Welcome to the QNAP Trust Center
At QNAP, we deliver secure, high-efficiency data and networking infrastructure worldwide. Our mission is to empower enterprises and individuals with resilient data management in AI-driven digital transformation—integrating stringent security practices throughout every phase of our product development lifecycle.
Global Compliance & Certifications: An Ongoing Commitment
QNAP maintains industry-leading security and privacy certifications. We ensure our products and services comply with stringent global regulatory standards, empowering your enterprise compliance journey.
Security & Privacy
-
ISO/IEC 27001
Information Security Management System
Establishes global security governance, helping enterprises streamline internal compliance audits. (Certified since 2014)
-
ISO/IEC 27017
Cloud Security Controls
Strengthens cloud service security controls to ensure reliable, end-to-end data transmission and access. (Certified since 2021)
-
ISO/IEC 27018
Cloud Privacy Protection
Safeguards sensitive cloud data to fulfill rigorous personal data privacy commitments. (Certified since 2021)
-
GDPR
EU General Data Protection Regulation
Adheres to strict privacy principles to help enterprises streamline compliance workflows.
-
HIPAA
US Healthcare Privacy Compliance
Integrates encryption, access controls, and anti-ransomware protection to help healthcare organizations secure ePHI.
-
PCI-DSS
Payment Card Data Security
Hosted on PCI-DSS compliant cloud infrastructure, leveraging transmission encryption and logging to secure transactions.
-
SOC 2
Cloud Infrastructure Compliance
Hosted on SOC 2 compliant cloud infrastructure, combining strict security controls to ensure data safety.
Supply Chain Security & Development Resilience
-
IEC 62443-4-1
Industrial Automation Security Standards
Applies secure development lifecycles (SDLC) to ensure built-in product resilience.
-
ISO/IEC 5230
Open Source License Compliance (OpenChain)
Enforces open-source compliance to mitigate software supply chain risks.
-
SSCRM
Software Supply Chain Security Declaration
Adheres to SSCRM frameworks and provides SBOMs to ensure component transparency and secure delivery.
-
NIS2
EU Cybersecurity Directive Compliance
Aligns with NIS2 directives to strengthen enterprise cybersecurity readiness.
-
CRA
EU Cyber Resilience Act Compliance
Complies with EU CRA requirements by establishing proactive vulnerability reporting and rapid patch response.
-
JC-STAR
Japan IoT Security Label
QNAP achieved Level 1 certification in 2026, streamlining enterprise security procurement.
Global Operations, Quality & Intellectual Property
-
ISO 9001
Quality Management System
Establishes standardized quality processes to deliver reliable products and services. (Certified since 2014)
-
TAA
US Trade Agreements Act Compliance
Ensures TAA compliance for public sector and enterprise supply chains.
-
TIPS
Taiwan Intellectual Property System
QNAP achieved Class A certification in 2025 to safeguard IP assets and mitigate legal risks.
Sustainability & Social Responsibility
-
ISO 14001
Environmental Management System
Drives green operations and resource recycling, serving as a reliable low-carbon supply chain partner. (Certified since 2019)
-
ISO 45001
Occupational Health and Safety Management
Establishes health and safety standards to protect our workforce and ensure business continuity. (Certified since 2019)
-
ISO 14064-1
Greenhouse Gas Verification
Provides transparent GHG emissions data to support enterprise Scope 3 decarbonization goals. (Certified since 2024)
Rigorous Security Governance: QNAP PSIRT
QNAP PSIRT Milestones
-
March2017
Dedicated Team Formed
Standardized response workflows to manage vulnerabilities and incidents.
-
August2017
MITRE CNA Authorized
Authorized to assign CVE IDs for product vulnerabilities independently.
-
March2019
Joined FIRST
Connected globally to share threat intelligence and incident insights.
-
October2019
Joined Taiwan CERT/CSIRT
Strengthened regional defense through shared threat intelligence and coordination.
-
June2021
Adopted BSIMM
Embedded security controls into every software development phase.
-
November2022
Launched Bounty Program
Engaged global white-hat hackers for crowd-sourced security.
-
September2026
EU Cyber Resilience Act Compliance
Implemented CRA compliance workflows for mandatory vulnerability reporting.
Swipe left or right to view the full timeline
-
Authorized MITRE CNA
Authorized as a MITRE CVE Numbering Authority (CNA), QNAP independently assigns CVE IDs and publishes standardized security advisories to ensure transparent vulnerability disclosures.
-
Global Incident Defense with FIRST
As a member of FIRST, QNAP collaborates with global response networks to share threat intelligence and rapidly deploy security patches.
Proactive Response & Remediation: PSIRT Standard Operating Procedure
- Scope: Conducts daily automated scanning across OSs, apps, and open-source packages alongside real-time threat tracking.
- Automated SCA: Uses Software Composition Analysis (SCA) for daily scans of open-source libraries (e.g., Linux Kernel, OpenSSL) against global CVE databases.
Key Deliverables: Daily Scan Reports, Internal Threat Alerts.
- Scope: Operates 24/7 intake for vulnerability reports from researchers, customers, Bug Bounty platforms, and internal testing.
- Secure Channel: Provides an OpenPGP key to encrypt report submissions and Proof-of-Concept (PoC) code.
