Cybersecurity Testing

2026-09-01

I. Product Export Certification

1. EU RED Cybersecurity

Standard Description Status
EN 18031‑1 Protection against cyberattacks (general cybersecurity requirements) Mandatory since 01 August 2025
EN 18031‑2 Personal data and privacy protection Same as above
EN 18031‑3 Anti-fraud protection for financial transaction / payment devices Same as above

This is based on Article 3(3)(d)(e)(f) of the RED Directive and Implementing Act (EU) 2022/30. All wireless-enabled devices (Wi‑Fi / Bluetooth / IoT / smart home / cameras, etc.) exported to the EU must comply. No exemptions apply from 1 August 2025.

2. Baseline Security for Consumer IoT

Standard Description Remarks
ETSI EN 303 645 Baseline security for consumer IoT devices (13 clauses: no default passwords, vulnerability management, software update, data protection, communication security, etc.) Currently voluntary; widely adopted as the foundation by UK PSTI (mandatory from Apr 2024), EU, Singapore and Australia
UK PSTI Act Product Security and Telecommunications Infrastructure Act Mandatory in the UK from 29 April 2024; compliance with requirements similar to EN 303 645 is required

3. Industrial & Other Standards

Standard Description
IEC 62443 series Cybersecurity for industrial automation and control systems (IEC 62443‑4‑1 / 62443‑4‑2 for product development and component requirements)
ISO/IEC 15408 (CC) Common Criteria for Information Technology Security Evaluation (EAL levels)
US SB‑327 / NIST California IoT Security Law; NIST IR 8259, NIST IR 8268 IoT device security baselines
EU CRA (Cyber Resilience Act) Cyber Resilience Act; mandatory at the end of 2027 (key upcoming regulatory trend)

II. Domestic Evaluation Framework (Classified Protection 2.0 + Special Assessments)

1. Cybersecurity Classified Protection (Classified Protection 2.0)

Standard Description
GB/T 22239‑2019 Basic Requirements for Cybersecurity Classified Protection (general requirements plus extended requirements for cloud computing / IoT / industrial control systems, Levels 1 to 5)
GB/T 28448‑2019 Evaluation Requirements for Classified Protection (testing methodology)
GB/T 25070‑2019 Technical Requirements for Security Design
GB/T 22240‑2020 Classification Guide for Classified Protection

2. Special Information Security Assessment Standards

Standard Description
GB/T 20984‑2022 Information Security Risk Assessment Methodology
GB/T 35273‑2020 Personal Information Security Specification
GB/T 39786‑2021 Security Protection Requirements for Critical Information Infrastructure
GB/T 24363 / 18336 Information Security Incident Response / Information Technology Security Evaluation (national standard corresponding to CC)
GM/T 系列 Security Assessment of Commercial Cryptography Applications