IMPORT PROCEDURES FOR STORAGE SECURITY APPLIANCES
Storage security refers to appliances or technical solutions used to protect data at rest, often involving encryption, access control, anomaly monitoring, protection for storage repositories, NAS/SAN, backup systems or enterprise storage environments. If the goods are declared only as “security appliance” or “storage device”, the importer may misclassify the HS code, miss a cyberinformation security import licence, confuse the product with civil cryptography regulation, or prepare insufficient technical documents before ETA. This article provides an E2E (End-to-End) compliance map covering HS code, duty, C/O, sectoral policy, customs documents and critical risk points before the shipment arrives.
QUICK FACTS
| Product | Storage security – data-at-rest protection appliance, server appliance, module or dedicated security device. |
|---|---|
| Related group | Vulnerability scanner; database security; storage security; DLP. |
| Reference HS codes | 8471.41.90 / 8471.49.90 / 8517.62.43; if the product is a civil cryptographic product for stored-data protection, also review 8523.51.11 / 8523.51.21 / 8523.51.99 / 8523.52.00 / 8542.32.00. |
| Indicative taxes | Common MFN reference: 0%; ordinary import duty reference: 5%; VAT reserve rate: 10%, with 8% to be reviewed if VAT reduction conditions are met at declaration time. |
| Key policy | May fall under the list of cyberinformation security products subject to import licence; if cryptographic algorithms are used for stored-data protection, civil cryptography policy must also be reviewed. |
| Application note | Review catalogue, datasheet, model, encryption function, import purpose and actual technical documents before declaring. |
SCOPE OF APPLICATION
This article applies only to storage security products, namely appliances or dedicated solutions used to protect stored data in enterprise storage, data centres, backup repositories, storage servers or network-connected storage infrastructure.
Covered products
- Dedicated appliances for data-at-rest protection.
- Server appliances pre-installed with stored-data protection software.
- Devices for access control, encryption, monitoring and storage repository protection.
- Dedicated modules imported with a system and supported by clear technical documents.
Not automatically covered
- Ordinary NAS/SAN devices used only for storage.
- HDD, SSD, memory card or smart card without a dedicated security function.
- Online software licence without physical goods.
- DLP, database security or vulnerability scanner although they are in the same menu group.
Catalogue, datasheet, model and actual import purpose must be reviewed. New goods, used goods, refurbished goods, samples, warranty replacements and project goods may trigger different policies and documents.
CLASSIFICATION & TECHNICAL IDENTIFICATION
Storage security should be identified by its principal function. The key point is not merely “storage device” but data-at-rest protection: data encryption, key control, access rights, anomaly detection, data leakage prevention, backup protection or monitoring over storage repositories.
| Checkpoint | Documents to review | Risk if misdescribed | Suggested goods description |
|---|---|---|---|
| Main function | Catalogue, datasheet, user manual | Misclassified as ordinary server/storage or networking equipment | Storage security appliance for data-at-rest protection, model…, brand… |
| Encryption function | Encryption whitepaper, security specification, admin guide | Civil cryptography policy may be missed or wrong licence may be applied for | State encryption/data-at-rest protection if applicable |
| Hardware configuration | BOM, CPU/RAM/storage/network ports | Confusion between headings 8471, 8517 and storage media heading 8523 | Clarify appliance/server appliance/module/storage media |
| Deployment model | Deployment guide, network diagram | Insufficient evidence of security function during customs query | Purpose: enterprise storage security/data protection |
| Condition of goods | Invoice, packing list, label photos, serial list | Used/refurbished goods may require additional explanation or policy review | New 100% or actual condition as declared |
HS CODE – DUTY – C/O
For storage security, HS classification depends on the form and technical function. The same commercial name may fall under automatic data processing machines in heading 84.71, communication equipment in heading 85.17, or storage media/memory ICs in headings 85.23/85.42 if it is a civil cryptographic product for stored-data protection.
