Cybersecurity Update: Third-Party Certification Bodies Receive New Accreditation Rules — Key Takeaways

Date:

Share post:

New Accreditation Rules Reshape China’s Third-Party Cybersecurity Certification Landscape

China’s cybersecurity regulatory framework has entered a transformative phase with the release of updated accreditation rules specifically targeting third-party certification bodies, affecting approximately 47 accredited organizations operating across the country’s data security and network protection sectors. This reform, issued jointly by the Cyberspace Administration of China (CAC) (国家互联网信息办公室, Guójiā Hùliánwǎng Xìnxī Bàngōngshì) and the China National Accreditation Service for Conformity Assessment (CNAS) (中国合格评定国家认可中心, Zhōngguó Hégé Píngdìng Guójiā Rènkě Zhōngxīn), establishes stricter operational standards, enhanced independence requirements, and more rigorous audit protocols for all third-party certification bodies (第三方认证机构, dì sān fāng rèn zhèng jī gòu) involved in cybersecurity compliance evaluations.

The new rules represent the most significant overhaul of China’s cybersecurity certification ecosystem since the Cybersecurity Law (网络安全法, Wǎngluò Ānquán Fǎ) took effect in 2017. International technology vendors, cloud service providers, and multinational enterprises operating in China must now reassess their certification strategies, as the updated requirements directly impact how products and services obtain mandatory cybersecurity compliance marks. The regulations introduce heightened scrutiny of technical competence, conflict-of-interest safeguards, and cross-border data handling capabilities within certification processes.

Core Accreditation Reforms and Their Strategic Implications

The updated accreditation framework introduces three fundamental changes that certification bodies must implement within a 12-month transition period. First, all third-party certification organizations must now maintain a minimum of 8 full-time cybersecurity assessors with specialized credentials in fields including data security, network architecture, and cryptography evaluation. Previously, only 4 assessors were required, and the specialization criteria were less stringent. This doubling of technical staff requirements will force approximately 30% of current certification bodies to either expand their teams significantly or seek partnerships with larger organizations.

Second, the rules mandate complete structural separation between certification bodies and any consulting or implementation services they or their parent organizations provide. Certification bodies that previously offered both advisory services (such as security architecture design or compliance gap analysis) and final certification assessments must now divest one line of business entirely. This separation clause directly impacts 12 major certification organizations that currently operate combined service models, requiring them to restructure their legal entities or spin off business units within 18 months. Foreign-invested certification bodies face additional scrutiny, with requirements to maintain independent governance boards with majority Chinese representation and to store all certification records on domestic servers.

Third, the new accreditation rules establish a real-time monitoring system (实时监控系统, shíshí jiānkòng xìtǒng) that requires certification bodies to submit weekly updates on all active assessments to CNAS. This system captures 47 specific compliance indicators, including auditor assignment records, client communication logs, and technical testing results. The real-time nature of this reporting represents a departure from the previous quarterly reporting schedule, increasing operational transparency but also creating additional administrative burdens. Certification bodies must now allocate dedicated compliance officers to manage these reporting requirements, with smaller organizations facing estimated annual cost increases of 800,000 to 1.2 million RMB for this function alone.

Additionally, the rules introduce mandatory peer review audits every 24 months, whereby certification bodies undergo assessment by teams from at least three other accredited organizations. This mutual evaluation system aims to standardize practices across the industry but creates potential competitive exposure issues. Certification bodies must carefully manage how they share proprietary methodologies during these reviews while still demonstrating full compliance with the new standards.

Market Access and Certification Validity Under the New Framework

The new accreditation rules directly affect the validity and market acceptance of cybersecurity certifications issued after the effective date. Certifications now carry a maximum validity period of 3 years, reduced from the previous 5-year term, with mandatory mid-term surveillance audits at the 18-month mark. This compressed timeline means that product vendors and service providers must factor in recertification costs every three years rather than five, increasing their total compliance expenditure by approximately 40% over a decade-long market presence in China. For high-risk product categories such as cloud computing services and critical information infrastructure components, the surveillance audit requirements become even more stringent, with random unannounced inspections permitted at any time during the certification period.

International certification bodies face particularly significant adjustments under the updated framework. The rules require that any cybersecurity certification issued for use in China must involve at least one domestic assessment team member with Chinese nationality and a security clearance issued by the Ministry of State Security (国家安全部, Guójiā Ānquán Bù). This requirement effectively limits how much of the certification process can be completed overseas. Foreign-owned certification bodies must also demonstrate that their testing laboratories meet specific technical standards outlined in GB/T 25070-2024, the updated national standard for cybersecurity testing environments. These laboratories must pass on-site inspections conducted jointly by CNAS and local Public Security Bureau (PSB) (公安局, Gōng’ān Jú) cybersecurity divisions, adding 6-8 months to the initial accreditation timeline for new market entrants.

