Follow us on

Current location:

Home > ChinaCompliance
China Issues Cybersecurity Labeling Rules for Consumer Connected Cameras – JUN 2026

2026.07.03 09:56

Author:admin

Tags: by ED02 #Cybersecurity

Share to--:

On June 15, 2026, the Cyberspace Administration of China (CAC), the Ministry of Industry and Information Technology (MIIT), and the Ministry of Public Security jointly issued the Catalog of Products Subject to Cybersecurity Labeling (First Batch) and its associated implementation rules. On the same day, the SAC/TC260 (cybersecurity) released Cybersecurity Labeling—Security Requirements for Consumer Connected Cameras (Cybersecurity Standard Practice Guide TC260-PG-20265A), which serves as the technical basis for implementing the cybersecurity labeling scheme for this product category.

These moves follow the three departments’ release of the Cybersecurity Labeling Management Measures back in April 2026, which took effect on July 1 and introduced a three-tier rating system—Basic, Enhanced, and Leading, marked by one to three stars—designed to give consumers a clearer signal of a product’s security posture. Consumer connected cameras made the first cut, which makes them the first product line to fall under the new framework.

The implementation rules are structured under the following aspects:

Ÿ   General Provisions

Ÿ   Label Specifications and Format

Ÿ   Cybersecurity Capability Testing

Ÿ   Determination of Label Information

Ÿ   Filing Procedures

Ÿ   Public Announcement

Ÿ   Printing, Use, and Display of Labels

For the purposes of these rules, a consumer connected camera means any standalone camera that consumers or organizations buy and use to capture and process audio or video over the internet; cameras used in public security settings are explicitly excluded.

A key feature of the scheme is that participation is voluntary—producers may obtain the cybersecurity label at their own discretion. The cybersecurity label itself is a blue mark (see below) measuring 46.9 mm by 50 mm, displaying the producer name, product model, security rating (one to three stars), validity period, the testing laboratory name, the applicable standard reference, and a QR code that links to the test report, key security indicators, and the producer’s compliance declaration.

Regarding testing requirements, products are rated Basic, Enhanced, or Leading based on evaluations against the above-mentioned Cybersecurity Standard Practice Guide TC260-PG-20265A. Products seeking one- or two-star ratings may be tested either by the producer’s in-house laboratory or by a qualified third-party body. However, for two-star ratings, the in-house laboratory must hold China National Accreditation Service for Conformity Assessment (CNAS) accreditation. Products seeking a three-star rating must undergo penetration testing conducted by an eligible third-party organization.

For the filing process, producers submit applications through the online platform operated by the China Electronics Standardization Institute (CESI), the designated filing body, which completes formal review within 10 working days and publicly announces approved products.

The label is valid for three years. If it expires, or if certain key technical aspects change, like the chip maker or generation, the firmware OS or third-party components, the communication module, the device management interface (web or app), or any security settings that could affect the attack surface, such as physical ports, network interfaces, authentication methods, access controls, or encryption—the product has to go through retesting and refiling.

The Practice Guide itself is the technical reference that runs through the whole scheme. It sets out cybersecurity requirements across five areas—physical and hardware security, system and software security, network and communication security, data security and personal information protection, and security assurance—and breaks those requirements into the same three progressive tiers that map directly to the star ratings.

The scheme is voluntary. Nonetheless, foreign companies may wish to monitor how the labels are received by the market, as they may influence procurement decisions and consumer trust. Early assessment of product security against the framework, along with familiarity with the testing and filing procedures, would be a prudent step for those considering participation.


Related News