NVR/VMS Guide to NIS Security Requirements V3.0 Certification: A Security Conformity Verification Strategy for Video Security Products

Since April 2024, NVRs (network video recorders) and VMS (video management systems) must pass the National Intelligence Service (NIS) security conformity verification before they can be supplied to Korean public institutions. As hacking and backdoor threats in Chinese-made CCTV became a public concern, video information processing devices were added as a new product category in the NIS Security Requirements V3.0.

With the Korean security market projected to grow to KRW 10.6082 trillion in 2026, video security is the area where certification demand is rising fastest. This post covers everything NVR/VMS manufacturers need to know to prepare for Security Requirements V3.0 certification: the structure of the certification scheme, the security functional requirements that apply to NVR/VMS, the process and cost of obtaining a Security Function Confirmation, and a practical checklist.

Why Security Conformity Verification Became Mandatory for NVR/VMS

The Reality of Video Security Threats

CCTV infrastructure in public institutions is directly tied to national security. If video equipment installed in government buildings, military facilities, or transportation infrastructure is hacked, the consequences can range from real-time video leaks to theft of recorded data and the disabling of entire systems. As backdoors were repeatedly discovered in Chinese-made IP cameras and NVRs, verifying the security of video information processing devices became an urgent priority.

Why Video Information Processing Devices Were Added in V3.0

The NIS Security Requirements V2.0 contained no provisions for video security products. With IP cameras, NVRs, and VMS added as a new product category in V3.0, security conformity verification for these products took full effect in April 2024. This is not merely an expansion of the scheme; it signals a national commitment to systematically protecting public-sector video infrastructure.

Impact on NVR/VMS Manufacturers

NVR/VMS manufacturers targeting the public sector have no choice. Without a Security Function Confirmation, entering the public market is simply impossible. According to a Boan News survey, 71.4% of companies plan to apply for a Security Function Confirmation, so competition for certification is intensifying.

The Structure of NIS Security Requirements V3.0 and Where NVR/VMS Fit

Overview of Security Requirements V3.0

The national security requirements are reference documents established by the NIS to verify the safety of security products introduced into national and public institutions. They are legally binding under Article 4 of the National Intelligence Service Act, Article 56 of the Electronic Government Act, and Article 9 of the Cybersecurity Work Regulations. The NIS oversees the scheme, while the National Cyber Security Center (NCSC) and the National Security Research Institute (NSR) handle the practical work.

V3.0 consists of two main pillars: Common Security Requirements and Product-Specific Security Requirements. Every product must meet the common security requirements, plus the product-specific requirements for its own product category.

Where Do NVR/VMS Belong?

In the NIS security requirements list, V3.0 defines 34 product types, and NVR and VMS belong to the video information processing device category.

CategoryIncluded Products
Intrusion Blocking/PreventionFirewall (FW), Web Application Firewall (WAF), DDoS mitigation equipment, IPS, Wireless IPS
Network Segment SecurityVPN, cross-network data transfer, wireless LAN authentication, NAC
EndpointAntivirus, MDM, ransomware protection, OS access control
Network EquipmentL3 and higher switches, routers, SDN equipment
Video Information Processing DevicesIP cameras, NVR, VMS
New CategoryQuantum cryptography communication equipment

NVR/VMS are subject to a Security Function Confirmation, not CC certification. This is the starting point for any certification strategy. Unlike the 21 product types subject to CC certification, such as firewalls, NVR/VMS are certified through the relatively streamlined Security Function Confirmation process.

The 7 Security Functional Requirements for NVR/VMS

The security functional requirements (SFRs) in V3.0 are divided into seven areas. Each item is assigned a compliance level of "mandatory", "conditionally mandatory", or "optional". Let's look at what NVR/VMS manufacturers need to implement in each area.

1. Identification & Authentication

Administrators and operators accessing the NVR/VMS must be accurately identified, and only legitimate users may access the system.