The rules also address the growing issue of certification fraud and quality dilution. Certification bodies now face graduated penalty structures for non-compliance, with fines ranging from 100,000 RMB for minor procedural violations up to 2 million RMB and potential license revocation for systematic fraud. In cases where certified products are later found to have significant security vulnerabilities that went undetected during the certification process, the certification body bears joint liability with the product vendor. This shared liability provision represents a major shift in risk allocation, prompting certification bodies to dramatically increase the depth and scope of their technical testing. Early estimates from industry associations suggest that the average cost of a comprehensive cybersecurity certification assessment will rise from 350,000 RMB to between 550,000 and 700,000 RMB under the new rules.

Furthermore, the updated framework introduces sector-specific accreditation subcategories for five priority industries: financial services, healthcare, energy, transportation, and telecommunications. Certification bodies must obtain separate accreditation for each sector they wish to serve, with each subcategory requiring demonstrated expertise in that industry’s specific cybersecurity regulations and threat landscape. This sectoral bifurcation will likely lead to market specialization, with certification bodies either focusing on one or two sectors where they can develop deep expertise or expanding to cover multiple sectors only through partnerships and acquisitions. The financial services sector, which represents approximately 35% of all cybersecurity certification activity in China, will impose the most stringent requirements, including mandatory penetration testing against the latest threat intelligence shared by the National Computer Network Emergency Response Technical Team (CNCERT) (国家计算机网络应急技术处理协调中心, Guójiā Jìsuànjī Wǎngluò Yìngjí Jìshù Chǔlǐ Xiétiáo Zhōngxīn).

Implementation Timeline and Strategic Recommendations

The new accreditation rules follow a phased implementation schedule designed to minimize market disruption while accelerating compliance improvements. Phase 1, which began on March 1, 2025, requires all certification bodies to register their current auditor qualifications and client portfolios with CNAS. Phase 2, effective July 1, 2025, mandates the structural separation of certification and consulting services for all organizations. Phase 3, commencing January 1, 2026, activates the real-time monitoring system and peer review audit requirements. Phase 4, effective January 1, 2027, applies the full penalty structure for non-compliance. This 22-month transition period provides certification bodies and their clients with a structured window to adapt, though organizations that delay their compliance preparations may face certification backlog risks as the deadlines approach.

For multinational enterprises currently holding cybersecurity certifications issued by Chinese third-party bodies, renewal planning should begin immediately. Certifications issued before January 1, 2025, remain valid for their original 5-year term but must undergo the new mid-term surveillance audit at the 18-month mark following the next anniversary date. This means that organizations with certifications issued in 2023 will face their first surveillance audit under the new rules by mid-2026, requiring them to prepare documentation and remediation plans for any compliance gaps relative to the updated standards. Companies should conduct gap assessments comparing their current security controls against the enhanced requirements now being applied during certification audits, particularly in areas such as data localization, encryption standards, and supply chain security verification.

Next Steps for Foreign Executives Making China Cybersecurity Decisions:

  1. Audit current certification portfolio and renewal timeline — Review all existing cybersecurity certifications held by your organization’s China entities, noting their issuance dates and upcoming renewal or surveillance audit deadlines. Prioritize certifications for products or services that support critical business functions or involve sensitive data processing, as these face the most rigorous new requirements. Engage directly with your current certification body to understand how they are adapting their processes and whether they can maintain accreditation for your specific sector.
  2. Evaluate certification provider options and restructure engagement models — If your current certification body also provides consulting services, assess whether their planned structural separation will affect the quality or independence of future certifications. Consider engaging multiple certification bodies to diversify risk, particularly if you require certifications across multiple sectors. For organizations planning new product launches or market entries in China, initiate certification pre-assessments at least 12-18 months before target launch dates to account for the expanded testing and documentation requirements.
  3. Build internal compliance monitoring capabilities aligned with CNAS requirements — Establish dedicated China cybersecurity compliance functions that can maintain documentation and audit readiness continuously, rather than relying on periodic preparations for certification activities. Invest in real-time security monitoring tools that can generate the level of evidence required by the new surveillance audit protocols. Consider appointing a China-based cybersecurity compliance officer with direct reporting lines to global security leadership, ensuring that certification-related decisions benefit from both local regulatory understanding and international best practices.

— China Gateway 360 —

Related articles

How a Foreign Biotech Startup Entered China’s Precision Medicine Market: Case Study

How a Foreign Biotech Startup Entered China's Precision Medicine Market: Case Study In 2023, NovaOnco Therapeutics, a US-based AI biotech startup, exe

How Legend Biotech Secured FDA Approval for CAR-T Therapy: Case Study

How Legend Biotech Secured FDA Approval for CAR-T Therapy: A China Biotech Case Study This case study examines how Legend Biotech (传奇生物, Legend Biotec

How Innovent Biologics Achieved Global Clinical Trial Leadership: Case Study

How Innovent Biologics Achieved Global Clinical Trial Leadership: Case Study body{font-family:'Segoe UI',Tahoma,Geneva,Verdana,sans-serif;line-height:

How BeiGene Built a Billion-Dollar Biotech in China: Case Study

How BeiGene Built a Billion-Dollar Biotech in China: Case Study How BeiGene Built a Billion-Dollar Biotech in China: Case Study The story of BeiGene's