| Reference HS code | Application condition | Risk if wrongly applied | Documents to review |
|---|---|---|---|
| 8471.30.90 | Portable ADP machine weighing not more than 10 kg, including at least a central processing unit, keyboard and display; apply only if the storage security product actually has the corresponding portable/specialized device form. | Wrong if the product is a fixed server appliance, system or network device. | Catalogue, product photos, hardware configuration, dimensions/weight, datasheet. |
| 8471.41.90 | ADP machine in the same housing with CPU and input/output units, dedicated to storage security. | May be treated as ordinary server or networking equipment if security function is unclear. | Catalogue, hardware configuration, datasheet, security function. |
| 8471.49.90 | ADP system used for stored-data protection. | Insufficient evidence of system structure or principal function. | System diagram, model list, deployment documents. |
| 8517.62.43 | Control/adaptor units, gateways, bridges, routers or similar apparatus designed for connection with ADP machines and protecting access to storage systems. | Wrong if the device is actually a server appliance rather than a data transmission/reception apparatus. | Port diagram, network protocol, datasheet, user manual. |
| 8523.51.11 / 8523.51.21 / 8523.51.99 / 8523.52.00 | Review only where the product is solid-state storage media or smart card with cryptographic stored-data protection. | Confusion between cyberinformation security appliance and civil cryptography product. | Cryptographic specification, memory description, encryption documents and licence if applicable. |
| 8542.32.00 | Review only where the product is memory integrated circuit related to stored-data protection. | Confusion between components and complete equipment. | BOM, IC datasheet, cryptographic technical document. |
Indicative duty table
| Code group | MFN import duty | Ordinary import duty | VAT | Special preferential duty under C/O | Note |
|---|---|---|---|---|---|
| 8471.30.90 / 8471.41.90 / 8471.49.90 | Reference 0% | Reference 5% | Reserve 10%; review 8% if VAT reduction conditions are met | May be 0% under FTA if C/O and origin rule are valid | Verify against the tariff schedule at declaration date. |
| 8517.62.43 | Reference 0% | Reference 5% | Reserve 10%; review 8% if eligible | May be 0% under applicable FTA | If treated as telecom/ICT goods, VAT reduction exclusion must be checked. |
| 8523.51.11 / 8523.51.21 / 8523.51.99 / 8523.52.00 | Reference 0% | Reference 5% | Reserve 10% | Review by FTA and C/O form | Use only where the goods are storage media/smart card with cryptographic function. |
| 8542.32.00 | Reference 0% | Reference 5% or 150% of MFN if not listed in ordinary tariff | Reserve 10% | Review by FTA and C/O form | Review carefully if it is a semiconductor memory component. |
C/O checklist
- Confirm the C/O form and exporting country match the applicable FTA.
- Check whether HS code on C/O matches the declaration or is acceptable under the agreement.
- Goods description must identify model, function and quantity.
- Origin criterion must match the rule of origin for the declared HS code.
- Third-party invoice, through bill of lading, transit and C/O issuance date should be checked before ETA.
APPLICABLE SECTORAL POLICY
| Goods scenario | Potential policy | Documents to check | Authority/portal if identifiable | Recommended timing | Risk note |
|---|---|---|---|---|---|
| Standard storage security appliance | Review list of cyberinformation security products subject to import licence. | Catalogue, datasheet, security function, model list. | Authority of Information Security, MIC or applicable public service portal. | Before ETA, preferably before shipment. | Do not conclude no licence before model/function review. |
| Device using cryptographic algorithms to protect stored data | May be civil cryptographic product for stored-data protection. | Encryption specification, algorithm, encryption purpose, cryptographic technical document. | Government Cipher Committee / Ministry of National Defence. | Before importation. | Separate cyberinformation security and civil cryptography policies. |
| With Wi‑Fi/Bluetooth/4G/5G | ICT/telecom conformity may arise under Group 2 goods list. | Wireless module, frequency, RF test report, user manual. | Competent ICT/telecom quality authority. | Before ETA or before distribution. | Integrated modules may trigger additional QCVNs. |
| With battery, adapter or charger | Review electrical safety, labelling and applicable technical regulations. | Power rating, adapter label, safety documents. | Sectoral authority depending on actual policy. | Before finalising the technical dossier. | Accessories may change policy of the whole set. |
| Used/refurbished goods | Used equipment policy, quality explanation and import purpose may arise. | Invoice, contract, year of manufacture, serial, condition. | Customs and sectoral authority if applicable. | Before purchasing. | Do not purchase before importability is checked. |
| Samples, warranty, project, EPE/FDI | Policy may differ by import purpose, end-user and project commitments. | PO, contract, warranty letter, project dossier, use purpose. | Customs or licensing authority if triggered. | Before declaration. | Import purpose must match documents and declaration. |
