Import Procedure Guide for Email Security Appliance

Electrical – Electronics – IT Equipment · Email Security

IMPORT PROCEDURE GUIDE FOR EMAIL SECURITY APPLIANCE

An Email Security appliance/gateway is a cybersecurity device used to filter spam, detect malware, control SMTP traffic, prevent phishing, sandbox attachments or enforce DLP policies in enterprise networks. If it is described only as “server”, “network appliance” or “security box”, the shipment may be exposed to wrong HS classification, cybersecurity import licensing issues, civil cryptography review, model mismatch between documents and catalogue, or DEM/DET costs due to missing pre-ETA files. This guide provides an E2E map for reviewing HS code, duties, specialized policies, documents, customs process and risks before cargo arrival.

QUICK FACT

Review itemDirection for Email SecurityOperational note
Recommended product nameEmail Security appliance or Email Security gateway used to control, filter and protect enterprise email trafficDo not describe it simply as “server” if the main function is email security or cybersecurity.
Suggested HS code8517.62.59 for a complete network apparatus that transmits, receives, converts or processes email data in a network; review separately if the device is essentially an automatic data processing serverIf it is a pure server, software license, virtual appliance or subscription, classification and procedures will differ.
Suggested taxesGeneral import duty 5%; MFN duty 0%; VAT 10%; FTA duty may be 0% with valid C/OVerify tariff schedule, C/O and goods condition on the customs declaration date.
Specialized policyMay fall under cybersecurity products subject to import license; civil cryptography review may arise if dedicated encryption functions existReview Circular 13/2018/TT-BTTTT, Circular 10/2022/TT-BTTTT, Decree 108/2016/ND-CP and technical files.
Key technical filesCatalogue, datasheet, admin guide, user manual, security feature list, license sheet, model list, test report if any, label and serial photosClarify whether it is hardware or software-only, and whether encryption/VPN/TLS inspection/key management, Wi-Fi/Bluetooth, battery or adapter is included.
Legal note: This content applies only to Email Security in the group Email Security, WAF, web app security appliance. It must not be automatically applied to WAF, web application security appliance, firewall, UTM, IDS/IPS, DLP appliance, proxy appliance, email security software license/subscription or cloud email security service. Review the actual catalogue, datasheet, model and import purpose before application.
Illustration for Import Procedure Guide for Email Security Appliance
Illustration of the product group and document review before customs clearance.

SCOPE OF APPLICATION

Applicable to

  • Hardware Email Security appliance/gateway as a complete physical device with Ethernet ports and specialized operating system/firmware.
  • Devices used for email filtering, anti-spam, anti-phishing, anti-malware, attachment inspection, sandboxing, DLP or enterprise email protection gateway.
  • New goods imported for trading, IT projects, EPE/FDI/factory deployment or enterprise systems.

Not automatically applicable to

  • WAF, firewall, UTM, IDS/IPS, load balancer, proxy gateway or web application security appliances.
  • Software license, cloud subscription, virtual appliance, activation key or implementation service not accompanied by physical equipment.
  • General purpose server installed with email security software after import; this case requires separate HS and policy review.

CLASSIFICATION & TECHNICAL IDENTIFICATION

Email Security must be identified by its main function, hardware configuration, network role, bundled license and security processing capability. A rackmount device may be a server, firewall, gateway or dedicated cybersecurity product; therefore, the goods description should be based on catalogue/datasheet rather than external appearance only.

Criteria to checkDocuments to compareRisk if described incorrectlySuggested description on documents/declaration
Main functionCatalogue, datasheet, solution brief, admin guideWrong HS code or wrong cybersecurity policyEmail Security appliance, model…, used to filter and protect enterprise email traffic, brand new.
Physical goods or licenseInvoice, packing list, license sheet, contract/POMisdeclaration between tangible goods and software/serviceSeparate hardware, license, subscription and support line items where applicable.
Network configurationDatasheet, port photos, deployment diagramCustoms may question why it is classified as data transmission/reception apparatusState that it has Ethernet ports, network communication and email data processing functions.
Security functionsSecurity feature list, admin guideMay trigger import license for cybersecurity productsSpecify anti-spam, anti-malware, sandbox, DLP and policy control if available.
Encryption/cryptographyDatasheet, compliance statement, encryption declarationMay trigger civil cryptography review if dedicated encryption existsSeparate TLS inspection, email encryption, key management or VPN functions if any.
Goods conditionInvoice, contract, label/serial photosMay trigger policy for used/refurbished ICT goodsState brand new; do not import used/refurbished goods without policy review.
Description warning: A generic goods name may lead to wrong HS code, wrong specialized policy, missing license if the product is a cybersecurity product, incorrect labeling and additional explanations during document or physical inspection.

