IPv6 Compliance Deadline Is Here: Interpreting China’s 2026–2030 IPv6 Implementation Plan — What Enterprises Must Do Now
In 2026, China’s Cyberspace Administration (CAC), jointly with the Ministry of Industry and Information Technology (MIIT) and other agencies, released the Deepening IPv6 Technology Innovation and Integrated Application Implementation Plan (2026–2030) — a clear roadmap for China’s transition from “scale deployment” to “full enablement” over the 15th Five-Year Plan period.
The Plan defines two hard deadlines:
- By 2027: IPv6 end-to-end connectivity must be comprehensively improved; fixed broadband IPv6 reachability must increase significantly; all new network terminals must fully support and enable IPv6 by default; government/enterprise leased-line IPv6 traffic share must see measurable growth.
- By 2030: New networks must prefer IPv6 by default; accelerate the migration to IPv6-only (single-stack); establish an IPv6-dominated network service and application ecosystem.
This means: any organization still running IPv4-only has less than four years to complete the transition.
The official document was published via the “网信中国” (CAC China) WeChat account and is the most authoritative IPv6 policy directive currently in effect.
1. IP Address Planning — Why “Just Flip the Switch” Is Not Enough
Many organizations assume that enabling IPv6 is as simple as asking their ISP to “turn it on.” In reality, the IPv6 address architecture is fundamentally different from IPv4:
| Comparison | IPv4 | IPv6 |
|---|---|---|
| Address length | 32 bits | 128 bits |
| Typical ISP allocation | 1 public IP + NAT | /56 or /60 prefix (~2⁷² addresses) |
| Planning required | Minimal | Mandatory subnet planning |
| Address acquisition | DHCP (stateful) | SLAAC or DHCPv6 |
| NAT | Ubiquitous | Not recommended |
Planning steps required:
- Request an IPv6 prefix from your ISP — typically a /56 or /60; check ISP policy in advance.
- Internal subnet planning — allocate the prefix across VLANs, departments, or business lines.
- Choose an address assignment strategy — SLAAC (stateless, auto-configuration) for end devices; DHCPv6 (stateful, fixed addresses) for servers.
- Update DNS records — add AAAA records for both internal and external DNS.
- Register IPv6 addresses — as required by Article 6 of the Plan.
2. Network Configuration — 10 Critical IPv6 Migration Tasks
Migrating from IPv4 to dual-stack (or future single-stack) requires the following technical adjustments:
Routing and Egress
- Routing protocol upgrade — OSPFv3 replaces OSPFv2; BGP must enable the IPv6 address-family.
- Firewall policy rewrite — IPv6 ACLs/rules are independent of IPv4 and must be configured separately.
- NAT strategy adjustment — With native end-to-end IPv6, security models that rely on NAT for hiding must be replaced by firewall policy.
LAN and Access
- VLAN SVI configuration — each VLAN’s SVI must be configured with both an IPv6 link-local address and a global unicast address.
- Router Advertisement (RA) — determines whether endpoints use SLAAC or DHCPv6.
- MTU handling — IPv6 minimum MTU is 1280; avoid dropping ICMPv6 packets that would break Path MTU Discovery.
Security and Operations
- IDS/IPS rule updates — verify that security appliances support IPv6 protocol parsing; otherwise IPv6 traffic becomes a blind spot.
- Logging and SIEM — SIEM/log systems must ingest IPv6 5-tuple records.
- SSL offload / load balancing — listeners must have separate IPv6 VIPs configured.
- Legacy security appliance replacement — any security device that does not support IPv6 must be replaced by 2027 (Plan Article 35).
3. Timeline — Key Milestones (2026–2030)

2026: Assessment and Planning (Do It Now)
This is the most urgent year. Start now:
- Full asset inventory — catalog all network devices, servers, endpoints, cloud resources, websites/apps for IPv6 readiness.
- IPv6 readiness scoring — record each device/system’s status (native support / upgradeable / not compatible).
- Procurement policy — all future IT procurement must mandate IPv6 support.
- Apply for IPv6 prefix — contact your ISP and begin internal address planning.
2027: End-to-End Dual-Stack Cutover
- Dual-stack deployment — all network segments run IPv4 and IPv6 simultaneously on production equipment.
- Office productivity validation — verify that OA systems, video conferencing, and collaboration tools work over IPv6.
- Cloud service IPv6 enablement — enable dual-stack on cloud VPCs, CDN, and DNS.
- Security policy audit — confirm IPv6 traffic passes through IDS/IPS and next-gen firewalls.
2028–2029: Traffic Migration and Optimization
- Traffic migration — adjust routing preferences to prefer IPv6.
- Performance monitoring — compare IPv6 vs. IPv4 latency, throughput, and failure rates.
- IPv4 dependency audit — identify and refactor systems still relying on IPv4 literals or NAT traversal.
2030: Single-Stack Target State
- IPv4 phased decommissioning — internal networks that no longer need IPv4 can be progressively shut down.
- Single-stack verification — full production traffic on IPv6-only; IPv4 as exception-only fallback.
- IPv4 decommission report — document residual IPv4 dependencies and long-tail devices.
4. Procurement & Compliance Risks
The Plan introduces concrete compliance consequences for organizations that fail to act:
- Government procurement qualification risk: Enterprises that cannot meet IPv6 requirements increasingly risk being disqualified from bidding on government digital projects and government cloud services. IPv6 support is becoming a scored requirement in government IT procurement tender documents — by 2027 it will likely be mandatory.
- Cybersecurity Classification (Classified Protection / 等保) audits: Class 3+ networks must demonstrate dual-stack protection capabilities. Failure to support IPv6 may result in non-compliance findings during periodic audits.
- Security appliance replacement: Any security device (firewall, IDS/IPS, VPN gateway) that does not support IPv6 must be replaced by 2027 (Plan Article 35).
- IP address registration: IPv6 addresses must be properly registered with authorities per Article 6 of the Plan.
5. The IPv6 Compliance Launch Checklist
Start these actions today. Each item has a clear owner, timeline, and decision dependency:
Week 1–2: Discovery
- Inventory all network equipment models and firmware versions
- Check ISP IPv6 prefix availability and application process
- Survey cloud provider IPv6 support (VPC, CDN, DNS, load balancers)
- Document current IPv4 subnet and VLAN plan
Week 3–4: Planning
- Design IPv6 subnet allocation scheme
- Draft dual-stack migration sequence (segment by segment)
- Identify IPv4-only applications that need upgrades or replacement
- Budget for new equipment (switches, firewalls, load balancers as needed)
Month 2–3: Pilot
- Enable dual-stack on a non-production segment
- Test DNS resolution, routing, firewalling, and application behavior over IPv6
- Validate SLAAC and/or DHCPv6 configuration
- Train IT operations team on IPv6 troubleshooting basics
Month 4–6: Production Cutover
- Roll out dual-stack segment by segment
- Update monitoring, logging, and SIEM pipelines for IPv6
- Update procurement policy to require IPv6 in all new IT purchases
- Run compliance audit against the Plan’s requirements
Need Help With Your IPv6 Compliance Journey?
DELine provides end-to-end IPv6 compliance services — from readiness assessment and address planning through dual-stack deployment, security policy migration, and compliance audit support. Whether you’re a corporate IT team, a government contractor, or a cloud service operator, our engineers can help you meet the 2027 and 2030 deadlines with minimum business disruption.
📞 Contact us via www.de-line.net/contact or email info@de-line.net for a no-obligation IPv6 readiness assessment.



