DATABASE SECURITY IMPORT PROCEDURE INTO VIETNAM
Database security refers to products used to secure database systems, whether imported as a hardware appliance, a software-integrated device, bundled license or deployment package for server/database environments. If the shipment is described only as “security device”, “database appliance” or “software appliance”, customs clearance may be affected by HS classification, cybersecurity import licensing, civil cryptography review, software/license valuation, C/O and labeling. This article provides an E2E (End-to-End) review map for HS code, duty, sectoral policy, customs dossier and pre-ETA risk control.
SCOPE OF APPLICATION
Database security product
Hardware appliance or solution designed to secure database systems, monitor database access, detect attacks, control risks and protect database servers or sensitive data.
No group-wide conclusion
Vulnerability scanner, storage security and DLP may share the same menu group but have different functions, technical dossiers and customs explanations.
Variants to separate
New goods, refurbished units, demo/lab devices, license renewal, subscription, RMA/warranty goods, project cargo and EPE/FDI/factory imports may require different handling.
Mandatory review condition
Review by catalogue, datasheet, model and actual import purpose, especially where the goods include transmission modules, encryption, server appliance, license or management software.
| Item | Review point |
|---|---|
| Product covered | Database security product used to secure database systems, monitor database access, detect attacks, control risks or protect sensitive database data. |
| Related group | Vulnerability scanner, database security, storage security and DLP. This article covers database security only and must not be applied automatically to the whole group. |
| Reference HS codes | 8471.30.90 / 8471.41.90 / 8471.49.90 / 8517.62.43, depending on configuration and principal function. |
| Proposed tax position | Ordinary import duty reference 5%, MFN duty 0%, VAT 10%; special preferential duty under valid C/O/FTA may generally be reviewed to 0%. |
| Key sectoral policy | Potential cybersecurity product import license; civil cryptography review if the model has dedicated encryption/key-management functions. |
| Pre-ETA control | Lock model, license, database protection features, encryption, deployment mode, serial list, original label and C/O before arrival. |
CLASSIFICATION & TECHNICAL IDENTIFICATION
Database security should not be identified by trade name only. The importer must determine whether the shipment is a physical appliance, an automatic data processing machine/unit, a data transmission device, software license or a database security solution package.
TECHNICAL IDENTIFICATION CRITERIA
| Technical criterion | Documents to check | Risk if misdescribed | Suggested goods description |
|---|---|---|---|
| Trade name and model | Catalogue, datasheet, original label, model list | May be confused with server, storage appliance or software license | Database security appliance, model…, for database system protection |
| Principal function | Datasheet, admin guide, feature matrix | Sectoral policy may be wrong if database protection function is not shown | State access monitoring, attack/intrusion protection and database data protection |
| Form of goods | Product photos, BOM, invoice, packing list | Hardware appliance may be mixed with software/license | Separate hardware, license/subscription and support if invoiced separately |
| Hardware configuration | CPU, RAM, storage, network ports, form factor | Wrong HS direction between 8471 and 8517 | Describe rack/desktop appliance, LAN/SFP ports, capacity and serial number |
| Encryption function | Security whitepaper, encryption statement, license sheet | Civil cryptography review may arise if dedicated encryption exists | State whether crypto module, key management or database encryption is included |
| Goods condition | Invoice, label photos, serial list, RMA letter | Used/refurbished goods may be declared as new | Declare brand-new, refurbished, demo or warranty status consistently |
HS CODE – DUTY – C/O
Under the cybersecurity product list, database security is described as a product securing database systems. HS review normally includes 8471 for automatic data processing machines/units and 8517.62.43 where the product is a data transmission/receiving device such as a controller, gateway, router/adaptor designed to connect to ADP machines. The applicable tariff must be checked at declaration date.
