" " indicates required fields
China’s GB Standards, which entered into force in May 2022, outline cybersecurity requirements for vehicle systems’ design, development, production, and post-production processes. GB/T Standards mark voluntary standards in China, all covered by the Cybersecurity Working Group (WG). These standards aim to enhance vehicle cybersecurity by ensuring secure product design, threat monitoring, incident response, and recovery mechanisms. As of June 2024, there are several standards and research projects under the Chinese Automotive Cybersecurity Standard System.
***
For additional background into Chinese Regulations and Standards, watch our Unmasking Global Regulations webinar, featuring David Mor-Ofek and ThunderSoft’s Ouyang Zhe.
***
Applicable to all automotive manufacturers and suppliers operating in China, the standards are comprehensive and cover multiple aspects of automotive cybersecurity, including risk assessment, management processes, and technical measures for vehicles and their network operations. These standards are part of China’s broader efforts to regulate and protect the increasingly connected and technologically advanced automotive industry.

Fines and Implications for Non-Compliance
Non-compliance with the Chinese GB Standards for Vehicle Cybersecurity can result in significant consequences for automotive companies. The regulatory authorities in China have the power to impose fines and other penalties to enforce compliance. Potential implications for non-compliant companies include:
***
Chinese GB Standards Requirements
Under the Chinese GB Standards, car makers are expected to implement a range of cybersecurity measures to protect their vehicles and related systems. These include:
***
**
Risk Management
**
Security and Operations by Design
Agile Product Security Development and Operations that optimize the needed security controls for development teams and enrich operations with product security data for faster incident response:
**
Context-based BOM and Vulnerability Management
Risk-driven approach for automated BOM and vulnerability management, prioritizing true impact on the product and optimizing mitigation based on cost and time.
**
Supply Chain Security Posture
***
To learn more about EVSec Platform and to schedule an exclusive demo for your product security team, click here.
Dynamic threat modeling and risk assessment aligned with global regulations
LLM-agnostic generative AI layer powering automation across every module
Aggregated threat feed contextualized against your actual products
Generate, manage, and triage all BOMs and vulnerabilities across the lifecycle
Quantitative optimization of mitigation strategy and security control allocation
Configurable dashboards and reports across every EVSec data layer
Extract software composition and risk from firmware and binaries without source code
Optimized anomaly detection for Ethernet and CAN, plus ECU runtime protection
Quantify and manage cybersecurity risk for products operating in the field
Enrich SOC events with deep product and architecture context
Context-driven test and validation with intelligent fuzzing, integrated into CI/CD
AI-powered static analysis integrated into CI/CD with reduced false positives
Foundational layer: cyber model, workspaces, and integration backbone to DevOps toolchain
Out-of-the-box and customizable workflows for regulatory and security processes
Centralized compliance management with evidence generated from live data