China's national cybersecurity labeling scheme for internet-connected devices took effect on July 1, 2026, and consumer network cameras are the first product category to get operational rules. The framework — the Administrative Measures for Cybersecurity Identification, issued jointly on April 2, 2026 by the Cyberspace Administration of China (CAC), the Ministry of Industry and Information Technology (MIIT), and the Ministry of Public Security (MPS) — establishes a three-tier star rating for connected products' security capability. Camera-specific implementation rules, adopted June 15, 2026 and published alongside the first product catalogue on June 18, apply the framework to "consumer-grade networked cameras" — internet-connected cameras sold for personal or organizational use, explicitly excluding public-security surveillance equipment.
How the Rating Works
A product earns one star for meeting a security floor: no weak or default passwords, an active vulnerability-patching mechanism, and ongoing software updates. Two stars require security capability above comparable peer products. Three stars — the "leading" tier — requires third-party penetration testing. For cameras specifically, testing follows technical guideline TC260-PG-20265A, labels carry a QR code and registration number, applications get a 10-working-day regulatory review, and a certified label is valid for three years before re-testing. A national public-service platform run by the cyberspace administration hosts the registry.
Critically, the underlying measure "adheres to the principle of voluntary participation" by manufacturers — but in the same clause, it "encourages consumers to prioritize labeled products." That pairing matters more than it looks.
The Case For It
Before critiquing the design, the problem it targets is real. Cheap, internet-connected cameras with hardcoded or default credentials have been a documented global security failure for a decade — the 2016 Mirai botnet, which knocked major US platforms offline, spread precisely by scanning for IoT cameras and DVRs still running factory-default passwords. China is both the world's largest manufacturer and one of its largest domestic markets for these devices, via firms like Hikvision and Dahua, so a baseline security floor there has outsized global effect: insecure cameras made or sold in China don't stay in China. Requiring patchable firmware and banning default passwords is cheap for manufacturers to implement and meaningfully reduces botnet recruitment. China is not inventing this concern — it's catching up to a consensus the EU's Cyber Resilience Act (2024) and the US FCC's now-stalled Cyber Trust Mark program were both built to address.
Where the Design Strains the "Voluntary" Label
The trouble is what "voluntary" tends to mean in Chinese regulatory practice. A scheme that pairs voluntary registration with explicit government encouragement for consumers and, implicitly, procurement bodies to prefer labeled products creates the same pressure a mandate would, without the transparency, appeal rights, or fixed compliance timeline a formal mandate carries. Foreign camera manufacturers face a structurally harder version of this bargain than domestic ones: they must register through the CESI platform directly or via a Chinese agent, remain liable for submission accuracy even when using an agent, and risk registration cancellation plus a flag on the National Credit Information Platform — a semi-public blacklist with reputational and commercial consequences — over fabricated or inaccurate test materials. None of that is unreasonable for genuine fraud. But combined with opaque, non-public technical standards like TC260-PG-20265A and testing routed through domestically designated labs, it hands Chinese regulators discretionary leverage over which foreign products clear the bar, dressed as a consumer-information label rather than a market-access control.
There's also an institutional tension worth naming plainly: the same agency pairing — CAC and MPS — that runs this "privacy protection" camera-labeling scheme is also China's primary content-control and public-security surveillance apparatus. A regime that scores cameras on data-handling security while its co-administrator runs the country's video-surveillance infrastructure isn't inherently contradictory, since consumer device security and state surveillance capacity are different questions. But it does mean outside observers have grounds to ask whether "cybersecurity capability" here is being defined solely around consumer protection, or partly around which data flows the state wants secured versus which it wants accessible — and the rules as published don't settle that question either way.
A Mirror, Not an Outlier
The irony is that Washington's parallel effort provides an unflattering comparison rather than a clean contrast. The FCC's Cyber Trust Mark, meant to do for US consumer IoT devices roughly what China's scheme now does for cameras, lost its lead administrator, UL Solutions, on December 19, 2025, after the FCC opened an investigation into UL's testing-lab ties to China. Two governments are now building parallel, mutually suspicious device-security labeling regimes, each one implicitly premised on distrust of the other's testing infrastructure. That's a worse outcome for device makers and consumers than either country's rules alone: manufacturers selling into both markets will need to certify twice, under incompatible technical standards, with no mutual recognition in sight.
The Right Fix Is Narrow
The underlying baseline — ban default passwords, require patchability, disclose it clearly — is worth keeping and worth other jurisdictions adopting on genuinely voluntary terms. What China's scheme needs to earn the "voluntary" label it claims is publishing the full TC260-PG-20265A standard, opening testing-lab accreditation to non-Chinese labs on equal terms, and keeping consumer "encouragement" limited to information disclosure rather than a proxy for procurement preference. Absent that, a scheme built to look voluntary but function as a market gate will do less for camera security than for regulatory control over who gets to sell cameras in China at all.