Database Security Import Procedure into Vietnam

Mục lục nội dung ẩn
IMPORT PROCEDURE BY PRODUCT · VULNERABILITY SCANNER / DATABASE SECURITY / STORAGE SECURITY / DLP

DATABASE SECURITY IMPORT PROCEDURE INTO VIETNAM

Database security refers to products used to secure database systems, whether imported as a hardware appliance, a software-integrated device, bundled license or deployment package for server/database environments. If the shipment is described only as “security device”, “database appliance” or “software appliance”, customs clearance may be affected by HS classification, cybersecurity import licensing, civil cryptography review, software/license valuation, C/O and labeling. This article provides an E2E (End-to-End) review map for HS code, duty, sectoral policy, customs dossier and pre-ETA risk control.

SCOPE OF APPLICATION

Database security product

Hardware appliance or solution designed to secure database systems, monitor database access, detect attacks, control risks and protect database servers or sensitive data.

No group-wide conclusion

Vulnerability scanner, storage security and DLP may share the same menu group but have different functions, technical dossiers and customs explanations.

Variants to separate

New goods, refurbished units, demo/lab devices, license renewal, subscription, RMA/warranty goods, project cargo and EPE/FDI/factory imports may require different handling.

Mandatory review condition

Review by catalogue, datasheet, model and actual import purpose, especially where the goods include transmission modules, encryption, server appliance, license or management software.

Illustration for Database Security Import Procedure into Vietnam
Illustration of the product group and document review before customs clearance.
ItemReview point
Product coveredDatabase security product used to secure database systems, monitor database access, detect attacks, control risks or protect sensitive database data.
Related groupVulnerability scanner, database security, storage security and DLP. This article covers database security only and must not be applied automatically to the whole group.
Reference HS codes8471.30.90 / 8471.41.90 / 8471.49.90 / 8517.62.43, depending on configuration and principal function.
Proposed tax positionOrdinary import duty reference 5%, MFN duty 0%, VAT 10%; special preferential duty under valid C/O/FTA may generally be reviewed to 0%.
Key sectoral policyPotential cybersecurity product import license; civil cryptography review if the model has dedicated encryption/key-management functions.
Pre-ETA controlLock model, license, database protection features, encryption, deployment mode, serial list, original label and C/O before arrival.
Legal note: Database security should be assessed only after reviewing the catalogue, datasheet, model, database protection function, deployment mode, license/subscription, encryption information and actual import purpose. If the transaction is purely cloud/SaaS with no physical goods crossing the border, this customs import procedure does not automatically apply.

CLASSIFICATION & TECHNICAL IDENTIFICATION

Database security should not be identified by trade name only. The importer must determine whether the shipment is a physical appliance, an automatic data processing machine/unit, a data transmission device, software license or a database security solution package.

TECHNICAL IDENTIFICATION CRITERIA

Technical criterionDocuments to checkRisk if misdescribedSuggested goods description
Trade name and modelCatalogue, datasheet, original label, model listMay be confused with server, storage appliance or software licenseDatabase security appliance, model…, for database system protection
Principal functionDatasheet, admin guide, feature matrixSectoral policy may be wrong if database protection function is not shownState access monitoring, attack/intrusion protection and database data protection
Form of goodsProduct photos, BOM, invoice, packing listHardware appliance may be mixed with software/licenseSeparate hardware, license/subscription and support if invoiced separately
Hardware configurationCPU, RAM, storage, network ports, form factorWrong HS direction between 8471 and 8517Describe rack/desktop appliance, LAN/SFP ports, capacity and serial number
Encryption functionSecurity whitepaper, encryption statement, license sheetCivil cryptography review may arise if dedicated encryption existsState whether crypto module, key management or database encryption is included
Goods conditionInvoice, label photos, serial list, RMA letterUsed/refurbished goods may be declared as newDeclare brand-new, refurbished, demo or warranty status consistently

HS CODE – DUTY – C/O

Under the cybersecurity product list, database security is described as a product securing database systems. HS review normally includes 8471 for automatic data processing machines/units and 8517.62.43 where the product is a data transmission/receiving device such as a controller, gateway, router/adaptor designed to connect to ADP machines. The applicable tariff must be checked at declaration date.