HS CODE – DUTIES – C/O

For a hardware Email Security appliance, HS code should be determined based on data transmission/reception/processing function in a network, hardware configuration, operating principle and technical documentation. HS 8517.62.59 is used as the main review direction for a device that processes, forwards or controls email data in a network. If the device is essentially an automatic data processing server or a software/license item without hardware, it must be classified separately.

Suggested HS codeApplication conditionRisk if wrongly appliedDocuments to compare
8517.62.59Complete network apparatus that transmits/receives/converts/processes email data and performs email security in a networkDuty reassessment, C/O rejection, classification explanation or customs channel escalationCatalogue, datasheet, deployment diagram, port photos, user/admin guide.
8471.50.90 / 8471.49.00Consider only if the goods are essentially an automatic data processing machine/server imported as server configuration and security function is software-basedWrong policy if server code is applied to a dedicated cybersecurity applianceBOM, CPU/RAM/storage configuration, OS, license sheet, main function description.
Not applicable to license-onlyCases involving only license, key, subscription, cloud service or activation codeWrong declaration of goods type, customs value and tax obligationService contract, license invoice, payment documents and electronic delivery description.
Tax itemSuggested rateApplication conditionRisk note
General import duty5%Applies when preferential treatment is not available or no suitable C/O is providedVerify the tariff schedule on the declaration date.
MFN import duty0%Applies if the goods originate from an MFN beneficiary and the final HS code is appropriateDoes not replace specialized policy obligations.
VAT10%Applies to imported goods unless another VAT rate is legally applicableDepends on final HS code, tax policy and import file at the time of import.
Special FTA dutyMay be 0% with valid C/OC/O must match form, origin criterion, goods description, quantity, value, transport route and HS codeC/O errors may lead to loss of preference even if HS is correct.

APPLICABLE SPECIALIZED POLICIES

Goods situationPossible policyDocuments to checkAuthority/processing portal if identifiableRecommended timingRisk note
Complete Email Security applianceReview cybersecurity product import licensingCatalogue, datasheet, security feature list, license sheet, admin guideCybersecurity authority/public service portal under current regulationsBefore booking or at least before ETADo not conclude “no license required” without checking the applicable appendix.
Device with anti-attack, intrusion prevention or security monitoring functionsMay fall under cybersecurity product categories under Decree 108/2016 and Circular 13/2018 as amended by Circular 10/2022Technical description, security functions, datasheet, model listAuthority of Information Security or successor authority under current structureBefore cargo arrivalIf listed and license is missing, cargo may be held for supplementation.
Dedicated encryption, email encryption, key management, VPN or advanced TLS inspectionCivil cryptography review may be requiredEncryption declaration, technical whitepaper, admin guideGovernment Cipher Committee/public service portal if applicableBefore PO confirmationDo not label as civil cryptography unless the actual functions match the regulated list.
With Wi-Fi/Bluetooth/4G/5GICT group 2 and radio conformity may ariseWireless module datasheet, frequency, output power, test reportICT/telecom authority under Circular 29/2025/TT-BKHCNBefore ETARackmount Email Security usually has no wireless function; review separately if any wireless module exists.
With adapter, battery or separate power supplyElectrical safety, labeling and DG review if lithium battery existsAccessory catalogue, battery MSDS, adapter specificationsCustoms, carrier, certification body if applicableBefore packingAccessories may trigger separate HS code or policy.
Used/refurbished goodsUsed ICT goods import prohibition/conditional permission reviewInvoice, contract, serial, goods condition, equipment photosSpecialized authority under Circular 26/2025/TT-BKHCN if within scopeBefore purchaseDo not import used/refurbished goods under a “project equipment” assumption without legal basis.