  • Account/password-based authentication is mandatory: applies to the NVR/VMS management console, web interface, and mobile clients
  • Forced initial password change: users must change the factory default password (e.g., admin/admin) at first login
  • Authentication failure handling: lock the account after no more than 5 consecutive failures, and keep it locked for at least 5 minutes
  • Password complexity: prohibit 4 or more horizontally adjacent keyboard characters/digits in sequence, enforce minimum length, special characters, etc.
  • Multi-factor authentication (MFA) support: FIDO, OTP, certificate-based authentication — conditionally mandatory

Because NVR/VMS operate in environments where many remote users connect simultaneously, session management and concurrent-session limits must also be considered.

2. Access Control

Because NVR/VMS handle sensitive data in the form of recorded video, role-based access control is especially important.

  • Role-based access control (RBAC) is mandatory: separation of roles such as administrator, operator, and auditor
    • Administrator: system configuration, user management, security policy changes
    • Operator: live monitoring, recorded video search/playback (cannot change settings)
    • Auditor: view audit logs (access to video data can be restricted)
  • Per-camera/channel access control: grant specific users viewing rights only to specific camera groups
  • External directory service integration: integration with Active Directory, LDAP, etc. (permitted from V3.0 R1)

Public institutions frequently need video access rights broken down by building and department, so a flexible RBAC structure is essential.

3. Encryption and Data Protection

This is the most technically demanding area for NVR/VMS. Video data must be protected by encryption both in transit and at rest.

  • Encryption of data in transit: encrypt communication between NVR/VMS and IP cameras, and between NVR/VMS and clients, using HTTPS with TLS 1.2 or higher
  • Protection of stored data: integrity verification for recorded video — you must be able to prove the video has not been tampered with
  • Encrypted log transmission: support for syslog over TLS (RFC 5424) and syslog over DTLS (RFC 6012) is mandatory
  • Algorithms subject to validation: ARIA, SEED (block ciphers), SHA-2 (hash), HMAC (message authentication), CTR_DRBG (random number generation), ECDSA (digital signature), ECDH (key establishment)

Important: DES and AES are not covered by KCMVP validation. Even though AES is widely used internationally, NVR/VMS supplied to Korean public institutions must use ARIA or SEED. NVR/VMS are not currently among the three product types (VPN, secure USB, data leakage prevention) that are directly required to embed a KCMVP-validated cryptographic module, but using a KCMVP-validated module when implementing encryption works in your favor during the certification review.

4. Audit

You must be able to trace who accessed which video and when, and who changed system settings.

  • Mandatory audit events: user login/logout, video playback/download, security policy changes, camera connection/disconnection, recording setting changes, etc.
  • Audit record protection: prevent tampering with audit logs — not even administrators should be able to delete or modify logs
  • External log server integration: forward to a central log server via syslog over TLS
  • Storage management: secure external backup or separate storage so that audit records are not exhausted

Because NVR/VMS must retain audit logs for long periods alongside large volumes of video, audit record capacity must also be accounted for when designing storage.

5. Security Management

These are the functions for configuring and managing security policies. The NVR/VMS management interface itself must be secure.

  • Security policy configuration/change functions: administrators configure password, access control, and encryption policies through a GUI
  • Management interface security: enforce HTTPS for the web management console, allow the management port to be changed
  • Secure firmware/software updates: verify the integrity of update files (signature check) before applying them

6. Self-Protection

The security functions of the NVR/VMS (TSF) themselves must be protected from attack.

  • Domain separation: separate security functions from general functions (video processing, etc.)
  • Non-bypassability: design so that video cannot be accessed directly by bypassing security functions
  • Secure Boot: for NVR hardware, verify firmware integrity at boot
  • TSF integrity verification: periodically check security function modules for tampering

Since an NVR is a hardware appliance, physical security (protection against direct removal of hard disks) must also be considered; since a VMS is software, self-protection designed in conjunction with the OS security of the installation environment is important.

7. Video Information Protection (New in V3.0 — Core NVR/VMS Requirement)

These requirements were added in V3.0 specifically for video information processing devices. They are the key differentiator of NVR/VMS certification.

