Skip to Main Content

(Yet) Another Approach to Product Cybersecurity Regulation: Comparing American and Chinese Regimes

07/07/2026 | 4 minute read

Posted in Cybersecurity

If you read my previous post on the topic, you know the U.S. Cyber Trust Mark remains an important potential component of federal procurement cybersecurity strategy in the U.S., with a requirement that regulations mandating federally procured Internet of Things (IoT) devices bear the Cyber Trust Mark be implemented by early 2027. Broadening our aperture to get better visibility into the future of product cybersecurity regulation, it’s worth comparing the quasi-compulsory Cyber Trust Mark regime to a voluntary (?) regime that came into force in China on July 1. The Measures for the Administration of Cybersecurity Labels, issued in late 2025 by the Cyberspace Administration of China (CAC), China’s Ministry of Industry and Information Technology (MIIT) and its Ministry of Public Security (MPS), bear some similarities to the Cyber Trust Mark scheme and have some key differences.

Here’s where things differ as the two regimes stand right now:

  • Regulatory authorities: China’s framework is jointly administered by the CAC, MIIT and MPS, signaling a broader state enforcement role, though nominally there are testing agencies that will be stood up. The U.S. program is led by a single agency – the Federal Communications Commission (FCC) – and relies on a public-private administration model with a lead administrator, cybersecurity label administrators and accredited labs. The Cyber Trust Mark regime can be expected to be limited to devices that fall within the FCC’s jurisdiction (it excludes, for example, products otherwise regulated by the Food and Drug Administration or National Highway Traffic Safety Administration).
  • Product scope: China’s measures apply to products with Internet connectivity, subject to a catalog of covered products issued in batches. The Cyber Trust Mark is focused on wireless consumer IoT products, with defined inclusions and exclusions under the FCC’s rules. Time will tell whether this will lead to a wide divergence between the cybersecurity posture of devices that communicate via wireless spectrum and those that do not, but for now it is possible to develop a device that communicates solely via wired means in order to avoid applicability of this regime.
  • Label architecture: China uses a tiered model with three security levels – basic, enhanced and leading – represented by one-, two- and three-star labels. The U.S. program uses a single trust mark rather than multiple consumer-facing security tiers.
  • Substantive benchmark: China’s model distinguishes among escalating levels of cybersecurity capability, including a top tier tied to advanced resistance testing. The U.S. model is built around baseline qualification against program criteria rather than a graduated rating system displayed to consumers. The relative scoring aspect of China’s regime, where a three-star-labeled product must exhibit controls on par with other similar products and a superlative posture relative to two-starred products, may prove difficult to administer against the backdrop of a fast-moving technology landscape. The average three-star device may not be a three-star device in three months; in the wake of a major cybersecurity incident, the bar may change.
  • Testing model: Under China’s measures, one- and two-star products may be tested in-house or by qualified third-party labs, while three-star products require additional third-party penetration testing. In the U.S. program, conformity assessment is routed through accredited labs and administrative bodies under the FCC framework.
  • Information disclosed on/through the label: China’s label is comparatively information-dense: It includes the manufacturer’s name, the model, the security level, the validity period, the lab’s name, referenced standards/technical documents and a filing information code that can surface the test report and conformity materials. The U.S. mark is paired with a QR code to a public registry containing additional cybersecurity information, emphasizing consumer-accessible disclosures rather than a tiered label face.
  • Government filing versus registry model: China requires a formal filing/recordation process through a designated filing platform before the label may be used. The U.S. program centers on authorization to use the mark and a decentralized public registry linked through the QR code.
  • Enforcement intensity: China’s final measures place heavier emphasis on supervision and post-market enforcement, including revocation, public announcements of violations, potential legal penalties and inclusion of misconduct in China’s national credit information sharing system. By contrast, the U.S. program is primarily a labeling and authorization regime overseen by the FCC, with compliance mechanisms tied to the label program rather than a broader cross-sector credit or enforcement system. With that said, the incorporation of the Cyber Trust Mark regime into federal procurement cycles may create compliance hooks that rely on the Federal Acquisition Regulations, Defense Federal Acquisition Regulation Supplement and False Claims Act, among other things.
  • Reassessment and life cycle obligations: China expressly requires refiling when key technical parameters affecting cybersecurity change or when the label validity period expires. The U.S. program also emphasizes life cycle cybersecurity information (such as support periods and update practices), but the structure is oriented more around ongoing consumer disclosures and program compliance than a formal refiling regime of the Chinese type.
  • Policy orientation: China’s measures reflect a combined consumer protection, industrial policy and state supervision approach, with explicit ties to national standards and administrative oversight. Outside the federal procurement context (note, for example, the Pennsylvania IT procurement policy preference!), the Cyber Trust Mark is framed more squarely as a consumer information and market incentive mechanism intended to encourage Security by Design and improve purchasing decisions.
  • Implementation maturity: China’s final measures were issued in April, with an effective date of July 1, while the U.S. program’s rules were adopted in 2024 and the FCC has continued standing up administrators and implementation mechanisms into 2026.