QNAP Inc. is pleased to announce that its eligible NAS products have been recognized for compliance with Level 1 of the "JC-STAR" IoT Product Security Certification Scheme, operated by the Information-technology Promotion Agency, Japan (IPA). This allows customers in sectors such as corporations, local governments, educational institutions, and medical facilities to consider QNAP NAS with greater confidence as one of the indicators for verifying security levels when selecting network storage products.
QuTS hero series / QTS series
Certification Label Registration Number
2026069900002756
Compliance Evaluation Level
★ (Star 1)
Certified Product Information Page
https://jc-star.ipa.go.jp/conformance/CNF_019e3877-7c2a-7255-ad19-f3be5118013d.html
Supporting Secure Data Storage Infrastructure Selection for Businesses and Local Governments
QNAP Inc. is pleased to announce that its NAS products have been recognized for compliance with Level 1 of the "JC-STAR" IoT Product Security Certification Scheme, operated by the Information-technology Promotion Agency, Japan (IPA).
JC-STAR is a scheme that evaluates and visualizes the compliance status of IoT products connected to networks with certain security requirements. Level 1 indicates compliance with basic security requirements common to IoT products and serves as one of the indicators for companies and organizations that introduce or procure products to verify their security level.
NAS is a critical IT infrastructure that handles various business data, including corporate file sharing, backups, surveillance video storage, storage for virtual environments, and backup destinations for ransomware countermeasures. Therefore, it is becoming increasingly important to select products not only based on their functionality and performance but also after confirming their security initiatives.
With QNAP NAS products now compliant with JC-STAR Level 1, customers can more easily verify the security compliance status when selecting a QNAP NAS. This is particularly useful for information systems departments, resellers, system integrators, local governments, educational institutions, and medical facilities, which are required to select IT equipment that meets certain security requirements, as a decision-making tool during product comparison and procurement.
QNAP has consistently worked on enhancing data protection and security through continuous OS and application updates, addressing vulnerability information, access control, snapshots, backups, WORM, Air Gap configurations, and ransomware countermeasures. The JC-STAR Level 1 compliance further clarifies these efforts.
As a storage vendor committed to protecting the critical data of businesses and organizations, QNAP will continue to strive for improved product security and enhanced information provision.
Importance of Obtaining JC-STAR Certification for NAS Products
In businesses and organizations, NAS serves as a vital IT infrastructure for storing and utilizing various business data, including file sharing, backups, surveillance video storage, storage for virtual environments, and cloud integration. In recent years, the use of NAS for storing backup data and critical files as part of ransomware countermeasures and business continuity planning (BCP) has also been increasing.
On the other hand, as NAS products are used connected to networks and interact with internal/external systems and users, it is important to verify the product's security compliance status, not just its performance and capacity, at the time of introduction. In particular, companies, local governments, educational institutions, and medical facilities require objective indicators to confirm the security level of products when procuring IT equipment.
JC-STAR is a scheme that evaluates and visualizes the security functions equipped in IoT products using a common yardstick. The IPA also explains that in the past, it has been difficult for procurers and users to assess the security measures of products.
With QNAP NAS products now compliant with JC-STAR Level 1, customers can use this as one of the decision-making materials when selecting a NAS to verify its security compliance status. This will enable information systems departments, resellers, and system integrators to consider QNAP NAS in a more easily explainable manner during product selection, proposal, and procurement.
Eligible Products
The main QNAP NAS products that have been recognized for JC-STAR Level 1 compliance are as follows:
TS-*64 Series
TS-*73A Series
TVS-h*74 Series
TS-h*77A Series
TS-h*87 Series
TS-h*90 Series
Other Eligible Products
*For details on eligible products, please refer to the IPA's JC-STAR Certified Product List and the official QNAP website.
QNAP NAS Security and Data Protection Features
To securely store and utilize critical data for businesses and organizations, QNAP NAS provides multi-layered security and data protection features that encompass access protection, threat countermeasures, backup, and recovery.
For account protection, it supports multi-factor authentication such as two-factor authentication and passwordless login, reducing the risk of unauthorized use of administrator and user accounts. It also includes mechanisms for safely operating the NAS on the network, such as communication control with QuFirewall, malware scanning with Malware Remover, and security status checking functions. QNAP operates a PSIRT as part of its product security initiatives and is also working to improve the transparency of vulnerability information as a CNA (CVE Numbering Authority).
For data protection, it offers rapid recovery with snapshots, backups, replication, and cloud integration with Hybrid Backup Sync (HBS). Furthermore, models equipped with QuTS hero can leverage ZFS-based data protection features and support immutable storage configurations that prevent modification and deletion with WORM (Write Once, Read Many). QNAP positions immutable technologies like WORM and Object Lock as an additional layer of defense against ransomware.
QNAP also offers an "Airgap+" solution that isolates backup data from the normal network, achieving a configuration where backup data is harder for attackers to find by disconnecting the communication path after backup completion. By combining HBS, ZFS WORM, immutable snapshots, and Airgap+, a more robust backup environment can be built for storing, protecting, and recovering critical data.
Through these features, QNAP supports secure data operations for a wide range of applications, including file sharing, backups, surveillance video storage, virtual environments, BCP measures, and ransomware countermeasures.
QNAP Inc. Comment
"NAS is a core IT infrastructure for storing the critical data of businesses and organizations. In recent years, as the importance of ransomware countermeasures, supply chain security, and security verification during IT equipment procurement has increased, we believe that the JC-STAR Level 1 compliance of QNAP NAS will serve as one of the peace-of-mind factors for our customers during product selection. QNAP will continue to provide reliable storage solutions and support our customers' data protection and secure IT operations."
About JC-STAR
JC-STAR is a security requirement compliance evaluation and labeling scheme for IoT products operated by the Information-technology Promotion Agency, Japan (IPA). Its purpose is to visualize the security level of products by level, making it easier for users and procurement managers to check security compliance status when selecting products.
Level 1, which QNAP NAS has complied with, indicates compliance with basic security requirements common to IoT products.
About QNAP Inc.
QNAP (Quality Network Appliance Provider) Systems, Inc. aims to deliver cutting-edge and comprehensive Network Attached Storage (NAS) and Network Video Recorder (NVR) solutions with ease-of-use and reliability, as promised by its brand name. We provide solutions with non-stop innovation and passion.
FACT BOX
- Source: PR TIMES
- Category: 製品認証