Valid

GB/Z 140-2025Cybersecurity aspects of devices used for power metering and monitoring, power quality monitoring, data collection and analysis (English PDF)

用于电量测量和监测、电能质量监测、数据采集和分析的装置的网络安全

Preview PDF

This is a limited preview

Buy now to download the full PDF (23 pages)

Need quotation for your management?

Get a formal quotation for GB/Z 140-2025 in 30 minutes.

Issued by

SAMR; SAC

Level / Type

National · Recommended

Issue date

December 3, 2025

Implementation date

December 3, 2025

Scope

GB/Z 140-2025 is the English-translated version of 用于电量测量和监测、电能质量监测、数据采集和分析的装置的网络安全.

GB/Z 140-2025 is a guiding technical document on cybersecurity for the devices that measure and monitor electrical quantities, check power quality and collect data. It is an identical adoption of IEC TS 63383:2022 and addresses power metering and monitoring devices, power quality instruments, data gateways, energy data loggers and energy servers installed in restricted areas. The text sets security objectives, a general risk assessment and risk management method illustrated with a simple three-by-three risk matrix, and management requirements covering risk assessment, countermeasures, testing, lifecycle security and the instructions for use, plus informative annexes with a worked device risk assessment and countermeasures from design through manufacture, commissioning, operation, maintenance and disposal. Organizational requirements such as end-user security policies are outside it, and it does not apply to instruments for trade settlement. It was issued on 3 December 2025.

Found what you need?

Document preview — GB/Z 140-2025

National Standard of the People's Republic of China

ICS
17.220.20
Classification
N 20

Issued by: State Administration for Market Regulation; Standardization Administration of the PRC

Contents

  • Preface
  • Introduction
  • 1.Scope
  • 2 Normative References
  • 3.Terms, Definitions, Symbols, and Abbreviations
  • 3.1 Definitions related to network security
  • 3.2 Definitions related to the apparatus
  • 3.3 Symbols and Abbreviations
  • 4.Safety Objectives
  • 5.Cybersecurity Risk Assessment (General Methodology)
  • 5.1 Risk Assessment
  • 5.2 Risk Management
  • 6.Network security management requirements
  • 6.1 Overview
  • 6.2 Risk Assessment Requirements
  • 6.3 Response Measures Requirements
  • 6.4 Test Requirements
  • 6.5 Lifecycle Safety Management Requirements
  • 6.6 Requirements for the Instructions for Use
  • Appendix A (Informative) Example of General Risk Assessment for PMD, PQI, DGW, EDL and ESE
  • A.1 Overview
  • A.2 General Roles
  • A.3 General System Use Case
  • A.4 General functions implemented by devices within the system
  • A.5 Universality assessment of devices within the system
  • Appendix B (Informative) Example of General Countermeasures
  • B.1 Overview
  • B.2 Recommendations for Manufacturers During the Design Phase
  • B.3 Recommendations for Manufacturers During the Manufacturing Process
  • B.4 Recommendations for manufacturers to launch devices on the market
  • B.5 Recommendations for integrators building systems within the facility
  • B.6 Debugging Recommendations
  • B.7 Recommendations for facility management personnel regarding operating systems within the facility
  • B.8 Recommendations for facility management personnel during maintenance
  • B.9 Recommendations for facility management personnel during shutdowns
  • B.10 Recommendations for facility management personnel during the disposal process
  • References

Foreword

This document is a standard or guiding technical document.

This document complies with the provisions of GB/T 1.1-2020 "Standardization Work Guidelines Part 1: Structure and Drafting Rules of Standardization Documents". Drafting.

This document is equivalent to IEC TS63383:2022 "Equipment for electrical quantity measurement and monitoring, power quality monitoring, data acquisition and analysis".

The document type of "Network Security" has been changed from an IEC technical specification to a national guiding technical document of my country.

The following minimal editorial changes have been made to this document.

---The header of Table A.4 has been corrected and is now consistent with the main text description;

---To comply with the drafting regulations of Chinese standards, the symbols in Table A.5 have been corrected, and a note has been added to explain the meaning of the symbols.

Introduction

This document is a common cybersecurity document cited in other SAC/TC104 publications, and includes information related to low-voltage applications.

General information on network security measurement devices and related systems.

With measuring devices (such as electrical quantity measuring and monitoring devices as defined in IEC 61557-12), power quality instruments (as defined in IEC 62586-1)

The use of data acquisition, collection, and analysis devices (such as gateways and energy servers as defined in IEC 62974-1) is increasing, and the network... Network security risks are also increasing, especially with the growing use of interconnected devices in electrical installations.

Therefore, facility managers limit risk by maintaining an acceptable level of information regarding facility and environmental strategies. To maintain maximum innovation... When designing devices, it is best to base them on risk assessment methods to ensure that they can withstand cybersecurity threats throughout their entire lifecycle.

1 Scope

This document pertains to measuring devices intended for installation in restricted areas (PMDs conforming to IEC 61557-12 and those conforming to IEC 62586-1).

Network security related to the required PQI and data acquisition devices (devices conforming to IEC 62974-1).

This document covers cybersecurity aspects of devices used for power measurement and monitoring, power quality monitoring, and data acquisition (e.g., installation of...).

(Enhancing or restoring devices), but does not include the organization's cybersecurity requirements (such as end-user security policies).

Note: An organization's cybersecurity is critical to the reliable operation of its devices.

This document aims to raise awareness among manufacturers and other stakeholders regarding cybersecurity and to provide protection against security threats and vulnerabilities.

To reasonably reduce safety risks, basic guidance is provided.

---This document is consistent with the device/system approach described in relevant standards such as IEC 62443 (all parts) and ISO /IEC 27001.

---This document is based on general system use cases.

This document does not apply to instruments used for trade settlement covered by the IEC 62053-2X series of standards.

2 Normative references

This document has no normative references.

3 Terms, definitions, symbols and abbreviations

The following terms and definitions apply to this document.

The URLs for the terminology databases maintained by ISO and IEC for standardization are as follows.

3.1 Definitions related to network security

3.1.1 Assets

An entity to which the component owner assigns value.

[Source: GB/T 18336.1-2015, 3.1.2, with modifications]

3.1.2 Attack

Attempts to damage, disclose, tamper with, disable, steal, or access or use assets without authorization.

[Source: GB/T 29246-2023, 3.2]

3.1.3 Attack vector

An attacker accesses a device to generate attack paths or methods.

......
This preview omits tables, figures, formulas and parts of the technical clauses. The complete document — 23 pages — is available in the English PDF.

Similar standards

How to Download GB/Z 140-2025

  1. 1

    Add to cart

    Click "Download PDF" on this page and choose "Buy this standard". You can add more standards before checkout.

  2. 2

    Checkout

    Enter your email and billing details. Payment is processed securely by Stripe (cards or bank transfer). Prefer bank details? Request a quotation (min. order $300).

  3. 3

    Instant delivery (0–9 sec)

    Delivery is automatic: within seconds of payment you'll receive an email with a secure download link. The link stays valid for 72 hours.

  4. 4

    Invoice included

    A tax invoice is attached to the confirmation email. Need a custom invoice? Contact us.

Related Standards

English PDF
23 pages
Instant delivery (0–9 sec)
Invoice included
View Cart

Secure payment via Stripe

Payments accepted

VisaMastercardAmerican ExpressApple PayGoogle PayStripe

GB/Z 140-2025

$425.00