Cybersecurity Testing
2026-09-01I. Product Export Certification
1. EU RED Cybersecurity
| Standard | Description | Status |
|---|---|---|
| EN 18031‑1 | Protection against cyberattacks (general cybersecurity requirements) | Mandatory since 01 August 2025 |
| EN 18031‑2 | Personal data and privacy protection | Same as above |
| EN 18031‑3 | Anti-fraud protection for financial transaction / payment devices | Same as above |
This is based on Article 3(3)(d)(e)(f) of the RED Directive and Implementing Act (EU) 2022/30. All wireless-enabled devices (Wi‑Fi / Bluetooth / IoT / smart home / cameras, etc.) exported to the EU must comply. No exemptions apply from 1 August 2025.
2. Baseline Security for Consumer IoT
| Standard | Description | Remarks |
|---|---|---|
| ETSI EN 303 645 | Baseline security for consumer IoT devices (13 clauses: no default passwords, vulnerability management, software update, data protection, communication security, etc.) | Currently voluntary; widely adopted as the foundation by UK PSTI (mandatory from Apr 2024), EU, Singapore and Australia |
| UK PSTI Act | Product Security and Telecommunications Infrastructure Act | Mandatory in the UK from 29 April 2024; compliance with requirements similar to EN 303 645 is required |
3. Industrial & Other Standards
| Standard | Description |
|---|---|
| IEC 62443 series | Cybersecurity for industrial automation and control systems (IEC 62443‑4‑1 / 62443‑4‑2 for product development and component requirements) |
| ISO/IEC 15408 (CC) | Common Criteria for Information Technology Security Evaluation (EAL levels) |
| US SB‑327 / NIST | California IoT Security Law; NIST IR 8259, NIST IR 8268 IoT device security baselines |
| EU CRA (Cyber Resilience Act) | Cyber Resilience Act; mandatory at the end of 2027 (key upcoming regulatory trend) |
II. Domestic Evaluation Framework (Classified Protection 2.0 + Special Assessments)
1. Cybersecurity Classified Protection (Classified Protection 2.0)
| Standard | Description |
|---|---|
| GB/T 22239‑2019 | Basic Requirements for Cybersecurity Classified Protection (general requirements plus extended requirements for cloud computing / IoT / industrial control systems, Levels 1 to 5) |
| GB/T 28448‑2019 | Evaluation Requirements for Classified Protection (testing methodology) |
| GB/T 25070‑2019 | Technical Requirements for Security Design |
| GB/T 22240‑2020 | Classification Guide for Classified Protection |
2. Special Information Security Assessment Standards
| Standard | Description |
|---|---|
| GB/T 20984‑2022 | Information Security Risk Assessment Methodology |
| GB/T 35273‑2020 | Personal Information Security Specification |
| GB/T 39786‑2021 | Security Protection Requirements for Critical Information Infrastructure |
| GB/T 24363 / 18336 | Information Security Incident Response / Information Technology Security Evaluation (national standard corresponding to CC) |
| GM/T 系列 | Security Assessment of Commercial Cryptography Applications |


