[重要安全性通知] 发现假冒 Qfinder Pro 网站。了解详情 >

Welcome to the QNAP Trust Center

At QNAP, we deliver secure, high-efficiency data and networking infrastructure worldwide. Our mission is to empower enterprises and individuals with resilient data management in AI-driven digital transformation—integrating stringent security practices throughout every phase of our product development lifecycle.

Global Compliance & Certifications: An Ongoing Commitment

QNAP maintains industry-leading security and privacy certifications. We ensure our products and services comply with stringent global regulatory standards, empowering your enterprise compliance journey.

Certification category filter Filter:

Security & Privacy

  • ISO/IEC 27001 certification badge

    ISO/IEC 27001

    Information Security Management System

    Establishes global security governance, helping enterprises streamline internal compliance audits. (Certified since 2014)

  • ISO/IEC 27017 certification badge

    ISO/IEC 27017

    Cloud Security Controls

    Strengthens cloud service security controls to ensure reliable, end-to-end data transmission and access. (Certified since 2021)

  • ISO/IEC 27018 certification badge

    ISO/IEC 27018

    Cloud Privacy Protection

    Safeguards sensitive cloud data to fulfill rigorous personal data privacy commitments. (Certified since 2021)

  • GDPR certification badge

    GDPR

    EU General Data Protection Regulation

    Adheres to strict privacy principles to help enterprises streamline compliance workflows.

  • HIPAA certification badge

    HIPAA

    US Healthcare Privacy Compliance

    Integrates encryption, access controls, and anti-ransomware protection to help healthcare organizations secure ePHI.

  • PCI-DSS certification badge

    PCI-DSS

    Payment Card Data Security

    Hosted on PCI-DSS compliant cloud infrastructure, leveraging transmission encryption and logging to secure transactions.

  • SOC 2 certification badge

    SOC 2

    Cloud Infrastructure Compliance

    Hosted on SOC 2 compliant cloud infrastructure, combining strict security controls to ensure data safety.

Supply Chain Security & Development Resilience

  • IEC 62443-4-1 certification badge

    IEC 62443-4-1

    Industrial Automation Security Standards

    Applies secure development lifecycles (SDLC) to ensure built-in product resilience.

  • ISO/IEC 5230 certification badge

    ISO/IEC 5230

    Open Source License Compliance (OpenChain)

    Enforces open-source compliance to mitigate software supply chain risks.

  • SSCRM certification badge

    SSCRM

    Software Supply Chain Security Declaration

    Adheres to SSCRM frameworks and provides SBOMs to ensure component transparency and secure delivery.

  • NIS2 certification badge

    NIS2

    EU Cybersecurity Directive Compliance

    Aligns with NIS2 directives to strengthen enterprise cybersecurity readiness.

  • CRA certification badge

    CRA

    EU Cyber Resilience Act Compliance

    Complies with EU CRA requirements by establishing proactive vulnerability reporting and rapid patch response.

  • JC-STAR certification badge

    JC-STAR

    Japan IoT Security Label

    QNAP achieved Level 1 certification in 2026, streamlining enterprise security procurement.

Global Operations, Quality & Intellectual Property

  • ISO 9001 certification badge

    ISO 9001

    Quality Management System

    Establishes standardized quality processes to deliver reliable products and services. (Certified since 2014)

  • TAA certification badge

    TAA

    US Trade Agreements Act Compliance

    Ensures TAA compliance for public sector and enterprise supply chains.

  • TIPS certification badge

    TIPS

    Taiwan Intellectual Property System

    QNAP achieved Class A certification in 2025 to safeguard IP assets and mitigate legal risks.

Sustainability & Social Responsibility

  • ISO 14001 certification badge

    ISO 14001

    Environmental Management System

    Drives green operations and resource recycling, serving as a reliable low-carbon supply chain partner. (Certified since 2019)

  • ISO 45001 certification badge

    ISO 45001

    Occupational Health and Safety Management

    Establishes health and safety standards to protect our workforce and ensure business continuity. (Certified since 2019)

  • ISO 14064-1 certification badge

    ISO 14064-1

    Greenhouse Gas Verification

    Provides transparent GHG emissions data to support enterprise Scope 3 decarbonization goals. (Certified since 2024)

Rigorous Security Governance: QNAP PSIRT

QNAP PSIRT Milestones

  1. March2017

    Dedicated Team Formed

    Standardized response workflows to manage vulnerabilities and incidents.

