China has introduced mandatory cybersecurity, data recording, and obstacle detection requirements for civil unmanned aircraft systems.
China Mandates Safety and Security for Drones
All civil drones must now meet new cybersecurity, data recording, and obstacle avoidance standards.
What changed
Cybersecurity required for all data links to ensure secure communication.
Data recording mandatory in flight control systems for safety and accountability.
Obstacle detection required on all systems to ensure safe flight operations.
Who it affects
Manufacturers of all civil unmanned aircraft (HS code 8806) must design systems to meet the new standards from the ground up.
Operators must only use drones that are compliant with the cybersecurity, recording, and obstacle detection rules.
Model aircraft and toy importers are not exempt; these standards apply across the full lifecycle with no exceptions.
Compliance Requirements for Civil Unmanned Aircraft Systems in China
China has established mandatory cybersecurity, data recording, and obstacle detection requirements for civil unmanned aircraft systems (UAS) through national standards. These requirements vary by UAS category (micro, light, small, medium, and large) and apply to manufacturers, operators, and system integrators.
Regulation Analysis
1. Cybersecurity Requirements for Data Links
The Cybersecurity requirements for data links of civil unmanned aircraft1 mandate technical safeguards for data transmission between UAS and control stations. Key provisions include:
- Dual-way authentication: Control stations and UAS must verify each other’s identity before establishing or re-establishing data links1.
- Data integrity and authenticity: Mechanisms must be in place to detect and prevent tampering or forgery of transmitted data1.
- Encryption: Uplink (control commands) and downlink (telemetry and payload data) must be encrypted to protect confidentiality1.
- Anti-replay attacks: Systems must identify and discard duplicated or delayed data packets1.
- Secure updates: Software/firmware updates must be verified for authenticity and integrity before installation1.
- Logging: Security events (e.g., authentication attempts, link disruptions) must be recorded in non-volatile memory, with logs retained for at least the last 3 flight sessions1.
- Resilience: Systems must recover from denial-of-service attacks and restore functionality1.
Applicability: Applies to all civil UAS except model aircraft, toys, and systems using proprietary operational identification links1.
2. Flight Control System Data Recording Requirements
The Data recording requirements of the flight control system for civil unmanned aircraft2 specify mandatory data collection, storage, and security for UAS flight operations. Key requirements include:
General Requirements
- Mandatory recording: Micro, light, and small UAS must include an onboard flight data recording unit (FDRU) that operates continuously from power-on to power-off2.
- No disable function: The FDRU cannot be manually deactivated during flight2.
- Pre-flight checks: The FDRU must self-test before takeoff; failures must trigger audible/visual alerts and prevent takeoff2.
- UTC synchronization: Recorded timestamps must align with Coordinated Universal Time (UTC), with a tolerance of ≤1 second2.
Data Content by UAS Category
| UAS Category | Data to Record | Citation |
|---|---|---|
| Micro | Unique product ID, software/firmware version, time, position (latitude/longitude), relative altitude, ground speed, vertical speed, track angle, battery level, remote signal strength, triggered alerts (e.g., geofence breach, lost link), and remote control inputs2. | 2 |
| Light | All micro UAS data + pitch/roll angles, barometric altitude, telemetry signal strength, and additional sensor alerts2. | 2 |
| Small | All light UAS data + airspeed (if available), payload status, and ground control station location (if equipped with positioning)2. | 2 |
| Medium/Large | Requirements specified in airworthiness certification standards (not detailed in this standard)2. | 2 |
Data Storage and Security
- Storage medium: Non-volatile memory must be used to ensure data persistence2.
- Recording frequency: ≥1 Hz (1 sample per second)2.
- Data retention: At least the last 3 flight sessions must be stored, with critical incident data (e.g., crashes) preserved indefinitely2.
- Data security: FDRUs must employ encryption, access controls, or write-protection to prevent tampering or unauthorized deletion. Tampering must be detectable2.
- Data export: FDRUs must provide an interface for data extraction, and manufacturers must supply tools/methods for data interpretation2.
Exemptions: Applies to all civil UAS except powered toys, model aircraft, and systems without autonomous flight capabilities2.
