US and China Product Cybersecurity Regulatory Regimes Compared
In-house counsel for cross-border consumer product, IoT, and tech hardware manufacturers operating in the U.S. and Chinese markets must act because divergent regulatory requirements create overlapping compliance obligations and elevated cross-border enforcement risk.
The alert compares key requirements of the U.S. Cybersecurity and Infrastructure Security Agency’s product cybersecurity rules and China’s parallel connected product regulatory framework. It highlights overlapping mandates for secure-by-design practices, vulnerability disclosure timelines, and post-market monitoring, as well as jurisdiction-specific requirements such as China’s mandatory local data storage for certain product types. In-house counsel should map their product lines to both sets of rules to identify gaps, update cross-border compliance programs, and align vendor contracts to meet the stricter of overlapping requirements where applicable.