GB/T 36959-2026 Cybersecurity technology—Capability requirements and evaluation specification for cybersecurity classified protection assessment organization English, Anglais, Englisch, Inglés, えいご
This is a draft translation for reference among interesting stakeholders. The finalized translation (passing through draft translation, self-check, revision and verification) will be delivered upon being ordered.
ICS
CCS
National Standard of the People's Republic of China
GB/T 36959-2026
Cybersecurity technology - Capability requirements and evaluation specification for cybersecurity classified protection assessment organization
网络安全技术 网络安全等级保护测评机构能力要求和评估规范
Issue date: 2026-01-28 Implementation date: 2027-02-01
Issued by the General Administration of Quality Supervision, Inspection and Quarantine of the People's Republic of China
the Standardization Administration of the People's Republic of China
Contents
Foreword
Introduction
1 Scope
2 Normative References
3 Terms and Definitions
4 Capability Requirements for Assessment Organizations
4.1 Classification of Assessment Organizations
4.2 Classification of Assessors
4.3 Capability Requirements for Class I Assessment Organizations
4.4 Capability Requirements for Class II Assessment Organizations
4.5 Capability Requirements for Class III Assessment Organizations
4.6 Requirements for Code of Conduct of Assessment Organizations
5 Capability Assessment Process for Assessment Organizations
5.1 Assessment Process
5.2 First-Time Evaluation
5.3 Continuous Evaluation
5.4 Capability Review
Annex A (Normative) Capability requirements for classified cybersecurity protection assessors
A.1 Junior Level Assessor
A.2 Intermediate Level Assessor
A.3 Senior Level Assessor
Bibliography
Cybersecurity technology — Capability requirements and evaluation specifications for assessment organizations of classified protection of cybersecurity
1 Scope
This document specifies the capability requirements and capability assessment for assessment organizations of classified protection of cybersecurity.
This document is applicable to the management and capability development of assessment organizations of classified protection of cybersecurity, as well as capability evaluation activities for assessment organizations of classified protection of cybersecurity.
2 Normative References
The following documents, in whole or in part, are normatively referenced in this document and are indispensable for its application. For dated references, only the edition cited applies. For undated references, the latest edition (including any amendments) applies.
GB/T 22239, Information security technology — Baseline for classified protection of cybersecurity
GB/T 28448, Information security technology — Evaluation requirements for classified protection of cybersecurity
3 Terms and Definitions
For the purposes of this document, the following terms and definitions apply.
3.1
assessment organization of classified protection of cybersecurity
professional third-party inspection and evaluation organization engaged in classified protection of cybersecurity assessment activities
3.2
classified cybersecurity protection assessor
professional technical personnel engaged in classified protection of cybersecurity assessment who have been recognized for their competence
3.3
capability evaluation
process of reviewing, verifying and evaluating the capability of applicant organizations for assessment organizations of classified protection of cybersecurity (hereinafter referred to as "assessment organizations") in accordance with standards and/or other normative documents
3.4
evaluation organization
professional technical organization authorized to conduct capability evaluation of enterprises and institutions applying to become assessment organizations
3.5
first-time evaluation
process in which the evaluation organization, for the first time, verifies, validates and evaluates the capability of an assessment organization in accordance with this document and related documents
3.6
continuous evaluation
regular or irregular evaluation and spot-check activities arranged during the validity period of the certificate to verify whether a certified assessment organization continuously meets the capability requirements
3.7
capability review
activity in which, before the expiry of the qualification validity period of an assessment organization, the evaluation organization conducts a comprehensive assessment to confirm whether it continuously meets the capability requirements, providing a basis for renewal to the next qualification validity period
3.8
evaluator
personnel designated by the evaluation organization to conduct capability evaluation of assessment organizations
4 Capability Requirements for Assessment Organizations
4.1 Classification of Assessment Organizations
Assessment organizations are classified into three levels according to capability requirements, from low to high: Class I, Class II and Class III. The progression between levels is achieved by adding new capability requirements or by imposing enhanced requirements on the basis of the original requirements.
4.2 Classification of Assessors
Personnel engaged in classified cybersecurity protection assessment work in assessment organizations are classified into three levels according to capability and job requirements, from low to high: Junior Level, Intermediate Level and Senior Level. The specific requirements shall comply with the provisions of Annex A.
