Back to Insights
National standardsPKICybersecurityInformation security 2025-08-11

China Approves Seven Cybersecurity National Standards

Seven Chinese national standards cover PKI management, interoperability, timestamps, risk management, cloud security, security operations and AI computing platforms, effective February 1, 2026.

Seven national cybersecurity standards administered by China’s National Technical Committee on Cybersecurity Standardization have been approved and published. They include PKI certificate management and timestamping specifications and will take effect on February 1, 2026. Titles below are descriptive translations of the Chinese originals.

The seven standards address certificate management protocols, minimum PKI component interoperability, timestamps, information security risk management, cloud service security assessment, cybersecurity operations and AI computing platform security. All share the effective date of February 1, 2026.

1. GB/T 19714-2025: PKI certificate management protocol

This standard describes certificate management protocols within public key infrastructure (PKI). It defines protocol information needed for certificate applications, revocation, key updates, key recovery and other certificate generation and management activities. It supports network operators, critical information infrastructure operators and cybersecurity service organizations in designing, developing and operating PKI.

2. GB/T 19771-2025: Minimum interoperability specifications for PKI components

This standard specifies basic functional and data-format requirements for minimum interoperability between PKI components and describes testing and evaluation methods. It applies to PKI design, development, testing and use in activities such as electronic signatures, electronic seals and identity management.

3. GB/T 20520-2025: PKI timestamp specifications

This standard describes the components of a PKI timestamp system, timestamp contents, and the request and issuance process. It specifies technical requirements and corresponding test and verification methods. It assists network operators, critical information infrastructure operators and cybersecurity service organizations with timestamp system development, assessment, procurement and use.

4. GB/T 31722-2025: Guidance on information security risk management

This standard helps organizations meet the requirements of GB/T 22080—2025 relating to activities that address information security risks. It also guides risk management implementation, particularly risk assessment and treatment. It applies to organizations of every type, size and sector.

5. GB/T 34942-2025: Assessment methods for cloud computing service security capabilities

This standard establishes assessment principles and processes based on GB/T 31168—2023 and describes methods for evaluating individual security requirements. It applies to third-party bodies assessing the security capabilities of cloud service providers and also provides a reference for providers’ self-assessments.

6. GB/T 45940-2025: Implementation guidance for cybersecurity operations

This standard introduces a reference framework, conditions for service providers and operations personnel, and a process for establishing cybersecurity operations services. It outlines implementation activities across operations management, identification, protection, monitoring and analysis, incident handling, coordination and effectiveness assessment.

It provides implementation guidance for both suppliers and customers of cybersecurity operations services. Customers and third-party organizations can also use it when assessing operational effectiveness and capabilities.

7. GB/T 45958-2025: Security framework for AI computing platforms

This standard establishes a security framework for artificial intelligence computing platforms, specifying security functions, security management and role-based security responsibilities. It applies to platform design, construction, use and operations.

Sources cited by the original article: China’s National Technical Committee on Cybersecurity Standardization, the MIIT cybersecurity center and the cybersecurity association.