Reference HS codeApplicable conditionRisk if misclassifiedDocuments to check
8471.30.90Portable appliance under 10kg with a central processing unit and configuration matching heading 8471HS may be rejected, affecting license and C/OCatalogue, weight, CPU/RAM/storage configuration, photos, original label
8471.41.90Device in one housing with CPU, input and output, used as a database security processing applianceIf it is essentially a network device, customs may request review under 8517Datasheet, hardware diagram, management interface, model list
8471.49.90System imported as multiple functional units of an ADP systemSystem may be split if system nature is not evidencedPacking list, system diagram, BOM, catalogue
8517.62.43Data transmission/receiving device, gateway/adaptor/controller designed to connect to ADP machinesIf it is a pure server/processing appliance, 8471 may be questionedNetwork port datasheet, transmission description, connectivity diagram

Tax and C/O review matrix

HS codeOrdinary import dutyMFN import dutyVATSpecial preferential duty with C/OApplication note
8471.30.905% reference0%10%May be reviewed to 0% if C/O and FTA conditions are metOnly when the product is correctly classified as a portable ADP machine/other portable unit.
8471.41.905% reference0%10%May be reviewed to 0% if C/O and FTA conditions are metFor units in one housing with CPU, input and output.
8471.49.905% reference0%10%May be reviewed to 0% if C/O and FTA conditions are metFor ADP systems imported as a system.
8517.62.435% reference0%10%May be reviewed to 0% if C/O and FTA conditions are metFor transmission/receiving controller/adaptor/gateway connected to ADP machines.
Bundled license/subscriptionDo not conclude under hardware lineReview by value and transaction natureReview separatelyDepends on transaction structureIf license/support is separately invoiced, value and description must be consistent.

SECTORAL POLICY MATRIX

Goods scenarioPossible policyDocuments to checkAuthority/portal if identifiableRecommended timingRisk note
Database security appliance listed as cybersecurity productMay require import license for cybersecurity productsDatasheet, feature matrix, business license if required, conformity documents if applicableDepartment of Cybersecurity and High-Tech Crime Prevention – Ministry of Public Security public service portal / National Public Service Portal or current portalBefore ETA, preferably before shipmentMissing license may hold the dossier or delay clearance.
Database encryption, key management or tokenizationCivil cryptography review if the product falls under the licensed civil cryptography listCrypto statement, admin guide, encryption module document, license sheetCivil cryptography authority/current portalBefore PO/invoice is lockedDo not assume all encryption is licensed; review by actual function and list.
Transmission module, network ports or connected applianceICT group-2/conformity review if the model falls under the ICT unsafe-goods listCatalogue, test report, QCVN, port photos, model listICT sectoral authority/current portalBefore ETAMissing test report or wrong model can prolong processing.
Standard new goodsCustoms dossier, goods label, HS, C/O and value reviewInvoice, Packing List, B/L/AWB, C/O, catalogue, original labelCustoms sub-departmentBefore declarationGoods name, model, serial and origin must match.
Demo/RMA/refurbished goodsReview condition, used-goods policy, declared value and import purposeRMA letter, warranty document, serial list, photos, invoiceCustoms and sectoral authority if applicableBefore arrivalDo not declare as new if goods are refurbished/demo.
EPE/FDI/factory importReview customs regime, use purpose, possible duty treatment and asset managementContract, PO, use purpose, transport documents, project dossierManaging customs authorityBefore customs regime is selectedWrong regime may affect duty and post-clearance audit.

