PC/Server Protection Appliance Import Procedure in Vietnam

CYBER SECURITY APPLIANCE / ENDPOINT PROTECTION

PC/SERVER PROTECTION APPLIANCE IMPORT PROCEDURE IN VIETNAM

A PC/server protection appliance can trigger customs classification, cybersecurity import licensing, civil cryptography review, ICT conformity, import labeling and technical dossier checks at the same time. This guide provides an E2E (End-to-End) map for reviewing HS code, proposed taxes, C/O, specialized policy, customs documents and pre-ETA risks before shipment arrival. For the product covered in this article, the importer should confirm the model, intended use, construction or composition, new/used condition, and technical documents before concluding the HS code, tax treatment, or specialist policy. The following sections organize the main controls from document receipt, catalogue and label review through dossier preparation, declaration, and coordination at the port of entry.

QUICK FACT

Review itemOperational recommendation
Product scopePC/server protection appliance in hardware form for protecting PCs/servers, managing endpoints, filtering malware, enforcing endpoint policy or acting as an endpoint protection gateway.
Not automatically coveredSoftware-only Mobile Security, endpoint agents/licenses, firewall/NAC/IPS/IDS/DDoS/SIEM/UTM, VPN appliance, WAF or web app security appliance if the model/function differs.
Reference HS8517.62.59 if the goods are network data transmission/reception equipment with Ethernet/SFP ports and endpoint/server protection functions over a network.
Proposed taxesOrdinary import duty: 5% reference; MFN import duty: 0%; VAT: 10%; special preferential duty under C/O: usually reviewed toward 0% if the C/O is valid and FTA conditions are met.
Key policiesReview cybersecurity product import license; civil cryptography if encryption/authentication/key-management functions exist; ICT Group-2 conformity if telecom/radio functions exist; used/refurbished IT goods policy if applicable.
Technical dossierCatalogue, datasheet, user manual, model list, security function description, encryption statement, software/license list and test report if available.
Illustration for PC/Server Protection Appliance Import Procedure in Vietnam
Illustration of the product group and document review before customs clearance.

SCOPE OF APPLICATION

This article covers PC/server protection appliance only. It must not be automatically applied to Mobile Security software, endpoint protection gateway, firewall, VPN appliance, NAC, IPS/IDS, UTM, WAF, web application security appliance or any product with different specifications/functions.

Legal note: Review by catalogue, datasheet, model and actual import purpose. Do not conclude that no license is required without checking the exact model, firmware, security functions, encryption functions, interfaces, license package and import purpose.

CLASSIFICATION & TECHNICAL IDENTIFICATION

Identify the goods by catalogue, datasheet, model, main function, hardware configuration, network interfaces, firmware, security function, license package, condition and actual use. Generic descriptions such as “security appliance” may lead to wrong HS code, wrong license position or missing technical evidence.

Criteria to checkDocuments to compareRisk if misdescribedSuggested goods description
Product natureCatalogue, datasheet, user manualConfusion among network equipment, server appliance, software license and specialized security productPC/server protection appliance, model…, brand…, new 100%, for endpoint/server protection
Network interfacesDatasheet, Ethernet/SFP photosWrong HS between heading 8517 and 8471Security gateway appliance with Ethernet ports and endpoint/server protection function
Security functionsSecurity datasheet, admin guideCybersecurity product license may be missedProtection appliance for PC/server, anti-malware/endpoint policy management
Encryption/VPN/authenticationEncryption statement, firmware feature listCivil cryptography review may be triggeredDescribe encryption/VPN functions based on technical dossier if any
Software/license packagePO, invoice, license sheetIncorrect customs value and unclear split between hardware/softwareSeparate hardware appliance, embedded software and subscription/license if any
Goods conditionInvoice, serial list, labelsUsed/refurbished policy riskDeclare new/refurbished/used accurately before shipment

HS CODE – DUTY – C/O

HS classification depends on technical nature: network data transmission/reception equipment, ADP unit or software/license. Do not classify solely by the commercial term “protection appliance”.

Reference HS codeApplication conditionRisk of wrong classificationDocuments to compare
8517.62.59Network data transmission/reception appliance used to protect PCs/servers over a network.Wrong telecom/cybersecurity policy, wrong duty and customs queries.Catalogue, datasheet, network diagram, gateway functions.
8471.50.90 / 8471.80.90Only considered if the product is essentially an ADP processing unit rather than network communication equipment.Wrong technical policy and customs explanation.CPU/RAM/storage, OS, system architecture.
8523 or software-related headingOnly if the import is software/license/subscription without hardware.Wrong valuation and goods nature.PO, license certificate, delivery method, activation key.

