2026-7-26 10.2.208.129
Code of China Chinese Classification Professional Classification ICS Classification Latest News Value-added Services

Position: Chinese Standard in English/GB/T 36959-2026
GB/T 36959-2026   Cybersecurity technology—Capability requirements and evaluation specification for cybersecurity classified protection assessment organization (English)
Standard No.: GB/T 36959-2026 Status:to be valid remind me the status change

Email:

Target Language:English File Format:PDF
Word Count: 17000 words Translation Price(USD):510.0 remind me the price change

Email:

Implemented on:2026-12-1 Delivery: via email in 1~5 business day

→ → →

,,2026-12-1,60E0AC6F665E756E1779868012048
Standard No.: GB/T 36959-2026
English Name: Cybersecurity technology—Capability requirements and evaluation specification for cybersecurity classified protection assessment organization
Chinese Name: 网络安全技术 网络安全等级保护测评机构能力要求和评估规范
Professional Classification: GB    National Standard
Source Content Issued by: SAMR, SAC
Issued on: 2026-05-25
Implemented on: 2026-12-1
Status: to be valid
Superseding:GB/T 36959-2018 Information security technology—Capability requirements and evaluation specification for assessment organization of classified protection of cybersecurity
Target Language: English
File Format: PDF
Word Count: 17000 words
Translation Price(USD): 510.0
Delivery: via email in 1~5 business day
GB/T 36959-2026 Cybersecurity technology—Capability requirements and evaluation specification for cybersecurity classified protection assessment organization English, Anglais, Englisch, Inglés, えいご This is a draft translation for reference among interesting stakeholders. The finalized translation (passing through draft translation, self-check, revision and verification) will be delivered upon being ordered. ICS CCS National Standard of the People's Republic of China ‌GB/T 36959-2026 Cybersecurity technology - Capability requirements and evaluation specification for cybersecurity classified protection assessment organization 网络安全技术 网络安全等级保护测评机构能力要求和评估规范 Issue date: 2026-01-28 Implementation date: 2027-02-01 Issued by the General Administration of Quality Supervision, Inspection and Quarantine of the People's Republic of China the Standardization Administration of the People's Republic of China Contents Foreword Introduction 1 Scope 2 Normative References 3 Terms and Definitions 4 Capability Requirements for Assessment Organizations 4.1 Classification of Assessment Organizations 4.2 Classification of Assessors 4.3 Capability Requirements for Class I Assessment Organizations 4.4 Capability Requirements for Class II Assessment Organizations 4.5 Capability Requirements for Class III Assessment Organizations 4.6 Requirements for Code of Conduct of Assessment Organizations 5 Capability Assessment Process for Assessment Organizations 5.1 Assessment Process 5.2 First-Time Evaluation 5.3 Continuous Evaluation 5.4 Capability Review Annex A (Normative) Capability requirements for classified cybersecurity protection assessors A.1 Junior Level Assessor A.2 Intermediate Level Assessor A.3 Senior Level Assessor Bibliography Cybersecurity technology — Capability requirements and evaluation specifications for assessment organizations of classified protection of cybersecurity 1 Scope This document specifies the capability requirements and capability assessment for assessment organizations of classified protection of cybersecurity. This document is applicable to the management and capability development of assessment organizations of classified protection of cybersecurity, as well as capability evaluation activities for assessment organizations of classified protection of cybersecurity. 2 Normative References The following documents, in whole or in part, are normatively referenced in this document and are indispensable for its application. For dated references, only the edition cited applies. For undated references, the latest edition (including any amendments) applies. GB/T 22239, Information security technology — Baseline for classified protection of cybersecurity GB/T 28448, Information security technology — Evaluation requirements for classified protection of cybersecurity 3 Terms and Definitions For the purposes of this document, the following terms and definitions apply. 3.1 assessment organization of classified protection of cybersecurity professional third-party inspection and evaluation organization engaged in classified protection of cybersecurity assessment activities 3.2 classified cybersecurity protection assessor professional technical personnel engaged in classified protection of cybersecurity assessment who have been recognized for their competence 3.3 capability evaluation process of reviewing, verifying and evaluating the capability of applicant organizations for assessment organizations of classified protection of cybersecurity (hereinafter referred to as "assessment organizations") in accordance with standards and/or other normative documents 3.4 evaluation organization professional technical organization authorized to conduct capability evaluation of enterprises and institutions applying to become assessment organizations 3.5 first-time evaluation process in which the evaluation organization, for the first time, verifies, validates and evaluates the capability of an assessment organization in accordance with