IMPORT PROCEDURE GUIDE FOR EMAIL SECURITY APPLIANCE
An Email Security appliance/gateway is a cybersecurity device used to filter spam, detect malware, control SMTP traffic, prevent phishing, sandbox attachments or enforce DLP policies in enterprise networks. If it is described only as “server”, “network appliance” or “security box”, the shipment may be exposed to wrong HS classification, cybersecurity import licensing issues, civil cryptography review, model mismatch between documents and catalogue, or DEM/DET costs due to missing pre-ETA files. This guide provides an E2E map for reviewing HS code, duties, specialized policies, documents, customs process and risks before cargo arrival.
QUICK FACT
| Review item | Direction for Email Security | Operational note |
|---|---|---|
| Recommended product name | Email Security appliance or Email Security gateway used to control, filter and protect enterprise email traffic | Do not describe it simply as “server” if the main function is email security or cybersecurity. |
| Suggested HS code | 8517.62.59 for a complete network apparatus that transmits, receives, converts or processes email data in a network; review separately if the device is essentially an automatic data processing server | If it is a pure server, software license, virtual appliance or subscription, classification and procedures will differ. |
| Suggested taxes | General import duty 5%; MFN duty 0%; VAT 10%; FTA duty may be 0% with valid C/O | Verify tariff schedule, C/O and goods condition on the customs declaration date. |
| Specialized policy | May fall under cybersecurity products subject to import license; civil cryptography review may arise if dedicated encryption functions exist | Review Circular 13/2018/TT-BTTTT, Circular 10/2022/TT-BTTTT, Decree 108/2016/ND-CP and technical files. |
| Key technical files | Catalogue, datasheet, admin guide, user manual, security feature list, license sheet, model list, test report if any, label and serial photos | Clarify whether it is hardware or software-only, and whether encryption/VPN/TLS inspection/key management, Wi-Fi/Bluetooth, battery or adapter is included. |
SCOPE OF APPLICATION
Applicable to
- Hardware Email Security appliance/gateway as a complete physical device with Ethernet ports and specialized operating system/firmware.
- Devices used for email filtering, anti-spam, anti-phishing, anti-malware, attachment inspection, sandboxing, DLP or enterprise email protection gateway.
- New goods imported for trading, IT projects, EPE/FDI/factory deployment or enterprise systems.
Not automatically applicable to
- WAF, firewall, UTM, IDS/IPS, load balancer, proxy gateway or web application security appliances.
- Software license, cloud subscription, virtual appliance, activation key or implementation service not accompanied by physical equipment.
- General purpose server installed with email security software after import; this case requires separate HS and policy review.
CLASSIFICATION & TECHNICAL IDENTIFICATION
Email Security must be identified by its main function, hardware configuration, network role, bundled license and security processing capability. A rackmount device may be a server, firewall, gateway or dedicated cybersecurity product; therefore, the goods description should be based on catalogue/datasheet rather than external appearance only.
| Criteria to check | Documents to compare | Risk if described incorrectly | Suggested description on documents/declaration |
|---|---|---|---|
| Main function | Catalogue, datasheet, solution brief, admin guide | Wrong HS code or wrong cybersecurity policy | Email Security appliance, model…, used to filter and protect enterprise email traffic, brand new. |
| Physical goods or license | Invoice, packing list, license sheet, contract/PO | Misdeclaration between tangible goods and software/service | Separate hardware, license, subscription and support line items where applicable. |
| Network configuration | Datasheet, port photos, deployment diagram | Customs may question why it is classified as data transmission/reception apparatus | State that it has Ethernet ports, network communication and email data processing functions. |
| Security functions | Security feature list, admin guide | May trigger import license for cybersecurity products | Specify anti-spam, anti-malware, sandbox, DLP and policy control if available. |
| Encryption/cryptography | Datasheet, compliance statement, encryption declaration | May trigger civil cryptography review if dedicated encryption exists | Separate TLS inspection, email encryption, key management or VPN functions if any. |
| Goods condition | Invoice, contract, label/serial photos | May trigger policy for used/refurbished ICT goods | State brand new; do not import used/refurbished goods without policy review. |
HS CODE – DUTIES – C/O
For a hardware Email Security appliance, HS code should be determined based on data transmission/reception/processing function in a network, hardware configuration, operating principle and technical documentation. HS 8517.62.59 is used as the main review direction for a device that processes, forwards or controls email data in a network. If the device is essentially an automatic data processing server or a software/license item without hardware, it must be classified separately.