- SLA Commitment: On-call specialists guarantee initial human response within 24–72 hours.
Key Deliverables: Incident Tracking ID, assigned security lead.
- Scope: Reproduces issues in sandbox environments to evaluate affected models, firmware, and system modules.
- CVSS Scoring: Leverages CVSS metrics to assign Critical, High, Medium, or Low severity to prioritize fixes.
- CVE Assignment: Sets remediation timelines and independently assigns CVE IDs under QNAP's CNA scope.
Key Deliverables: Prioritized fix schedule. High-risk issues receive initial assessment within 9 hours.
- Scope: R&D develops patches and hotfix; security teams conduct penetration and regression testing to ensure patch stability.
- Dual Verification: Executes attack simulations to verify complete vulnerability closure.
- Cross-Platform QA: Validates package compatibility across all supported OS platforms and apps.
Key Deliverables: QA-verified firmware and app update packages.
| Severity | R&D Patch SLA |
|---|---|
| Critical | Within 12 hours of confirmation |
| High | Within 14 hours of confirmation |
| Medium | Within 90 days of confirmation |
| Low | Within 90 days of confirmation |
For third-party or architectural dependencies, QNAP provides interim mitigations while adjusting final patch release dates.
- Scope: Issues QNAP Security Advisory (QSA) with vulnerability scope, mitigations, and updates via proactive alerts.
- Global Sync: Publishes CVE Records to cve.org and syncs with global databases (e.g., US NVD) under QNAP's CNA authority.
- Proactive Protection: For high-risk incidents prior to patch release, QNAP updates Malware Remover definitions for automated malware scanning/removal and delivers security policy guidance via Security Counselor.
Key Deliverables: Official SAs, push alerts, updated malware definitions, synced CVE Records.
- Scope: Conducts Root Cause Analysis (RCA) to feed insights back into DevSecOps and recognize external researchers.
- Shift-Left Security: Converts signatures into automated SAST/DAST rules to embed security early in development.
- Hall of Fame: Credits contributing security researchers on the official QNAP Hall of Fame.
Key Deliverables: RCA reports, updated SAST/DAST rule bases, Hall of Fame updates.
Global & Local Security Partnerships
To counter evolving cyber threats, QNAP actively collaborates with premier global and regional security alliances, extending our defense perimeter through real-time threat intelligence sharing and coordinated incident response.
-
2019
Taiwan CERT/CSIRT Alliance
Joined regional defense networks to drive threat intelligence sharing and enterprise incident coordination.
-
2020
FIRST (Forum of Incident Response and Security Teams)
Joined the premier global alliance to exchange threat intelligence and align with international incident response standards.
-
2025
Taiwan CISO Alliance
Participates in the Product Security Working Group to drive PSIRT framework adoption and standardization across the ICT industry.
Battle-Tested Security Validation
True security is forged through real-world stress testing. QNAP proactively subjects products to premier global competitions and state-level offensive security exercises, inviting elite white-hat hackers and research teams to rigorously test our defenses and push system resilience limits.
-
Pwn2Own Ireland Competitions
Hosted by Trend Micro's Zero Day Initiative (ZDI), Pwn2Own is a premier global ethical hacking competition. QNAP participated in Pwn2Own Ireland (2024–2025), subjecting NAS and router platforms to live testing. Through Coordinated Vulnerability Disclosure (CVD), QNAP PSIRT rapidly addresses novel attack vectors and deploys verified patches to global users.
-
NICS National Product Bug Bounty Program
Organized by Taiwan's National Institute of Cyber Security (NICS), this national-level exercise tests real-world defense capabilities. In 2025, QNAP submitted ADRA NDR, QHora, and QuTS hero for penetration testing, awarding over $6,500 in bug bounties. Close collaboration with NICS enables our PSIRT to map attack paths quickly and deliver swift mitigations.
Third-Party Security Partnerships
Beyond internal secure development, QNAP collaborates with industry-leading security experts for deep product penetration testing and joint defensive engineering, leveraging independent perspectives to ensure uncompromised security.
-
DEVCORE
Product Penetration Testing & Red Teaming
Engages premier red teams to conduct high-intensity product penetration testing using adversary simulation mindsets.
Active:20142015201720212022
-
CyCraft
Endpoint Detection & Response (EDR) & Security Resilience (DR)
Partners with AI cybersecurity specialists to strengthen system perimeters and build highly resilient disaster recovery architectures.
Active:2021
-
Viettel Cyber Security
Global Penetration Testing & Security Validation
Completed third-party penetration testing, achieving an official Cyber Security Certificate of Completion.
Active:2026
-
Lionic
Deep Packet Inspection (DPI) & Malware Threat Engine
Integrates patented enterprise anti-malware and intrusion detection engines into QuWAN, delivering real-time threat prevention and embedded defense-in-depth.
Active:20212022202320242025
More Resources
Explore how QNAP safeguards your enterprise data—from real-time advisories to resilient storage architectures.
-
Security Advisories
Report security vulnerabilities and receive real-time updates on the latest Security Advisories and patch releases.
-
QNAP Secure Storage Solutions
Discover how QNAP delivers defense-in-depth to build secure NAS storage environments.
-
Bounty Program
Join our global community of security researchers to strengthen product security together.