this document and related documents 3.6 continuous evaluation regular or irregular evaluation and spot-check activities arranged during the validity period of the certificate to verify whether a certified assessment organization continuously meets the capability requirements 3.7 capability review activity in which, before the expiry of the qualification validity period of an assessment organization, the evaluation organization conducts a comprehensive assessment to confirm whether it continuously meets the capability requirements, providing a basis for renewal to the next qualification validity period 3.8 evaluator personnel designated by the evaluation organization to conduct capability evaluation of assessment organizations 4 Capability Requirements for Assessment Organizations 4.1 Classification of Assessment Organizations Assessment organizations are classified into three levels according to capability requirements, from low to high: Class I, Class II and Class III. The progression between levels is achieved by adding new capability requirements or by imposing enhanced requirements on the basis of the original requirements. 4.2 Classification of Assessors Personnel engaged in classified cybersecurity protection assessment work in assessment organizations are classified into three levels according to capability and job requirements, from low to high: Junior Level, Intermediate Level and Senior Level. The specific requirements shall comply with the provisions of Annex A. 4.3 Capability Requirements for Class I Assessment Organizations 4.3.1 Basic Conditions Assessment organizations shall meet the following basic conditions: a) Registered and established within the territory of the People's Republic of China, invested by Chinese citizens, legal persons, or state-owned enterprises and public institutions; b) Independently operated and accounted, with no record of violations of laws or regulations, and shall provide documentary materials on the nature of the organization, equity structure, investment situation, legal representative and shareholder identity, demonstrating regulatory compliance and clear property rights; c) The legal representative, head of the organization, report authorization signatory and assessment-related personnel of the assessment organization shall have Chinese nationality, reside in the territory on a long-term basis, have no permanent residence overseas, and shall provide certificates of no criminal record; d) Engaged in cybersecurity services for 2 years or more, with certain cybersecurity testing and evaluation capabilities; e) Having fixed office premises, equipped with testing equipment and tools, laboratory environments, etc. that meet the needs of assessment operations; f) Having comprehensive rules and regulations for security and confidentiality management, project management, quality management, personnel management, archives management and training and education, etc.; g) Not involved in cybersecurity product development, sales or information system security integration, etc., that may affect the impartiality of assessment results (except for self-use); h) All employees shall not hold concurrent positions in information system security integration or cybersecurity product R&D, production or sales enterprises, nor hold equity in such enterprises (including cases where shareholding in such listed companies reaches or exceeds the information disclosure standard); i) Other conditions stipulated by the national cybersecurity regulatory authorities. 4.3.2 Organization and Management Capability 4.3.2.1 The management of the assessment organization shall have knowledge of classified protection policy documents and be familiar with relevant standards. 4.3.2.2 The assessment organization shall establish relevant departments according to the requirements of classified assessment activities, with clear responsibilities, authorities and interrelationships, to ensure the orderly implementation of various tasks. 4.3.2.3 The assessment organization shall have professional technical personnel competent for classified assessment work, with the proportion of personnel holding a bachelor's degree or above not less than 70 % in principle. 4.3.2.4 The assessment organization shall establish positions that meet the needs of classified assessment work, such as assessment technician, assessment project team leader, technical supervisor, quality supervisor, confidentiality and security officer, equipment administrator and archives administrator, etc., with clearly defined responsibilities and stable personnel. 