In mid March 2024 the Ministry of State Security issued a directive that required a range of state linked organisations to remove a specialised version of Windows 10 that had been built for exclusive government use. The order marks the latest step in Beijing’s effort to tighten control over software that processes sensitive data.
Background on the government only Windows edition
Microsoft has long offered a standard commercial version of Windows 10 that is used worldwide. In response to Chinese security requirements, the company also supplied a customised edition that removed certain telemetry features and added Chinese language support. The version was marketed as a government only product and was pre‑installed on many computers purchased by ministries, research institutes and state owned enterprises.
Why a separate edition was created
The Chinese authorities wanted an operating system that would not send usage data to foreign servers. By working with Microsoft, they obtained a build that disabled many background services that collect diagnostic information. The customised version also integrated local authentication protocols and compliance checks that align with national cybersecurity regulations.
Official directive and its scope
The recent notice, circulated through internal channels, instructed all agencies that handle classified or critical infrastructure data to uninstall the government edition within a thirty day window. The memo referenced a “planned retirement” of the customised build, citing concerns that the software no longer meets the latest data protection standards.
Organizations instructed to uninstall
- Ministries of defence, public security and finance
- State owned energy and telecommunications companies
- National research laboratories and university labs that receive government funding
- Regional data centres that host citizen information
Each entity is required to replace the removed OS with a version that has been approved by the national cybersecurity authority. The replacement could be a newer domestic operating system or a standard commercial edition that has been vetted for compliance.
Data security concerns driving the move
Chinese officials have warned that the ageing customised Windows build contains vulnerabilities that could be exploited by foreign actors. The directive cites three main risk factors:
- Outdated security patches that are no longer supported by the vendor.
- Legacy code that may expose backdoors for data exfiltration.
- Insufficient integration with the latest national encryption standards.
By retiring the older edition, the government hopes to close these gaps before they can be leveraged in cyber espionage campaigns.
Risks of the customised OS
Security analysts have pointed out that a customised operating system can become a single point of failure if it is not regularly updated. The Reuters report noted that the lack of automatic updates makes the system more vulnerable than the mainstream Windows releases that receive monthly patches.
Implications for the Chinese tech industry
The order sends a clear signal to domestic software vendors that the government expects higher security standards across all platforms. Companies that develop local operating systems may see increased demand as agencies look for alternatives that satisfy the new requirements.
Potential impact on software vendors
- Microsoft may need to negotiate new licensing terms for any future government builds.
- Domestic firms such as Huawei and Kylin could receive government contracts to provide replacement OS solutions.
- Third‑party security firms are likely to offer migration services to help agencies transition smoothly.
These shifts could accelerate the growth of a homegrown software ecosystem that is less dependent on foreign code bases.
International perspective
Other nations have also explored sovereign operating systems to protect critical data. The United States, for example, has issued guidance through the Cybersecurity and Infrastructure Security Agency on how to evaluate and deploy trusted software supply chains.
How other countries handle sovereign OS
The CISA guidance on critical software supply chain outlines best practices for assessing risk in customised platforms. European countries have launched initiatives to develop secure, locally controlled operating systems for government use. China’s latest move aligns with this global trend toward greater software sovereignty.
Next steps and timeline
According to the Ministry of State Security, agencies must complete the uninstallation process by the end of April 2024. Technical teams are advised to back up all essential data before removing the OS and to verify that the new platform meets the required encryption and access controls.
Stakeholders are encouraged to consult the official Chinese government portal for detailed implementation guidelines. Microsoft has also released a public statement confirming its cooperation with the Chinese authorities and offering support for the transition.
As the deadline approaches, the cybersecurity community will be watching closely to see whether the retirement of the customised Windows build reduces the attack surface for state linked networks. The outcome could shape future policy decisions on how governments balance the need for secure software with the practicalities of maintaining large‑scale IT environments.
Comments
No comments yet. Be first.
Please log in to comment.