DCC summary, not a translation. The certification rules are copyrighted by Beijing CESI Certification Co., Ltd., which reserves all rights of reproduction. The structured summary below is DCC’s own paraphrase grounded in the published text; specific clauses should be checked against the rules.
Published by: Beijing CESI Certification Co., Ltd. (北京赛西认证有限责任公司), the certification body of the China Electronics Standardization Institute; rules formulated under the Regulations on Certification and Accreditation and filed with the Certification and Accreditation Administration of China (CNCA).
Document No.: CESI-SC-OD15. First issued April 3, 2023; V1.1 August 31, 2025; V1.2 issued and implemented May 18, 2026. The reference library also holds the companion general Certification Rules for Data Security Risk Assessment Services (Annex 2 to the same filing) with its impartiality statement, certificate and mark templates and fee schedule.
Scope
The rules set the basic principles and requirements for certifying assessment institutions (评估机构) that provide data security risk assessment services in the industry and information technology sector. The certification field is CNCA service category SC12 (“telecommunications services; information retrieval and provision services”), and the scheme covers a single domain: industrial and IT-sector data security risk assessment services.
Certification basis. CESI/TS SC003-2023 Technical Specification for Data Security Risk Assessment Services in the Industry and Information Technology Sector; YD/T 6415-2025 Specification for Data Security Risk Assessment in the Industrial Sector; and YD/T 3956-2024 Specification for Data Security Risk Assessment in the Telecommunications Sector.
Certification model. Service-characteristic evaluation plus service-management audit plus post-certification surveillance, using three of the nine modes in GB/T 27207: mode F (inspection of past service footprints), mode G (confirmation or verification of service capability) and mode I (service-management audit). Initial certification, surveillance and re-certification all use F + G + I.
Key contents
Application (5.1–5.2). Applicants may be organizations that develop or provide the service or bodies controlling such organizations. They must have clear legal status (or evidence of independent liability if part of a larger entity), comply with the rules, not be under a regulatory suspension order, and not be on the national lists of seriously dishonest enterprises. The scope is defined by site (where the service is realized and delivered) and activity (industrial and IT-sector risk assessment). Applicants submit their service specifications, service-delivery and inspection specifications, business licence and an application describing premises, staff, qualifications and outsourced processes affecting conformity. CESI reviews within five working days and, if accepted, signs a legally effective certification contract covering fees, payment and liabilities.
Evaluation (5.3). Evaluation is carried out on site at every location in scope for initial and re-certification (with sampling permitted at surveillance for similar sites under common control), scheduled when services are actually running so that real operation can be observed. Auditor-days: at least six on site and twelve in total for initial and re-certification; at least three on site and four in total for surveillance; service-characteristic evaluation days equal twice the number of on-site samples plus once the number of remote samples, and must not be fewer than the management-audit days. Team: at least two registered service-certification auditors trained and evaluated for this scheme, optionally with technical experts (who, with observers and trainees, do not count toward days or audit independently); the same auditor may not audit the same institution for five or more consecutive years. Process: a task order, an audit plan, an opening meeting attended by top management, evidence-gathering by interview, document review and observation with the auditee obliged to grant access to records, premises, staff and facilities, and a closing meeting with one of three conclusions — recommend, do not recommend, or recommend after corrective action is implemented and verified. Audits are terminated for non-cooperation, absence of top management from the opening or closing meetings, material inconsistency with the application, or inability to complete the procedure; disagreements are recorded and reported. Service-characteristic evaluation (5.3.6): the sample size is the square root of the number of client sites (data processors assessed) in the previous year; 20% of samples, rounded up, are live capability confirmations or verifications observed at the client’s site with the client’s consent, the rest are footprint inspections of contracts, reports and process records; samples should not repeat across a certificate’s life. Confirmation tests the design layer (feasible plans, reasonable processes, adequate resources); verification tests execution (results that can be delivered, reproduced and measured). Both are scored against chapters 7 (methods), 8 (process), 9 (implementation), 10 (tools) and Annex B (report template) of YD/T 6415-2025 and YD/T 3956-2024, and the service must show standard-conformant methods, full coverage, complete traceable evidence, risks that reflect the real business, and results with explicit risk grades and actionable recommendations. Management audit (5.3.7): under CESI/TS SC003-2023, covering organizational structure, processes, procedures and records; staffing and resources; control of service characteristics; assessment tools; response to interruptions and service recovery; dispute handling; complaint handling; and internal audit. Report and termination (5.3.8–5.3.9): a written report with purpose, scope, criteria, institution profile, sampling, results, conformity statement, period and conclusion; certification is terminated where a law-enforcement body finds the services unlawful or corrective actions are not completed and verified in time.