| Reference HS code | Applicable condition | Risk if misclassified | Documents to check |
|---|---|---|---|
| 8471.30.90 | Portable appliance under 10kg with a central processing unit and configuration matching heading 8471 | HS may be rejected, affecting license and C/O | Catalogue, weight, CPU/RAM/storage configuration, photos, original label |
| 8471.41.90 | Device in one housing with CPU, input and output, used as a database security processing appliance | If it is essentially a network device, customs may request review under 8517 | Datasheet, hardware diagram, management interface, model list |
| 8471.49.90 | System imported as multiple functional units of an ADP system | System may be split if system nature is not evidenced | Packing list, system diagram, BOM, catalogue |
| 8517.62.43 | Data transmission/receiving device, gateway/adaptor/controller designed to connect to ADP machines | If it is a pure server/processing appliance, 8471 may be questioned | Network port datasheet, transmission description, connectivity diagram |
Tax and C/O review matrix
| HS code | Ordinary import duty | MFN import duty | VAT | Special preferential duty with C/O | Application note |
|---|---|---|---|---|---|
| 8471.30.90 | 5% reference | 0% | 10% | May be reviewed to 0% if C/O and FTA conditions are met | Only when the product is correctly classified as a portable ADP machine/other portable unit. |
| 8471.41.90 | 5% reference | 0% | 10% | May be reviewed to 0% if C/O and FTA conditions are met | For units in one housing with CPU, input and output. |
| 8471.49.90 | 5% reference | 0% | 10% | May be reviewed to 0% if C/O and FTA conditions are met | For ADP systems imported as a system. |
| 8517.62.43 | 5% reference | 0% | 10% | May be reviewed to 0% if C/O and FTA conditions are met | For transmission/receiving controller/adaptor/gateway connected to ADP machines. |
| Bundled license/subscription | Do not conclude under hardware line | Review by value and transaction nature | Review separately | Depends on transaction structure | If license/support is separately invoiced, value and description must be consistent. |
SECTORAL POLICY MATRIX
| Goods scenario | Possible policy | Documents to check | Authority/portal if identifiable | Recommended timing | Risk note |
|---|---|---|---|---|---|
| Database security appliance listed as cybersecurity product | May require import license for cybersecurity products | Datasheet, feature matrix, business license if required, conformity documents if applicable | Department of Cybersecurity and High-Tech Crime Prevention – Ministry of Public Security public service portal / National Public Service Portal or current portal | Before ETA, preferably before shipment | Missing license may hold the dossier or delay clearance. |
| Database encryption, key management or tokenization | Civil cryptography review if the product falls under the licensed civil cryptography list | Crypto statement, admin guide, encryption module document, license sheet | Civil cryptography authority/current portal | Before PO/invoice is locked | Do not assume all encryption is licensed; review by actual function and list. |
| Transmission module, network ports or connected appliance | ICT group-2/conformity review if the model falls under the ICT unsafe-goods list | Catalogue, test report, QCVN, port photos, model list | ICT sectoral authority/current portal | Before ETA | Missing test report or wrong model can prolong processing. |
| Standard new goods | Customs dossier, goods label, HS, C/O and value review | Invoice, Packing List, B/L/AWB, C/O, catalogue, original label | Customs sub-department | Before declaration | Goods name, model, serial and origin must match. |
| Demo/RMA/refurbished goods | Review condition, used-goods policy, declared value and import purpose | RMA letter, warranty document, serial list, photos, invoice | Customs and sectoral authority if applicable | Before arrival | Do not declare as new if goods are refurbished/demo. |
| EPE/FDI/factory import | Review customs regime, use purpose, possible duty treatment and asset management | Contract, PO, use purpose, transport documents, project dossier | Managing customs authority | Before customs regime is selected | Wrong regime may affect duty and post-clearance audit. |
LEGAL DOCUMENTS TO REVIEW
| Document group | Document name/number | Issuing body | Effective timing | Role in procedure | Article/appendix to note | Review note |
|---|---|---|---|---|---|---|
| Law | Law on Customs 2014 | National Assembly | In force; check at declaration date | Basis for customs dossier, inspection and clearance | Rules on dossier, inspection and clearance | Review by import regime and goods condition. |
| Law | Law on Cyberinformation Security 2015 | National Assembly | In force; check amendments if any | Basis for cybersecurity products and civil cryptography management | Rules on cybersecurity/civil cryptography products and services | Apply only where model falls within scope. |
| Circular | Circular 13/2018/TT-BTTTT | MIC | Effective from 01/12/2018; amended/supplemented | Cybersecurity product import license list and licensing procedure | Cybersecurity product list and license dossier | Check the current amended version. |