LEGAL DOCUMENTS TO REVIEW

Document groupDocument name/numberIssuing authorityEffective date/application timingRole in the procedureKey article/appendix if anyReview note
LawLaw on Cyberinformation Security No. 86/2015/QH13National AssemblyEffective from 01/07/2016Legal framework for cybersecurity products/services and civil cryptographyReview chapters on civil cryptography and cybersecurity productsCompare with actual Email Security functions.
DecreeDecree 108/2016/ND-CPGovernmentEffective from 01/07/2016Conditions for trading cybersecurity products/services and import-licensed cybersecurity productsArticles 1, 2, 3 and related forms/appendices if applicableDo not invent licensing conclusions; check the list.
CircularCircular 13/2018/TT-BTTTTMinistry of Information and CommunicationsEffective from 01/12/2018List of cybersecurity products subject to import license and licensing dossierAppendix I and Article 3 on complete equipmentCritical for security appliances.
Amending circularCircular 10/2022/TT-BTTTTMinistry of Information and CommunicationsEffective from 15/09/2022Amends Circular 13/2018 and replaces appendices/procedure detailsAppendix I, Appendix II, Article 1Check the consolidated/current text at import date.
CircularCircular 29/2025/TT-BKHCNMinistry of Science and TechnologyEffective from 31/12/2025List of goods posing safety risks in ICT and telecommunicationsICT group 2 appendixReview if ICT/telecom functions fall within the list.
CircularCircular 26/2025/TT-BKHCNMinistry of Science and TechnologyEffective from 31/10/2025Management of used ICT goods on the prohibited import list and permitted casesArticle 1, Article 3 and appendices if applicableApplies to used/refurbished goods.
DecreeDecree 58/2016/ND-CP, Decree 53/2018/ND-CP and Decree 32/2023/ND-CPGovernmentCheck current validityFramework for civil cryptography products exported/imported under licenseList of civil cryptography products subject to licenseApply only if the model has regulated civil cryptography functions.
DecreeDecree 37/2026/ND-CPGovernmentEffective from 23/01/2026Quality inspection, traceability, conformity and imported goods quality handling frameworkImported goods quality control provisionsUse for quality mechanism review if goods are group 2.
TariffCurrent import-export tariff scheduleMinistry of Finance/GovernmentAt declaration dateDetermines general duty, MFN, VAT and special preferential dutyHS 8517.62.59 and alternatives if anyCheck the customs tariff system on declaration date.

VIEW / DOWNLOAD ORIGINAL LEGAL DOCUMENTS

Enterprises may search documents by number on the legal document portal, the Government e-portal or websites of issuing authorities. Enterprises should also verify the documents on the legal document portal or the issuing authority’s website before applying them.

CUSTOMS DOCUMENT SET

Commercial documents

Specialized files if applicable

  • Import license for cybersecurity products if the model falls within the list.
  • Civil cryptography file if the device has regulated cryptographic functions.
  • Quality inspection registration, conformity certification/declaration if classified as ICT group 2.
  • Test report, technical documents, license sheet, security feature list.
  • Goods labeling file, Vietnamese sub-label and origin evidence.
File groupRequired documentsUsed for which stepCommon preparerCommon errorPre-ETA check method
Commercial documentsInvoice, Packing List, B/L or AWB, contract/POCustoms declaration, value, quantity and trade termsImporter, shipper, forwarderGeneric goods name, mismatched model, no email security function shownCompare each model, quantity and origin against catalogue and label.
Technical documentsCatalogue, datasheet, admin guide, user manual, security feature listHS, cybersecurity, civil cryptography and ICT group 2 reviewManufacturer, buyer, compliance teamOnly marketing brochure, no technical functionsRequest datasheet and declaration before booking.
Cybersecurity license if applicableDossier for import license of cybersecurity productsClearance if goods are listedImporter/compliance and competent authorityAppendix I not checked or license does not match modelReview list and model before ETA.
Civil cryptography file if applicableLicense/conformity documents for civil cryptography products if listedClearance/market circulation when cryptographic functions are regulatedImporter, manufacturer, Government Cipher authority/consultantConfusing ordinary encryption with regulated civil cryptography or missing key management functionRequest manufacturer encryption function confirmation.
Origin fileC/O, through transport document, third-party invoice if anyFTA duty preferenceShipper, exporter, importerWrong form, origin criterion, goods description or HS codeCheck draft C/O before official issuance.
Label fileOriginal label, Vietnamese sub-label, responsible party details, model/serialClearance/domestic circulationImporter, supplier, warehouseMissing model, origin or responsible organizationObtain original label photos before ETA.

Matching rule: Goods name, quantity, model, serial, origin and technical specifications must match across commercial documents, catalogue, labels, specialized files and customs declaration.

DECISION POINTS THAT MAY HOLD THE SHIPMENT

Decision pointQuestion to answerProof documentsConsequence if unclearRecommended handling
HS codeIs the device sufficiently supported under 8517.62.59 or essentially a server/ADP machine?Datasheet, catalogue, admin guide, port photosReclassification request and delayed clearancePrepare classification memo with technical files.
Cybersecurity licenseDoes the model fall under cybersecurity products subject to import license?Circular 13/2018, Circular 10/2022, datasheetCargo may be held pending license supplementationReview list by model and functions before ETA.
Civil cryptographyDoes the device have dedicated encryption, key management or regulated VPN/email encryption?Encryption declaration, whitepaper, admin guideAdditional license/MMDS review may ariseRequest manufacturer written confirmation.
Model/serialDo documents, catalogue, label and license sheet match?Invoice, packing list, label, model list, license sheetChannel escalation and lengthy explanationLock model list before shipper issues documents.
C/OIs C/O correct in form, origin criterion, description and HS code?Draft C/O, invoice, bill, packing listLoss of preferential FTA dutyCheck draft C/O line by line.
Goods conditionIs the cargo brand new, used or refurbished?Invoice, contract, product photos, serialUsed ICT policy may applyDo not buy used/refurbished goods before policy review.

