Import Procedures for Storage Security Appliances

ELECTRICAL – ELECTRONICS – IT EQUIPMENT / INFORMATION SECURITY

IMPORT PROCEDURES FOR STORAGE SECURITY APPLIANCES

Storage security refers to appliances or technical solutions used to protect data at rest, often involving encryption, access control, anomaly monitoring, protection for storage repositories, NAS/SAN, backup systems or enterprise storage environments. If the goods are declared only as “security appliance” or “storage device”, the importer may misclassify the HS code, miss a cyberinformation security import licence, confuse the product with civil cryptography regulation, or prepare insufficient technical documents before ETA. This article provides an E2E (End-to-End) compliance map covering HS code, duty, C/O, sectoral policy, customs documents and critical risk points before the shipment arrives.

QUICK FACTS

ProductStorage security – data-at-rest protection appliance, server appliance, module or dedicated security device.
Related groupVulnerability scanner; database security; storage security; DLP.
Reference HS codes8471.41.90 / 8471.49.90 / 8517.62.43; if the product is a civil cryptographic product for stored-data protection, also review 8523.51.11 / 8523.51.21 / 8523.51.99 / 8523.52.00 / 8542.32.00.
Indicative taxesCommon MFN reference: 0%; ordinary import duty reference: 5%; VAT reserve rate: 10%, with 8% to be reviewed if VAT reduction conditions are met at declaration time.
Key policyMay fall under the list of cyberinformation security products subject to import licence; if cryptographic algorithms are used for stored-data protection, civil cryptography policy must also be reviewed.
Application noteReview catalogue, datasheet, model, encryption function, import purpose and actual technical documents before declaring.
Legal note: This article is for operational guidance only. HS code, duty rate, licence, conformity and labelling obligations must be checked at customs declaration date according to the model, configuration, encryption function and technical dossier of each shipment.
Illustration for Import Procedures for Storage Security Appliances
Illustration of the product group and document review before customs clearance.

SCOPE OF APPLICATION

This article applies only to storage security products, namely appliances or dedicated solutions used to protect stored data in enterprise storage, data centres, backup repositories, storage servers or network-connected storage infrastructure.

Covered products

  • Dedicated appliances for data-at-rest protection.
  • Server appliances pre-installed with stored-data protection software.
  • Devices for access control, encryption, monitoring and storage repository protection.
  • Dedicated modules imported with a system and supported by clear technical documents.

Not automatically covered

  • Ordinary NAS/SAN devices used only for storage.
  • HDD, SSD, memory card or smart card without a dedicated security function.
  • Online software licence without physical goods.
  • DLP, database security or vulnerability scanner although they are in the same menu group.

Catalogue, datasheet, model and actual import purpose must be reviewed. New goods, used goods, refurbished goods, samples, warranty replacements and project goods may trigger different policies and documents.

CLASSIFICATION & TECHNICAL IDENTIFICATION

Storage security should be identified by its principal function. The key point is not merely “storage device” but data-at-rest protection: data encryption, key control, access rights, anomaly detection, data leakage prevention, backup protection or monitoring over storage repositories.

CheckpointDocuments to reviewRisk if misdescribedSuggested goods description
Main functionCatalogue, datasheet, user manualMisclassified as ordinary server/storage or networking equipmentStorage security appliance for data-at-rest protection, model…, brand…
Encryption functionEncryption whitepaper, security specification, admin guideCivil cryptography policy may be missed or wrong licence may be applied forState encryption/data-at-rest protection if applicable
Hardware configurationBOM, CPU/RAM/storage/network portsConfusion between headings 8471, 8517 and storage media heading 8523Clarify appliance/server appliance/module/storage media
Deployment modelDeployment guide, network diagramInsufficient evidence of security function during customs queryPurpose: enterprise storage security/data protection
Condition of goodsInvoice, packing list, label photos, serial listUsed/refurbished goods may require additional explanation or policy reviewNew 100% or actual condition as declared
Legal caution: Generic naming may cause wrong HS classification, wrong sectoral policy, missing cyberinformation/civil cryptography licence and incorrect labelling.

HS CODE – DUTY – C/O

For storage security, HS classification depends on the form and technical function. The same commercial name may fall under automatic data processing machines in heading 84.71, communication equipment in heading 85.17, or storage media/memory ICs in headings 85.23/85.42 if it is a civil cryptographic product for stored-data protection.