| Circular | Circular 10/2022/TT-BTTTT | MIC | Effective from 15/09/2022 | Amends Circular 13/2018 and includes products securing database systems | Appendix I – Data protection products | Key reference for database security. |
| Circular | Circular 29/2025/TT-BKHCN | MOST | Effective from 31/12/2025 | ICT goods with potential safety risks | Appendix/list for ICT group-2 goods | Apply only if the model is within scope or has relevant ICT modules. |
| Decree | Decree 211/2025/ND-CP | Government | Effective from 09/09/2025 | Civil cryptography management review if dedicated encryption exists | Licensed civil cryptography scope/conditions | Do not apply automatically to ordinary security functions. |
| Decree | Decree 43/2017/ND-CP and Decree 111/2021/ND-CP | Government | In force; check validity | Goods labeling and Vietnamese supplementary label | Mandatory labeling contents | Review original label before ETA. |
| Tariff | Current import-export tariff | Government/MOF | Applicable on declaration date | Determines ordinary duty, MFN, VAT and special preferential duty | By HS code and origin | Do not quote outdated tariff tables. |
VIEW / DOWNLOAD ORIGINAL LEGAL DOCUMENTS
Businesses may search documents by number on the official legal document portal, the Government portal or the issuing authority website. Cross-check official sources before application.
CUSTOMS CLEARANCE DOSSIER
Commercial documents
Commercial Invoice, Packing List, Bill of Lading/Air Waybill, Sales Contract/Purchase Order, C/O if preferential duty is claimed, catalogue/datasheet, product photos, original label, model list and serial list.
Sectoral documents if applicable
Cybersecurity product import license, civil cryptography documents if applicable, conformity declaration/certification if applicable, test report, technical documents, license/subscription, database security function description and goods label.
OPERATIONAL DOSSIER CHECKLIST
| Dossier group | Required documents | Used for step | Typical preparer | Common error | Pre-ETA check |
|---|---|---|---|---|---|
| Commercial | Invoice, Packing List, B/L or AWB | Declaration, value, quantity and origin | Shipper, importer, logistics/docs | Goods name too generic or model missing | Cross-check goods name, model, serial, quantity and origin before ETA |
| Technical | Catalogue, datasheet, admin guide, feature matrix | HS, cybersecurity, civil cryptography and ICT policy review | Supplier, IT, procurement | Database protection function not shown | Request official documents and highlight database security functions |
| Cybersecurity | Import license if listed | Sectoral dossier and customs explanation | Importer, legal/compliance | Filing after ETA delays clearance | Review list and prepare before arrival |
| Civil cryptography | Crypto statement, encryption document, license if applicable | Determine whether civil cryptography license is required | Supplier, importer, legal | Confusing ordinary encryption with licensed civil cryptography product | Request model-based encryption/key-management confirmation |
| C/O | Draft/original C/O, through B/L if transit applies | Claim special preferential duty | Shipper, importer | Wrong form, description, HS or origin criterion | Check C/O before original issuance |
| Labeling | Original label photo, Vietnamese supplementary label, serial label | Clearance and market circulation | Importer, warehouse, compliance | Missing model, origin, specification or manufacturer | Take label photos before shipment and prepare supplementary label |
DECISION POINTS THAT MAY HOLD THE SHIPMENT
| Decision point | Question to answer | Evidence | Consequence if unclear | Recommended handling |
|---|---|---|---|---|
| Product nature | Is it a database security appliance, server appliance, software license or cloud/SaaS? | Catalogue, invoice, license sheet, photos | Wrong goods nature and policy | Separate hardware, license, support and service. |
| HS code | Does the product fall under 8471 or 8517? | Datasheet, configuration, network ports, operation description | HS consultation or explanation may be required | Classify by principal function and actual structure. |
| Cybersecurity license | Does the model fall under products securing database systems? | Circular 10/2022, feature matrix, datasheet | Additional license may be required | Review before shipment. |
| Civil cryptography | Does it include dedicated encryption, key management or database encryption module? | Security whitepaper, crypto declaration | License/explanation may be required | Obtain written supplier confirmation. |
| C/O | Are form, origin criterion, description and HS aligned? | C/O draft, invoice, B/L | Preferential duty may be denied | Check before C/O issuance. |
| Goods condition | New, refurbished, demo or warranty replacement? | Serial list, RMA letter, label photos | Wrong policy/value declaration | Declare the actual condition consistently. |
PRACTICAL E2E IMPORT PROCESS
Step 1: Pre-ETA review
Confirm reference HS, cybersecurity license, civil cryptography, ICT/conformity if any, taxes, C/O, label, goods condition and license/subscription.
