top of page

China Cybersecurity Labeling for Connected Cameras (2026)

11 hours ago
4 min read

China Joins the Global Camera Security Race: What Notice No. 3 of 2026 Really Changes for Manufacturers


Connected cameras have quietly become the proving ground for a global experiment: can a star rating on a box actually tell a buyer whether a device is secure? Singapore started testing that idea in 2020. The US followed with the Cyber Trust Mark. The EU took the harder legislative route with the Cyber Resilience Act. Now China has entered the same race and it picked consumer connected cameras as its opening move.

On June 15, 2026, the Cyberspace Administration of China (CAC), the Ministry of Industry and Information Technology (MIIT), and the Ministry of Public Security (MPS) jointly signed Notice No. 3 of 2026 (国信办通字〔2026〕3号), published on the CAC's website three days later. It activated on July 1, 2026, making connected cameras the first product category to carry China's new cybersecurity label.


Why Cameras, and Why Now


The choice of product category is not incidental. Connected cameras sit at the intersection of everything regulators worldwide are worried about: they collect biometric-adjacent data (faces, movement patterns, sometimes audio), they're mass-manufactured at low margins that incentivize security shortcuts, and they've been the poster child for IoT botnets since the Mirai attacks nearly a decade ago. Starting a labeling regime here lets Beijing pilot the mechanics testing infrastructure, registration workflow, enforcement teeth on a product category where the security stakes are easy to explain to consumers.


A modern smart home security camera showcasing China's 3-star cybersecurity rating label, flanked by infographic elements illustrating global IoT security standards.

How China's Cybersecurity Labeling Rating Actually Works


Unlike the EU's mandatory Cyber Resilience Act, China cybersecurity labeling for connected cameras is opt-in. Manufacturers who choose to participate are tested against TC260-PG-20265A, a technical standard developed by China's National Cybersecurity Standardization Technical Committee (TC260), across five domains:


  • Physical and hardware security

  • System and software security

  • Network and communication security

  • Data security and personal information protection

  • Overall security assurance


Products earn one of three star ratings but only by clearing every applicable requirement within that tier, not by averaging across categories:


  • 1-Star (Basic): entry level cybersecurity capability

  • 2-Star (Enhanced): materially stronger protections across the five domains

  • 3-Star (Leading): the ceiling of the current framework


Where China's approach diverges most from its global peers is in who can test what. For 1-Star and 2-Star, manufacturers can self-test using their own lab or send products to a qualified third party. But 2-Star self-testing requires the in-house lab to carry CNAS accreditation specific to cybersecurity testing a meaningful barrier that pushes most manufacturers toward third-party labs by default. At 3-Star, self-testing disappears entirely: an independent lab must run penetration testing, no exceptions. It's a structure that echoes Singapore's CLS, where Levels 3 and 4 similarly require third-party binary review and penetration testing suggesting China's framers were paying attention to how earlier schemes handled the "who grades the homework" problem.


Certification Impact Summary


What changes

Detail

Legal status

Voluntary no product is blocked from the China market for lacking the label

Competitive effect

Labeled products gain a visible trust signal; CAC-run public disclosure of violations raises the cost of skipping it

Testing burden

Rises sharply between tiers self-lab (1★) → accredited self-lab or third party (2★) → mandatory third-party penetration testing (3★)

Label lifespan

3 years from the date registration is publicly announced, then mandatory re-testing

Parallel obligations

Cameras connecting to China's telecom network still need separate network access licensing the label doesn't replace it

Registration authority

China Electronics Standardization Institute, via China's national labeling platform


What This Means for Manufacturers


If you sell connected cameras into China or are weighing whether to the practical question isn't "do we need this label," since legally you don't. The real question is where your product sits on a spectrum most competitors are about to start moving along:


If you're a budget or mid-tier brand: A 1-Star label is achievable with existing in-house testing capacity for many manufacturers and becomes a low-cost way to differentiate from unlabeled competitors on marketplaces where security-conscious buyers are starting to compare listings.


If you're targeting premium retail, B2B, or export-adjacent buyers: 2-Star and 3-Star are where the label starts doing real work but only if your security architecture was built to support it. Retrofitting authentication strength, encryption schemes, or firmware update mechanisms after a product has shipped is far more expensive than designing for a target tier from the start.


If your camera connects to China's telecom network: Treat the cybersecurity label and telecom network access approval as two separate workstreams that need to be sequenced together, not assumed to be bundled.


If you already hold certifications in other markets: Don't assume Singapore's CLS, the US Cyber Trust Mark, or CRA conformity will transfer. The underlying security engineering overlaps significantly, but TC260-PG-20265A is a distinct standard with its own test protocol budget for a dedicated evaluation cycle even if your product is already "secure by design" elsewhere.


Timeline and Required Actions


When

What happens

What manufacturers should do

Now

Program is live and voluntary

Decide whether to pursue labeling and which tier fits your product roadmap

Before applying

Confirm lab strategy: in-house (1★/2★ with CNAS accreditation) or third-party (required for 3★)

At application

10-working-day formal review of submitted materials

Prepare the full registration package: application form, test report, label design, declaration of conformity, business license, lab qualification evidence, telecom network access documentation if applicable

Post-approval

Label and registration code go live on the national platform

Apply the label correctly per CAC's format rules; do not alter colors, text, or proportions

Ongoing

Any change to chipset, firmware, communication module, device management, or security-relevant configuration

Reassess whether the change triggers mandatory re-testing before the product ships with the existing label

At 3 years

Label expires

Re-test and re-register before the expiry date to maintain continuous coverage


The Bigger Picture


China's move brings four of the world's largest electronics markets the US, EU, Singapore, and now China into the same basic pattern: voluntary or mandatory star/tier ratings, third-party testing requirements that scale with claimed security level, and public registries consumers can check. For manufacturers building global camera lines, that convergence is worth watching closely: the testing infrastructure and security engineering investment made for one market's label is increasingly reusable groundwork for the next one, even where the standards themselves don't formally align.

bottom of page