  • Video data integrity: a mechanism to verify that recorded video has not been forged or altered (hashes, watermarks, etc.)
  • Video export control: permission checks and history logging when video is downloaded/exported
  • Privacy protection: support for masking personal information (faces, etc.) in video — aligned with the Personal Information Protection Act
  • Video deletion protection: prevent unauthorized deletion of video within the retention period

The Certification Path for NVR/VMS: Security Function Confirmation

NVR/VMS are subject to a Security Function Confirmation, not CC certification. The process is simpler and shorter than CC certification, making it more accessible in practice.

The 5 Steps to Obtaining a Security Function Confirmation

  1. Document submission: the manufacturer prepares and submits five documents.
    • Product description — NVR/VMS hardware/software configuration, supported camera protocols, etc.
    • Security function implementation specification — detailed description of how the 7 security functions are implemented
    • Security function operation guide — how administrators/operators configure and use the security functions
    • Test report — evidence from in-house testing that the security functions work correctly
    • Vulnerability remediation report — record of responses to known vulnerabilities
  2. Security function testing: an accredited testing laboratory such as Korea System Assurance (KOSYAS) performs the security function tests. This takes about 30 days.
  3. Result review: the National Security Research Institute (NSR) reviews the test results.
  4. Issuance: after review by the NIS, the Security Function Confirmation is issued.
  5. Post-certification maintenance: when the product changes, an identity check (KRW 3.11 million, 3 days) or re-testing is required.

NVR/VMS Security Function Confirmation: Cost and Validity Period

According to a Boan News report, testing costs vary by product type.

ItemCostNotes
IP cameraKRW 14.9 million20% SME discount may apply
NVR/VMS (storage · management products)KRW 16.3 million20% SME discount may apply
Identity checkKRW 3.11 million3 days, when the product changes

The validity period is 5 years under Security Requirements V3.0 and 2 years under the basic security requirements (V2.0). In terms of validity, certifying against V3.0 is clearly the better choice.

CC Certification vs. Security Function Confirmation — Where Do NVR/VMS Fall?

ItemCC CertificationSecurity Function Confirmation
Scope21 types of information security products, such as firewallsNetwork equipment, NVR/VMS, IP cameras, etc.
International recognitionMutual recognition among CCRA membersKorea only
Evaluation periodSeveral months to over a yearAbout 30 days (testing period)
Validity5 years for new, 3 years for existing5 years under V3.0, 2 years under V2.0
CostRelatively highKRW 16.3 million for NVR/VMS
Applies to NVR/VMS✕✓

NVR/VMS manufacturers should pursue certification via the Security Function Confirmation path. You can check the certification type for each product category on the KISIA security conformity verification guide page.

Essential Technical Implementation for NVR/VMS Certification

Passing Security Requirements V3.0 certification is not just about having the features; they must be implemented to the level defined in the requirements. Below are the technical elements to focus on when developing NVR/VMS products.

1. Encrypting Video Transmission Paths

  • IP camera → NVR: apply RTSP over TLS or SRTP
  • NVR/VMS → client: HTTPS (TLS 1.2 or higher) is mandatory
  • NVR → VMS integration: encrypted API communication
  • Implementation based on Korean validated algorithms (ARIA, SEED) is mandatory

2. Ensuring Recorded Video Integrity

  • Generate and verify hash values (SHA-256) for recording files
  • Embed a watermark or digital signature when exporting video
  • Mechanism to prevent unauthorized deletion of recorded data

3. User Authentication and Access Control

  • RBAC-based access control per camera/channel
  • Forced initial password change — block use of factory default accounts
  • Automatic lockout after consecutive authentication failures (5 attempts / 5 minutes)
  • Strengthened ONVIF protocol authentication security

4. Audit Logging and Central Management

  • Record every video playback/download/deletion event
  • External SIEM integration via syslog over TLS
  • Tamper protection and long-term retention of audit logs

5. Self-Protection and Firmware Security

  • NVR: Secure Boot support, firmware signature verification
  • VMS: installer integrity verification, integration with OS security
  • Non-bypassable security design — prevent video theft via direct HDD access

Certification Readiness Checklist for NVR/VMS Manufacturers

Here is a core checklist for NVR/VMS manufacturer staff starting certification preparation.

