On June 15, 2026, the Cyberspace Administration of China (CAC), the Ministry of Industry and Information Technology (MIIT), and the Ministry of Public Security jointly issued the Catalog of Products Subject to Cybersecurity Labeling (First Batch) and its associated implementation rules. On the same day, the SAC/TC260 (cybersecurity) released Cybersecurity Labeling—Security Requirements for Consumer Connected Cameras (Cybersecurity Standard Practice Guide TC260-PG-20265A), which serves as the technical basis for implementing the cybersecurity labeling scheme for this product category.
These moves follow the three departments’ release of the Cybersecurity Labeling Management Measures back in April 2026, which took effect on July 1 and introduced a three-tier rating system—Basic, Enhanced, and Leading, marked by one to three stars—designed to give consumers a clearer signal of a product’s security posture. Consumer connected cameras made the first cut, which makes them the first product line to fall under the new framework.
The implementation rules are structured under the following aspects:
General Provisions
Label Specifications and Format
Cybersecurity Capability Testing
Determination of Label Information
Filing Procedures
Public Announcement
Printing, Use, and Display of Labels
For the purposes of these rules, a consumer connected camera means any standalone camera that consumers or organizations buy and use to capture and process audio or video over the internet; cameras used in public security settings are explicitly excluded.
A key feature of the scheme is that participation is voluntary—producers may obtain the cybersecurity label at their own discretion. The cybersecurity label itself is a blue mark (see below) measuring 46.9 mm by 50 mm, displaying the producer name, product model, security rating (one to three stars), validity period, the testing laboratory name, the applicable standard reference, and a QR code that links to the test report, key security indicators, and the producer’s compliance declaration.

Regarding testing requirements, products are rated Basic, Enhanced, or Leading based on evaluations against the above-mentioned Cybersecurity Standard Practice Guide TC260-PG-20265A. Products seeking one- or two-star ratings may be tested either by the producer’s in-house laboratory or by a qualified third-party body. However, for two-star ratings, the in-house laboratory must hold China National Accreditation Service for Conformity Assessment (CNAS) accreditation. Products seeking a three-star rating must undergo penetration testing conducted by an eligible third-party organization.
For the filing process, producers submit applications through the online platform operated by the China Electronics Standardization Institute (CESI), the designated filing body, which completes formal review within 10 working days and publicly announces approved products.
The label is valid for three years. If it expires, or if certain key technical aspects change, like the chip maker or generation, the firmware OS or third-party components, the communication module, the device management interface (web or app), or any security settings that could affect the attack surface, such as physical ports, network interfaces, authentication methods, access controls, or encryption—the product has to go through retesting and refiling.
The Practice Guide itself is the technical reference that runs through the whole scheme. It sets out cybersecurity requirements across five areas—physical and hardware security, system and software security, network and communication security, data security and personal information protection, and security assurance—and breaks those requirements into the same three progressive tiers that map directly to the star ratings.
The scheme is voluntary. Nonetheless, foreign companies may wish to monitor how the labels are received by the market, as they may influence procurement decisions and consumer trust. Early assessment of product security against the framework, along with familiarity with the testing and filing procedures, would be a prudent step for those considering participation.
China Eases Personal Information Protection Duties for Small-Scale Handlers – JUL, 2026
China Proposes Seven Mandatory Standards for Data and Cybersecurity Case Handling – AUG, 2026
Call for Comment: Six Energy Efficiency Standards Updated for Appliances and Industrial Equipment – JUL 2026
Top Read Articles
Switch articles-
2026.08.28China Proposes Seven Mandatory Standards for Data and Cybersecurity Case Handling – AUG, 2026
-
2026.08.28China Eases Personal Information Protection Duties for Small-Scale Handlers – JUL, 2026
-
2026.08.25Five-Year Plan for China’s Power System Support Emerging Sectors – AUG, 2026
-
2026.08.24National ICV Standard Revised into Mandatory Requirements in China – AUG, 2026
-
2026.08.21Regulation of China on Integrated Circuits Design Protection Revised – AUG, 2026