DPO Radio

The Law on Cybersecurity (LoCS) 116/2025/QH15 is Vietnam’s consolidated cybersecurity law. It took effect on 1 July 2026, replacing the earlier Law 24/2018 framework while preserving the need to understand evidence and obligations created during the transition.
Status: in force since 1 July 2026. The obligations apply now. Điều 45 khoản 1 preserves an information-system level already determined under the earlier stack, and gives twelve months from that date — to 30 June 2027 — to meet this Law's conditions, standards and protection measures for the preserved level. That deadline is the live piece of work for organisations that were already classified.
The operational burden spans incident response, authority cooperation, information and data security, provider content action, protection for vulnerable users, security controls, and localization readiness. These activities cross legal, security, technology, trust-and-safety, and management teams, so the quality of ownership and evidence matters as much as the written policy.
For domestic and foreign providers offering telecommunications, Internet, or value-added cyberspace services in Vietnam, Article 25(2)(b) sets a 24-hour window after a request from the Ministry of Public Security's specialist cybersecurity force to block sharing, delete unlawful information, or remove the affected service or application. The narrower emergency window is six hours when the request concerns an emergency threat to national security. These are provider action clocks, not generic incident-report deadlines.
The Law also requires named state bodies, state enterprises, political and socio-political organizations, and publicly funded service units to budget for cybersecurity. Article 38(1)'s minimum 15% allocation applies to the total budget of applicable digital-transformation and IT investment programmes, schemes, and projects. It is not a universal percentage for private businesses.
The framework's shared enforcement layer is now final law: Decree 330/2026/NĐ-CP, in force since 19 August 2026, sanctions both cybersecurity and personal data protection in one instrument. Cybersecurity fines are stated per individual with organizations at twice the level, to a 200 million VND organizational ceiling.
In force since 1 July 2026. Preserved levels must meet this Law's requirements by 30 June 2027 (Điều 45 khoản 1).
Organizations operating information systems, online platforms, or digital infrastructure in Vietnam, including domestic online service providers and organizations whose data processing affects national security, social order, or economic rights.
Replaces Law 24/2018 while historical records and in-flight work may remain relevant.
Data security, provider response, cybersecurity incidents, authority cooperation, protected users, security governance, localization readiness, and supporting evidence.
Incident records, decisions, approvals, authority interactions, control evidence, remediation, and audit history.
Promulgated implementing decrees for general implementation, information-systems protection, violating-information handling and products/services licensing, active since 19 August 2026; a false-information decree in force from 5 October 2026; a civil-cryptography decree in force since 1 September 2026; Decree 343 on Ministry of National Defence cybersecurity duties and information-conflict response in force since 3 September 2026; and the shared Decree 330 sanctions layer.
The consolidated Law treats data security as an independent part of cybersecurity. Readiness work should cover collection, processing, storage, transmission, sharing, access, encryption, personnel controls, risk assessment, cross-border activity, and protection of important databases, data centres, and storage systems. Personal-data activity may also trigger separate obligations under the Personal Data Protection Law; one framework does not replace the other.
The prohibited-conduct framework includes unlawful use of artificial intelligence or new technology to impersonate another person's video, image, or voice, alongside prohibited false and fabricated information. Providers also need technical measures and usable reporting routes for content harmful to children, with appropriate warning and prioritized handling for older people and people who have difficulty with cognition or controlling their behaviour. Child account and guardian duties remain connected to child-protection law.
Vietnam’s consolidated Cybersecurity Law, effective 1 July 2026, replacing the earlier Law 24/2018 framework while preserving relevant transition obligations and evidence.
Records created under the earlier framework may still matter for historical periods, contracts, incidents, and regulator review during transition.
In force since 19 August 2026. Decree 333 sets general cybersecurity implementation procedures and provider duties, including verification, information provision, content removal, system-log retention, data localization, IP identification, and certified training. Key requirements include 24 hours (or 3 hours in emergencies) for information provision, 24 hours (or 6 hours in emergencies) for content removal, at least 12 months for retrievable system logs, and at least 24 months for required data localization. Whether a service is a covered provider depends on definitions under telecommunications law and may require deployment-specific legal analysis.
In force since 19 August 2026. Decree 331 implements the five-level information-system classification regime, including classification criteria, protection duties, cloud and data-centre rules, incident reporting, and annual reporting. Incident requirements follow a 72-hour, 24-hour or immediate reporting ladder. Decree 85/2016 remains relevant during the transition for previously classified systems.
In force since 19 August 2026. Decree 327 covers preventing and handling violating information and acts in cyberspace, including provider duties, serious-attack reporting, data provision and content-removal deadlines, and continuous coordination requirements. Key deadlines include 24 hours for serious-attack reporting, 24 hours (or 3 hours in emergencies) for data provision, and 24 hours (or 6 hours in emergencies) for content removal.
Issued and in force since 19 August 2026, defines the regulated taxonomy; 8 product and 11 service categories, and the conditions and clocks of the 10-year trading licence, with no capital threshold anywhere in its conditions.
Issued on 19 August 2026 and taking effect on 5 October 2026. It establishes the umbrella definition of fake and false information, the six-step handling process, authority-side labeling and publication clocks and a 24/7 provider contact point. It sets no numeric provider-side removal deadline; direction-based clocks arise under Decree 327.
In force since 1 September 2026. Decree 341 covers civil-cryptography business licensing, conformity requirements before products circulate, and separate import/export licensing. Ban Cơ yếu Chính phủ (the Government Cipher Committee) issues civil-cryptography licences, while the Ministry of Public Security handles only dual-use products with both civil-cryptographic and cybersecurity features.
In force since 3 September 2026. Decree 343 covers Cybersecurity Law matters within the Ministry of National Defence's remit, including military information systems, military-purpose cybersecurity products and services, and information-conflict prevention and response. Its conflict-response provisions do not set a general numeric response period, and Decree 333's deadlines should not be applied to them automatically.
In force since 19 August 2026. Decree 330 sets penalty schedules for cybersecurity and personal data protection, including cybersecurity penalties relating to content-removal deadlines, authentication-log retention, and data localization. It is maintained separately from NQ22 procedural changes.
The Cybersecurity Law intersects with the Electronic Transactions Law 2023, Telecommunications Law 2023, Personal Data Protection Law, and relevant civil, criminal, and child-protection rules. These are parallel legal frameworks, not child instruments of Law 116. The Law also connects with the UN Convention against Cybercrime (Hanoi Convention) for international cooperation, electronic evidence, data preservation, and tracing where a relevant cooperation or investigation context applies.