Preliminary Review

  • Clearly classify your product as an NVR, a VMS, or an integrated product
  • Confirm it is subject to a Security Function Confirmation (not CC certification)
  • Obtain the common security requirements (server) + product-specific requirements for video information processing devices
  • Freeze the hardware/software versions of the product to be certified

Technical Implementation

  • Implement ARIA/SEED-based video transmission encryption (not AES)
  • TLS 1.2 or higher — across the management console, APIs, and all video transmission paths
  • Implement syslog over TLS/DTLS integration
  • RBAC-based access control — separate administrator/operator/auditor roles
  • Per-camera/channel access control
  • Forced initial password change
  • Authentication failure handling (lock after 5 attempts, 5-minute wait)
  • Recorded video integrity verification (hash/watermark)
  • Video export control and history management
  • Audit records — log every access, playback, download, and configuration change
  • Self-protection — Secure Boot (NVR), firmware signature verification

Document Preparation

  • Product description — hardware specifications, software configuration, supported protocols
  • Security function implementation specification — detailed implementation for each of the 7 security functions
  • Security function operation guide — administrator/operator manual
  • Test report — results of in-house security function testing
  • Vulnerability remediation report — including CVE responses

Schedule and Budget Planning

  • Security function testing period: about 30 days
  • Testing cost: KRW 16.3 million for NVR/VMS (20% SME discount available)
  • Identity check (when the product changes): KRW 3.11 million / 3 days
  • Pre-certification consulting: 3–6 months of technical remediation may be needed depending on product status

From V2.0 to V3.0 — What Changed for NVR/VMS

ItemV2.0V3.0
Video security productsNot includedSecurity conformity verification for IP cameras/NVR/VMS in effect
Access controlOnly in-product implementation allowedUse of external directory services (AD, etc.) allowed
Protection of data in transitBasic encryption requiredExplicit requirement for syslog over TLS/DTLS added
Security Function Confirmation validity2 yearsExtended to 5 years under V3.0
Password policyAmbiguous criteriaClarified as "4 or more horizontally adjacent characters/digits"

For NVR/VMS manufacturers, the most important change is clear: under V2.0 they were not even subject to certification, but under V3.0 certification is mandatory. Certifying against V3.0 also brings a 5-year validity period, so it makes sense to prepare against V3.0 from the start.

Outlook — The NVR/VMS Security Certification Market

  • Transition from TTA certification: new applications for the existing TTA (Telecommunications Technology Association) certification stopped in April 2025, and its validity expires in April 2028. The trend is toward consolidation under the NIS Security Function Confirmation scheme.
  • Surging certification demand: as security conformity verification for video security products becomes mandatory, demand for NVR/VMS certification is rising sharply. Waiting times at testing labs may grow, so applying early is an advantage.
  • Stricter requirements expected: just as quantum cryptography communication equipment was added, requirements for video information processing devices are expected to tighten gradually. Security criteria for new technologies such as AI-based video analytics and cloud VMS are likely to be added.
  • Replacement demand in the public sector: as demand arises to replace installed products that have not passed security conformity verification, manufacturers that obtain certification early will have the chance to capture the market first.

Conclusion: Why NVR/VMS Manufacturers Should Start V3.0 Certification Now

The NIS Security Requirements V3.0 are both a threat and an opportunity for NVR/VMS manufacturers. The key points are as follows.

First, since April 2024, a Security Function Confirmation has been mandatory for NVR/VMS supplied to public institutions. Without certification, entering the market is impossible. Second, NVR/VMS are certified through the Security Function Confirmation path, with a testing period of about 30 days and a cost of around KRW 16.3 million. The 5-year validity under V3.0 is a significant advantage. Third, core technical elements such as ARIA/SEED-based encryption, RBAC, video integrity verification, and audit logging must be implemented correctly.

With certification demand surging, waiting times at testing labs keep getting longer. If technical remediation takes 3–6 months and testing takes another month, you need to start now to obtain certification within this year. If you are an NVR/VMS manufacturer, don't put off V3.0 certification preparation any longer.

References


Related Posts