4.3 Capability Requirements for Class I Assessment Organizations
4.3.1 Basic Conditions
Assessment organizations shall meet the following basic conditions:
a) Registered and established within the territory of the People's Republic of China, invested by Chinese citizens, legal persons, or state-owned enterprises and public institutions;
b) Independently operated and accounted, with no record of violations of laws or regulations, and shall provide documentary materials on the nature of the organization, equity structure, investment situation, legal representative and shareholder identity, demonstrating regulatory compliance and clear property rights;
c) The legal representative, head of the organization, report authorization signatory and assessment-related personnel of the assessment organization shall have Chinese nationality, reside in the territory on a long-term basis, have no permanent residence overseas, and shall provide certificates of no criminal record;
d) Engaged in cybersecurity services for 2 years or more, with certain cybersecurity testing and evaluation capabilities;
e) Having fixed office premises, equipped with testing equipment and tools, laboratory environments, etc. that meet the needs of assessment operations;
f) Having comprehensive rules and regulations for security and confidentiality management, project management, quality management, personnel management, archives management and training and education, etc.;
g) Not involved in cybersecurity product development, sales or information system security integration, etc., that may affect the impartiality of assessment results (except for self-use);
h) All employees shall not hold concurrent positions in information system security integration or cybersecurity product R&D, production or sales enterprises, nor hold equity in such enterprises (including cases where shareholding in such listed companies reaches or exceeds the information disclosure standard);
i) Other conditions stipulated by the national cybersecurity regulatory authorities.
4.3.2 Organization and Management Capability
4.3.2.1 The management of the assessment organization shall have knowledge of classified protection policy documents and be familiar with relevant standards.
4.3.2.2 The assessment organization shall establish relevant departments according to the requirements of classified assessment activities, with clear responsibilities, authorities and interrelationships, to ensure the orderly implementation of various tasks.
4.3.2.3 The assessment organization shall have professional technical personnel competent for classified assessment work, with the proportion of personnel holding a bachelor's degree or above not less than 70 % in principle.
4.3.2.4 The assessment organization shall establish positions that meet the needs of classified assessment work, such as assessment technician, assessment project team leader, technical supervisor, quality supervisor, confidentiality and security officer, equipment administrator and archives administrator, etc., with clearly defined responsibilities and stable personnel.
4.3.2.5 The assessment organization shall formulate comprehensive rules and regulations, including but not limited to the following:
a) Confidentiality management systems shall be formulated in accordance with relevant state confidentiality regulations, clearly defining the scope of confidential matters, personnel confidentiality responsibilities, various measures and requirements for confidentiality management during the assessment process, as well as penalties for violations of confidentiality systems.
b) Complete assessment project management procedures shall be formulated in accordance with GB/T 28449-2018 that are adapted to the organization's own characteristics, mainly including the organizational form and work responsibilities of assessment work, as well as the work content and management requirements at each stage of the assessment process.
c) Equipment management systems shall be formulated, mainly including the relevant responsibilities of personnel in the management of instruments and equipment (including testing equipment and tools), as well as the work content and management requirements for the procurement, use, operation and maintenance of instruments and equipment.
d) Document management systems shall be formulated, mainly including the relevant responsibilities of personnel in the management of assessment documents (including electronic documents), as well as the work content and management requirements for document borrowing, storage, and destruction.
e) Personnel management systems shall be formulated, mainly including the work content and management requirements for personnel recruitment, assessment, daily management, and resignation/departure, etc.
f) Training and education systems shall be formulated, mainly including the work content and management requirements for the formulation of training plans, implementation of training, training assessment and onboarding, and establishment of personnel training files, etc.
g) Systems for handling complaints, appeals and disputes shall be formulated, clearly defining the respective responsibilities of personnel in various positions within the assessment organization in complaint, appeal and dispute handling activities, and establishing a complete procedure from acceptance, confirmation, disposition to response.
4.3.3 Assessment Implementation Capability
4.3.3.1 Personnel Capability
4.3.3.1.1 Professional technical personnel engaged in classified assessment work in assessment organizations (hereinafter referred to as "assessors") shall obtain the classified cybersecurity protection assessor certificate, have the knowledge and ability to grasp national laws and policies, understand and master relevant technical standards, be familiar with the methods, procedures and work specifications of classified assessment, and have the ability to make professional judgments based on assessment results and issue classified assessment reports.
4.3.3.1.2 The assessment organization shall organize pre-job training for assessors, and only those who have passed the assessment shall be certified to work.
4.3.3.1.3 The number of assessors shall not be less than 15, including not less than 2 senior assessors and not less than 3 intermediate assessors, with reasonable personnel allocation.
Standard
GB/T 36959-2026 Cybersecurity technology—Capability requirements and evaluation specification for cybersecurity classified protection assessment organization (English)
Standard No.
