Key takeaway: Obtaining the JC-STAR certification is a concrete result of QNAP's long-term investment in international security compliance and governance
In July 2026, QNAP NAS passed the JC-STAR (IoT Product Security Certification System) Level 1 Certification led by Japan's IPA (Information-technology Promotion Agency). Available Models covers the TS-x64, TS-x73A, TVS-hx74, TS-hx77A, TS-hx87, TS-hx90 series, demonstrating QNAP's ongoing commitment and accumulation in security certification and product compliance.
The JC-STAR Level 1 currently obtained by QNAP means that NAS products under its brand have met the basic security requirements defined by this system, and further serve as an objective reference for product compliance in the Japanese market for evaluation by enterprises and government procurement.
Extended Reading: Visit the QNAP Trust Center to learn more about QNAP's international certification and compliance information

JC-STAR Level 1 Coverage Scope
The official JC-STAR statement indicates that its standards are extensively referenced and cover internationally adopted consumer IoT security baselines such as ETSI EN 303 645, with a coverage scope that even exceeds the requirements of the UK PSTI (Product Security and Telecommunications Infrastructure) regulations. The core principles of ETSI EN 303 645 include: prohibition of universal default passwords, establishment of vulnerability reporting and handling mechanisms, provision of secure software update channels, proper protection of credentials and other sensitive data, and minimizing the attack surface as much as possible.
These requirements are addressed within QNAP's existing mechanisms: password policies require users to set up a dedicated password during initial setup and prohibit the use of default account passwords, with the option to enable QNAP Authenticator multi-factor authentication; the QNAP PSIRT team leads the security protection cycle, from proactive continuous monitoring and vulnerability reporting to subsequent handling, all governed by comprehensive mechanisms and publicly disclosed in Security Advisories; for authentication and protection of other sensitive data, SED self-encrypting hard disk drives and AES-256 encryption support are provided; for software security design, threat modeling and code review processes under the SSDLC policy are incorporated.
The password management, vulnerability response, data encryption, and secure development required by JC-STAR Level 1 have long been integrated into QNAP's daily information security governance framework. Passing this certification reflects the accumulated results of ongoing efforts, and also demonstrates QNAP's concrete commitment to aligning its defense mechanisms with international standards and maintaining strong information security governance.
QNAP can provide reliable and trustworthy IoT product procurement information
The original intention of Japan's official promotion of JC-STAR is to provide objective and comparable data for buyers when evaluating storageunit and other IoT products through a standardized labeling system, thus freeing them from the predicament of relying solely on manufacturers' claims. QNAP's passing of Level 1 certification means that its products have the basic protection capabilities recognized by official standards, and it provides publicly accessible protection records.
If you have any questions about the certification scope or Available Models, please contact QNAP sales or technical support, or visit the QNAP Trust Center for more certification information.
FAQ:
Q1: What impact does Japan's promotion of JC-STAR certification have on multinationals or supply chains?
The Japanese market has already incorporated JC-STAR into the practical evaluation criteria for enterprise and government procurement. For companies with Japanese subsidiaries or those belonging to supply chains serving Japan, choosing QNAP NAS certified through this process can directly serve as proof of cybersecurity compliance, avoiding issues such as disqualification from bidding or supply chain audits being delayed due to unit not meeting local cybersecurity standards.
Q2: After importing a QNAP NAS authenticated via JC-STAR, what best practices should IT administrators follow when logging in for the first time?
It is recommended that IT administrators immediately implement three security settings after powering on the unit:
- Account protection: Disable the default account, use a custom administrator account, and enforce MFA (Multi-Factor Authentication).
- Patch Automation: Enable QTS/QuTS hero firmware auto security updates to ensure timely receipt of PSIRT security updates.
- Configuration Scan: Perform system vulnerability checks and security assessments using QNAP NAS built-in Security Center (Security Center).
Q3: Besides the JC-STAR mark, what other internationally recognized security and compliance certifications does QNAP hold?
QNAP’s comprehensive cybersecurity defense system ensures that its product development process is certified by IEC 62443-4-1, guaranteeing the highest security standards from design to release. QNAP has also obtained ISO/IEC 27001 information security management certification and is authorized by MITRE as an international CNA (CVE Numbering Authority), with official qualifications for independently reviewing and issuing global CVE numbers. The PSIRT team proactively provides timely security updates.
Nøglepointe: Opnåelsen af JC-STAR-certificeringen er et konkret resultat af QNAPs langsigtede investering i international sikkerhedsoverholdelse og -styring
I juli 2026 bestod QNAP NAS JC-STAR (IoT Product Security Certification System) Niveau 1-certificeringen, ledet af Japans IPA (Information-technology Promotion Agency). Tilgængelige modeller omfatter TS-x64, TS-x73A, TVS-hx74, TS-hx77A, TS-hx87, TS-hx90-serierne, hvilket demonstrerer QNAPs vedvarende engagement og opbygning inden for sikkerhedscertificering og produktoverholdelse.
Det JC-STAR Niveau 1, som QNAP aktuelt har opnået, betyder, at NAS-produkter under dette brand har opfyldt de grundlæggende sikkerhedskrav defineret af dette system, og yderligere fungerer som en objektiv reference for produktefterlevelse på det japanske marked til evaluering af virksomheder og offentlige indkøb.