LEGAL DOCUMENTS TO REVIEW
| Document group | Name / number | Issuing authority | Effective timing | Role in procedure | Key article/appendix | Review note |
|---|---|---|---|---|---|---|
| Law | Law on Cyberinformation Security 2015 | National Assembly | In force | Legal basis for cyberinformation security and civil cryptography products. | Provisions on trading and import of security/cryptographic products. | Review by import purpose. |
| Decree | Decree 69/2018/ND-CP | Government | 15 May 2018 | Foreign trade management and goods subject to licence/conditions. | Appendices on conditional/licensed import goods. | Apply where the goods are sector-managed. |
| Circular | Circular 13/2018/TT-BTTTT as amended by Circular 10/2022/TT-BTTTT | MIC | Circular 10/2022 effective from 15 Sep 2022 | List and licensing procedure for cyberinformation security products. | Appendix; Data storage security products. | Review by both HS code and technical function. |
| Decree | Decree 211/2025/ND-CP | Government | 9 Sep 2025 | Civil cryptography products/services and import/export licence. | Appendix I, II; stored-data protection products. | Applies only if cryptographic technical characteristics match. |
| Circular | Circular 29/2025/TT-BKHCN | Ministry of Science and Technology | 31 Dec 2025 | Group 2 ICT and telecom goods list. | Appendices I/II and rules for integrated goods. | Review if wireless/ICT modules are integrated. |
| Tariff | Decree 26/2023/ND-CP, Decision 15/2023/QD-TTg and current tariff schedule | Government / Prime Minister | Check at declaration date | MFN, ordinary duty, VAT and FTA duty. | Tariff line by actual HS code. | Do not use outdated tariff rates. |
| VAT | Decree 174/2025/ND-CP | Government | 01 Jul 2025–31 Dec 2026 | 2% VAT reduction policy for certain goods/services. | Article 1 and exclusion appendices. | Check carefully if goods are telecom/ICT or excluded. |
VIEW / DOWNLOAD ORIGINAL LEGAL DOCUMENTS
Enterprises may search the legal documents by number on official legal portals, the Government portal or websites of issuing authorities. Enterprises should cross-check the documents on official portals or issuing authority websites before applying them.
CUSTOMS DOCUMENT SET
Commercial documents
- Commercial Invoice.
- Packing List.
- Bill of Lading or Air Waybill.
- Sales Contract/Purchase Order if available.
- C/O if preferential duty is claimed.
- Catalogue, datasheet, label photos, model list, serial list.
Sectoral documents if triggered
- Import licence for cyberinformation security product.
- Import licence for civil cryptographic product if applicable.
- Test report, technical document, encryption whitepaper.
- Goods labelling/sub-label documents.
- ICT conformity dossier if Group 2 function is triggered.
| Document group | Required documents | Used for | Usually prepared by | Common error | Pre-ETA check |
|---|---|---|---|---|---|
| Commercial | Invoice, Packing List, B/L/AWB, Contract/PO | Declaration, value and quantity check | Importer, exporter, forwarder | Generic name, missing model, wrong origin | Match each item with catalogue and label |
| Technical | Catalogue, datasheet, user manual, model list | HS and sectoral policy classification | Supplier, technical team | No storage security function shown | Request security function and deployment description |
| Cybersecurity | Import licence, security function documents | Customs clearance for licensed products | Importer/licensed entity | Late licence application, missing end-user information | Review list and file before ETA |
| Civil cryptography | Civil cryptography licence, technical plan, algorithm details | Import of civil cryptographic products | Licensed enterprise/importer | Confusing attack monitoring with cryptographic function | Separate encryption purpose and stored-data protection |
| Origin | C/O, through B/L, third-party invoice if any | FTA preferential duty | Exporter, importer | Wrong HS, description or origin criterion | Check form, origin criterion and goods description before ETA |
DECISION POINTS THAT MAY HOLD THE SHIPMENT
| Decision point | Question to answer | Supporting document | Consequence if unclear | Recommended handling |
|---|---|---|---|---|
| HS code | Is it ADP appliance, network gateway or storage media? | Catalogue, datasheet, hardware configuration | Reclassification, duty adjustment | Determine HS by principal function and technical dossier |
| Cybersecurity licence | Is it under the licensed cyberinformation product list? | List, model, function description | Clearance delay or additional filing | Review before ETA and apply if applicable |
| Civil cryptography | Does it use cryptographic algorithms to protect stored data? | Encryption whitepaper, algorithm document | Wrong or missing civil cryptography licence | Separate data-security function from cryptographic function |
| Model/serial | Does invoice model match catalogue, label and licence? | Invoice, packing list, label photo, model list | Customs query or physical inspection | Lock model list before documents are issued |
| C/O | Does C/O qualify for FTA preferential duty? | C/O, invoice, B/L, origin criterion | Loss of preferential duty | Review C/O before arrival and before declaration |
PRACTICAL E2E PROCEDURE
Step 1: Pre-ETA review
Confirm HS, cybersecurity/civil cryptography policy, duty, C/O, labelling and goods condition.