4.3.2.5 The assessment organization shall formulate comprehensive rules and regulations, including but not limited to the following: a) Confidentiality management systems shall be formulated in accordance with relevant state confidentiality regulations, clearly defining the scope of confidential matters, personnel confidentiality responsibilities, various measures and requirements for confidentiality management during the assessment process, as well as penalties for violations of confidentiality systems. b) Complete assessment project management procedures shall be formulated in accordance with GB/T 28449-2018 that are adapted to the organization's own characteristics, mainly including the organizational form and work responsibilities of assessment work, as well as the work content and management requirements at each stage of the assessment process. c) Equipment management systems shall be formulated, mainly including the relevant responsibilities of personnel in the management of instruments and equipment (including testing equipment and tools), as well as the work content and management requirements for the procurement, use, operation and maintenance of instruments and equipment. d) Document management systems shall be formulated, mainly including the relevant responsibilities of personnel in the management of assessment documents (including electronic documents), as well as the work content and management requirements for document borrowing, storage, and destruction. e) Personnel management systems shall be formulated, mainly including the work content and management requirements for personnel recruitment, assessment, daily management, and resignation/departure, etc. f) Training and education systems shall be formulated, mainly including the work content and management requirements for the formulation of training plans, implementation of training, training assessment and onboarding, and establishment of personnel training files, etc. g) Systems for handling complaints, appeals and disputes shall be formulated, clearly defining the respective responsibilities of personnel in various positions within the assessment organization in complaint, appeal and dispute handling activities, and establishing a complete procedure from acceptance, confirmation, disposition to response. 4.3.3 Assessment Implementation Capability 4.3.3.1 Personnel Capability 4.3.3.1.1 Professional technical personnel engaged in classified assessment work in assessment organizations (hereinafter referred to as "assessors") shall obtain the classified cybersecurity protection assessor certificate, have the knowledge and ability to grasp national laws and policies, understand and master relevant technical standards, be familiar with the methods, procedures and work specifications of classified assessment, and have the ability to make professional judgments based on assessment results and issue classified assessment reports. 4.3.3.1.2 The assessment organization shall organize pre-job training for assessors, and only those who have passed the assessment shall be certified to work. 4.3.3.1.3 The number of assessors shall not be less than 15, including not less than 2 senior assessors and not less than 3 intermediate assessors, with reasonable personnel allocation.
Code of China
Standard
GB/T 36959-2026  Cybersecurity technology—Capability requirements and evaluation specification for cybersecurity classified protection assessment organization (English)
Standard No.GB/T 36959-2026
Statusto be valid
LanguageEnglish
File FormatPDF
Word Count17000 words
Translation Price(USD)510.0
Implemented on2026-12-1
Deliveryvia email in 1~5 business day
Detail of GB/T 36959-2026
Standard No.
GB/T 36959-2026
English Name
Cybersecurity technology—Capability requirements and evaluation specification for cybersecurity classified protection assessment organization
Chinese Name
网络安全技术 网络安全等级保护测评机构能力要求和评估规范
Chinese Classification
Professional Classification
GB
ICS Classification
Issued by
SAMR, SAC
Issued on
2026-05-25
Implemented on
2026-12-1
Status
to be valid
Superseded by
Superseded on
Abolished on
Superseding
GB/T 36959-2018 Information security technology—Capability requirements and evaluation specification for assessment organization of classified protection of cybersecurity
Language
English
File Format
PDF
Word Count
17000 words
Translation Price(USD)
510.0
Keywords
GB/T 36959-2026, GB 36959-2026, GBT 36959-2026, GB/T36959-2026, GB/T 36959, GB/T36959, GB36959-2026, GB 36959, GB36959, GBT36959-2026, GBT 36959, GBT36959
Introduction of GB/T 36959-2026
GB/T 36959-2026 Cybersecurity technology—Capability requirements and evaluation specification for cybersecurity classified protection assessment organization English, Anglais, Englisch, Inglés, えいご This is a draft translation for reference among interesting stakeholders. The finalized translation (passing through draft translation, self-check, revision and verification) will be delivered upon being ordered. ICS CCS National Standard of the People's Republic of China ‌GB/T 36959-2026 Cybersecurity technology - Capability requirements and evaluation specification for cybersecurity classified protection assessment organization 网络安全技术 网络安全等级保护测评机构能力要求和评估规范 Issue date: 2026-01-28 Implementation date: 2027-02-01 Issued by the General Administration of Quality Supervision, Inspection and Quarantine of the People's Republic of China the Standardization Administration of the People's Republic of China Contents Foreword Introduction 1 Scope 2 Normative References 3 Terms and Definitions 4 Capability Requirements for Assessment Organizations 4.1 Classification of Assessment Organizations 4.2 Classification of Assessors 4.3 Capability Requirements for Class I Assessment Organizations 4.4 Capability Requirements for Class II Assessment Organizations 4.5 Capability Requirements for Class III Assessment Organizations 4.6 Requirements for Code of Conduct of Assessment Organizations 5 Capability Assessment Process for Assessment Organizations 5.1 Assessment Process 5.2 First-Time Evaluation 5.3 Continuous Evaluation 5.4 Capability Review Annex A (Normative) Capability requirements for classified cybersecurity protection assessors A.1 Junior Level Assessor A.2 Intermediate Level Assessor A.3 Senior Level Assessor Bibliography Cybersecurity technology — Capability requirements and evaluation specifications for assessment organizations of classified protection of cybersecurity 1 Scope This document specifies the capability requirements and capability assessment for assessment organizations of classified protection of cybersecurity. This document is applicable to the management and capability development of assessment organizations of classified protection of cybersecurity, as well as capability evaluation activities for assessment organizations of classified protection of cybersecurity. 