GB/T 39404-2026General security requirements for the control units of industrial robots (English PDF)
工业机器人控制单元的信息安全通用要求
Open the GB/T 39404-2026 preview as PDF
This is a limited preview
Buy now to download the full PDF (37 pages)
Issued by
SAMR; SAC
Level / Type
National · Recommended
Issue date
April 30, 2026
Implementation date
November 1, 2026
Scope
GB/T 39404-2026 is the English-translated version of 工业机器人控制单元的信息安全通用要求.
GB/T 39404-2026 is the Chinese national standard covering the cybersecurity of a robot controller - the authentication and access control on the teach pendant and the network interfaces, the integrity of the program and the firmware, the logging, and the interaction between security measures and the safety functions they must not compromise. It replaces GB/T 39404-2020 after only six years, which says how quickly the expectations here have moved. In force since 1 November 2026. It was issued on 30 April 2026 and takes effect on 1 November 2026, replacing GB/T 39404-2020. The document is under the responsibility of the China Machinery Industry Federation. This page is published from the official record of the 2026 edition; the clause text of a standard this recent is not yet in circulation, and the figures, limits and tables it contains are those of the document itself, delivered in full with the English translation.
Document preview — GB/T 39404-2026
National Standard of the People's Republic of China
- ICS
- 25.040.30
- Classification
- J 28
- Replacing
- GB/T 39404-2020
Issued by: State Administration for Market Regulation; Standardization Administration of the PRC
Contents
- 6 Information Security Requirements
- 6.3 General Technical Requirements for Information Security
- 6.3.1 Audit Requirements
- 6.3.2 Integrity Requirements
- 6.3.3 Confidentiality Requirements
- 6.3.4 Communication Reliability Requirements
- 6.3.5 Availability Requirements
- 6.3.6 System Requirements
- 6.4 Information security requirements between the main control and control units
- 6.4.1 Time Requirements
- 6.4.2 Labelling and Certification Requirements
- 6.5 Information security requirements within the control unit
- 6.5.1 Labelling and Certification Requirements
- 6.5.4 Programming Code Requirements
Foreword
This document complies with the provisions of GB/T 1.1-2020 "Standardization Work Guidelines Part
1.Structure and Drafting Rules of Standardization Documents". Drafting. This document supersedes GB/T 39404-2020 "General Requirements for Information Security of Industrial Robot Control Units" and is consistent with GB/T 39404- Compared to 2020, aside from structural adjustments and editorial changes, the main technical changes are as follows:
a) The definition of "information security" has been changed (see 3.4, 2020 version 3.4);
b) The communication architecture diagram of the industrial robot control unit has been modified (see Chapter 5,
5.1 of the 2020 edition);
c) Removed "Vulnerability between teach pendant and industrial robot CU", "Vulnerability between main controller and industrial robot CU", and "Machine" Vulnerability between robot controllers and private server drivers (see sections 5.2, 5.3, and
5.4 in the 2020 edition);
d) The description of audit storage capacity has been changed (see 6.3.1.2,
6.3.1.3 in the 2020 version), and the protection of audit information has been modified (see 6.3.1.4, 2020 version). Version
6.3.1.5 of the.2018 version added "issue a warning when the audit log storage capacity limit is reached" (see 6.3.1.3), and removed "central..." "Managed, system-wide audit trails," "Responses to audit process failures," and "Audit logs written to media in a one-time process." "Accessibility of audit logs" (see 6.3.1.2, 6.3.1.4, 6.3.1.6, and
6.3.1.7 in the 2020 edition);
e) The description of communication integrity (see 6.3.2.1, 2020 version 6.3.2.1) and the description of cryptographic integrity protection (see...) have been modified. 6.3.2.2 (
6.3.2.2 in the 2020 version), software and information integrity description (see 6.3.2.3,
6.3.2.3 in the 2020 version), and damage control. Automatic notifications for bad integrity are now provided (see 6.3.2.4, version
6 Information Security Requirements
6.1 General Rules Information security for industrial robot control units should primarily include.
a) Information security between the main control and control units;
b) Information security within the control unit. Information security requirements for industrial robot control units include system requirements (SR) and system enhancement requirements (RE), and should comply with GB/T 30976.1- The relevant requirements of.2014 and GB/T 33008.1-2016 apply. See Appendix B for the information security classification requirements for industrial robot control units.
6.2 Physical Requirements for Information Security Information security physical requirements shall comply with the requirements of B.7 in GB/T 32919-2016.
6.3.1 Audit Requirements
6.3.1.1 Auditable Events Auditable events (SR2.8) should comply with the requirements of
6.3.8 in GB/T 30976.1-2014.The control unit should generate the following events. Audit Log.
a) Access control;
b) Request error;
c) System events;
d) Backup and storage events;
e) Configuration changes;
f) Potential investigative activities and audit log events.