PRACTICAL E2E PROCESS

Pre-ETA review

Finalize HS code, duty, C/O, label, goods condition, cybersecurity license, civil cryptography if any and ICT group 2 possibility. For Email Security, review security and encryption functions before booking.

Lock commercial and technical documents

Compare Invoice, Packing List, B/L/AWB, catalogue, datasheet, model list, license sheet and original label. Goods name must be consistent across commercial documents, technical files and customs declaration.

Apply for license/specialized inspection if applicable

If the model falls under cybersecurity, civil cryptography or ICT group 2 lists, prepare license files, test reports or conformity files before ETA. Do not wait until cargo arrival to ask the manufacturer about security functions.

Submit customs declaration

Green channel may clear under system conditions; Yellow channel checks documents; Red channel checks documents and actual goods. Sensitive points include HS, value, model, C/O, cybersecurity function and encryption.

Clearance, delivery and post-clearance file closure

Move cargo to warehouse, complete sub-label/conformity mark if applicable, archive shipment file, license sheet and explanation package for post-clearance audit.

PRE-ETA RISK CHECKLIST

RiskConsequencePre-ETA preventionDocuments to check
Goods described too generally as “server/security appliance”Wrong HS, wrong license, request for additional documentsState Email Security appliance/gateway, model and email filtering/protection functionInvoice, packing list, catalogue, datasheet.
Cybersecurity import licensing list not reviewedCargo held pending licenseCompare Circular 13/2018 and Circular 10/2022 by model and functionDatasheet, feature list, legal list.
Encryption/civil cryptography function missedMMDS review and delayed clearanceAsk manufacturer to confirm encryption/VPN/key management/TLS inspection functionsAdmin guide, whitepaper, declaration.
Model mismatch among invoice, packing list, label and licenseChannel escalation and lengthy explanationLock model and serial list before shipper issues documentsInvoice, PL, label, license sheet.
C/O wrong form or wrong goods descriptionLoss of special preferential dutyCheck draft C/O, origin criterion, HS code, goods description and transport routeDraft C/O, invoice, bill.
Goods condition not reviewedUsed ICT policy issueConfirm goods condition in contract, invoice and labelsContract, invoice, product photos, serial.

FAQ – COMMON ENTERPRISE QUESTIONS

Does Email Security import require a license?

It may require import license review if the product is listed as a cybersecurity product. Do not conclude by product name only; check model, functions and technical files.

Is quality inspection or conformity certification required?

Review is needed if the device falls under ICT group 2 or has telecom/radio functions. The conclusion depends on actual model and specifications.

Is a Vietnamese sub-label required?

It may be required when goods circulate in Vietnam. The label should match model, origin, manufacturer and responsible organization in the actual file.

Can C/O reduce duty?

It may, provided the C/O is valid, issued under the correct agreement, form, origin criterion, goods description and HS code.

Are samples/warranty replacements processed like commercial goods?

Not automatically. Samples or warranty replacements must still be declared according to actual nature, quantity, value, condition and applicable specialized policies.

What if the invoice model differs from the catalogue?

Request the shipper to amend documents or provide a model confirmation letter before customs declaration. Do not leave model discrepancies until cargo arrives.

TGIMEX EXECUTION SOLUTION

This guide provides a map of HS code, duties, documents and specialized policies for Email Security. For a real shipment, enterprises should still review actual catalogue, datasheet, model, documents, origin and import purpose.

Support scope

  • Pre-ETA review: HS code, specialized policy, cybersecurity/MMDS license, C/O, duties and labeling.
  • Cross-check Invoice, Packing List, B/L/AWB, catalogue, test report, license sheet, labels and technical files.
  • Coordinate international freight, pre-alert, ETA and customs dossier.

Operational risk control

  • Prepare customs declaration file and handle Green/Yellow/Red channels.
  • Support explanation on HS code, customs value, origin and specialized policy.
  • Archive shipment files and review sub-label/conformity mark if applicable.

For shipments that may involve specialized inspection, licenses, C/O or labeling requirements, enterprises should not wait until cargo arrival to start dossier review. A small inconsistency among Invoice, Packing List, catalogue, datasheet, C/O or labels may lead to additional document requests, delayed clearance or unplanned storage costs.

QUICK CONSULTATION

NEED TO REVIEW IMPORT PROCEDURES OR A SHIPPING PLAN?

Send us the product name, shipping route, current dossier, or implementation request in advance so we can suggest a suitable approach that is practical, focused, and aligned with your shipment.

CALL NOW
Zalo
HOTLINE 0963 856 664 / 0982 135 393
EMAIL info@tgimex.com
SUITABLE FOR International shipping · Customs procedures · Import licenses · B2B logistics

Leave a Reply

Discover more from TGIMEX VIETNAM JSC

Subscribe now to keep reading and get access to the full archive.

Continue reading