the notice; where a testing agency issues a fraudulent testing report, its testing results shall be excluded from reliance for one year. Article 17 of the Administrative Measures further clarifies that such conduct shall be subject to sanctions by the competent authorities under the Cybersecurity Law and the Measures for the Supervision and Administration of Inspection and Testing Institutions, thereby layering administrative penalties on top of the Administrative Measures’ own sanctions regime. The first batch of the Product Catalogue is limited to consumer network cameras, which are precisely the products governed by the Implementation Rules.
The Implementation Rules and Security Requirements convert the above framework provisions of the Administrative Measures into operational technical indicators and testing procedures specific to the consumer network camera product category, specifying in detail the technical requirements for each of the three security capability tiers, the testing and evaluation methodology, and the qualification criteria for testing bodies, thereby serving as the lex specialis of the Administrative Measures in the consumer network camera sector.
Viewed in this light, the three instruments form a three-tier hierarchical legal framework: the Cybersecurity Law is the foundational statute, setting out the baseline security obligations of network product providers and the mandatory certification framework; the Administrative Measures is the next-level implementing regulation, deploying a tiered labeling mechanism as its primary instrument to convert statutory duties into quantifiable, comparable, and enforceable technical standards and procedural rules in respect of connected products falling outside the scope of mandatory certification; and the Implementation Rules and Security Requirements constitute the product-specific rules addressing technical details and enforcement standards for consumer network cameras—serving both as the first operational vehicle for the Administrative Measures and as a reference template for the formulation of implementation rules for subsequent product categories.
The Implementation Rules: Procedural Provisions
The Implementation Rules serve as procedural provisions, addressing the procedural questions of how to apply for a label, how to use a label, and how labels are to be supervised and administered. They set forth the complete workflow for a product manufacturer to apply for and use a cybersecurity label, including the application conditions; testing modalities (for the Basic and Enhanced grades, manufacturers may use their own testing laboratories or engage a third-party testing agency; for the Advanced grade, they must engage a qualified third-party agency to conduct penetration testing); the list of record-filing materials; and label specifications. They further specify dynamic management requirements regarding the label’s validity period, re-filing upon a change in circumstances, and suspension and revocation of labels.
The Security Requirements: A Three-Tier Progressive Technical Baseline
The Security Requirements address the substantive question of what security level each tier must achieve and how compliance is determined. In the form of normative and informative annexes, they set out, across five dimensions—physical and hardware security, system and software security, network and communication security, data security and personal information protection, and security assurance—the specific technical indicators that must be satisfied at each of the Basic, Enhanced, and Advanced grades, together with the corresponding testing and evaluation methodology. These can be summarized as a three-tier progressive structure: baseline requirements, defense-in-depth, and adversarial validation.
1. Basic Grade (One Star)—Baseline Requirements: Focused on addressing market baseline deficiencies such as eliminating default weak passwords, establishing a vulnerability management mechanism, and implementing personal information protection. Every device must ship with a unique, randomly generated initial password; the use of universal or common default passwords is prohibited; and a vulnerability management mechanism must be in place to ensure that the product has no vulnerabilities at the high-risk level or above published in national vulnerability databases. This constitutes, in substance, the minimum cybersecurity baseline for a product to enter the market.
2. Enhanced Grade (Two Stars)—Defense-in-Depth: Introduces defense-in-depth requirements including hardware secure boot, firmware rollback prevention, least-privilege access control, communications encryption, and log auditing. It significantly strengthens protection of physical interfaces and the underlying system, requiring, among other things, that device binding be completed through interactive confirmation with the device (such as a physical button, Bluetooth pairing, acoustic waves, or QR code scanning), thereby preventing the device from being physically compromised or maliciously bound.
3. Advanced Grade (Three Stars)—Adversarial Validation: Further requires that the device root key be protected by a hardware security chip; that the product undergo third-party penetration testing lasting no fewer than 14 days with no fewer than five testers, as well as security crowd-testing with no fewer than 20 participants, to verify the absence of medium- or high-risk vulnerabilities under high-intensity adversarial conditions; and that the product manufacturer establish a full-lifecycle cybersecurity management mechanism covering design, development, testing, delivery, and operations and maintenance.
The Implementation Rules and the Security Requirements share a dual-layer complementary relationship of “procedural rules—technical baseline”. Together they constitute the complete compliance framework for a consumer network camera to apply for a cybersecurity label. A product manufacturer must deploy both instruments as an integrated compliance toolkit to complete the entire compliance workflow from security capability development and testing verification through to record-filing and public notice.
Comparison with Comparable Regimes in the European Union and the United States
The global governance of consumer IoT security is crystallizing along three parallel paths, with China, the United States, and the European Union representing three distinct regulatory choices.
The European Union has opted for a mandatory legislative path. The Cyber Resilience Act (“CRA”), which entered into force in December 2024, imposes full-lifecycle mandatory cybersecurity obligations on all “products with digital elements” placed on the EU market—requiring prevention of attack surfaces from the design phase, prohibiting the presence of known exploitable vulnerabilities at the time of placing on the market, and mandating post-market active reporting of exploited vulnerabilities and serious security incidents to the EU cybersecurity agency. The CRA directly ties compliance to the CE marking, such that a non-compliant digital product cannot bear the CE mark and is therefore excluded from the European single market. Violations may be sanctioned with fines of up to EUR 15 million or 2.5% of global annual turnover. This is, in essence, a baseline control model of “comply or exit the market”—the government draws the safety red line, and enterprises have no choice but to comply.
The United States has, like China, chosen a voluntary labeling path, but there are marked divergences in design. The Rules for IoT Cybersecurity Labeling Program established by the Federal Communications Commission (FCC) in March 2024 likewise follows the principle of “voluntary participation, market-driven”, using NIST IR 8425 as its technical baseline and relying on a third-party administrator to assess product compliance. It differs from the Chinese regime in two core respects. First, the U.S. adopts a single-tier standard rather than a tiered grading system: a product either meets the standard and receives the mark, or it does not, depriving consumers of the ability to intuitively compare the relative security capabilities of different products in the way one might compare star-rated hotels. Second, the United States issued a rule in November 2025 expressly prohibiting IoT products manufactured by enterprises on designated source lists from using the FCC cybersecurity label, thereby embedding a supply chain security screening dimension into the labeling regime.
China’s cybersecurity labeling regime has charted a third path between the above two approaches. Compared with the EU model, it is voluntary rather than mandatory—an enterprise may decide on its own whether to apply for a label and for which tier, affording greater flexibility at the market access threshold. Yet compared with the U.S. model, its three-star progressive grading system provides consumers with a more granular information structure—not a binary “compliant/non-compliant” signal, but a vertical comparative dimension of “adequate”, “good” and “excellent”. China further distinguishes its approach by adopting a batch-based catalogue management system rather than an omnibus roll-out, using consumer network cameras as the pilot to accumulate experience and reserving policy calibration space for the progressive inclusion of additional product categories.
Conclusion
The draft Implementation Rules and Security Requirements signal the extension of China’s cyberspace governance from platform regulation to end-device regulation. By constructing a transparent security market through tiered labeling, they present significant legal compliance challenges for camera manufacturers both domestically and internationally. Subsequent batches of the Product Catalogue may cover high-frequency consumer IoT categories such as smart door locks, smart speakers, and home routers.