Duty and C/O review table

ItemSpecific proposed levelApplication conditionRisk note
Main proposed HS8517.62.59When the product is a network data transmission/reception appliance.Confirm against actual model and customs tariff at declaration date.
Ordinary import duty5% referenceUsed as a planning reference where preferential schemes are not available.Re-check current tariff before customs declaration.
MFN import duty0%Reference data for HS 8517.62.59.Not a binding customs classification ruling.
VAT10%Reference data for HS 8517.62.59.Review VAT policy at import date.
Special preferential duty under C/OUsually reviewed toward 0% if validDepends on FTA, C/O form, origin criterion and goods description.Wrong C/O form, HS or description may lead to rejection.

SPECIALIZED POLICY MATRIX

Goods situationPossible policyDocuments to checkAuthority/portal if identifiedRecommended timingRisk note
Standard PC/server protection applianceCybersecurity product import license review.Catalogue, datasheet, security functions, model list.MIC/AIS or relevant public service portal.Before ETA, preferably before PO.Do not conclude “no license” without list review.
Endpoint protection gatewayCybersecurity product policy and HS 8517.62.59 review.Network diagram, admin guide.Specialized authority/customs.Before shipping documents.May be confused with firewall/VPN/NAC/UTM.
Encryption/VPN/key management functionsCivil cryptography review if listed.Encryption statement, firmware guide.Government Cipher Committee/related portal if applicable.Before ETA.General encryption and licensed civil cryptography must be separated by dossier.
Wireless module integratedICT Group-2/conformity/radio review if applicable.RF specification, test report.MoST/MIC or designated bodies.Before ETA.May trigger conformity/quality procedures.
Software/license/subscriptionCustoms valuation and software nature review.PO, invoice, license certificate.Customs/tax review if necessary.Before invoice finalization.Avoid unclear aggregation with hardware value.
Used/refurbished goodsUsed IT goods policy review.Condition statement, serial list.Customs/specialized authority.Before purchase.High risk if declared new while serial/labels show refurbished.

LEGAL DOCUMENTS TO REVIEW

Document groupDocument number/nameIssuing bodyEffective date/timingRole in procedureKey article/appendix if anyReview note
LawLaw on Cyberinformation Security No. 86/2015/QH13National AssemblyReview current validityLegal foundation for cybersecurity and civil cryptography products.Relevant provisions on products/services.Review implementing documents.
DecreeDecree 108/2016/ND-CPGovernmentEffective from 01/07/2016Conditions for cybersecurity products/services business.Product/service conditions.Check amendments if any.
CircularCircular 13/2018/TT-BTTTTMICEffective from 01/12/2018List and licensing procedure for imported cybersecurity products.Appendix/list and licensing dossier.Review with Circular 10/2022.
Amending CircularCircular 10/2022/TT-BTTTTMICEffective from 15/09/2022Amends Circular 13/2018.Amended list/procedure if applicable.Use consolidated/updated text.
CircularCircular 29/2025/TT-BKHCNMoSTEffective from 31/12/2025ICT Group-2 goods and conformity review.Appendices/QCVN where applicable.Apply only if the model/function is listed.
DecreeDecree 211/2025/ND-CPGovernmentEffective from 09/09/2025Civil cryptography activities and import/export licensing.Appendices for civil cryptography products.Apply only if functions are listed.
LabelingDecree 43/2017/ND-CP and Decree 111/2021/ND-CPGovernmentReview current validityImport labeling.Mandatory label contents.Model, origin and importer must match.
TariffCurrent import/export tariff and customs databaseMoF/GDVCAt declaration dateDuty, VAT and FTA rates.HS 8517.62.59 and alternatives.Re-check before declaration.

VIEW / DOWNLOAD ORIGINAL LEGAL TEXTS

Enterprises should re-check the official legal database or the issuing authority website before application.

CUSTOMS DOCUMENT DOSSIER

Commercial documents

Specialized documents if applicable

  • Cybersecurity product import license.
  • Civil cryptography dossier/license where applicable.
  • ICT conformity/quality inspection dossier where applicable.
  • Test report, security datasheet, encryption statement, software/license list.
  • Import labeling dossier.
Document groupRequired documentsUsed forUsually prepared byCommon errorPre-ETA check
CommercialInvoice, Packing List, Contract/PODeclaration, valuation, C/OImporter/seller/docs teamGeneric goods descriptionApprove drafts before issue.
TechnicalCatalogue, datasheet, manual, model/serial listHS and policy explanationSupplier/importer technical teamWrong model datasheetLock model list before shipment.
Cybersecurity/cryptoLicense/dossier, security functions, encryption statementSpecialized policyImporter/compliance/supplierFunctions not clearly separatedReview product list before ETA.
C/OC/O draft/originalPreferential dutySeller/exporter/importerWrong HS/form/descriptionCheck C/O draft before issuance.
LabelingOriginal label, Vietnamese sub-labelCirculation/post-clearanceImporter/warehouseMissing model/origin/importerPrepare sub-labels before distribution.