GB/T 36959-2026
Status
to be valid
Language
English
File Format
PDF
Word Count
17000 words
Translation Price(USD)
510.0
Implemented on
2026-12-1
Delivery
via email in 1~5 business day
Detail of GB/T 36959-2026
Standard No.
GB/T 36959-2026
English Name
Cybersecurity technology—Capability requirements and evaluation specification for cybersecurity classified protection assessment organization
GB/T 36959-2026 Cybersecurity technology—Capability requirements and evaluation specification for cybersecurity classified protection assessment organization English, Anglais, Englisch, Inglés, えいご
This is a draft translation for reference among interesting stakeholders. The finalized translation (passing through draft translation, self-check, revision and verification) will be delivered upon being ordered.
ICS
CCS
National Standard of the People's Republic of China
GB/T 36959-2026
Cybersecurity technology - Capability requirements and evaluation specification for cybersecurity classified protection assessment organization
网络安全技术 网络安全等级保护测评机构能力要求和评估规范
Issue date: 2026-01-28 Implementation date: 2027-02-01
Issued by the General Administration of Quality Supervision, Inspection and Quarantine of the People's Republic of China
the Standardization Administration of the People's Republic of China
Contents
Foreword
Introduction
1 Scope
2 Normative References
3 Terms and Definitions
4 Capability Requirements for Assessment Organizations
4.1 Classification of Assessment Organizations
4.2 Classification of Assessors
4.3 Capability Requirements for Class I Assessment Organizations
4.4 Capability Requirements for Class II Assessment Organizations
4.5 Capability Requirements for Class III Assessment Organizations
4.6 Requirements for Code of Conduct of Assessment Organizations
5 Capability Assessment Process for Assessment Organizations
5.1 Assessment Process
5.2 First-Time Evaluation
5.3 Continuous Evaluation
5.4 Capability Review
Annex A (Normative) Capability requirements for classified cybersecurity protection assessors
A.1 Junior Level Assessor
A.2 Intermediate Level Assessor
A.3 Senior Level Assessor
Bibliography
Cybersecurity technology — Capability requirements and evaluation specifications for assessment organizations of classified protection of cybersecurity
1 Scope
This document specifies the capability requirements and capability assessment for assessment organizations of classified protection of cybersecurity.
This document is applicable to the management and capability development of assessment organizations of classified protection of cybersecurity, as well as capability evaluation activities for assessment organizations of classified protection of cybersecurity.
2 Normative References
The following documents, in whole or in part, are normatively referenced in this document and are indispensable for its application. For dated references, only the edition cited applies. For undated references, the latest edition (including any amendments) applies.
GB/T 22239, Information security technology — Baseline for classified protection of cybersecurity
GB/T 28448, Information security technology — Evaluation requirements for classified protection of cybersecurity
3 Terms and Definitions
For the purposes of this document, the following terms and definitions apply.
3.1
assessment organization of classified protection of cybersecurity
professional third-party inspection and evaluation organization engaged in classified protection of cybersecurity assessment activities
3.2
classified cybersecurity protection assessor
professional technical personnel engaged in classified protection of cybersecurity assessment who have been recognized for their competence
3.3
capability evaluation
process of reviewing, verifying and evaluating the capability of applicant organizations for assessment organizations of classified protection of cybersecurity (hereinafter referred to as "assessment organizations") in accordance with standards and/or other normative documents
3.4
evaluation organization
professional technical organization authorized to conduct capability evaluation of enterprises and institutions applying to become assessment organizations
3.5
first-time evaluation
process in which the evaluation organization, for the first time, verifies, validates and evaluates the capability of an assessment organization in accordance with this document and related documents
3.6
continuous evaluation
regular or irregular evaluation and spot-check activities arranged during the validity period of the certificate to verify whether a certified assessment organization continuously meets the capability requirements
3.7
capability review
activity in which, before the expiry of the qualification validity period of an assessment organization, the evaluation organization conducts a comprehensive assessment to confirm whether it continuously meets the capability requirements, providing a basis for renewal to the next qualification validity period
3.8
evaluator
personnel designated by the evaluation organization to conduct capability evaluation of assessment organizations
4 Capability Requirements for Assessment Organizations
4.1 Classification of Assessment Organizations
Assessment organizations are classified into three levels according to capability requirements, from low to high: Class I, Class II and Class III. The progression between levels is achieved by adding new capability requirements or by imposing enhanced requirements on the basis of the original requirements.
4.2 Classification of Assessors
Personnel engaged in classified cybersecurity protection assessment work in assessment organizations are classified into three levels according to capability and job requirements, from low to high: Junior Level, Intermediate Level and Senior Level. The specific requirements shall comply with the provisions of Annex A.