Step 2: Lock documents and technical dossier
Lock Invoice, Packing List, B/L/AWB, catalogue, datasheet, model list, serial list, license sheet, database security function and original label photos.
Step 3: Register license/sectoral dossier if required
If the model falls under cybersecurity, civil cryptography or ICT group-2 management, prepare the dossier before ETA.
Step 4: Lodge customs declaration
Declare accurate goods name, model, principal function, HS code, origin and license if any. Prepare explanations for yellow/red channel.
Step 5: Clearance, delivery and record retention
After clearance, control Vietnamese label and retain license, C/O, catalogue, test report, license, label photos and HS rationale for audit.
PRE-ETA RISK CHECKLIST
| Risk | Consequence | Pre-ETA control | Documents to check |
|---|---|---|---|
| Generic goods name | HS and sectoral policy may be questioned | State Database security appliance and main function | Invoice, Packing List, catalogue |
| Missing cybersecurity license | Clearance delay and storage cost | Review Circular 10/2022 before shipment | Datasheet, feature matrix, license |
| Encryption not reviewed | Civil cryptography dossier may arise | Ask supplier to confirm crypto/key-management functions | Security whitepaper, crypto statement |
| License/subscription inconsistent with invoice | Value and transaction description mismatch | Align hardware and license presentation | PO, invoice, license certificate |
| C/O description or HS mismatch | Preferential duty may be denied | Check draft C/O before issuance | C/O, invoice, B/L |
| Model/serial discrepancy | Document amendment or inspection risk | Lock model and serial list before ETA | Packing list, label photo, catalogue |
FAQ – COMMON BUSINESS QUESTIONS
Does database security import require a license?
It may require a cybersecurity product import license if the model falls under the listed products. Review by function, model and technical dossier.
Which HS code should be used?
Review 8471.30.90, 8471.41.90, 8471.49.90 or 8517.62.43 depending on structure and principal function.
Is conformity testing required?
Only after reviewing the model, transmission module, interface, applicable QCVN and current ICT list.
What if only a software/cloud license is purchased?
If no physical goods cross the border, it is usually not handled as a standard import shipment; review by software/service transaction nature.
Can C/O reduce duty?
Yes, if C/O is valid and matches form, origin criterion, goods description and HS code.
Are RMA/warranty goods handled like commercial goods?
Not automatically. Review customs regime, value, warranty documents, serials, condition and sectoral policy.
What if invoice model differs from catalogue?
Correct documents before ETA. If the declaration is already lodged, an explanation or amendment may be required.
Tiếng Việt
中文 (中国)
NEED TO REVIEW IMPORT PROCEDURES OR A SHIPPING PLAN?
Send us the product name, shipping route, current dossier, or implementation request in advance so we can suggest a suitable approach that is practical, focused, and aligned with your shipment.
Cargo Damage at a Port or Warehouse: An Immediate Response Checklist
What Is General Average? How Cargo Interests Should Respond to a GA Notice
When should businesses photograph or video container stuffing and opening?
When Can Cargo Insurers Reject or Reduce a Claim?
Risks of Failing to Inspect a Container Before Cargo Stuffing
Risks of Failing to Inspect a Container Before Cargo Stuffing
What Documents Are Required for a Cargo Insurance Claim?
What Information Should a Cargo Damage Survey Record Contain?
Total Loss vs Partial Loss in Cargo Insurance: What Is the Difference?
Cargo Dented, Wet or Missing Packages: What Should a Business Do?
Who Must Arrange Insurance under CIF and CIP?
Export Process: From Purchase Order to Final Document Set
How Is Cargo Insurance Value Determined?
How Do ICC-A, ICC-B and ICC-C Cargo Insurance Conditions Differ?
When Should a Business Buy Separate Cargo Insurance?