DPO Radio

Vietnam Cybersecurity Law

Overview Image

Why the Vietnam Cybersecurity Law Matters

The Law on Cybersecurity (LoCS) 116/2025/QH15 is Vietnam’s consolidated cybersecurity law. It took effect on 1 July 2026, replacing the earlier Law 24/2018 framework while preserving the need to understand evidence and obligations created during the transition.

Status: in force since 1 July 2026. The obligations apply now. Điều 45 khoản 1 preserves an information-system level already determined under the earlier stack, and gives twelve months from that date — to 30 June 2027 — to meet this Law's conditions, standards and protection measures for the preserved level. That deadline is the live piece of work for organisations that were already classified.

The operational burden spans incident response, authority cooperation, information and data security, provider content action, protection for vulnerable users, security controls, and localization readiness. These activities cross legal, security, technology, trust-and-safety, and management teams, so the quality of ownership and evidence matters as much as the written policy.

For domestic and foreign providers offering telecommunications, Internet, or value-added cyberspace services in Vietnam, Article 25(2)(b) sets a 24-hour window after a request from the Ministry of Public Security's specialist cybersecurity force to block sharing, delete unlawful information, or remove the affected service or application. The narrower emergency window is six hours when the request concerns an emergency threat to national security. These are provider action clocks, not generic incident-report deadlines.

The Law also requires named state bodies, state enterprises, political and socio-political organizations, and publicly funded service units to budget for cybersecurity. Article 38(1)'s minimum 15% allocation applies to the total budget of applicable digital-transformation and IT investment programmes, schemes, and projects. It is not a universal percentage for private businesses.

The framework's shared enforcement layer is now final law: Decree 330/2026/NĐ-CP, in force since 19 August 2026, sanctions both cybersecurity and personal data protection in one instrument. Cybersecurity fines are stated per individual with organizations at twice the level, to a 200 million VND organizational ceiling.

What the Vietnam Cybersecurity Law Covers

Dimension

Coverage

Status

In force since 1 July 2026. Preserved levels must meet this Law's requirements by 30 June 2027 (Điều 45 khoản 1).

Scope

Organizations operating information systems, online platforms, or digital infrastructure in Vietnam, including domestic online service providers and organizations whose data processing affects national security, social order, or economic rights.

Transition

Replaces Law 24/2018 while historical records and in-flight work may remain relevant.

Operational areas

Data security, provider response, cybersecurity incidents, authority cooperation, protected users, security governance, localization readiness, and supporting evidence.

Evidence requirements

Incident records, decisions, approvals, authority interactions, control evidence, remediation, and audit history.

Child instruments

Promulgated implementing decrees for general implementation, information-systems protection, violating-information handling and products/services licensing, active since 19 August 2026; a false-information decree in force from 5 October 2026; a civil-cryptography decree in force since 1 September 2026; Decree 343 on Ministry of National Defence cybersecurity duties and information-conflict response in force since 3 September 2026; and the shared Decree 330 sanctions layer.

Data Security Across the Lifecycle

The consolidated Law treats data security as an independent part of cybersecurity. Readiness work should cover collection, processing, storage, transmission, sharing, access, encryption, personnel controls, risk assessment, cross-border activity, and protection of important databases, data centres, and storage systems. Personal-data activity may also trigger separate obligations under the Personal Data Protection Law; one framework does not replace the other.

Online Safety and Protected Users

The prohibited-conduct framework includes unlawful use of artificial intelligence or new technology to impersonate another person's video, image, or voice, alongside prohibited false and fabricated information. Providers also need technical measures and usable reporting routes for content harmful to children, with appropriate warning and prioritized handling for older people and people who have difficulty with cognition or controlling their behaviour. Child account and guardian duties remain connected to child-protection law.

The Cybersecurity Instrument Stack

Law 116/2025/QH15

Active

Vietnam’s consolidated Cybersecurity Law, effective 1 July 2026, replacing the earlier Law 24/2018 framework while preserving relevant transition obligations and evidence.

Law 24/2018 and Decree 53 – Transition Context

Legacy

Records created under the earlier framework may still matter for historical periods, contracts, incidents, and regulator review during transition.

Decree 333/2026/NĐ-CP – General Implementation

Active

In force since 19 August 2026. Decree 333 sets general cybersecurity implementation procedures and provider duties, including verification, information provision, content removal, system-log retention, data localization, IP identification, and certified training. Key requirements include 24 hours (or 3 hours in emergencies) for information provision, 24 hours (or 6 hours in emergencies) for content removal, at least 12 months for retrievable system logs, and at least 24 months for required data localization. Whether a service is a covered provider depends on definitions under telecommunications law and may require deployment-specific legal analysis.

Decree 331/2026/NĐ-CP – Information Systems Protection

Active

In force since 19 August 2026. Decree 331 implements the five-level information-system classification regime, including classification criteria, protection duties, cloud and data-centre rules, incident reporting, and annual reporting. Incident requirements follow a 72-hour, 24-hour or immediate reporting ladder. Decree 85/2016 remains relevant during the transition for previously classified systems.

Decree 327/2026/NĐ-CP – Violating-Information Handling

Active

In force since 19 August 2026. Decree 327 covers preventing and handling violating information and acts in cyberspace, including provider duties, serious-attack reporting, data provision and content-removal deadlines, and continuous coordination requirements. Key deadlines include 24 hours for serious-attack reporting, 24 hours (or 3 hours in emergencies) for data provision, and 24 hours (or 6 hours in emergencies) for content removal.