Reference HS codeApplication conditionRisk if wrongly appliedDocuments to review
8471.30.90Portable ADP machine weighing not more than 10 kg, including at least a central processing unit, keyboard and display; apply only if the storage security product actually has the corresponding portable/specialized device form.Wrong if the product is a fixed server appliance, system or network device.Catalogue, product photos, hardware configuration, dimensions/weight, datasheet.
8471.41.90ADP machine in the same housing with CPU and input/output units, dedicated to storage security.May be treated as ordinary server or networking equipment if security function is unclear.Catalogue, hardware configuration, datasheet, security function.
8471.49.90ADP system used for stored-data protection.Insufficient evidence of system structure or principal function.System diagram, model list, deployment documents.
8517.62.43Control/adaptor units, gateways, bridges, routers or similar apparatus designed for connection with ADP machines and protecting access to storage systems.Wrong if the device is actually a server appliance rather than a data transmission/reception apparatus.Port diagram, network protocol, datasheet, user manual.
8523.51.11 / 8523.51.21 / 8523.51.99 / 8523.52.00Review only where the product is solid-state storage media or smart card with cryptographic stored-data protection.Confusion between cyberinformation security appliance and civil cryptography product.Cryptographic specification, memory description, encryption documents and licence if applicable.
8542.32.00Review only where the product is memory integrated circuit related to stored-data protection.Confusion between components and complete equipment.BOM, IC datasheet, cryptographic technical document.

Indicative duty table

Code groupMFN import dutyOrdinary import dutyVATSpecial preferential duty under C/ONote
8471.30.90 / 8471.41.90 / 8471.49.90Reference 0%Reference 5%Reserve 10%; review 8% if VAT reduction conditions are metMay be 0% under FTA if C/O and origin rule are validVerify against the tariff schedule at declaration date.
8517.62.43Reference 0%Reference 5%Reserve 10%; review 8% if eligibleMay be 0% under applicable FTAIf treated as telecom/ICT goods, VAT reduction exclusion must be checked.
8523.51.11 / 8523.51.21 / 8523.51.99 / 8523.52.00Reference 0%Reference 5%Reserve 10%Review by FTA and C/O formUse only where the goods are storage media/smart card with cryptographic function.
8542.32.00Reference 0%Reference 5% or 150% of MFN if not listed in ordinary tariffReserve 10%Review by FTA and C/O formReview carefully if it is a semiconductor memory component.

C/O checklist

  • Confirm the C/O form and exporting country match the applicable FTA.
  • Check whether HS code on C/O matches the declaration or is acceptable under the agreement.
  • Goods description must identify model, function and quantity.
  • Origin criterion must match the rule of origin for the declared HS code.
  • Third-party invoice, through bill of lading, transit and C/O issuance date should be checked before ETA.

APPLICABLE SECTORAL POLICY

Goods scenarioPotential policyDocuments to checkAuthority/portal if identifiableRecommended timingRisk note
Standard storage security applianceReview list of cyberinformation security products subject to import licence.Catalogue, datasheet, security function, model list.Authority of Information Security, MIC or applicable public service portal.Before ETA, preferably before shipment.Do not conclude no licence before model/function review.
Device using cryptographic algorithms to protect stored dataMay be civil cryptographic product for stored-data protection.Encryption specification, algorithm, encryption purpose, cryptographic technical document.Government Cipher Committee / Ministry of National Defence.Before importation.Separate cyberinformation security and civil cryptography policies.
With Wi‑Fi/Bluetooth/4G/5GICT/telecom conformity may arise under Group 2 goods list.Wireless module, frequency, RF test report, user manual.Competent ICT/telecom quality authority.Before ETA or before distribution.Integrated modules may trigger additional QCVNs.
With battery, adapter or chargerReview electrical safety, labelling and applicable technical regulations.Power rating, adapter label, safety documents.Sectoral authority depending on actual policy.Before finalising the technical dossier.Accessories may change policy of the whole set.
Used/refurbished goodsUsed equipment policy, quality explanation and import purpose may arise.Invoice, contract, year of manufacture, serial, condition.Customs and sectoral authority if applicable.Before purchasing.Do not purchase before importability is checked.
Samples, warranty, project, EPE/FDIPolicy may differ by import purpose, end-user and project commitments.PO, contract, warranty letter, project dossier, use purpose.Customs or licensing authority if triggered.Before declaration.Import purpose must match documents and declaration.