2 Normative References The following documents, in whole or in part, are normatively referenced in this document and are indispensable for its application. For dated references, only the edition cited applies. For undated references, the latest edition (including any amendments) applies. GB/T 22239, Information security technology — Baseline for classified protection of cybersecurity GB/T 28448, Information security technology — Evaluation requirements for classified protection of cybersecurity 3 Terms and Definitions For the purposes of this document, the following terms and definitions apply. 3.1 assessment organization of classified protection of cybersecurity professional third-party inspection and evaluation organization engaged in classified protection of cybersecurity assessment activities 3.2 classified cybersecurity protection assessor professional technical personnel engaged in classified protection of cybersecurity assessment who have been recognized for their competence 3.3 capability evaluation process of reviewing, verifying and evaluating the capability of applicant organizations for assessment organizations of classified protection of cybersecurity (hereinafter referred to as "assessment organizations") in accordance with standards and/or other normative documents 3.4 evaluation organization professional technical organization authorized to conduct capability evaluation of enterprises and institutions applying to become assessment organizations 3.5 first-time evaluation process in which the evaluation organization, for the first time, verifies, validates and evaluates the capability of an assessment organization in accordance with this document and related documents 3.6 continuous evaluation regular or irregular evaluation and spot-check activities arranged during the validity period of the certificate to verify whether a certified assessment organization continuously meets the capability requirements 3.7 capability review activity in which, before the expiry of the qualification validity period of an assessment organization, the evaluation organization conducts a comprehensive assessment to confirm whether it continuously meets the capability requirements, providing a basis for renewal to the next qualification validity period 3.8 evaluator personnel designated by the evaluation organization to conduct capability evaluation of assessment organizations 4 Capability Requirements for Assessment Organizations 4.1 Classification of Assessment Organizations Assessment organizations are classified into three levels according to capability requirements, from low to high: Class I, Class II and Class III. The progression between levels is achieved by adding new capability requirements or by imposing enhanced requirements on the basis of the original requirements. 4.2 Classification of Assessors Personnel engaged in classified cybersecurity protection assessment work in assessment organizations are classified into three levels according to capability and job requirements, from low to high: Junior Level, Intermediate Level and Senior Level. The specific requirements shall comply with the provisions of Annex A. 4.3 Capability Requirements for Class I Assessment Organizations 4.3.1 Basic Conditions Assessment organizations shall meet the following basic conditions: a) Registered and established within the territory of the People's Republic of China, invested by Chinese citizens, legal persons, or state-owned enterprises and public institutions; b) Independently operated and accounted, with no record of violations of laws or regulations, and shall provide documentary materials on the nature of the organization, equity structure, investment situation, legal representative and shareholder identity, demonstrating regulatory compliance and clear property rights; c) The legal representative, head of the organization, report authorization signatory and assessment-related personnel of the assessment organization shall have Chinese nationality, reside in the territory on a long-term basis, have no permanent residence overseas, and shall provide certificates of no criminal record; d) Engaged in cybersecurity services for 2 years or more, with certain cybersecurity testing and evaluation capabilities; e) Having fixed office premises, equipped with testing equipment and tools, laboratory environments, etc. that meet the needs of assessment operations; f) Having comprehensive rules and regulations for security and confidentiality management, project management, quality management, personnel management, archives management and training and education, etc.; g) Not involved in cybersecurity product development, sales or information system security integration, etc., that may affect the impartiality of assessment results (except for self-use); h) All employees shall not hold concurrent positions in information system security integration or cybersecurity product R&D, production or sales enterprises, nor hold equity in such enterprises (including cases where shareholding in such listed companies reaches or exceeds the information disclosure standard); i) Other conditions stipulated by the national cybersecurity regulatory authorities. 