| Suggested HS code | Application condition | Risk if wrongly applied | Documents to compare |
|---|---|---|---|
| 8517.62.59 | Complete network apparatus that transmits/receives/converts/processes email data and performs email security in a network | Duty reassessment, C/O rejection, classification explanation or customs channel escalation | Catalogue, datasheet, deployment diagram, port photos, user/admin guide. |
| 8471.50.90 / 8471.49.00 | Consider only if the goods are essentially an automatic data processing machine/server imported as server configuration and security function is software-based | Wrong policy if server code is applied to a dedicated cybersecurity appliance | BOM, CPU/RAM/storage configuration, OS, license sheet, main function description. |
| Not applicable to license-only | Cases involving only license, key, subscription, cloud service or activation code | Wrong declaration of goods type, customs value and tax obligation | Service contract, license invoice, payment documents and electronic delivery description. |
| Tax item | Suggested rate | Application condition | Risk note |
|---|---|---|---|
| General import duty | 5% | Applies when preferential treatment is not available or no suitable C/O is provided | Verify the tariff schedule on the declaration date. |
| MFN import duty | 0% | Applies if the goods originate from an MFN beneficiary and the final HS code is appropriate | Does not replace specialized policy obligations. |
| VAT | 10% | Applies to imported goods unless another VAT rate is legally applicable | Depends on final HS code, tax policy and import file at the time of import. |
| Special FTA duty | May be 0% with valid C/O | C/O must match form, origin criterion, goods description, quantity, value, transport route and HS code | C/O errors may lead to loss of preference even if HS is correct. |
APPLICABLE SPECIALIZED POLICIES
| Goods situation | Possible policy | Documents to check | Authority/processing portal if identifiable | Recommended timing | Risk note |
|---|---|---|---|---|---|
| Complete Email Security appliance | Review cybersecurity product import licensing | Catalogue, datasheet, security feature list, license sheet, admin guide | Cybersecurity authority/public service portal under current regulations | Before booking or at least before ETA | Do not conclude “no license required” without checking the applicable appendix. |
| Device with anti-attack, intrusion prevention or security monitoring functions | May fall under cybersecurity product categories under Decree 108/2016 and Circular 13/2018 as amended by Circular 10/2022 | Technical description, security functions, datasheet, model list | Authority of Information Security or successor authority under current structure | Before cargo arrival | If listed and license is missing, cargo may be held for supplementation. |
| Dedicated encryption, email encryption, key management, VPN or advanced TLS inspection | Civil cryptography review may be required | Encryption declaration, technical whitepaper, admin guide | Government Cipher Committee/public service portal if applicable | Before PO confirmation | Do not label as civil cryptography unless the actual functions match the regulated list. |
| With Wi-Fi/Bluetooth/4G/5G | ICT group 2 and radio conformity may arise | Wireless module datasheet, frequency, output power, test report | ICT/telecom authority under Circular 29/2025/TT-BKHCN | Before ETA | Rackmount Email Security usually has no wireless function; review separately if any wireless module exists. |
| With adapter, battery or separate power supply | Electrical safety, labeling and DG review if lithium battery exists | Accessory catalogue, battery MSDS, adapter specifications | Customs, carrier, certification body if applicable | Before packing | Accessories may trigger separate HS code or policy. |
| Used/refurbished goods | Used ICT goods import prohibition/conditional permission review | Invoice, contract, serial, goods condition, equipment photos | Specialized authority under Circular 26/2025/TT-BKHCN if within scope | Before purchase | Do not import used/refurbished goods under a “project equipment” assumption without legal basis. |
LEGAL DOCUMENTS TO REVIEW
| Document group | Document name/number | Issuing authority | Effective date/application timing | Role in the procedure | Key article/appendix if any | Review note |
|---|---|---|---|---|---|---|
| Law | Law on Cyberinformation Security No. 86/2015/QH13 | National Assembly | Effective from 01/07/2016 | Legal framework for cybersecurity products/services and civil cryptography | Review chapters on civil cryptography and cybersecurity products | Compare with actual Email Security functions. |
| Decree | Decree 108/2016/ND-CP | Government | Effective from 01/07/2016 | Conditions for trading cybersecurity products/services and import-licensed cybersecurity products | Articles 1, 2, 3 and related forms/appendices if applicable | Do not invent licensing conclusions; check the list. |
| Circular | Circular 13/2018/TT-BTTTT | Ministry of Information and Communications | Effective from 01/12/2018 | List of cybersecurity products subject to import license and licensing dossier | Appendix I and Article 3 on complete equipment | Critical for security appliances. |
| Amending circular | Circular 10/2022/TT-BTTTT | Ministry of Information and Communications | Effective from 15/09/2022 | Amends Circular 13/2018 and replaces appendices/procedure details | Appendix I, Appendix II, Article 1 | Check the consolidated/current text at import date. |
| Circular | Circular 29/2025/TT-BKHCN | Ministry of Science and Technology | Effective from 31/12/2025 | List of goods posing safety risks in ICT and telecommunications | ICT group 2 appendix | Review if ICT/telecom functions fall within the list. |
| Circular | Circular 26/2025/TT-BKHCN | Ministry of Science and Technology | Effective from 31/10/2025 | Management of used ICT goods on the prohibited import list and permitted cases | Article 1, Article 3 and appendices if applicable | Applies to used/refurbished goods. |
| Decree | Decree 58/2016/ND-CP, Decree 53/2018/ND-CP and Decree 32/2023/ND-CP | Government | Check current validity | Framework for civil cryptography products exported/imported under license | List of civil cryptography products subject to license | Apply only if the model has regulated civil cryptography functions. |
| Decree | Decree 37/2026/ND-CP | Government | Effective from 23/01/2026 | Quality inspection, traceability, conformity and imported goods quality handling framework | Imported goods quality control provisions | Use for quality mechanism review if goods are group 2. |
| Tariff | Current import-export tariff schedule | Ministry of Finance/Government | At declaration date | Determines general duty, MFN, VAT and special preferential duty | HS 8517.62.59 and alternatives if any | Check the customs tariff system on declaration date. |
VIEW / DOWNLOAD ORIGINAL LEGAL DOCUMENTS
Enterprises may search documents by number on the legal document portal, the Government e-portal or websites of issuing authorities. Enterprises should also verify the documents on the legal document portal or the issuing authority’s website before applying them.
