SDV SectorNews and signals from the software-defined vehicle sector. Global coverage, daily.
SDV WikiUpdated September 4, 2026

China's vehicle market access

The permissions a vehicle needs before it can be sold in China — and how, during 2026, software validation, cybersecurity and update logging became conditions of keeping them.

Market access is the set of permissions a vehicle needs before it can be sold in China: an entry in the ministry’s product catalog, a China Compulsory Certification for the product, and registration of the individual vehicle. Europe reaches the same result through a single instrument, type approval; China distributes it across several, which is why an enforcement action there can arrive as a suspended catalog entry rather than as a withdrawn approval.

What changed in 2026 is not the structure but what the structure is now used to check. Through August, four separate instruments moved software validation, cybersecurity and update logging from guidance into the conditions attached to those permissions.

The mandatory standards underneath

China’s in-vehicle software requirements sit in mandatory national standards rather than in the access rules themselves. Three matter for vehicle software:

  • GB 44495 — vehicle cybersecurity requirements. MIIT’s own announcements pair it with UN R155.
  • GB 44496 — vehicle software update requirements, paired in the same way with R156.
  • GB 44721 — the safety standard for automated driving, which becomes mandatory in July 2027.

The pairing with the UN regulations is the ministry’s own framing, and it is a useful shorthand rather than an equivalence: the obligations are similar in subject, and the enforcement route is not. A European manufacturer that fails R155 loses an approval. A Chinese one that fails the corresponding check can lose the catalog entry, the certification, or both.

Access as an inspection, not only a filing

The clearest demonstration of that difference came before the rules were tightened. In late July 2026, MIIT inspectors spent two days at Chery, NIO and JAC in Anhui, selecting sample vehicles and battery packs on site for national-standard compliance testing tied to production access. The audit was physical and unannounced in character, and it tested capability rather than paperwork.

The four-ministry campaign

On August 27, 2026, MIIT published a joint notice — numbered 工信厅联通装函〔2026〕407号, executed August 21 — launching a one-year national campaign on production conformity and quality in road motor vehicles, issued with the general offices of the Ministry of Public Security, the Ministry of Ecology and Environment, and the State Administration for Market Regulation.

One of its four inspection areas covers the validation of new technology. Under it, inspectors check whether combined driving assistance and automated driving functions have been adequately test-validated; whether data security, network security and artificial-intelligence protections on the product and its cloud platform are adequate and were planned, built and put into use in step with the vehicle; and whether log retention is complete enough to support investigation of an incident.

The attached work plan is specific about method and record-keeping in a way that matters to a supplier:

  • unannounced checks, with functional safety, safety of the intended function, cybersecurity, data security and software update among the capabilities examined at makers of intelligent connected vehicles;
  • for over-the-air updates, four named checks — impact assessment, test validation, execution assurance and log recording;
  • testing organizations to keep test records, images and video for six years, and to video-record the test process.

Manufacturers were told to complete self-inspection and report to provincial authorities by the end of December 2026, and to file recall plans with SAMR where a defect is found. Software-update management is listed among the gates applied alongside CCC certification and vehicle registration, and the sanctions run to suspension of catalog entries and CCC certificates.

That last sentence is the whole point of the campaign. An update-logging failure is not answered with a fine; it is answered with the ability to sell.

The validation gate

The day before the campaign notice, on August 26, MIIT vice minister Xin Guobin told a State Council Information Office briefing that the ministry had drawn up a five-year plan for the intelligent connected new-energy vehicle industry covering 2026 to 2030. Setting out the problems it addresses, he said some aggressive innovative designs had been fitted to vehicles without sufficient experimental validation, and that individual incidents involving product quality and autonomous-driving safety had drawn public attention.

The plan’s industry-governance strand commits the ministry to reform group-level management of production qualifications, strengthen market-entry review of innovative product design and the management of testing and validation, and strictly prohibit products that have not been adequately tested and validated from entering the market.

Read against the campaign, the two documents describe the same mechanism at two ranges: a five-year policy that makes validation evidence a condition of entry, and a one-year audit that goes and looks.

Into statute

On August 28, 2026, the National People’s Congress opened the revised Road Traffic Safety Law for public comment, with comments due September 26. The published draft runs to nine chapters and 170 articles, and the accompanying explanation — made on the State Council’s behalf and published by the NPC — sets out its autonomous-vehicle provisions.

Under Article 96, an autonomous vehicle may be driven on roads only after passing a road traffic rule compliance test and being registered. Articles 97 and 103 place responsibility for traffic violations on the producing or importing enterprise. Article 99 extends compulsory motor traffic accident liability insurance to autonomous vehicles. Articles 100 and 102 require producers and importers to ensure the road driving safety, network security and data security of autonomous vehicles, and state that they must not make false or exaggerated claims about autonomous driving functions.

Two things separate this from the ministry instruments. The obligation attaches to the manufacturer rather than to a product approval, and it sits in a statute rather than in a notice — which is a different thing to be found in breach of.

Why the four instruments are one subject

Across eight days in late August 2026, four documents from three different levels of the Chinese state aimed at the same target: capability claimed but not demonstrated.

DateInstrumentWhat it does
Aug 26MIIT five-year plan, announced at SCIO briefingMakes validation evidence a market-entry condition
Aug 27Four-ministry conformity noticeAudits validation, cybersecurity and update logs for a year
Aug 28Draft Road Traffic Safety Law, out for commentPuts security duties and a ban on exaggerated autonomy claims into statute
Aug 12MIIT comment on a vehicle-cloud communication security standardExtends the security perimeter to the link back to the cloud

The instruments differ in force and in timescale, and none of them is unusual on its own. Together they describe a regulator that has stopped treating a driving function as a product to be certified once, and started treating it as a claim that has to remain provable while the software keeps changing.

What this means for a supplier outside China

Three consequences follow for a company that ships software into a Chinese vehicle program.

The first is evidentiary. The inspections check records, not intentions: test validation for a driver-assistance function, an impact assessment for an update, logs complete enough to reconstruct an incident, and six years of retained test media. A supplier whose validation evidence lives only in a customer’s system will be asked for it through that customer.

The second is that the cloud is inside the perimeter. The campaign names the cloud platform alongside the vehicle and requires the two to have been planned, built and put into use in step. A backend delivered after the vehicle is a finding rather than a schedule.

The third is that the sanction is commercial. Catalog entry and CCC certification are what a Chinese customer needs in order to sell, so a software defect that would be a corrective action elsewhere reaches procurement in China through the same document that reaches engineering.

What to watch

The open question is how the validation gate is applied in practice, because a market-entry review that turns on validation evidence has no published threshold. GB 44721 becoming mandatory in July 2027 gives the automated-driving half of the question a fixed date; the self-inspection reports due to provincial authorities at the end of December 2026 give the campaign one.

The second thing to watch is whether the statutory route holds its shape. The traffic law draft attaches network and data security duties, and the honesty of autonomy marketing, to the producing enterprise. If it is enacted in that form, China will have written into law an obligation that most jurisdictions handle through approval conditions — and an obligation about what a manufacturer may claim, which is not a subject vehicle law usually addresses at all.

Sources: State Council Information Office briefing, August 26, 2026; MIIT joint notice on production conformity, August 27, 2026; State Council explanation of the draft Road Traffic Safety Law, published by the National People’s Congress; MIIT notice on communications-industry standards, August 12, 2026; MIIT inspection report, Anhui, July 2026.

Related: ISO/SAE 21434 · OTA update · Software-defined vehicle (SDV) · Type approval / homologation · UNECE R155 · UNECE R156