LEGAL DOCUMENTS TO REVIEW

Document groupName / numberIssuing authorityEffective timingRole in procedureKey article/appendixReview note
LawLaw on Cyberinformation Security 2015National AssemblyIn forceLegal basis for cyberinformation security and civil cryptography products.Provisions on trading and import of security/cryptographic products.Review by import purpose.
DecreeDecree 69/2018/ND-CPGovernment15 May 2018Foreign trade management and goods subject to licence/conditions.Appendices on conditional/licensed import goods.Apply where the goods are sector-managed.
CircularCircular 13/2018/TT-BTTTT as amended by Circular 10/2022/TT-BTTTTMICCircular 10/2022 effective from 15 Sep 2022List and licensing procedure for cyberinformation security products.Appendix; Data storage security products.Review by both HS code and technical function.
DecreeDecree 211/2025/ND-CPGovernment9 Sep 2025Civil cryptography products/services and import/export licence.Appendix I, II; stored-data protection products.Applies only if cryptographic technical characteristics match.
CircularCircular 29/2025/TT-BKHCNMinistry of Science and Technology31 Dec 2025Group 2 ICT and telecom goods list.Appendices I/II and rules for integrated goods.Review if wireless/ICT modules are integrated.
TariffDecree 26/2023/ND-CP, Decision 15/2023/QD-TTg and current tariff scheduleGovernment / Prime MinisterCheck at declaration dateMFN, ordinary duty, VAT and FTA duty.Tariff line by actual HS code.Do not use outdated tariff rates.
VATDecree 174/2025/ND-CPGovernment01 Jul 2025–31 Dec 20262% VAT reduction policy for certain goods/services.Article 1 and exclusion appendices.Check carefully if goods are telecom/ICT or excluded.

VIEW / DOWNLOAD ORIGINAL LEGAL DOCUMENTS

Enterprises may search the legal documents by number on official legal portals, the Government portal or websites of issuing authorities. Enterprises should cross-check the documents on official portals or issuing authority websites before applying them.

CUSTOMS DOCUMENT SET

Commercial documents

  • Commercial Invoice.
  • Packing List.
  • Bill of Lading or Air Waybill.
  • Sales Contract/Purchase Order if available.
  • C/O if preferential duty is claimed.
  • Catalogue, datasheet, label photos, model list, serial list.

Sectoral documents if triggered

  • Import licence for cyberinformation security product.
  • Import licence for civil cryptographic product if applicable.
  • Test report, technical document, encryption whitepaper.
  • Goods labelling/sub-label documents.
  • ICT conformity dossier if Group 2 function is triggered.
Document matching rule: Goods name, quantity, model, serial, origin, security function and technical specifications must match across commercial documents, catalogue, labels, sectoral documents and customs declaration.
Document groupRequired documentsUsed forUsually prepared byCommon errorPre-ETA check
CommercialInvoice, Packing List, B/L/AWB, Contract/PODeclaration, value and quantity checkImporter, exporter, forwarderGeneric name, missing model, wrong originMatch each item with catalogue and label
TechnicalCatalogue, datasheet, user manual, model listHS and sectoral policy classificationSupplier, technical teamNo storage security function shownRequest security function and deployment description
CybersecurityImport licence, security function documentsCustoms clearance for licensed productsImporter/licensed entityLate licence application, missing end-user informationReview list and file before ETA
Civil cryptographyCivil cryptography licence, technical plan, algorithm detailsImport of civil cryptographic productsLicensed enterprise/importerConfusing attack monitoring with cryptographic functionSeparate encryption purpose and stored-data protection
OriginC/O, through B/L, third-party invoice if anyFTA preferential dutyExporter, importerWrong HS, description or origin criterionCheck form, origin criterion and goods description before ETA

DECISION POINTS THAT MAY HOLD THE SHIPMENT

Decision pointQuestion to answerSupporting documentConsequence if unclearRecommended handling
HS codeIs it ADP appliance, network gateway or storage media?Catalogue, datasheet, hardware configurationReclassification, duty adjustmentDetermine HS by principal function and technical dossier
Cybersecurity licenceIs it under the licensed cyberinformation product list?List, model, function descriptionClearance delay or additional filingReview before ETA and apply if applicable
Civil cryptographyDoes it use cryptographic algorithms to protect stored data?Encryption whitepaper, algorithm documentWrong or missing civil cryptography licenceSeparate data-security function from cryptographic function
Model/serialDoes invoice model match catalogue, label and licence?Invoice, packing list, label photo, model listCustoms query or physical inspectionLock model list before documents are issued
C/ODoes C/O qualify for FTA preferential duty?C/O, invoice, B/L, origin criterionLoss of preferential dutyReview C/O before arrival and before declaration

PRACTICAL E2E PROCEDURE

Step 1: Pre-ETA review

Confirm HS, cybersecurity/civil cryptography policy, duty, C/O, labelling and goods condition.