4.3.2 Organization and Management Capability 4.3.2.1 The management of the assessment organization shall have knowledge of classified protection policy documents and be familiar with relevant standards. 4.3.2.2 The assessment organization shall establish relevant departments according to the requirements of classified assessment activities, with clear responsibilities, authorities and interrelationships, to ensure the orderly implementation of various tasks. 4.3.2.3 The assessment organization shall have professional technical personnel competent for classified assessment work, with the proportion of personnel holding a bachelor's degree or above not less than 70 % in principle. 4.3.2.4 The assessment organization shall establish positions that meet the needs of classified assessment work, such as assessment technician, assessment project team leader, technical supervisor, quality supervisor, confidentiality and security officer, equipment administrator and archives administrator, etc., with clearly defined responsibilities and stable personnel. 4.3.2.5 The assessment organization shall formulate comprehensive rules and regulations, including but not limited to the following: a) Confidentiality management systems shall be formulated in accordance with relevant state confidentiality regulations, clearly defining the scope of confidential matters, personnel confidentiality responsibilities, various measures and requirements for confidentiality management during the assessment process, as well as penalties for violations of confidentiality systems. b) Complete assessment project management procedures shall be formulated in accordance with GB/T 28449-2018 that are adapted to the organization's own characteristics, mainly including the organizational form and work responsibilities of assessment work, as well as the work content and management requirements at each stage of the assessment process. c) Equipment management systems shall be formulated, mainly including the relevant responsibilities of personnel in the management of instruments and equipment (including testing equipment and tools), as well as the work content and management requirements for the procurement, use, operation and maintenance of instruments and equipment. d) Document management systems shall be formulated, mainly including the relevant responsibilities of personnel in the management of assessment documents (including electronic documents), as well as the work content and management requirements for document borrowing, storage, and destruction. e) Personnel management systems shall be formulated, mainly including the work content and management requirements for personnel recruitment, assessment, daily management, and resignation/departure, etc. f) Training and education systems shall be formulated, mainly including the work content and management requirements for the formulation of training plans, implementation of training, training assessment and onboarding, and establishment of personnel training files, etc. g) Systems for handling complaints, appeals and disputes shall be formulated, clearly defining the respective responsibilities of personnel in various positions within the assessment organization in complaint, appeal and dispute handling activities, and establishing a complete procedure from acceptance, confirmation, disposition to response. 4.3.3 Assessment Implementation Capability 4.3.3.1 Personnel Capability 4.3.3.1.1 Professional technical personnel engaged in classified assessment work in assessment organizations (hereinafter referred to as "assessors") shall obtain the classified cybersecurity protection assessor certificate, have the knowledge and ability to grasp national laws and policies, understand and master relevant technical standards, be familiar with the methods, procedures and work specifications of classified assessment, and have the ability to make professional judgments based on assessment results and issue classified assessment reports. 4.3.3.1.2 The assessment organization shall organize pre-job training for assessors, and only those who have passed the assessment shall be certified to work. 4.3.3.1.3 The number of assessors shall not be less than 15, including not less than 2 senior assessors and not less than 3 intermediate assessors, with reasonable personnel allocation.
Contents of GB/T 36959-2026
About Us   |    Contact Us   |    Terms of Service   |    Privacy   |    Cancellation & Refund Policy   |    Payment
Tel: +86-10-8572 5655 | Fax: +86-10-8581 9515 | Email: coc@codeofchina.com | QQ: 3680948734
Copyright: Beijing COC Tech Co., Ltd. 2008-2040
 
 
Keywords:
GB/T 36959-2026, GB 36959-2026, GBT 36959-2026, GB/T36959-2026, GB/T 36959, GB/T36959, GB36959-2026, GB 36959, GB36959, GBT36959-2026, GBT 36959, GBT36959