Decision (5.4). CESI’s technical committee reviews the complete file and decides within ten working days. Certification requires a signed contract, lawful service activities, a compliant procedure and complete file, conformity with the standards and rules with all non-conformities corrected and verified, and no other major legal, regulatory or media-exposed problems; applicants may be given a deadline to rectify. Certificates are signed by CESI’s general manager and certified organizations are listed on CESI’s website.
Maintenance and surveillance (5.5). Conditions include continuing legal status and qualifications, acceptance of surveillance, proper use of certificate and mark, sustained consistency of the service, timely change reporting and payment of fees. Surveillance occurs at least once per calendar year, the first within twelve months of the decision; immediate on-site surveillance follows serious regulatory findings, serious service-quality problems such as cybersecurity incidents or major complaints attributed to the institution, serious incidents in assessed systems, or major legal or media problems, and frequency may be raised where conformity is in doubt or changes may affect it. Surveillance checks changes since the last evaluation, effective operation of the service, changes to law and standards, continuing management processes, use of the mark and complaint handling, sampling at least half the certification clauses each time so that two surveillances cover all. Certified institutions must notify CESI within 48 hours (at most a week) of service incidents or major complaints and regulatory findings of non-conformity, and within a month of other changes to legal status, ownership, premises, scope or capability. Changes of name, address, scope, capability or level require a change application; scope expansion needs a year free of major incidents and failed inspections; scope is reduced where parts persistently fail. Re-certification may be applied for three months before expiry and repeats the initial procedure with equal auditor-days. The overall certification time limit is 60 working days excluding rectification.
Certificates and marks (6–9). Certificates, numbered IITDSRA-CESI-date-serial, state the issuer, holder, sites, scope, standards and validity, and are valid for three years, with renewal applications due six months before expiry. Suspension for three months follows failure to accept surveillance, misuse of the certificate, violations or failed regulatory spot checks not warranting revocation, substantiated client complaints affecting report validity, non-payment, or mutual agreement; revocation, with a six-month bar on re-application, follows failed surveillance, unlawful services, failure to correct during suspension, cessation of the business, serious violations or unhandled major complaints, refusal of supervision, fraud, transfer of the certificate or refusal to pay; cancellation follows failure to meet updated criteria, expiry without renewal, or voluntary surrender; restoration follows verified correction. The mark may be used only for industrial and IT-sector risk-assessment services, in unaltered form and basic or black color, on assessment reports and publicity, never on products or in ways implying product or management-system certification, and not during suspension.
Disputes and fees (7, 10–11). Technical disputes and complaints may be lodged within ten working days, CESI responds within a month, a second challenge may be lodged within fifteen working days, after which CESI need not respond, and complaints may be escalated to superior authorities or CNCA. Fees are a one-time registration fee of RMB 2,000, an annual fee of RMB 2,000 and audit fees at RMB 5,000 per auditor-day excluding travel, which the applicant bears for site sampling. CESI is responsible for evaluation results and decisions; institutions are responsible for the truth and legality of their submissions.
How it fits the regime
MIIT’s Industrial and Information Technology Data Security Measures require processors of important and core data to conduct annual risk assessments, and the Risk Assessment Implementing Rules allow those assessments to be performed by third-party institutions; the 2024–2026 Capability Plan calls for certification, testing and evaluation standards to build the supporting industry. CESI’s scheme is the market’s answer to the question of which assessors are competent: it is voluntary and commercial, but its basis — the YD/T industry standards and CESI’s own technical specification — is the same as the one MIIT provincial bureaus apply when reviewing submitted reports, and the live-observation mode means a certified assessor has been watched conducting an assessment at a real client. For foreign-invested manufacturers subject to the MIIT regime, the certificate is a due-diligence filter when appointing an assessor; for assessment firms, V1.2’s alignment with CNCA’s 2026 service-certification opinions signals that the scheme is intended to be durable. It sits alongside the general data-security risk-assessment method in GB/T 45577 and the CAC’s Network Data Security Risk Assessment Measures, which govern assessments outside the MIIT sector.