It is 2026, and a hyperscale operator ships the security stack for a new facility in Southeast Asia: firewalls, security gateways, encrypted storage, the routers and switches that tie it together. The export side is handled properly. The classification is confirmed, the parties are screened, the filing is made, and the shipment leaves the origin country entirely in the clear. Weeks later the hardware is sitting in a bonded warehouse near the destination port, and the reason has nothing to do with the export licence. The destination country controls encryption on the way in, and the licence required to bring it in is one the importing company is not eligible to hold. A customs hold of this kind is not resolved by producing better export paperwork.
Encryption is regulated in both directions. Export control governs whether hardware may leave the origin country and is the half most compliance teams plan for. Import control on cryptography is a separate regime, administered by a different authority in the destination country, and it governs whether the same hardware may legally enter. Clearing one says nothing about the other. In several of the fastest-growing data centre markets, the import-side authorisation can only be held by a locally registered entity, which means the foreign company doing the importing cannot obtain it at all.
Importing encrypted network equipment catches sophisticated buyers out precisely because the export side is so well documented that it absorbs all the attention. Teams that would never ship without confirming an export classification will book freight into a market with cryptographic import licensing without ever asking the question, because the question is not on the familiar checklist. And the markets where it bites hardest are the ones absorbing the most data centre investment right now.
Encryption Import Restrictions: Why Two Regimes Apply to One Box
Cryptography has been treated as sensitive by governments for as long as it has been commercially available, and the reasoning runs in both directions. An exporting state cares about strong encryption leaving its jurisdiction, which is the concern driving the exporter of record obligations most technology companies already know well. An importing state cares about foreign encryption entering its networks, because cryptography it cannot inspect is cryptography it cannot police. Those are different anxieties, and they produce different rules, administered by different agencies, with no reciprocity between them.
A single shipment of network security hardware therefore has to satisfy two unrelated bodies of law. The origin country asks whether this technology may leave. The destination country asks whether this cryptography may enter. There is no mechanism by which a clean export filing recognises, informs, or substitutes for the import-side requirement. Encryption customs clearance at the destination is judged entirely on the destination country’s own rules. Our guides to ITAR and EAR compliance for IT hardware and shipping AI servers internationally cover the export half. This article is about the half waiting on the other side of the border.
The United States is worth naming here, because it explains why this catches capable teams. American controls on encryption are built around export: classification, licensing and party screening all govern what leaves the country. There is no comparable general import licensing regime for commercial encryption entering the United States. A compliance function shaped by that framework is trained, correctly and thoroughly, to ask whether something may go out. It has no established habit of asking whether it may come in, because for its home market the question has rarely arisen. When the destination changes, the missing habit is the exposure.
Vietnam: Two Authorisations, and You Cannot Hold Either
Vietnam is the clearest illustration of the problem, and it matters commercially because Vietnam is absorbing serious data centre and cloud investment. Under the Law on Cyber Information Security, given effect by Decree No. 58/2016/ND-CP, civil cryptography products are regulated by the National Agency of Cryptography and Information Security, known as NACIS, which sits under the Government Cipher Committee, itself under the Ministry of Defence.
What is caught is set out in the decree’s appendices and covers the categories a data centre is built from: products for cryptographic key generation, management or storage, stored data security products, and equipment using cryptography for data confidentiality. In practical terms that may include firewalls, security gateways, security routers, switches, storage systems, servers, and application delivery controllers, depending on the cryptographic function of the specific product. It is not a niche list. It reaches into the security and networking layer of a facility.
Two separate authorisations are required, and the sequence is what traps foreign companies.
First, a civil cryptography product trading licence. To obtain one, the applicant must be a company legally operating in Vietnam, holding a business registration certificate, and submitting both a technical plan complying with the applicable national technical regulations and a business plan matching the scope applied for.
The application must also evidence that the responsible technical staff and managers hold relevant qualifications in information security. This is not a form. It is a corporate licensing exercise, and a foreign company with no Vietnamese legal entity and no locally qualified personnel is not eligible to apply.
Second, an import permit for the importation itself. Holding the trading licence is not sufficient. A separate import permit application is required, supported by a copy of the trading licence and a copy of the type approval certificate for the product, issued against the applicable Ministry of Defence technical regulations. Expanding the range of products covered by an existing licence requires a further application to modify it.
The structural point is the one worth taking away. This is not a case of unfamiliar paperwork that a determined importer can complete under time pressure. The authorisation is tied to a qualifying local entity, so a foreign operator’s only routes are to establish and license a Vietnamese entity, which is a project rather than a task, or to import through a party that already holds the licence. Our guide to acting as importer of record in Vietnam covers the wider position for technology hardware entering the market.