  2. August2017

    MITRE CNA Authorized

    Authorized to assign CVE IDs for product vulnerabilities independently.

  3. March2019

    Joined FIRST

    Connected globally to share threat intelligence and incident insights.

  4. October2019

    Joined Taiwan CERT/CSIRT

    Strengthened regional defense through shared threat intelligence and coordination.

  5. June2021

    Adopted BSIMM

    Embedded security controls into every software development phase.

  6. November2022

    Launched Bounty Program

    Engaged global white-hat hackers for crowd-sourced security.

  7. September2026

    EU Cyber Resilience Act Compliance

    Implemented CRA compliance workflows for mandatory vulnerability reporting.

Swipe left or right to view the full timeline

  • CVE Program

    Authorized MITRE CNA

    Authorized as a MITRE CVE Numbering Authority (CNA), QNAP independently assigns CVE IDs and publishes standardized security advisories to ensure transparent vulnerability disclosures.

  • FIRST — Forum of Incident Response and Security Teams

    Global Incident Defense with FIRST

    As a member of FIRST, QNAP collaborates with global response networks to share threat intelligence and rapidly deploy security patches.

Proactive Response & Remediation: PSIRT Standard Operating Procedure

PSIRT & Security Team Continuous Monitoring Vulnerability Analysis Non-security Issue Confirmed Vulnerability Track & Handle CVE Identification Patch Vulnerability Risk Mitigation Security Advisory Patch / Update Continuous Improvement

  • Scope: Conducts daily automated scanning across OSs, apps, and open-source packages alongside real-time threat tracking.
  • Automated SCA: Uses Software Composition Analysis (SCA) for daily scans of open-source libraries (e.g., Linux Kernel, OpenSSL) against global CVE databases.

Key Deliverables: Daily Scan Reports, Internal Threat Alerts.

  • Scope: Operates 24/7 intake for vulnerability reports from researchers, customers, Bug Bounty platforms, and internal testing.
  • Secure Channel: Provides an OpenPGP key to encrypt report submissions and Proof-of-Concept (PoC) code.
  • SLA Commitment: On-call specialists guarantee initial human response within 24–72 hours.

Key Deliverables: Incident Tracking ID, assigned security lead.

  • Scope: Reproduces issues in sandbox environments to evaluate affected models, firmware, and system modules.
  • CVSS Scoring: Leverages CVSS metrics to assign Critical, High, Medium, or Low severity to prioritize fixes.
  • CVE Assignment: Sets remediation timelines and independently assigns CVE IDs under QNAP's CNA scope.

Key Deliverables: Prioritized fix schedule. High-risk issues receive initial assessment within 9 hours.

  • Scope: R&D develops patches and hotfix; security teams conduct penetration and regression testing to ensure patch stability.
  • Dual Verification: Executes attack simulations to verify complete vulnerability closure.
  • Cross-Platform QA: Validates package compatibility across all supported OS platforms and apps.

Key Deliverables: QA-verified firmware and app update packages.

R&D Patch SLA by Severity
Severity R&D Patch SLA
Critical Within 12 hours of confirmation
High Within 14 hours of confirmation
Medium Within 90 days of confirmation
Low Within 90 days of confirmation

For third-party or architectural dependencies, QNAP provides interim mitigations while adjusting final patch release dates.

  • Scope: Issues QNAP Security Advisory (QSA) with vulnerability scope, mitigations, and updates via proactive alerts.
  • Global Sync: Publishes CVE Records to cve.org and syncs with global databases (e.g., US NVD) under QNAP's CNA authority.
  • Proactive Protection: For high-risk incidents prior to patch release, QNAP updates Malware Remover definitions for automated malware scanning/removal and delivers security policy guidance via Security Counselor.