Note. Auditable events can be viewed on the teach pendant, programming software, or other human-machine interfaces.
6.3.1.2 Audit Storage Capacity The audited storage capacity (SR2.9) should comply with the requirements of
6.3.9 in GB/T 30976.1-2014.The control unit should be based on log management... The system should be configured to allocate sufficient audit log storage capacity. The control unit should provide auditing mechanisms to reduce the possibility of exceeding this capacity. The system can provide sufficient audit storage capacity based on factors including, but not limited to, storage policies and audits to be performed.
6.3.1.3 Issue a warning when the audit log storage capacity limit is reached. A warning should be issued when the audit log storage capacity limit is reached [SR2.9RE(1)], which should comply with
6.3.9.1 of GB/T 30976.1-2014. Requirements. When the allocated audit log storage volume reaches a configurable proportion of the maximum audit log storage capacity, the control unit should issue a warning, and It should have the capability to back up audit logs to a separate external storage space to ensure their integrity. Simultaneously, warning messages and backup operation status should be displayed. It can be viewed through the human-computer interface.
6.3.1.4 Protection of Audit Information The protection of audit information (SR3.9) shall comply with the requirements of
6.3.2 Integrity Requirements
6.3.2.1 Communication Integrity Communication integrity (SR3.1) shall comply with the requirements of
6.4.1 in GB/T 30976.1-2014.Robot controller and teach pendant, programming. Software should protect the integrity of information transmitted over communication channels.
6.3.2.2 Integrity Protection Based on Cryptographic Technology Integrity protection based on cryptographic technology [SR3.1RE(1)] shall comply with the requirements of
6.4.1.1 in GB/T 30976.1-2014.Control The unit should employ cryptographic mechanisms to identify changes to information during communication, and to protect communications where information has been protected by other alternative physical measures. This requirement does not apply to links. Note
1.Cryptographic mechanisms include, but are not limited to, message digest algorithms, message authentication codes, digital signatures, and other technologies. Note
2.Physical protection measures include, but are not limited to, dedicated cables, physically isolated networks, and enclosed communication backplanes.
6.3.2.3 Software and Information Integrity Software and information integrity (SR3.4) shall comply with the requirements of
6.4.4 in GB/T 30976.1-2014.The control unit shall possess software, The ability of firmware to resist unauthorized modifications.
6.3.2.4 Automatically notify of breaches of integrity Automatic notification of breaches of integrity [SR3.4RE(1)] shall comply with the requirements of
6.4.4.1 in GB/T 30976.1-2014.Control The unit should notify the user if any discrepancies are found during integrity verification.
6.3.3 Confidentiality Requirements
6.3.3.1 Information confidentiality Information confidentiality (SR4.1) shall comply with the requirements of
6.5.1 in GB/T 30976.1-2014.The control unit shall ensure that information is stored and Confidentiality during transmission.
6.3.3.2 Encryption Protocol Security The security of the data encryption algorithm should be guaranteed, and there should be no security risks such as weak keys, predictable random numbers, or identity forgery.
6.3.3.3 Information Retention Information retention (SR4.2) shall comply with the requirements of
6.5.2 in GB/T 30976.1-2014.The control unit shall provide decommissioning capability and clear [data/information]. All security-related data in components released by services in use.
6.3.4 Communication Reliability Requirements
6.3.4.1 Bus Topology The high-speed communication bus used for control unit communication can form a site network structure that conforms to tree, chain, star, or ring network structures. One or more of the structures.
6.3.4.2 Error Checking The high-speed communication bus data link layer protocol of the control unit should include error detection and correction functions for the transmitted data.
6.3.4.3 Maximum Communication Delay The maximum communication delay of the control unit's high-speed communication bus should meet the real-time communication requirements of the specific application.
6.3.4.4 Time Synchronization Accuracy The control unit should achieve time synchronization between all stations. The time synchronization accuracy of its high-speed communication bus should meet the real-time requirements of the specific application. The letter requires...
6.3.4.5 Bus Arbitration The arbitration method for the control unit's high-speed communication bus control rights can be master station management of slave stations, masterless coordination management of multiple slave stations, or masterless management. Methods such as multi-site preemption.
6.3.4.6 Network Fault Tolerance and Self-Healing The control unit provides the following capabilities for industrial robots.
a) The high-speed communication bus of the control unit should have network fault tolerance. Under the influence of accidental external interference, the communication bus should be able to transmit data. Errors caused during transmission are handled with fault tolerance to prevent interruption or cessation of communication due to occasional errors;
b) In the event of a short-term anomaly at a communication site causing a network communication interruption, the high-speed communication bus should have self-healing capabilities after the site returns to normal. The time required to restore normal communication on the communication bus should meet the specific application requirements.