LEGAL DOCUMENTS TO REVIEW

Document groupDocument name/numberIssuing bodyEffective timingRole in procedureArticle/appendix to noteReview note
LawLaw on Customs 2014National AssemblyIn force; check at declaration dateBasis for customs dossier, inspection and clearanceRules on dossier, inspection and clearanceReview by import regime and goods condition.
LawLaw on Cyberinformation Security 2015National AssemblyIn force; check amendments if anyBasis for cybersecurity products and civil cryptography managementRules on cybersecurity/civil cryptography products and servicesApply only where model falls within scope.
CircularCircular 13/2018/TT-BTTTTMICEffective from 01/12/2018; amended/supplementedCybersecurity product import license list and licensing procedureCybersecurity product list and license dossierCheck the current amended version.
CircularCircular 10/2022/TT-BTTTTMICEffective from 15/09/2022Amends Circular 13/2018 and includes products securing database systemsAppendix I – Data protection productsKey reference for database security.
CircularCircular 29/2025/TT-BKHCNMOSTEffective from 31/12/2025ICT goods with potential safety risksAppendix/list for ICT group-2 goodsApply only if the model is within scope or has relevant ICT modules.
DecreeDecree 211/2025/ND-CPGovernmentEffective from 09/09/2025Civil cryptography management review if dedicated encryption existsLicensed civil cryptography scope/conditionsDo not apply automatically to ordinary security functions.
DecreeDecree 43/2017/ND-CP and Decree 111/2021/ND-CPGovernmentIn force; check validityGoods labeling and Vietnamese supplementary labelMandatory labeling contentsReview original label before ETA.
TariffCurrent import-export tariffGovernment/MOFApplicable on declaration dateDetermines ordinary duty, MFN, VAT and special preferential dutyBy HS code and originDo not quote outdated tariff tables.

VIEW / DOWNLOAD ORIGINAL LEGAL DOCUMENTS

Businesses may search documents by number on the official legal document portal, the Government portal or the issuing authority website. Cross-check official sources before application.

CUSTOMS CLEARANCE DOSSIER

Commercial documents

Commercial Invoice, Packing List, Bill of Lading/Air Waybill, Sales Contract/Purchase Order, C/O if preferential duty is claimed, catalogue/datasheet, product photos, original label, model list and serial list.

Sectoral documents if applicable

Cybersecurity product import license, civil cryptography documents if applicable, conformity declaration/certification if applicable, test report, technical documents, license/subscription, database security function description and goods label.

OPERATIONAL DOSSIER CHECKLIST

Dossier groupRequired documentsUsed for stepTypical preparerCommon errorPre-ETA check
CommercialInvoice, Packing List, B/L or AWBDeclaration, value, quantity and originShipper, importer, logistics/docsGoods name too generic or model missingCross-check goods name, model, serial, quantity and origin before ETA
TechnicalCatalogue, datasheet, admin guide, feature matrixHS, cybersecurity, civil cryptography and ICT policy reviewSupplier, IT, procurementDatabase protection function not shownRequest official documents and highlight database security functions
CybersecurityImport license if listedSectoral dossier and customs explanationImporter, legal/complianceFiling after ETA delays clearanceReview list and prepare before arrival
Civil cryptographyCrypto statement, encryption document, license if applicableDetermine whether civil cryptography license is requiredSupplier, importer, legalConfusing ordinary encryption with licensed civil cryptography productRequest model-based encryption/key-management confirmation
C/ODraft/original C/O, through B/L if transit appliesClaim special preferential dutyShipper, importerWrong form, description, HS or origin criterionCheck C/O before original issuance
LabelingOriginal label photo, Vietnamese supplementary label, serial labelClearance and market circulationImporter, warehouse, complianceMissing model, origin, specification or manufacturerTake label photos before shipment and prepare supplementary label

DECISION POINTS THAT MAY HOLD THE SHIPMENT

Decision pointQuestion to answerEvidenceConsequence if unclearRecommended handling
Product natureIs it a database security appliance, server appliance, software license or cloud/SaaS?Catalogue, invoice, license sheet, photosWrong goods nature and policySeparate hardware, license, support and service.
HS codeDoes the product fall under 8471 or 8517?Datasheet, configuration, network ports, operation descriptionHS consultation or explanation may be requiredClassify by principal function and actual structure.
Cybersecurity licenseDoes the model fall under products securing database systems?Circular 10/2022, feature matrix, datasheetAdditional license may be requiredReview before shipment.
Civil cryptographyDoes it include dedicated encryption, key management or database encryption module?Security whitepaper, crypto declarationLicense/explanation may be requiredObtain written supplier confirmation.
C/OAre form, origin criterion, description and HS aligned?C/O draft, invoice, B/LPreferential duty may be deniedCheck before C/O issuance.
Goods conditionNew, refurbished, demo or warranty replacement?Serial list, RMA letter, label photosWrong policy/value declarationDeclare the actual condition consistently.

PRACTICAL E2E IMPORT PROCESS

Step 1: Pre-ETA review

Confirm reference HS, cybersecurity license, civil cryptography, ICT/conformity if any, taxes, C/O, label, goods condition and license/subscription.