Udvidet læsning: Besøg QNAP Trust Center for at lære mere om QNAPs internationale certificeringer og compliance-information

JC-STAR Niveau 1 dækningsområde
Den officielle JC-STAR-erklæring angiver, at dens standarder er bredt refereret og dækker internationalt anvendte forbruger-IoT-sikkerhedsbaselines såsom ETSI EN 303 645, med et dækningsområde, der endda overstiger kravene i de britiske PSTI (Product Security and Telecommunications Infrastructure) regler. Kerneprincipperne i ETSI EN 303 645 omfatter: forbud mod universelle standardadgangskoder, etablering af mekanismer til rapportering og håndtering af sårbarheder, levering af sikre softwareopdateringskanaler, korrekt beskyttelse af legitimationsoplysninger og andre følsomme data samt minimering af angrebsfladen så meget som muligt.
Disse krav håndteres inden for QNAPs eksisterende mekanismer: adgangskodepolitikker kræver, at brugere opretter en dedikeret adgangskode under den indledende opsætning og forbyder brugen af standardkonto-adgangskoder, med mulighed for at aktivere QNAP Authenticator multifaktorautentificering; QNAP PSIRT-teamet leder sikkerhedsbeskyttelsescyklussen, fra proaktiv kontinuerlig overvågning og sårbarhedsrapportering til efterfølgende håndtering, alt styret af omfattende mekanismer og offentligt offentliggjort i Security Advisories; til autentificering og beskyttelse af andre følsomme data tilbydes SED selvkrypterende harddiske og AES-256-krypteringsunderstøttelse; til software-sikkerhedsdesign indarbejdes trusselsmodellering og kodegennemgangsprocesser under SSDLC-politikken.
Adgangskodehåndtering, sårbarhedsrespons, datakryptering og sikker udvikling, som kræves af JC-STAR Niveau 1, har længe været integreret i QNAPs daglige informationssikkerhedsstyringsramme. At bestå denne certificering afspejler de akkumulerede resultater af løbende indsats og demonstrerer også QNAPs konkrete engagement i at tilpasse sine forsvarsmekanismer til internationale standarder og opretholde stærk informationssikkerhedsstyring.
QNAP kan levere pålidelig og troværdig IoT-produktindkøbsinformation
Formålet med Japans officielle promovering af JC-STAR er at give objektive og sammenlignelige data til købere, når de evaluerer lagringsenheder og andre IoT-produkter gennem et standardiseret mærkningssystem, så de ikke længere er afhængige af producenternes egne påstande. QNAPs beståelse af Niveau 1-certificeringen betyder, at dets produkter har de grundlæggende beskyttelsesfunktioner, der anerkendes af officielle standarder, og at det leverer offentligt tilgængelige beskyttelsesregistre.
Hvis du har spørgsmål om certificeringsomfanget eller tilgængelige modeller, kontakt venligst QNAPs salg eller tekniske support, eller besøg QNAP Trust Center for mere certificeringsinformation.
FAQ:
Q1: Hvilken betydning har Japans promovering af JC-STAR-certificeringen for multinationale virksomheder eller forsyningskæder?
Det japanske marked har allerede indarbejdet JC-STAR i de praktiske evalueringskriterier for virksomheds- og offentlige indkøb. For virksomheder med japanske datterselskaber eller dem, der indgår i forsyningskæder, der betjener Japan, kan valg af QNAP NAS certificeret gennem denne proces direkte tjene som bevis på cybersikkerhedsoverholdelse og undgå problemer som diskvalifikation fra udbud eller forsinkelser i forsyningskædeaudit på grund af, at enheden ikke opfylder lokale cybersikkerhedsstandarder.
Q2: Hvilke bedste praksisser bør IT-administratorer følge, når de logger ind første gang efter import af en QNAP NAS, der er godkendt via JC-STAR?
Det anbefales, at IT-administratorer straks implementerer tre sikkerhedsindstillinger efter opstart af enheden:
- Kontobeskyttelse: Deaktiver standardkontoen, brug en brugerdefineret administrator-konto og håndhæv MFA (Multi-Factor Authentication).
- Patch-automatisering: Aktiver QTS/QuTS hero firmware automatiske sikkerhedsopdateringer for at sikre rettidig modtagelse af PSIRT-sikkerhedsopdateringer.
- Konfigurationsscanning: Udfør system-sårbarhedstjek og sikkerhedsvurderinger ved hjælp af QNAP NAS indbyggede Security Center (Security Center).
Q3: Udover JC-STAR-mærket, hvilke andre internationalt anerkendte sikkerheds- og compliance-certificeringer har QNAP?
QNAPs omfattende cybersikkerhedsforsvarssystem sikrer, at dets produktudviklingsproces er certificeret efter IEC 62443-4-1, hvilket garanterer de højeste sikkerhedsstandarder fra design til frigivelse. QNAP har også opnået ISO/IEC 27001 informationssikkerhedsledelsescertificering og er autoriseret af MITRE som en international CNA (CVE Numbering Authority) med officielle kvalifikationer til selvstændigt at gennemgå og udstede globale CVE-numre. PSIRT-teamet leverer proaktivt rettidige sikkerhedsopdateringer.