Key takeaway: Obtaining the JC-STAR certification is a concrete result of QNAP's long-term investment in international security compliance and governance
In July 2026, QNAP NAS passed the JC-STAR (IoT Product Security Certification System) Level 1 Certification led by Japan's IPA (Information-technology Promotion Agency). Available Models covers the TS-x64, TS-x73A, TVS-hx74, TS-hx77A, TS-hx87, TS-hx90 series, demonstrating QNAP's ongoing commitment and accumulation in security certification and product compliance.
The JC-STAR Level 1 currently obtained by QNAP means that NAS products under its brand have met the basic security requirements defined by this system, and further serve as an objective reference for product compliance in the Japanese market for evaluation by enterprises and government procurement.
Extended Reading: Visit the QNAP Trust Center to learn more about QNAP's international certification and compliance information

JC-STAR Level 1 Coverage Scope
The official JC-STAR statement indicates that its standards are extensively referenced and cover internationally adopted consumer IoT security baselines such as ETSI EN 303 645, with a coverage scope that even exceeds the requirements of the UK PSTI (Product Security and Telecommunications Infrastructure) regulations. The core principles of ETSI EN 303 645 include: prohibition of universal default passwords, establishment of vulnerability reporting and handling mechanisms, provision of secure software update channels, proper protection of credentials and other sensitive data, and minimizing the attack surface as much as possible.
These requirements are addressed within QNAP's existing mechanisms: password policies require users to set up a dedicated password during initial setup and prohibit the use of default account passwords, with the option to enable QNAP Authenticator multi-factor authentication; the QNAP PSIRT team leads the security protection cycle, from proactive continuous monitoring and vulnerability reporting to subsequent handling, all governed by comprehensive mechanisms and publicly disclosed in Security Advisories; for authentication and protection of other sensitive data, SED self-encrypting hard disk drives and AES-256 encryption support are provided; for software security design, threat modeling and code review processes under the SSDLC policy are incorporated.
The password management, vulnerability response, data encryption, and secure development required by JC-STAR Level 1 have long been integrated into QNAP's daily information security governance framework. Passing this certification reflects the accumulated results of ongoing efforts, and also demonstrates QNAP's concrete commitment to aligning its defense mechanisms with international standards and maintaining strong information security governance.
QNAP can provide reliable and trustworthy IoT product procurement information
The original intention of Japan's official promotion of JC-STAR is to provide objective and comparable data for buyers when evaluating storageunit and other IoT products through a standardized labeling system, thus freeing them from the predicament of relying solely on manufacturers' claims. QNAP's passing of Level 1 certification means that its products have the basic protection capabilities recognized by official standards, and it provides publicly accessible protection records.
If you have any questions about the certification scope or Available Models, please contact QNAP sales or technical support, or visit the QNAP Trust Center for more certification information.
FAQ:
Q1: What impact does Japan's promotion of JC-STAR certification have on multinationals or supply chains?
The Japanese market has already incorporated JC-STAR into the practical evaluation criteria for enterprise and government procurement. For companies with Japanese subsidiaries or those belonging to supply chains serving Japan, choosing QNAP NAS certified through this process can directly serve as proof of cybersecurity compliance, avoiding issues such as disqualification from bidding or supply chain audits being delayed due to unit not meeting local cybersecurity standards.
Q2: After importing a QNAP NAS authenticated via JC-STAR, what best practices should IT administrators follow when logging in for the first time?
It is recommended that IT administrators immediately implement three security settings after powering on the unit:
- Account protection: Disable the default account, use a custom administrator account, and enforce MFA (Multi-Factor Authentication).
- Patch Automation: Enable QTS/QuTS hero firmware auto security updates to ensure timely receipt of PSIRT security updates.
- Configuration Scan: Perform system vulnerability checks and security assessments using QNAP NAS built-in Security Center (Security Center).
Q3: Besides the JC-STAR mark, what other internationally recognized security and compliance certifications does QNAP hold?
QNAP’s comprehensive cybersecurity defense system ensures that its product development process is certified by IEC 62443-4-1, guaranteeing the highest security standards from design to release. QNAP has also obtained ISO/IEC 27001 information security management certification and is authorized by MITRE as an international CNA (CVE Numbering Authority), with official qualifications for independently reviewing and issuing global CVE numbers. The PSIRT team proactively provides timely security updates.
Belangrijkste conclusie: Het behalen van de JC-STAR-certificering is een concreet resultaat van QNAP's langdurige investering in internationale beveiligingsnaleving en governance
In juli 2026 heeft QNAP NAS de JC-STAR (IoT Product Security Certification System) Level 1 Certificering behaald, geleid door Japan's IPA (Information-technology Promotion Agency). De beschikbare modellen omvatten de TS-x64, TS-x73A, TVS-hx74, TS-hx77A, TS-hx87, TS-hx90 series, wat QNAP's voortdurende inzet en opgebouwde ervaring in beveiligingscertificering en productnaleving aantoont.
Het door QNAP behaalde JC-STAR Level 1 betekent dat NAS-producten onder haar merk voldoen aan de basisbeveiligingseisen die door dit systeem zijn gedefinieerd, en verder dienen als een objectieve referentie voor productnaleving op de Japanse markt voor evaluatie door bedrijven en overheidsaankopen.
