CC-IS

CC-IS is the Chinese certification scheme (within CCC) for information security products. The certification is compulsory for government procurement, and voluntary in all other cases. A trend toward the implementation of these same standards by state owned enterprises (SOEs), such as most banks, airlines, etc has been observed.

The relevant regulations are issued and implemented by the General Administration of Quality Supervision, Inspection and Quarantine of  the PRC (AQSIQ) and the Certification and Accreditation Administration of the PRC (CNCA). The certification body administering CC-IS is the China Information Security Certification Center(ISCCC).

CC-IS consists of the National Certification for Information Security Product certificate and the CC-IS Mark

13 product categories require CC-IS; they are listed in the Catalogue of Products Subject to Compulsory Certification (CCC Catalogue).

The 13 product categories can be divided into two main groups:

Group I: No Cryptography

Group II: Cryptography

· Network security separated cards and line selectors

· Data backup and recovery products

· Anti-spam products

· Intrusion detection system products

· Network vulnerability scanning products

· Security audit products

· Site restoration products

· Firewall products*

· Isolation and exchange of information security products*

· Secure routers

· Smart cards COS

· Secure operating system products

· Secure database system products

* According to the level of protection of the product, you may not need the ‘Cipher Test Certification’

 

Group I: Certification of these product categories follows the standard procedure for all products requiring CCC certification listed in the CCC Catalogue. Based upon current regulations and under normal circumstances, the process for obtaining the relevant CC-IS certificate varies between 70 and 80 days.

 

Group II: Products falling under these product categories require a certification of their cryptography called ‘Cipher Test Certification’ before applying for CC-IS. Such certification is issued by the Office of the StateCommercial Cryptography Administration (OSCCA). The combined certification of CC-IS and cryptography might take up to 200 days.

CC-IS registration is valid for 5 years and renewal should be initiated about 3 months before expiration. Before leaving the factory, all products must be labeled with the appropriate CC-IS mark, either on the item itself, the packaging, or both.

 

Eaststep Consulting Ltd. is here to assist you in evaluating whether your products need OSCCA certification and in obtaining CC-IS.

Consultation includes all aspects, such as:

– which Chinese standards apply.

– optimal solutions for minimizing the related testing and inspection time.

– ensuring you obtain your certification in the fastest possible time.

– minimizing the risk of loss of your IP during the certification process.