Step 2: Lock documents

Match Invoice, Packing List, B/L/AWB, catalogue, datasheet, model/serial list and function description.

Step 3: Handle licence/sectoral dossier

File cybersecurity or civil cryptography licence if required; prepare test reports, technical documents and labelling dossier.

Step 4: Customs declaration

Declare correct goods name, HS, value and origin; prepare explanations for Yellow/Red channel if assigned.

Step 5: Clearance and post-clearance control

Deliver goods, complete Vietnamese sub-label/conformity marking if triggered, archive shipment dossier and prepare post-clearance explanations.

PRE-ETA RISK CHECKLIST

RiskConsequencePre-ETA controlDocument to check
Goods described only as “storage device”Wrong HS and missed licenceState storage security appliance and data-protection functionCatalogue, datasheet
Cybersecurity and civil cryptography not separatedWrong licence, clearance delayReview monitoring/security function and cryptographic function separatelySecurity specification, encryption whitepaper
Model discrepancyAdditional explanation requiredLock model list before shipmentInvoice, Packing List, label photo
C/O errorPreferential duty deniedCheck form, origin criterion and description before ETAC/O, B/L, Invoice
Refurbished goods declared as newInspection and violation riskVerify condition, year of manufacture and serialsContract, invoice, photos

FAQ – COMMON BUSINESS QUESTIONS

Does storage security require an import licence?

Possibly, if it falls under the licensed cyberinformation security product list or civil cryptography list. Do not conclude without catalogue and datasheet.

Are all storage devices storage security?

No. Ordinary NAS/SAN/SSD remains storage equipment if no dedicated security function is shown in technical documents.

Is Vietnamese sub-labelling required?

Yes, if imported goods are circulated in Viet Nam. Label information must match model, origin, manufacturer and mandatory labelling rules.

Can C/O reduce duty?

Yes, if HS code, origin, C/O form and origin criterion meet the applicable FTA. Incorrect description or HS may lead to refusal.

Are samples or warranty goods handled like commercial goods?

Not entirely. Import purpose, value, end-user, licence and sectoral policy should be reviewed separately.

What if invoice says “storage security” but catalogue says “encryption storage”?

Ask the supplier to align descriptions, provide function documents and immediately review civil cryptography exposure.

IMPLEMENTATION SOLUTION FROM TGIMEX

This article provides a map of HS code, duties, documents and sectoral policies for storage security. In real shipments, enterprises still need to review catalogue, datasheet, model, commercial documents, origin, encryption function and import purpose.

Pre-ETA review

Review HS, cybersecurity/civil cryptography policy, C/O, taxes, labels, model and datasheet before arrival.

Compliance dossier control

Cross-check Invoice, Packing List, B/L/AWB, C/O, catalogue, test report, labels and technical documents.

International logistics & customs

Coordinate agents, carriers/airlines, ETA, pre-alert, declaration and channel handling.

Post-clearance archive

Archive the shipment dossier, review sub-labels/conformity marks if required and prepare post-clearance explanations.

For shipments that may trigger sectoral inspection, licence, C/O or labelling requirements, enterprises should not wait until the goods arrive to start document review. Minor discrepancies among Invoice, Packing List, catalogue, datasheet, C/O or labels may lead to additional document requests, customs delay or unplanned storage costs.

QUICK CONSULTATION

NEED TO REVIEW IMPORT PROCEDURES OR A SHIPPING PLAN?

Send us the product name, shipping route, current dossier, or implementation request in advance so we can suggest a suitable approach that is practical, focused, and aligned with your shipment.

CALL NOW
Zalo
HOTLINE 0963 856 664 / 0982 135 393
EMAIL info@tgimex.com
SUITABLE FOR International shipping · Customs procedures · Import licenses · B2B logistics

Leave a Reply

Discover more from TGIMEX VIETNAM JSC

Subscribe now to keep reading and get access to the full archive.

Continue reading