China cybersecurity labeling offers connected camera manufacturers a voluntary way to demonstrate product security. The program took effect on July 1, 2026. It introduces three security ratings covering device protection, personal information, and security assurance.
Three Chinese authorities issued Notice No. 3 of 2026 on June 15, 2026. These authorities include the Cyberspace Administration of China (CAC), the Ministry of Industry and Information Technology (MIIT), and the Ministry of Public Security (MPS).
The notice introduced the Catalog of Products for Cybersecurity Labeling Implementation (First Batch). It also established implementation rules for consumer connected cameras under CSL 001-2026.
How China cybersecurity labeling works
Manufacturers can voluntarily apply for cybersecurity labeling based on technical standard TC260-PG-20265A. The program defines three security ratings:
- 1-Star (Basic): Basic cybersecurity capabilities.
- 2-Star (Enhanced): Higher security capabilities.
- 3-Star (Leading): The highest security level within the framework.
Products must meet all applicable requirements to obtain their target rating. Therefore, manufacturers should review the complete requirements for their intended level.
The framework covers standalone cameras with internet connectivity that collect and process audio and video information. Individuals or organizations may purchase and use these products. However, the document excludes cameras for public security applications.
Technical requirements for connected cameras
The framework addresses five security areas:
- Physical and hardware security.
- System and software security.
- Network and communication security.
- Data security and personal information protection.
- Security assurance.
At the Basic level, cameras must meet requirements for unique device identifiers, password protection, and identity authentication. They must also protect critical security parameters.
When manufacturers configure initial login passwords, they must assign a unique, randomly generated password to each device. The requirements prohibit fixed or shared default passwords.
Additionally, the document addresses personal information processing, information erasure, and vulnerability management. Manufacturers must establish mechanisms to track and address security defects and vulnerabilities.
Higher ratings introduce further protections. For example, the Enhanced level requires secure boot mechanisms to verify firmware and boot component authenticity and integrity. The Leading level adds product lifecycle security management requirements.
Registration validity and label placement
The China Electronic Standardization Institute (CESI) processes registrations, which remain valid for three years.
Participants must display certified labels on product packaging, user manuals, app interfaces, or e-commerce listing pages.
However, participation remains voluntary. Manufacturers should distinguish the program’s assessment and labeling requirements from mandatory market access obligations.
For support assessing applicable conformity requirements, explore Entirety’s Product Certification Service.
Impact Assessment
-
Technical Standards?
Yes
-
Type Approval & Market Access?
Yes
-
Imports, Customs, Trade, or Market Surveillance?
Yes
-
Spectrum Management?
No