Step 2: Lock documents
Match Invoice, Packing List, B/L/AWB, catalogue, datasheet, model/serial list and function description.
Step 3: Handle licence/sectoral dossier
File cybersecurity or civil cryptography licence if required; prepare test reports, technical documents and labelling dossier.
Step 4: Customs declaration
Declare correct goods name, HS, value and origin; prepare explanations for Yellow/Red channel if assigned.
Step 5: Clearance and post-clearance control
Deliver goods, complete Vietnamese sub-label/conformity marking if triggered, archive shipment dossier and prepare post-clearance explanations.
PRE-ETA RISK CHECKLIST
| Risk | Consequence | Pre-ETA control | Document to check |
|---|---|---|---|
| Goods described only as “storage device” | Wrong HS and missed licence | State storage security appliance and data-protection function | Catalogue, datasheet |
| Cybersecurity and civil cryptography not separated | Wrong licence, clearance delay | Review monitoring/security function and cryptographic function separately | Security specification, encryption whitepaper |
| Model discrepancy | Additional explanation required | Lock model list before shipment | Invoice, Packing List, label photo |
| C/O error | Preferential duty denied | Check form, origin criterion and description before ETA | C/O, B/L, Invoice |
| Refurbished goods declared as new | Inspection and violation risk | Verify condition, year of manufacture and serials | Contract, invoice, photos |
FAQ – COMMON BUSINESS QUESTIONS
Does storage security require an import licence?
Possibly, if it falls under the licensed cyberinformation security product list or civil cryptography list. Do not conclude without catalogue and datasheet.
Are all storage devices storage security?
No. Ordinary NAS/SAN/SSD remains storage equipment if no dedicated security function is shown in technical documents.
Is Vietnamese sub-labelling required?
Yes, if imported goods are circulated in Viet Nam. Label information must match model, origin, manufacturer and mandatory labelling rules.
Can C/O reduce duty?
Yes, if HS code, origin, C/O form and origin criterion meet the applicable FTA. Incorrect description or HS may lead to refusal.
Are samples or warranty goods handled like commercial goods?
Not entirely. Import purpose, value, end-user, licence and sectoral policy should be reviewed separately.
What if invoice says “storage security” but catalogue says “encryption storage”?
Ask the supplier to align descriptions, provide function documents and immediately review civil cryptography exposure.
Tiếng Việt
中文 (中国)
NEED TO REVIEW IMPORT PROCEDURES OR A SHIPPING PLAN?
Send us the product name, shipping route, current dossier, or implementation request in advance so we can suggest a suitable approach that is practical, focused, and aligned with your shipment.
Vietnam Import Procedure for Fruit Wine: HS, Food Safety, Alcohol Stamps and 2026 Taxes
Import procedure guide for herbal alcoholic drinks
Sparkling wine import procedures into Vietnam 2026: licensing, food safety, e-stamps, taxes and origin
Import procedure guide for whisky
Import Procedures for Sake / Soju into Vietnam: HS, Food Safety, E-stamps, SCT and C/O 2026
Brandy / Cognac Import Procedures into Vietnam: HS, Alcohol Licence, Food Safety, Stamps and 2026 Taxes
Import procedure guide for energy drinks
Herbal Drink Import Procedures in Vietnam: HS, Food Safety, Self-Declaration and Labelling 2026
Bottled / Canned Coffee Import Procedure in Vietnam: HS, Food Safety, VAT and Labeling 2026
Beer Import Procedures into Vietnam: HS, Food Safety, SCT, VAT, Origin and Labelling 2026
Baijiu and distilled spirits import procedures into Vietnam 2026: HS, licensing, food safety, stamps and taxes
Guide to Vietnam import procedure for bottled/canned milk tea
Import procedures for carbonated soft drinks into Vietnam: HS, food safety, VAT, excise tax, C/O and labels
Import Procedures for Fruit Juice into Vietnam 2026
Vietnam bottled tea import procedures: HS, food safety, labeling, VAT and sugar tax