6.3.5 Availability Requirements
6.3.5.1 Deterministic Output The deterministic output (SR3.6) shall comply with the requirements of
6.4.6 in GB/T 30976.1-2014.The control unit shall be able to withstand attacks without... While maintaining normal operation, the output is set to a predefined safe state. These states include.
b) The final definite value can be determined;
c) Fixed value determined by the asset owner or application.
6.3.5.2 Protection against Denial of Service Denial-of-service protection (SR7.1) shall comply with the requirements of
6.8.1 in GB/T 30976.1-2014.The control unit shall be equipped with anti-DoS attack capabilities. It has the ability to withstand attacks, ensuring that critical control loops can still maintain basic functions under DoS attacks.
6.3.5.3 Managing Communication Load The management of communication load [SR7.1RE(1)] shall comply with the requirements of
6.8.1.1 in GB/T 30976.1-2014.The control unit shall provide management... The ability to manage communication load can mitigate denial-of-service attacks such as information flooding.
6.3.6 System Requirements
6.3.6.1 Error Handling Error handling (SR3.7) shall comply with the requirements of
6.4.7 in GB/T 30976.1-2014.The control unit shall be able to identify and process error messages. The method used should enable effective remediation, and should not provide information that could be exploited to attack the control unit, unless this information is leaked. Information is essential for the timely detection and repair of problems.
6.3.6.2 Network and Security Configuration Settings Network and security configuration settings (SR7.6) should comply with the requirements of
6.8.6 in GB/T 30976.1-2014.The control unit should support network... It includes security configuration and provides an interface for viewing and modifying currently deployed configurations.
6.3.6.3 Minimal Functionality Minimum functionality (SR7.7) should comply with the requirements of
6.8.7 in GB/T 30976.1-2014.The control unit should limit the use of unnecessary functions. Ports, protocols, and services.
6.3.6.4 Component List The component list (SR7.8) shall comply with the requirements of
6.8.8 in GB/T 30976.1-2014.The control unit shall provide a report on currently installed components. The ability of the control unit to access components and their associated attributes.
a) Provide a method for reporting installed components and their associated properties;
b) Ensure that the installed components are correctly listed in the system parts inventory catalog;
c) Correctly update the system component inventory catalog when components are added, removed, or component attributes are changed.
6.3.7 Data Security Requirements The control unit should have the ability to classify and classify data and set data sensitivity levels.
6.4.1 Time Requirements
6.4.1.1 Timestamp The timestamp (SR2.11) shall comply with the requirements of.3.11 in GB/T 30976.1-2014.The control unit shall provide a timestamp for generation. Create audit records.
6.4.1.2 Internal Time Synchronization Internal time synchronization [SR2.11RE(1)] shall comply with the requirements of
6.3.11.1 in GB/T 30976.1-2014.The control unit shall provide... The ability to synchronize the internal system clock at a configurable frequency.
6.4.1.3 Integrity Protection of Time Sources The integrity protection of the time source [SR2.11RE(2)] shall comply with the requirements of
6.3.11.2 in GB/T 30976.1-2014.The time source shall... Protected from unauthorized changes, any such changes should trigger an audit event.
6.4.2 Labelling and Certification Requirements
6.4.2.1 Identification and Authentication of the Master Controller The control unit should provide the following capabilities for the industrial robot.
a) Provide the ability to identify and authenticate the master controller;
b) Enable the master control identifier to be authenticated on the access interface, and deny access to invalid master control identifiers.
6.4.2.2 Unique Identifier and Authentication The unique identifier and authentication [SR1.2RE(1)] shall comply with the requirements of
6.2.2.1 in GB/T 30976.1-2014.The control unit shall be responsible for the main Control provides the ability to provide unique identifiers and authentication.
6.4.2.3 Public Key Infrastructure Certificates Public Key Infrastructure (PKI) certificates (SR1.8) should comply with the requirements of
6.2.8 in GB/T 30976.1-2014.When using public key infrastructure... When using PKI, the control unit should provide the ability to run the public key infrastructure in accordance with best practices or obtain public key certificates from an existing PKI.
6.4.2.5 Hardware Security with Public Key Authentication The hardware security of public key authentication [SR1.9RE(1)] shall comply with the requirements of
6.2.9.1 in GB/T 30976.1-2014.The control unit shall Protect the relevant private keys through hardware mechanisms.
6.4.3 Explicit approval of access requests Explicit approval of access requests [SR1.13RE(1)] shall comply with the requirements of
6.2.13.1 in GB/T 30976.1-2014.Control Units should provide the ability to deny access from untrusted networks unless approved by a designated role. Example. Deny access from untrusted networks, such as restricting access from unauthorized IP addresses.
6.5.1 Labelling and Certification Requirements
6.5.1.1 User (person) identification and authentication User (person) identification and authentication (SR1.1) shall comply with the requirements of
6.2.1 in GB/T 30976.1-2014.The control unit shall handle all... Users (people) are provided with role-based identification and authentication capabilities.
