Categories
Latest News

Rewrite Security DNA from the Ground Up! QNAP Earns IEC 62443-4-1 Certification, Continues to Strengthen Its Cybersecurity Commitment

QNAP Builds a Proactive Defense Architecture

In 2026, QNAP officially obtained IEC 62443-4-1 certification, the most stringent secure development lifecycle standard in the industrial control systems (ICS) field, making it one of the few hardware manufacturers in Taiwan to achieve this certification. Over the years, QNAP has embedded security at the core of its development process through expanding its Bounty Program, participating in the world-class Pwn2Own competition, completing penetration testing and validation with the Viettel Cyber Security Red Team, collaborating with the National Institute of Cyber Security, and comprehensively adopting Software Bill of Materials (SBOM) and DevSecOps, building a new “proactive defense” architecture.

Obtaining IEC 62443-4-1 Certification Means Passing a Rigorous Audit of Secure Development Processes

IEC 62443-4-1 is a part of the cybersecurity standards framework for Industrial Automation and Control Systems (IACS) developed by the International Electrotechnical Commission (IEC). It specifically defines the “Product Security Development Life-Cycle Requirements.”

The audit under this standard focuses not on the product itself, but on the development process. Specifically, it covers eight key areas: security management, security requirements definition, secure design, secure implementation guidance, security verification and validation testing, security issue management, security update management, and security guidance documentation. Each area must be supported by traceable documentation and implementation records, which are reviewed by an independent certification body before issuance.

Obtaining IEC 62443-4-1 certification means that QNAP’s product development processes comply with security requirements at the industrial control systems level and have received formal recognition from a third-party organization. Developed for industrial automation and critical infrastructure, the standard imposes more stringent requirements than those typically applied to general IT product certifications. It not only demonstrates QNAP’s maturity in R&D management but also serves as an important compliance foundation as enterprises face next-generation international cybersecurity regulations such as the European Union’s Cyber Resilience Act (CRA).

2025: Turning Commitment into a System

QNAP turned its cybersecurity commitment into an actionable framework, making “rapid response” part of its everyday operations.

After receiving reports of high-severity vulnerabilities, QNAP’s Product Security Incident Response Team (PSIRT) completes investigations within 9 hours, remediation within 14 hours, and case closure within 24 hours. In 2025, QNAP assigned more than 224 CVE IDs (Common Vulnerabilities and Exposures), contributing to the global cybersecurity database, while all Critical-severity vulnerabilities were remediated within one week. This is a Service-Level Agreement (SLA), as well as QNAP’s commitment to all customers.

QNAP also formally introduced a Software Bill of Materials (SBOM) to ensure transparency and security of software components, while working with trusted suppliers to manage risks at the source and uphold its highest commitment to data security.

2026: QNAP Works with External Partners to Validate Its Cybersecurity Achievements

In addition to establishing and refining its internal security processes, QNAP has also actively collaborated with external partners, allowing cybersecurity organizations to validate the effectiveness of its processes and the security of its products.

In 2026, QNAP received the “Cyber Security Certificate of Completion” issued by Viettel Cyber Security (VCS). VCS is a leading cybersecurity organization in Asia, having won multiple Pwn2Own championships and produced nearly 500 zero-day vulnerability research findings. The testing focused on QuTS hero, the core operating system powering QNAP’s enterprise-grade NAS solutions and built on the highly reliable ZFS file system. All vulnerabilities identified during the testing were fully remediated and successfully validated before the certificate was issued.

QNAP also actively participated in the “Product Security Bug Bounty Program,” guided by the Administration for Cyber Security, Ministry of Digital Affairs, and organized by the National Institute of Cyber Security (NICS). The testing covered QNAP’s ADRD NDR (Network Detection and Response) products and QHora series next-generation routers. Meanwhile, the QuTS hero system demonstrated a high level of architectural stability under rigorous testing.

At the same time, the scale of the Bounty Program has expanded significantly, with more than 151 external security researchers from around the world participating and over US$88,000 in bounties awarded in a single year. QNAP has also participated in Pwn2Own, an international cybersecurity competition recognized worldwide as one of the most prestigious real-time attack challenges, for multiple consecutive years. In 2024, QNAP also sponsored Trend Micro’s Zero Day Initiative (ZDI). These efforts demonstrate that QNAP has become an active participant in the zero-day vulnerability research community, extending cybersecurity protection beyond internal testing to a collaborative effort with cybersecurity professionals worldwide.

Obtaining a Certification Is Just One Milestone; Maintaining High Cybersecurity Standards Is an Ongoing Process

QNAP holds ISO 27001 (Information Security Management), ISO 27017 (Cloud Security Controls), and ISO 27018 (Protection of Personal Information in the Cloud), together with IEC 62443-4-1, forming a comprehensive certification framework that spans organizational management, product development, and cloud services. AI-Assisted Code Review and Vulnerability Scanning have been integrated into the CI/CD pipeline, while an SOP for reviewing GenAI-generated code has also been established.

Cybersecurity threats continue to evolve, and QNAP’s commitment to cybersecurity remains unwavering.

Visit the QNAP Trust Center >>

Frequently Asked Questions (FAQ)

Q1: How can I participate in the QNAP Bounty Program?

External security researchers can submit vulnerability reports through the Bounty Program. QNAP awards bounties based on the severity of each vulnerability. Critical-severity vulnerabilities are remediated within one week, and reporters are notified.

Q2: How can users protect their NAS against ransomware? What cybersecurity protection measures does QNAP recommend for users?

While no cybersecurity measure can provide absolute protection, good security practices can reduce risk to near zero. We strongly recommend that users implement the following three core practices:

  • Secure Remote Access: Never expose your NAS directly to the public internet. Be sure to disable your router’s UPnP automatic port forwarding and avoid using default port numbers. Use a VPN or myQNAPcloud Link for secure remote access. (Read the Blog)
  • Implement Basic Security Measures: Be sure to enable Two-Factor Authentication (2FA), strictly follow the “3-2-1 backup rule,” and regularly perform restore tests to ensure that backups are always available.
  • Use Immutable Storage: Choose a QuTS hero NAS or myQNAPcloud One cloud storage to create WORM folders or immutable snapshots. These features lock files in place, preventing malware or personnel from modifying their contents during the predefined retention period.

Q3: Beyond obtaining IEC 62443-4-1 certification, how does QNAP help enterprises address next-generation international cybersecurity regulations such as the CRA?

In response to the implementation of the EU Cyber Resilience Act (CRA), QNAP has established a dedicated QNAP CRA Cybersecurity Incident Reporting Platform. If you discover an actively exploited vulnerability or a confirmed major cybersecurity incident while deploying or operating QNAP solutions, you can report it through this official channel. Our PSIRT team will immediately initiate the security response process.


AI Disclosure: Some images and text in this article were created or refined with the assistance of Artificial Intelligence (AI) and reviewed by human editors.

Leave a comment

Your email address will not be published. Required fields are marked *