Step 2: Lock documents and technical dossier

Lock Invoice, Packing List, B/L/AWB, catalogue, datasheet, model list, serial list, license sheet, database security function and original label photos.

Step 3: Register license/sectoral dossier if required

If the model falls under cybersecurity, civil cryptography or ICT group-2 management, prepare the dossier before ETA.

Step 4: Lodge customs declaration

Declare accurate goods name, model, principal function, HS code, origin and license if any. Prepare explanations for yellow/red channel.

Step 5: Clearance, delivery and record retention

After clearance, control Vietnamese label and retain license, C/O, catalogue, test report, license, label photos and HS rationale for audit.

PRE-ETA RISK CHECKLIST

RiskConsequencePre-ETA controlDocuments to check
Generic goods nameHS and sectoral policy may be questionedState Database security appliance and main functionInvoice, Packing List, catalogue
Missing cybersecurity licenseClearance delay and storage costReview Circular 10/2022 before shipmentDatasheet, feature matrix, license
Encryption not reviewedCivil cryptography dossier may ariseAsk supplier to confirm crypto/key-management functionsSecurity whitepaper, crypto statement
License/subscription inconsistent with invoiceValue and transaction description mismatchAlign hardware and license presentationPO, invoice, license certificate
C/O description or HS mismatchPreferential duty may be deniedCheck draft C/O before issuanceC/O, invoice, B/L
Model/serial discrepancyDocument amendment or inspection riskLock model and serial list before ETAPacking list, label photo, catalogue

FAQ – COMMON BUSINESS QUESTIONS

Does database security import require a license?

It may require a cybersecurity product import license if the model falls under the listed products. Review by function, model and technical dossier.

Which HS code should be used?

Review 8471.30.90, 8471.41.90, 8471.49.90 or 8517.62.43 depending on structure and principal function.

Is conformity testing required?

Only after reviewing the model, transmission module, interface, applicable QCVN and current ICT list.

What if only a software/cloud license is purchased?

If no physical goods cross the border, it is usually not handled as a standard import shipment; review by software/service transaction nature.

Can C/O reduce duty?

Yes, if C/O is valid and matches form, origin criterion, goods description and HS code.

Are RMA/warranty goods handled like commercial goods?

Not automatically. Review customs regime, value, warranty documents, serials, condition and sectoral policy.

What if invoice model differs from catalogue?

Correct documents before ETA. If the declaration is already lodged, an explanation or amendment may be required.

EXECUTION SUPPORT FOR DATABASE SECURITY SHIPMENTS

This article provides a map of HS code, duty, dossier and sectoral policy. For an actual shipment, the enterprise must still review catalogue, datasheet, model, documents, origin, license/subscription and import purpose.

Pre-ETA review

Review HS, cybersecurity license, civil cryptography, C/O, duties, labeling, catalogue/datasheet/model.

Compliance dossier control

Cross-check Invoice, Packing List, B/L/AWB, C/O, catalogue, test report, license, label and technical documents.

International logistics & customs

Coordinate agents, carriers/airlines, ETA, pre-alert, customs declaration and green/yellow/red channel handling.

Post-clearance retention

Retain shipment dossier, license, C/O, supplementary label, catalogue, HS rationale and sectoral documents.

For shipments that may involve sectoral inspection, licensing, C/O or labeling requirements, businesses should not wait until arrival to review the dossier. Even a small mismatch among Invoice, Packing List, catalogue, datasheet, C/O or label may lead to additional document requests, clearance delay or unplanned storage cost. TGIMEX supports an E2E import execution approach: pre-ETA policy review, document checking, international freight coordination, customs declaration, clearance handling, inland delivery and post-clearance record retention.

QUICK CONSULTATION

NEED TO REVIEW IMPORT PROCEDURES OR A SHIPPING PLAN?

Send us the product name, shipping route, current dossier, or implementation request in advance so we can suggest a suitable approach that is practical, focused, and aligned with your shipment.

CALL NOW
Zalo
HOTLINE 0963 856 664 / 0982 135 393
EMAIL info@tgimex.com
SUITABLE FOR International shipping · Customs procedures · Import licenses · B2B logistics

Leave a Reply

Discover more from TGIMEX VIETNAM JSC

Subscribe now to keep reading and get access to the full archive.

Continue reading