China: Commercial Encryption Under the Encryption Law
China regulates commercial encryption in both directions under its Encryption Law, in force since 2020, with the Ministry of Commerce and the State Cryptography Administration jointly empowered to apply import licensing to commercial encryption products where national security or public interest considerations arise. Those authorities, with the customs administration, published an Import Licensing List and an Export Control List giving effect to it.
Here the honest position matters more than the alarming one, because China’s import list is narrower than many importers assume. It identifies a small set of dedicated cryptographic devices, broadly encrypted telephones, encrypted fax machines, cryptographic machines and cards whose main function is cryptographic computing, and security devices built for specific sectors such as electricity, tax, public security and financial services. Items are caught where key length or encryption and decryption rate exceed defined technical thresholds, and a listed item requires a cryptographic import licence from the commerce ministry.
What that means in practice is that general network equipment, a firewall or a switch with encryption capability, is not automatically captured by China’s encryption import licensing in the way it is by Vietnam’s civil cryptography regime. The exposure in China more often sits in other requirements applying to the same shipment. That distinction is worth getting right, because misdirected worry about China is frequently paired with no attention at all to markets where the constraint is genuinely binding.
A separate technology control also exists. The Catalogue of Technologies Subject to Import Prohibition and Restriction has identified foreign data encryption technology above a defined key length as restricted, requiring a permit when transferred to a Chinese party. That is a technology transfer control rather than a hardware one, and commentators have noted genuine uncertainty about its practical scope, including whether it extends to software. Because the position here has moved before and may move again, verify the current lists against your specific products rather than relying on any secondary summary, including this one.
The discipline for China is therefore to check the product against the published lists rather than reason from what it is called. Our guide to acting as importer of record in China sets out the wider certification and registration position that more commonly affects a data centre build.
Shipping network security hardware into a market with cryptographic import controls? In several of them the authorisation can only be held by a qualifying local entity, which means the gap cannot be closed by the importing company under time pressure. Carra Globe acts as importer of record across 175+ countries and checks the import-side cryptographic position alongside the export classification, before freight is booked.
India and the Wider Type Approval Gate
Not every market operates a cryptography-specific regime, and it would be wrong to imply otherwise. But the absence of one does not mean network security hardware enters freely, because a second gate frequently applies: mandatory type approval of telecommunications equipment.
India is the significant example, and one of the largest data centre growth markets in the world. Mandatory testing and certification of telecommunications equipment originates in the Indian Telegraph (Amendment) Rules of 2017 and now sits within India’s newer telecommunications framework, under which notified equipment may not be sold, deployed in a network, or otherwise used in the country without a valid certificate of conformity assessment. The scheme, known as MTCTE, is administered by the Telecommunication Engineering Centre and has been rolled out progressively by product group since becoming mandatory in 2019.
Two details matter for anyone shipping a security stack. The scheme has extended to security certification for products including IP routers, so the security dimension is not absent merely because the regime is not labelled cryptographic. And importers are required to be registered on the customs portal in order to submit the certificate, which ties the certification directly to the border rather than leaving it a market-access formality. The effect is the same as an encryption licence: hardware without it cannot lawfully enter.
The same structural pattern repeats across other markets attracting data centre investment, through their own telecom and conformity authorities. The specific instrument differs. The operational consequence does not. Equipment arrives, the certification or licence is not in place, and the hardware waits. Our guide on importing into India as importer of record covers the certification landscape there in more detail.
For completeness, a cryptography-specific notification regime also operates across the Eurasian Economic Union under a Eurasian Economic Commission decision of 2015, where registration is a prerequisite for import and is triggered by a device being capable of encryption rather than actively using it. It is a useful illustration of how wide these definitions can run, though for most data centre programmes the commercially relevant markets are the ones above.
What Applies Where
| Market | What controls it | What is required | Who can hold it |
|---|---|---|---|
| Vietnam | Civil cryptography regime under the cyber information security framework | Trading licence plus a separate import permit and type approval | A qualifying entity legally operating in Vietnam |
| China | Encryption Law, with published import and export lists | Import licence, but the list targets dedicated cryptographic devices rather than general network equipment | The importing party, via the commerce ministry |
| India | Mandatory telecom equipment testing and certification | Certification before sale, import or use | Obtained against the product, via the certification scheme |
| United States | Framework oriented around export control rather than import licensing | No comparable general import licence for commercial encryption | Not applicable, which is precisely why the habit is missing |
| Eurasian Economic Union | Cryptographic notification regime | Registered notification before import | The manufacturer or a locally registered representative |
The column that decides your timeline is the last one. Where the authorisation attaches to a local entity or to the manufacturer, the importing company cannot resolve a gap on its own schedule, however urgent the deployment.