4.3 Capability Requirements for Class I Assessment Organizations
4.3.1 Basic Conditions
Assessment organizations shall meet the following basic conditions:
a) Registered and established within the territory of the People's Republic of China, invested by Chinese citizens, legal persons, or state-owned enterprises and public institutions;
b) Independently operated and accounted, with no record of violations of laws or regulations, and shall provide documentary materials on the nature of the organization, equity structure, investment situation, legal representative and shareholder identity, demonstrating regulatory compliance and clear property rights;
c) The legal representative, head of the organization, report authorization signatory and assessment-related personnel of the assessment organization shall have Chinese nationality, reside in the territory on a long-term basis, have no permanent residence overseas, and shall provide certificates of no criminal record;
d) Engaged in cybersecurity services for 2 years or more, with certain cybersecurity testing and evaluation capabilities;
e) Having fixed office premises, equipped with testing equipment and tools, laboratory environments, etc. that meet the needs of assessment operations;
f) Having comprehensive rules and regulations for security and confidentiality management, project management, quality management, personnel management, archives management and training and education, etc.;
g) Not involved in cybersecurity product development, sales or information system security integration, etc., that may affect the impartiality of assessment results (except for self-use);
h) All employees shall not hold concurrent positions in information system security integration or cybersecurity product R&D, production or sales enterprises, nor hold equity in such enterprises (including cases where shareholding in such listed companies reaches or exceeds the information disclosure standard);
i) Other conditions stipulated by the national cybersecurity regulatory authorities.
4.3.2 Organization and Management Capability
4.3.2.1 The management of the assessment organization shall have knowledge of classified protection policy documents and be familiar with relevant standards.
4.3.2.2 The assessment organization shall establish relevant departments according to the requirements of classified assessment activities, with clear responsibilities, authorities and interrelationships, to ensure the orderly implementation of various tasks.
4.3.2.3 The assessment organization shall have professional technical personnel competent for classified assessment work, with the proportion of personnel holding a bachelor's degree or above not less than 70 % in principle.
4.3.2.4 The assessment organization shall establish positions that meet the needs of classified assessment work, such as assessment technician, assessment project team leader, technical supervisor, quality supervisor, confidentiality and security officer, equipment administrator and archives administrator, etc., with clearly defined responsibilities and stable personnel.
4.3.2.5 The assessment organization shall formulate comprehensive rules and regulations, including but not limited to the following:
a) Confidentiality management systems shall be formulated in accordance with relevant state confidentiality regulations, clearly defining the scope of confidential matters, personnel confidentiality responsibilities, various measures and requirements for confidentiality management during the assessment process, as well as penalties for violations of confidentiality systems.
b) Complete assessment project management procedures shall be formulated in accordance with GB/T 28449-2018 that are adapted to the organization's own characteristics, mainly including the organizational form and work responsibilities of assessment work, as well as the work content and management requirements at each stage of the assessment process.
c) Equipment management systems shall be formulated, mainly including the relevant responsibilities of personnel in the management of instruments and equipment (including testing equipment and tools), as well as the work content and management requirements for the procurement, use, operation and maintenance of instruments and equipment.
d) Document management systems shall be formulated, mainly including the relevant responsibilities of personnel in the management of assessment documents (including electronic documents), as well as the work content and management requirements for document borrowing, storage, and destruction.
e) Personnel management systems shall be formulated, mainly including the work content and management requirements for personnel recruitment, assessment, daily management, and resignation/departure, etc.
f) Training and education systems shall be formulated, mainly including the work content and management requirements for the formulation of training plans, implementation of training, training assessment and onboarding, and establishment of personnel training files, etc.
g) Systems for handling complaints, appeals and disputes shall be formulated, clearly defining the respective responsibilities of personnel in various positions within the assessment organization in complaint, appeal and dispute handling activities, and establishing a complete procedure from acceptance, confirmation, disposition to response.
4.3.3 Assessment Implementation Capability
4.3.3.1 Personnel Capability
4.3.3.1.1 Professional technical personnel engaged in classified assessment work in assessment organizations (hereinafter referred to as "assessors") shall obtain the classified cybersecurity protection assessor certificate, have the knowledge and ability to grasp national laws and policies, understand and master relevant technical standards, be familiar with the methods, procedures and work specifications of classified assessment, and have the ability to make professional judgments based on assessment results and issue classified assessment reports.
4.3.3.1.2 The assessment organization shall organize pre-job training for assessors, and only those who have passed the assessment shall be certified to work.
4.3.3.1.3 The number of assessors shall not be less than 15, including not less than 2 senior assessors and not less than 3 intermediate assessors, with reasonable personnel allocation.