Uitgebreid lezen: Bezoek het QNAP Trust Center voor meer informatie over QNAP's internationale certificeringen en nalevingsinformatie

JC-STAR Level 1 Dekking Scope
De officiële JC-STAR-verklaring geeft aan dat haar standaarden uitgebreid worden geraadpleegd en internationaal toegepaste consumenten IoT-beveiligingsbaselines zoals ETSI EN 303 645 omvatten, met een dekkingsscope die zelfs de eisen van de Britse PSTI (Product Security and Telecommunications Infrastructure) regelgeving overtreft. De kernprincipes van ETSI EN 303 645 omvatten: verbod op universele standaardwachtwoorden, het opzetten van mechanismen voor kwetsbaarheidsrapportage en -afhandeling, het bieden van veilige software-updatekanalen, juiste bescherming van inloggegevens en andere gevoelige data, en het minimaliseren van het aanvalsoppervlak zoveel mogelijk.
Deze eisen worden aangepakt binnen QNAP's bestaande mechanismen: wachtwoordbeleid vereist dat gebruikers een eigen wachtwoord instellen tijdens de eerste installatie en verbiedt het gebruik van standaardaccountwachtwoorden, met de optie om QNAP Authenticator multi-factor authenticatie in te schakelen; het QNAP PSIRT-team leidt de beveiligingsbeschermingscyclus, van proactieve continue monitoring en kwetsbaarheidsrapportage tot daaropvolgende afhandeling, alles geregeld door uitgebreide mechanismen en openbaar gemaakt in Security Advisories; voor authenticatie en bescherming van andere gevoelige data worden SED zelfversleutelende harde schijven en AES-256 encryptie ondersteund; voor softwarebeveiligingsontwerp worden threat modeling en code review-processen onder het SSDLC beleid geïntegreerd.
Het wachtwoordbeheer, de respons op kwetsbaarheden, data-encryptie en veilige ontwikkeling die door JC-STAR Level 1 worden vereist, zijn al lang geïntegreerd in QNAP's dagelijkse informatiebeveiligingsgovernance. Het behalen van deze certificering weerspiegelt de opgebouwde resultaten van voortdurende inspanningen en toont tevens QNAP's concrete inzet om haar verdedigingsmechanismen af te stemmen op internationale standaarden en sterke informatiebeveiligingsgovernance te behouden.
QNAP kan betrouwbare en geloofwaardige IoT-productinformatie voor inkoop bieden
De oorspronkelijke bedoeling van de officiële promotie van JC-STAR door Japan is om objectieve en vergelijkbare gegevens te bieden aan kopers bij het evalueren van opslagunits en andere IoT-producten via een gestandaardiseerd labelsysteem, zodat ze niet langer alleen afhankelijk zijn van de claims van fabrikanten. QNAP's behalen van Level 1-certificering betekent dat haar producten beschikken over de basisbeschermingsmogelijkheden die door officiële standaarden worden erkend, en het biedt openbaar toegankelijke beschermingsrecords.
Als u vragen heeft over de certificeringsscope of beschikbare modellen, kunt u contact opnemen met QNAP verkoop of technische ondersteuning, of het QNAP Trust Center bezoeken voor meer certificeringsinformatie.
FAQ:
Q1: Welke impact heeft de promotie van JC-STAR-certificering door Japan op multinationals of toeleveringsketens?
De Japanse markt heeft JC-STAR al opgenomen in de praktische evaluatiecriteria voor bedrijfs- en overheidsaankopen. Voor bedrijven met Japanse dochterondernemingen of die deel uitmaken van toeleveringsketens die Japan bedienen, kan het kiezen van QNAP NAS die via dit proces is gecertificeerd direct dienen als bewijs van naleving van cyberbeveiliging, waardoor problemen zoals diskwalificatie bij aanbestedingen of vertragingen bij toeleveringsketenaudits door het niet voldoen aan lokale cyberbeveiligingsstandaarden worden voorkomen.
Q2: Welke best practices moeten IT-beheerders volgen bij het voor het eerst inloggen op een QNAP NAS die via JC-STAR is geauthenticeerd?
Het wordt aanbevolen dat IT-beheerders direct drie beveiligingsinstellingen implementeren nadat het apparaat is ingeschakeld:
- Accountbescherming: Schakel het standaardaccount uit, gebruik een aangepast beheerdersaccount en dwing MFA (Multi-Factor Authenticatie) af.
- Patchautomatisering: Schakel QTS/QuTS hero firmware automatische beveiligingsupdates in om tijdig PSIRT-beveiligingsupdates te ontvangen.
- Configuratiescan: Voer systeemkwetsbaarheidscontroles en beveiligingsbeoordelingen uit met behulp van het ingebouwde Security Center van QNAP NAS (Security Center).
Q3: Naast het JC-STAR-keurmerk, welke andere internationaal erkende beveiligings- en nalevingscertificeringen heeft QNAP?
QNAP's uitgebreide cyberbeveiligingsverdedigingssysteem zorgt ervoor dat haar productontwikkelingsproces gecertificeerd is volgens IEC 62443-4-1, wat de hoogste beveiligingsstandaarden van ontwerp tot release garandeert. QNAP heeft ook ISO/IEC 27001 informatiebeveiligingsmanagementcertificering behaald en is door MITRE geautoriseerd als een internationale CNA (CVE Numbering Authority), met officiële kwalificaties om wereldwijd CVE-nummers zelfstandig te beoordelen en uit te geven. Het PSIRT-team levert proactief tijdige beveiligingsupdates.