CLEARANCE DECISION POINTS THAT MAY HOLD THE SHIPMENT

Decision pointQuestion to answerSupporting documentConsequence if unclearRecommended handling
HS codeNetwork appliance, ADP unit or software/license?Catalogue, datasheet, diagramWrong duty/policyFinalize HS before ETA.
Cybersecurity licenseIs the model listed as licensed cybersecurity product?Circular 13/2018, 10/2022, function listLicense/explanation requestReview list before purchase.
Civil cryptographyDoes it include listed encryption/key management?Encryption statementLicense riskGet supplier confirmation.
Model/licenseAre hardware and license separated?Invoice, PO, license certificateValuation and description riskSplit clearly in documents.
C/OCorrect form, HS, description and origin criterion?C/O draft, invoiceFTA rejectedReview draft before shipment.
ConditionNew, demo, refurbished or used?Serials, labels, invoiceUsed-goods policy riskVerify before contract.

PRACTICAL E2E PROCESS

Pre-ETA review. Finalize HS, taxes, C/O, cybersecurity, civil cryptography, ICT conformity, labeling, goods condition and import purpose.
Lock documents and technical dossier. Confirm Invoice, Packing List, B/L/AWB, catalogue, datasheet, model/serial list, security function list and encryption statement.
Apply for license/specialized procedure if applicable. Prepare cybersecurity, civil cryptography or ICT conformity dossier by exact model before the goods arrive.
Submit customs declaration. Prepare explanations for value, HS, product name, model, license, C/O, catalogue and specialized policy under Yellow/Red channel.
Clearance, delivery and post-clearance control. Release goods, apply sub-labels if required, archive dossier by shipment and manage license/software records.

PRE-ETA RISK CHECKLIST

RiskConsequencePre-ETA controlDocuments to check
Generic “security appliance” descriptionAdditional query and delayUse detailed model/function descriptionInvoice, PL, catalogue
Wrong HS between 8517 and 8471Wrong duty/policyConfirm technical natureDatasheet, diagram
Missing cybersecurity license reviewPossible license requestReview Circular 13/2018 and 10/2022Security function list
Encryption functions not checkedCivil cryptography riskGet written encryption statementFirmware/admin guide
Model mismatchSpecialized dossier rejectedLock model/serial listInvoice, label, datasheet
C/O mismatchFTA benefit lostReview C/O draftC/O, invoice, B/L
Refurbished/used misdeclaredPenalty/re-export riskVerify goods conditionInvoice, serial, statement

FAQ

Does a PC/server protection appliance need an import license?

Possibly, if the exact model is listed as a cybersecurity product requiring import licensing. Do not conclude without reviewing model, firmware and security functions.

Is it a civil cryptography product?

Only after checking encryption, authentication, key management, VPN and use purpose. If listed, a separate license may be required.

Can HS 8517.62.59 be used for all models?

No. It is only a reference where the goods are network data transmission/reception appliances. Server appliances or software-only imports require separate review.

Is Vietnamese labeling required?

If the goods circulate in Vietnam, import labeling requirements should be reviewed and the label must match model, origin and importer information.

Does C/O reduce duty?

It may. Although MFN may already be 0% for the reference HS, C/O is still important for FTA preference and origin control.

Should license/subscription be declared separately?

Review the contract, invoice and delivery method. If separately priced, customs value and goods description must be controlled clearly.

EXECUTION SUPPORT FROM TGIMEX

This article provides a map of HS code, duties, documents and specialized policy. In real shipments, enterprises still need to review catalogue, datasheet, model, documents, origin and import purpose.

Pre-ETA review HS, cybersecurity, civil cryptography, ICT conformity, C/O, tax, labeling and technical dossier.
Compliance control Cross-check Invoice, Packing List, B/L/AWB, C/O, catalogue, security functions and labels.
International logistics Coordinate agents, carriers/airlines, ETA, pre-alert and transport documents.
Declaration & post-clearance Prepare customs dossier, handle Green/Yellow/Red channels and archive records.

For shipments with potential specialized inspection, licensing, C/O or labeling issues, enterprises should not wait until arrival to start dossier review.

QUICK CONSULTATION

NEED TO REVIEW IMPORT PROCEDURES OR A SHIPPING PLAN?

Send us the product name, shipping route, current dossier, or implementation request in advance so we can suggest a suitable approach that is practical, focused, and aligned with your shipment.

CALL NOW
Zalo
HOTLINE 0963 856 664 / 0982 135 393
EMAIL info@tgimex.com
SUITABLE FOR International shipping · Customs procedures · Import licenses · B2B logistics

Leave a Reply

Discover more from TGIMEX VIETNAM JSC

Subscribe now to keep reading and get access to the full archive.

Continue reading