3. Obstacle Detection and Avoidance Requirements
The Detect and obstacle avoid requirements for civil unmanned aircraft3 define technical standards for UAS to sense and avoid static obstacles. Key provisions include:
UAS Categorization
| Category | Definition | Citation |
|---|---|---|
| Micro | Empty weight <0.25 kg, max altitude ≤50 m, max speed ≤40 km/h3. | 3 |
| Light | Empty weight ≤4 kg, max takeoff weight ≤7 kg, max speed ≤100 km/h3. | 3 |
| Small | Empty weight ≤15 kg, max takeoff weight ≤25 kg3. | 3 |
| Medium | Max takeoff weight ≤150 kg3. | 3 |
| Large | Max takeoff weight >150 kg3. | 3 |
Obstacle Detection Requirements
| UAS Category | Obstacle Types | Detection Direction | Citation |
|---|---|---|---|
| Micro | Static obstacles with clear textures and frontal area >0.5 m² (e.g., buildings, trees, towers)3. | No directional requirements specified3. | 3 |
| Light/Small | All micro UAS obstacles + non-reflective, non-transparent static obstacles >2.5 cm diameter (e.g., power lines, branches) if equipped with LiDAR or millimeter-wave radar3. | Light: Forward, backward, left, right, up, down (360° horizontal plane)3. Small: Omnidirectional (360° horizontal + vertical)3. | 3 |
| Medium/Large | Requirements specified in airworthiness standards3. | Requirements specified in airworthiness standards3. | 3 |
Avoidance Capabilities
- Weather adaptability:
- Maximum avoidance speeds:
| UAS Category | Horizontal Speed | Vertical Speed | Citation |
|---|---|---|---|
| Micro | ≥18 km/h | ≥5 km/h (if vertical capability) | 3 |
| Light (rotary-wing) |
- <250 g | ≥18 km/h | ≥5 km/h |3 |
- 250 g–1.0 kg | ≥25 km/h (forward), ≥18 km/h (other directions) | ≥10 km/h |3 |
- 1.0–4.0 kg | ≥30 km/h | ≥10 km/h |3 |
- 4.0–7.0 kg | ≥40 km/h | ≥10 km/h |3 |
- Failure handling:
- Micro UAS: Must alert operators and prevent takeoff if obstacle avoidance fails pre-flight3.
- Light UAS: Must alert and prevent takeoff pre-flight; trigger hover/return-to-home/landing/parachute deployment during flight if failure occurs3.
- Small UAS: Must switch to redundant sensors (if available) or trigger safety protocols (e.g., hover, landing) if all sensors fail3.
- Medium/large UAS: Requirements defined in airworthiness standards3.
Operational Requirements
- Manuals: UAS manuals must specify maximum avoidance speeds, operational weather conditions, and supported scenarios (e.g., urban, night)3.
- Logging: Systems must record obstacle avoidance events (e.g., alerts, evasive maneuvers)3.
Exemptions: Applies to all civil UAS except toys, model aircraft, UAS with physical propeller guards, indoor-only UAS (excluding public spaces), and UAS used for emergency services (e.g., search-and-rescue, firefighting)3.
Summary Answer
China’s regulatory framework for civil unmanned aircraft systems (UAS) mandates cybersecurity protections for data links1, comprehensive flight data recording2, and obstacle detection/avoidance capabilities3. Cybersecurity requirements include authentication, encryption, anti-tampering measures, and logging for all data links1. Flight data recording obligations vary by UAS category, with micro/light/small UAS required to log operational parameters, alerts, and control inputs in non-volatile memory, while medium/large UAS follow airworthiness standards2. Obstacle detection and avoidance standards specify minimum detection ranges, avoidance speeds (e.g., ≥18 km/h for micro UAS), and failure-handling protocols, with exemptions for toys, indoor UAS, and emergency-service aircraft3. These regulations apply to UAS manufacturers, operators, and integrators, with compliance enforced by the Ministry of Industry and Information Technology (MIIT) and the Civil Aviation Administration of China (CAAC)1, 2, 3.
Sources
- ↩ WTO TBT notification 26-03407 — China https://members.wto.org/crnattachments/2026/TBT/CHN/26_03407_00_x.pdf
- ↩ WTO TBT notification 26-03406 — China https://members.wto.org/crnattachments/2026/TBT/CHN/26_03406_00_x.pdf
- ↩ WTO TBT notification 26-03405 — China https://members.wto.org/crnattachments/2026/TBT/CHN/26_03405_00_x.pdf