Which Equipment Actually Triggers This
Teams importing network security equipment across borders often assume the rules reach only dedicated cryptographic products: hardware security modules, VPN concentrators, encryption appliances. Those are certainly caught. The broader reality is that modern data centre hardware is saturated with cryptographic capability, much of it incidental to the product’s purpose. It is the same trap as assuming classification can be judged from a product name rather than a specification.
- Almost always in scope: firewalls, security gateways, VPN appliances, hardware security modules, encrypted storage arrays.
- Frequently in scope and frequently missed: routers and switches with encrypted management interfaces, application delivery controllers, servers with encrypted drives or secure boot, and management controllers supporting secure remote access.
- The wrong test: asking whether the product is “an encryption product”. The right test is whether it falls within the destination country’s definition, which is usually written around capability rather than marketing category.
This is why the problem concentrates in facility build-outs rather than single shipments. A data centre build brings security appliances, networking, storage and management hardware in together, and the exposure is spread across the whole stack rather than sitting in one obvious box. The same is true of data centre equipment imports generally, where one entry can cover dozens of distinct product types.
What to Do Before the Freight Is Booked
- Make the import side a named step in your network security equipment import compliance checklist. Put it on the pre-shipment list as its own line, separate from export classification: does this destination control the import of cryptographic or telecom equipment, and does this specific model fall within it. The answer differs by country and cannot be inferred from the export position.
- Establish who is eligible to hold the authorisation. This is the decisive question. If the licence can only be held by a qualifying local entity, your options are set from that moment: license an entity, or import through a party that already holds one. Discovering this at the border removes both options.
- Check whether an existing approval already covers the product. Where registrations or certifications are published and reusable, an existing one can turn a licensing problem into a documentation exercise. Established models from major vendors are more likely to be covered than a recent release.
- Treat newly launched models as higher risk. The gap between a product launching and its import-side approvals being in place across your markets is real. Specifying the previous generation, already approved, sometimes beats specifying the newest.
- Confirm the importing entity can actually satisfy the obligation. Because these requirements attach to the importing party, the entity named on the entry has to be one that qualifies. Our guide to the difference between a paper IOR and an operational IOR sets out why that distinction stops being academic here.
Frequently Asked Questions
Does clearing export controls mean my equipment can be imported anywhere?
No. Export control governs whether hardware may leave the origin country. Import control on cryptography is a separate regime in the destination country, administered by a different authority. Clearing one has no bearing on the other.
Both must be satisfied independently, and the import side is the one usually discovered late. Our guide to what an importer of record does covers where that responsibility lands.
Can I import firewalls and security gateways into Vietnam?
Yes, but only through a party holding a civil cryptography trading licence, which requires a qualifying entity legally operating in Vietnam. A separate import permit is then needed for the importation, supported by type approval for the product.
A foreign company without a licensed Vietnamese entity cannot complete this itself.
Can I file the import authorisation myself as the importer?
Often not. In several markets the authorisation attaches to a qualifying local entity or to the manufacturer. A foreign buyer is typically neither, which makes closing a gap dependent on a third party’s timetable rather than your own.
That is why the question belongs in planning, not at the border.
Do ordinary switches and servers really count as encryption products?
For import control purposes, often yes. Definitions are usually written around cryptographic capability, so equipment with encrypted management interfaces, secure boot, or encrypted storage can fall in scope even when it is not marketed as security hardware.
Judging by product category rather than specification is the most common way this is missed.
Export controls get the attention because they are well documented, heavily enforced, and sit at the start of the process where compliance teams are already looking. Import controls on cryptography sit at the far end of the journey, in a jurisdiction the shipping team does not deal with, governed by an authority they have never filed with, and frequently requiring an authorisation they are not eligible to hold. That combination is what makes this an operational risk rather than a paperwork detail, and it is concentrated in exactly the markets where data centre capacity is being built fastest. It is also part of a wider pattern across a facility build, where the binding constraint frequently sits after the border rather than at it: the same is true of cooling fluids, of generating sets, and of structured cabling. The organisations that move security hardware across borders without incident are the ones that added a second question to the checklist and ask it for every destination: not only may this leave, but may this arrive, and who is allowed to bring it in.
Disclaimer: This article is for informational purposes only and does not constitute legal, customs, or export control advice. Cryptographic and telecommunications import requirements vary by product, specification, jurisdiction, and date, and are subject to change. Always confirm the current position for your specific equipment and destination markets with the relevant authority or qualified counsel before shipping.