ComplianceOne structures cybersecurity incidents from intake through assessment, escalation, investigation, remediation, and closure. Evidence remains linked to the case, including who contributed, who reviewed, and which decisions were approved.
Authority interactions can be recorded with the request, scope, responsible owner, legal review, response material, and proof of completion. This creates a coherent record for both planned cooperation and urgent response work.
Security and localization readiness can be managed through assigned reviews, control evidence, findings, and remediation tasks. Vendor or service-provider dependencies can be linked to the same work so third-party evidence does not sit outside the compliance record.
Draft enforcement readiness is maintained as a separate change-management track. Teams can assess whether current evidence would support an inspection or enforcement response without treating draft provisions or fine amounts as enacted.
Coordinates investigation, evidence, escalation, remediation, and closure.
Explore Incident OperationsSupports notifications, response records, and authority interactions.
Explore IncidentsTracks recurring data-security, provider-response, protected-user, and transition reviews.
Explore Monitoring ProgramsMaintains access-control and accountability evidence.
Explore Access AccountabilityOrganizes readiness reviews, policy ownership, and regulatory change.
Explore Program Governance


ComplianceOne supports cross-team incident and authority-response work with reviewable evidence from first report through closure.

Transition context, current readiness, and the shared draft enforcement layer remain distinct, reducing the risk of misleading status or penalty claims.

Where the same event also involves personal data, related records can be connected while each framework keeps its own obligations and history.
Ready to see how ComplianceOne manages cybersecurity obligations operationally? Request a demo tailored to your organization's needs.

Law 116/2025/QH15 took effect on 1 July 2026. Article 45 preserves an information-system level determined under the earlier stack but gives twelve months to meet the new conditions, preserves qualifying earlier licences until their recorded expiry, and gives qualifying products, services, solutions, and technical means already in use a separate twelve-month conformance period.
They are provider action windows under Article 25(2)(b). An in-scope provider has up to 24 hours after a request from the Ministry of Public Security's specialist cybersecurity force to block sharing, delete unlawful information, or remove the affected service or application. The six-hour window applies only to the stated emergency threat to national security; neither period is a universal incident-report deadline.
No. Article 38(1) names state bodies, state enterprises, political and socio-political organizations, and publicly funded service units, and applies the minimum to qualifying digital-transformation and IT investment programmes, schemes, and projects. It should not be presented as a universal private-sector percentage.
Yes. Law 116/2025/QH15 Điều 45 khoản 1 preserves a level already determined under the earlier stack, and gives twelve months from 1 July 2026 to 30 June 2027 to meet the new Law's conditions, standards and protection measures for that level. ComplianceOne keeps the determination readable alongside that date.
Yes. The cluster was promulgated on 19 August 2026: the general implementing decree (333), the information-systems protection decree (331), the violating-information handling decree (327) and the products-and-services business decree (332) are in force from that date, and the false-information decree (328) is signed final law taking effect on 5 October 2026. The two consultation drafts are retained as legacy records for lineage. Two further decrees followed in September 2026; the civil-cryptography decree (341), in force since 1 September, and the signed cyber-conflict response decree (343), issued and effective on 3 September.
The Incident Operations module manages the full incident lifecycle: detection, triage, escalation based on severity classification, authority notification through defined channels, investigation with evidence collection, remediation tracking, and case closure. Evidence chain of custody is maintained throughout, with tamper-evident records of every action.
Yes. The Monitoring Programs module manages all types of authority requests – information requests, system access requests, operational data requests – through a structured workflow with verification, legal review, management approval, response execution, and closure. Every interaction is logged in a centralized disclosure register.
Data localization readiness is managed through the Program Governance module with governance workflows that document in-scope determination (based on service type, user count, and data types), localization assessment, compliance status, and ongoing review schedules. Evidence of compliant storage and retention practices is maintained with audit trail coverage.
Yes. ComplianceOne supports Vietnam regulatory frameworks within a shared workflow engine. Organizations subject to both the Cybersecurity Law and the PDPL manage all obligations from a single platform. When a cybersecurity incident also involves a personal data breach, both the cybersecurity incident workflow and the PDPL breach notification workflow operate in coordination with consistent evidence production.

Test incident, authority-response, and transition-readiness workflows with your team.

Talk to our team about cybersecurity compliance operations, multi-framework coverage, and deployment for your organization.