CUSTOMS DOCUMENT SET
Commercial documents
- Commercial Invoice.
- Packing List.
- Bill of Lading or Air Waybill.
- Sales Contract/Purchase Order if any.
- Certificate of Origin – C/O if preferential duty is claimed.
- Catalogue, datasheet, product photos, label photos and model–serial list.
Specialized files if applicable
- Import license for cybersecurity products if the model falls within the list.
- Civil cryptography file if the device has regulated cryptographic functions.
- Quality inspection registration, conformity certification/declaration if classified as ICT group 2.
- Test report, technical documents, license sheet, security feature list.
- Goods labeling file, Vietnamese sub-label and origin evidence.
| File group | Required documents | Used for which step | Common preparer | Common error | Pre-ETA check method |
|---|---|---|---|---|---|
| Commercial documents | Invoice, Packing List, B/L or AWB, contract/PO | Customs declaration, value, quantity and trade terms | Importer, shipper, forwarder | Generic goods name, mismatched model, no email security function shown | Compare each model, quantity and origin against catalogue and label. |
| Technical documents | Catalogue, datasheet, admin guide, user manual, security feature list | HS, cybersecurity, civil cryptography and ICT group 2 review | Manufacturer, buyer, compliance team | Only marketing brochure, no technical functions | Request datasheet and declaration before booking. |
| Cybersecurity license if applicable | Dossier for import license of cybersecurity products | Clearance if goods are listed | Importer/compliance and competent authority | Appendix I not checked or license does not match model | Review list and model before ETA. |
| Civil cryptography file if applicable | License/conformity documents for civil cryptography products if listed | Clearance/market circulation when cryptographic functions are regulated | Importer, manufacturer, Government Cipher authority/consultant | Confusing ordinary encryption with regulated civil cryptography or missing key management function | Request manufacturer encryption function confirmation. |
| Origin file | C/O, through transport document, third-party invoice if any | FTA duty preference | Shipper, exporter, importer | Wrong form, origin criterion, goods description or HS code | Check draft C/O before official issuance. |
| Label file | Original label, Vietnamese sub-label, responsible party details, model/serial | Clearance/domestic circulation | Importer, supplier, warehouse | Missing model, origin or responsible organization | Obtain original label photos before ETA. |
Matching rule: Goods name, quantity, model, serial, origin and technical specifications must match across commercial documents, catalogue, labels, specialized files and customs declaration.
DECISION POINTS THAT MAY HOLD THE SHIPMENT
| Decision point | Question to answer | Proof documents | Consequence if unclear | Recommended handling |
|---|---|---|---|---|
| HS code | Is the device sufficiently supported under 8517.62.59 or essentially a server/ADP machine? | Datasheet, catalogue, admin guide, port photos | Reclassification request and delayed clearance | Prepare classification memo with technical files. |
| Cybersecurity license | Does the model fall under cybersecurity products subject to import license? | Circular 13/2018, Circular 10/2022, datasheet | Cargo may be held pending license supplementation | Review list by model and functions before ETA. |
| Civil cryptography | Does the device have dedicated encryption, key management or regulated VPN/email encryption? | Encryption declaration, whitepaper, admin guide | Additional license/MMDS review may arise | Request manufacturer written confirmation. |
| Model/serial | Do documents, catalogue, label and license sheet match? | Invoice, packing list, label, model list, license sheet | Channel escalation and lengthy explanation | Lock model list before shipper issues documents. |
| C/O | Is C/O correct in form, origin criterion, description and HS code? | Draft C/O, invoice, bill, packing list | Loss of preferential FTA duty | Check draft C/O line by line. |
| Goods condition | Is the cargo brand new, used or refurbished? | Invoice, contract, product photos, serial | Used ICT policy may apply | Do not buy used/refurbished goods before policy review. |
PRACTICAL E2E PROCESS
Pre-ETA review
Finalize HS code, duty, C/O, label, goods condition, cybersecurity license, civil cryptography if any and ICT group 2 possibility. For Email Security, review security and encryption functions before booking.