Key Deliverables: Official SAs, push alerts, updated malware definitions, synced CVE Records.

  • Scope: Conducts Root Cause Analysis (RCA) to feed insights back into DevSecOps and recognize external researchers.
  • Shift-Left Security: Converts signatures into automated SAST/DAST rules to embed security early in development.
  • Hall of Fame: Credits contributing security researchers on the official QNAP Hall of Fame.

Key Deliverables: RCA reports, updated SAST/DAST rule bases, Hall of Fame updates.

Global & Local Security Partnerships

To counter evolving cyber threats, QNAP actively collaborates with premier global and regional security alliances, extending our defense perimeter through real-time threat intelligence sharing and coordinated incident response.

  • 2019

    Taiwan CERT/CSIRT Alliance

    Joined regional defense networks to drive threat intelligence sharing and enterprise incident coordination.

  • 2020

    FIRST (Forum of Incident Response and Security Teams)

    Joined the premier global alliance to exchange threat intelligence and align with international incident response standards.

  • 2025

    Taiwan CISO Alliance

    Participates in the Product Security Working Group to drive PSIRT framework adoption and standardization across the ICT industry.

Battle-Tested Security Validation

True security is forged through real-world stress testing. QNAP proactively subjects products to premier global competitions and state-level offensive security exercises, inviting elite white-hat hackers and research teams to rigorously test our defenses and push system resilience limits.

  • Pwn2Own Ireland ethical hacking competition testing scenario

    Pwn2Own Ireland Competitions

    Hosted by Trend Micro's Zero Day Initiative (ZDI), Pwn2Own is a premier global ethical hacking competition. QNAP participated in Pwn2Own Ireland (2024–2025), subjecting NAS and router platforms to live testing. Through Coordinated Vulnerability Disclosure (CVD), QNAP PSIRT rapidly addresses novel attack vectors and deploys verified patches to global users.

  • Taiwan NICS National Product Bug Bounty Program testing scenario

    NICS National Product Bug Bounty Program

    Organized by Taiwan's National Institute of Cyber Security (NICS), this national-level exercise tests real-world defense capabilities. In 2025, QNAP submitted ADRA NDR, QHora, and QuTS hero for penetration testing, awarding over $6,500 in bug bounties. Close collaboration with NICS enables our PSIRT to map attack paths quickly and deliver swift mitigations.

Third-Party Security Partnerships

Beyond internal secure development, QNAP collaborates with industry-leading security experts for deep product penetration testing and joint defensive engineering, leveraging independent perspectives to ensure uncompromised security.

  • DEVCORE

    Product Penetration Testing & Red Teaming

    Engages premier red teams to conduct high-intensity product penetration testing using adversary simulation mindsets.

    Active:20142015201720212022

  • CyCraft

    Endpoint Detection & Response (EDR) & Security Resilience (DR)

    Partners with AI cybersecurity specialists to strengthen system perimeters and build highly resilient disaster recovery architectures.

    Active:2021

  • Viettel Cyber Security

    Global Penetration Testing & Security Validation

    Completed third-party penetration testing, achieving an official Cyber Security Certificate of Completion.

    Active:2026

  • Lionic

    Deep Packet Inspection (DPI) & Malware Threat Engine

    Integrates patented enterprise anti-malware and intrusion detection engines into QuWAN, delivering real-time threat prevention and embedded defense-in-depth.

    Active:20212022202320242025

More Resources

Explore how QNAP safeguards your enterprise data—from real-time advisories to resilient storage architectures.

  • Security advisories illustration

    Security Advisories

    Report security vulnerabilities and receive real-time updates on the latest Security Advisories and patch releases.

  • QNAP secure storage solutions illustration

    QNAP Secure Storage Solutions

    Discover how QNAP delivers defense-in-depth to build secure NAS storage environments.

  • Bounty Program illustration

    Bounty Program

    Join our global community of security researchers to strengthen product security together.

选择规格

      显示更多 隐藏更多
      欢迎随时咨询! 欢迎随时咨询!
      back to top