6.5.1.2 Unique Identifier and Authentication The unique identifier and authentication [SR1.2RE(1)] shall comply with the requirements of
6.2.2.1 in GB/T 30976.1-2014.The control unit shall... It has the ability to provide unique identifiers and authentication for users (people).
6.5.1.3 Account Management Account management (SR1.3) shall comply with the requirements of
6.2.3 in GB/T 30976.1-2014.The control unit shall provide management of all accounts. Account management includes the ability to create, modify, and remove accounts. When one or more accounts are modified or removed, the accounts that were not modified retain account rights. The limit remains unchanged.
6.5.1.4 Authentication Code Management Authentication code management (SR1.5) shall comply with the requirements of
6.2.5 in GB/T 30976.1-2014.The control unit shall.
a) Provide the initial authentication code content for the capability definition;
b) Provides the ability to prevent unauthorized changes/updates of the authentication code.
6.5.1.5 Password Authentication Strength The strength of password authentication (SR1.7) should comply with the requirements of
6.2.7 in GB/T 30976.1-2014.For controls using password authentication... The unit and control unit should implement configurable password strength based on minimum length and different character types.
6.5.1.6 Restrictions on user (person) password generation and password validity period The restrictions on user (person) password generation and password validity period [SR1.7RE(1)] shall comply with GB/T 30976.1-2014. Requirements of 6.2.7.1.The control unit shall provide users with configurable capabilities for password reuse counts and password validity periods.
6.5.1.7 Certification Feedback The certification feedback (SR1.10) shall comply with the requirements of
6.5.4 Programming Code Requirements
6.5.4.1 Programming Code Licensing The programming code (SR2.4) shall comply with the requirements of
6.3.4 in GB/T 30976.1-2014.The control unit shall provide access for editing and modifying the code. Personnel involved in the code should have access control and identity verification.
6.5.4.2 Integrity Check of Programming Code The integrity check of the programming code [SR2.4RE(1)] shall comply with the requirements of
6.3.4.1 in GB/T 30976.1-2014.Control Unit The integrity of the code should be verified before allowing it to be executed.
6.5.4.3 Restrictions on the Use of Programming Code The usage restrictions of the programming code [SR2.4RE(2)] shall comply with the requirements of
5.3.2.8 in GB/T 33008.1-2016.The control unit shall... Provide the following capabilities for industrial robots.
a) Require appropriate authentication and authorization for the code source;
b) Restrict code input/output to and from the control unit;
c) Use of monitoring code.
6.5.4.4 Protection against Malicious Code Malicious code protection (SR3.2) should comply with the requirements of
6.4.2 in GB/T 30976.1-2014.The control unit should be able to detect programming languages. The code can identify potential security risks, issue warnings, or block execution to prevent malware attacks and exploitation.
6.5.4.5 Encryption of Programming Code The control unit should be protected by hardening measures such as code obfuscation, encryption or packing.
6.5.5 Vulnerability Management Requirements The control unit should provide a vulnerability management mechanism and should not have any high-risk or above vulnerabilities that have been publicly disclosed for more than 6 months.
Note. Vulnerability information sources include, but are not limited to, CNVD, CNNVD, NVD, and CVE.
......
This preview omits tables, figures, formulas and parts of the technical clauses. The complete document — 37 pages — is available in the English PDF.
Editions of GB/T 39404
| Edition | Title | Revision | Status |
|---|---|---|---|
| GB/T 39404-2026 | General security requirements for the control units of industrial robots | current edition | Current |
| GB/T 39404-2020 | General security requirements for the control units of industrial robots | previous edition | In force until 1 November 2026 |
This page sells the current edition, GB/T 39404-2026. Earlier editions are listed for reference only.
How to Buy GB/T 39404-2026
- 1Add to cart. Click the "Buy GB/T 39404-2026" button on this page. You can add more standards before checkout.
- 2Checkout. Enter your email and billing details. Payment is processed securely by Stripe (cards, Apple Pay, Google Pay supported).
- 3Instant delivery (0–9 sec). Delivery is automatic: within seconds of payment you'll receive an email with a secure download link. The link stays valid for 72 hours.
- 4Invoice included. A tax invoice is attached to the confirmation email. Need a custom invoice? Contact us.
Related Standards
GB/T 47310-2026 — Determination of total silicon, aluminium, iron, potassium, sodium, calcium, magnesium, manganese, phosphorus, titanium and sulfur in soil - Monochromatic excitation energy dispersive X-ray fluorescence spectrometry
GB/T 47321-2026 — Specification for the warning data exchange of the national emergency early warning dissemination system
GB/T 47293-2026 — Determination of available mercury in soil
Secure payment via Stripe
Payments accepted
GB/T 39404-2026
$365.00