Lock commercial and technical documents
Compare Invoice, Packing List, B/L/AWB, catalogue, datasheet, model list, license sheet and original label. Goods name must be consistent across commercial documents, technical files and customs declaration.
Apply for license/specialized inspection if applicable
If the model falls under cybersecurity, civil cryptography or ICT group 2 lists, prepare license files, test reports or conformity files before ETA. Do not wait until cargo arrival to ask the manufacturer about security functions.
Submit customs declaration
Green channel may clear under system conditions; Yellow channel checks documents; Red channel checks documents and actual goods. Sensitive points include HS, value, model, C/O, cybersecurity function and encryption.
Clearance, delivery and post-clearance file closure
Move cargo to warehouse, complete sub-label/conformity mark if applicable, archive shipment file, license sheet and explanation package for post-clearance audit.
PRE-ETA RISK CHECKLIST
| Risk | Consequence | Pre-ETA prevention | Documents to check |
|---|---|---|---|
| Goods described too generally as “server/security appliance” | Wrong HS, wrong license, request for additional documents | State Email Security appliance/gateway, model and email filtering/protection function | Invoice, packing list, catalogue, datasheet. |
| Cybersecurity import licensing list not reviewed | Cargo held pending license | Compare Circular 13/2018 and Circular 10/2022 by model and function | Datasheet, feature list, legal list. |
| Encryption/civil cryptography function missed | MMDS review and delayed clearance | Ask manufacturer to confirm encryption/VPN/key management/TLS inspection functions | Admin guide, whitepaper, declaration. |
| Model mismatch among invoice, packing list, label and license | Channel escalation and lengthy explanation | Lock model and serial list before shipper issues documents | Invoice, PL, label, license sheet. |
| C/O wrong form or wrong goods description | Loss of special preferential duty | Check draft C/O, origin criterion, HS code, goods description and transport route | Draft C/O, invoice, bill. |
| Goods condition not reviewed | Used ICT policy issue | Confirm goods condition in contract, invoice and labels | Contract, invoice, product photos, serial. |
FAQ – COMMON ENTERPRISE QUESTIONS
Does Email Security import require a license?
It may require import license review if the product is listed as a cybersecurity product. Do not conclude by product name only; check model, functions and technical files.
Is quality inspection or conformity certification required?
Review is needed if the device falls under ICT group 2 or has telecom/radio functions. The conclusion depends on actual model and specifications.
Is a Vietnamese sub-label required?
It may be required when goods circulate in Vietnam. The label should match model, origin, manufacturer and responsible organization in the actual file.
Can C/O reduce duty?
It may, provided the C/O is valid, issued under the correct agreement, form, origin criterion, goods description and HS code.
Are samples/warranty replacements processed like commercial goods?
Not automatically. Samples or warranty replacements must still be declared according to actual nature, quantity, value, condition and applicable specialized policies.
What if the invoice model differs from the catalogue?
Request the shipper to amend documents or provide a model confirmation letter before customs declaration. Do not leave model discrepancies until cargo arrives.
Tiếng Việt
中文 (中国)
NEED TO REVIEW IMPORT PROCEDURES OR A SHIPPING PLAN?
Send us the product name, shipping route, current dossier, or implementation request in advance so we can suggest a suitable approach that is practical, focused, and aligned with your shipment.
Cargo Damage at a Port or Warehouse: An Immediate Response Checklist
What Is General Average? How Cargo Interests Should Respond to a GA Notice
When should businesses photograph or video container stuffing and opening?
When Can Cargo Insurers Reject or Reduce a Claim?
Risks of Failing to Inspect a Container Before Cargo Stuffing
Risks of Failing to Inspect a Container Before Cargo Stuffing
What Documents Are Required for a Cargo Insurance Claim?
What Information Should a Cargo Damage Survey Record Contain?
Total Loss vs Partial Loss in Cargo Insurance: What Is the Difference?
Cargo Dented, Wet or Missing Packages: What Should a Business Do?
Who Must Arrange Insurance under CIF and CIP?
Export Process: From Purchase Order to Final Document Set
How Is Cargo Insurance Value Determined?
How Do ICC-A, ICC-B and ICC-C Cargo Insurance Conditions Differ?
When Should a Business Buy Separate Cargo Insurance?