 

Decree 332/2026/NĐ-CP – Products and Services Business

Active

Issued and in force since 19 August 2026, defines the regulated taxonomy; 8 product and 11 service categories, and the conditions and clocks of the 10-year trading licence, with no capital threshold anywhere in its conditions. 

 

Decree 328/2026/NĐ-CP – False Information

Upcoming

Issued on 19 August 2026 and taking effect on 5 October 2026. It establishes the umbrella definition of fake and false information, the six-step handling process, authority-side labeling and publication clocks and a 24/7 provider contact point. It sets no numeric provider-side removal deadline; direction-based clocks arise under Decree 327.

 

Decree 341/2026/NĐ-CP – Civil Cryptography

Active

In force since 1 September 2026. Decree 341 covers civil-cryptography business licensing, conformity requirements before products circulate, and separate import/export licensing. Ban Cơ yếu Chính phủ (the Government Cipher Committee) issues civil-cryptography licences, while the Ministry of Public Security handles only dual-use products with both civil-cryptographic and cybersecurity features.

 

Decree 343/2026/NĐ-CP – Cyber-Conflict Response

Active

In force since 3 September 2026. Decree 343 covers Cybersecurity Law matters within the Ministry of National Defence's remit, including military information systems, military-purpose cybersecurity products and services, and information-conflict prevention and response. Its conflict-response provisions do not set a general numeric response period, and Decree 333's deadlines should not be applied to them automatically.

  • Explore Decree 343 Cyber-Conflict Response
 

Decree 330/2026/NĐ-CP – Enforcement Penalties

Active

In force since 19 August 2026. Decree 330 sets penalty schedules for cybersecurity and personal data protection, including cybersecurity penalties relating to content-removal deadlines, authentication-log retention, and data localization. It is maintained separately from NQ22 procedural changes.

 

Related Laws and International Cooperation

The Cybersecurity Law intersects with the Electronic Transactions Law 2023, Telecommunications Law 2023, Personal Data Protection Law, and relevant civil, criminal, and child-protection rules. These are parallel legal frameworks, not child instruments of Law 116. The Law also connects with the UN Convention against Cybercrime (Hanoi Convention) for international cooperation, electronic evidence, data preservation, and tracing where a relevant cooperation or investigation context applies.

Overview Image

How ComplianceOne Supports the Vietnam Cybersecurity Law

ComplianceOne structures cybersecurity incidents from intake through assessment, escalation, investigation, remediation, and closure. Evidence remains linked to the case, including who contributed, who reviewed, and which decisions were approved.

Authority interactions can be recorded with the request, scope, responsible owner, legal review, response material, and proof of completion. This creates a coherent record for both planned cooperation and urgent response work.

Security and localization readiness can be managed through assigned reviews, control evidence, findings, and remediation tasks. Vendor or service-provider dependencies can be linked to the same work so third-party evidence does not sit outside the compliance record.

Draft enforcement readiness is maintained as a separate change-management track. Teams can assess whether current evidence would support an inspection or enforcement response without treating draft provisions or fine amounts as enacted.

Related Modules

Incident OperationsIncident Operations

Coordinates investigation, evidence, escalation, remediation, and closure.

Explore Incident Operations

Incident ResponseIncident Response

Supports notifications, response records, and authority interactions.

Explore Incidents

Monitoring ProgramsMonitoring Programs

Tracks recurring data-security, provider-response, protected-user, and transition reviews.

Explore Monitoring Programs

Access AccountabilityAccess Accountability

Maintains access-control and accountability evidence.

Explore Access Accountability

Audit TrailAudit Trail

Preserves contributor, decision, approval, and evidence history.

Explore Audit Trail

Program GovernanceProgram Governance

Organizes readiness reviews, policy ownership, and regulatory change.

Explore Program Governance

Compare the Difference

Graphic Image

Without Structured Framework Operations

Graphic Image

With ComplianceOne

IconIncidents are handled across chat, email, and documents with no single evidence chain.
IconIncidents follow a governed case process with linked evidence and decisions.
IconAuthority requests lose verification, approval, or response context.
IconAuthority interactions retain ownership, review, response, and completion proof.
IconLocalization and control reviews become static assessments that are not maintained.
IconReadiness reviews connect findings to accountable remediation work.
IconTransition records under the earlier law are difficult to retrieve.
IconHistorical and current framework records remain distinguishable and searchable.
IconDraft sanctions are confused with current legal consequences.
IconDraft enforcement preparation stays separate from enacted obligations.

Built for Cybersecurity Law Compliance Operations

Build For Image

ComplianceOne supports cross-team incident and authority-response work with reviewable evidence from first report through closure.

Build For Image

Transition context, current readiness, and the shared draft enforcement layer remain distinct, reducing the risk of misleading status or penalty claims.

Build For Image

Where the same event also involves personal data, related records can be connected while each framework keeps its own obligations and history.

Background Image

See Vietnam Cybersecurity Law Compliance in Action

Ready to see how ComplianceOne manages cybersecurity obligations operationally? Request a demo tailored to your organization's needs.

Demo Image
Ronni K. Gothard Christiansen

Ronni K. Gothard Christiansen - Technical Privacy Engineer & CEO

Technical Compliance Expert, 32+ Years Open Source Advocate, X-BoD Open Source Matters Inc.

Or contact via

ronni@aesirx.io+84 909 500 760

People Also Ask

Law 116/2025/QH15 took effect on 1 July 2026. Article 45 preserves an information-system level determined under the earlier stack but gives twelve months to meet the new conditions, preserves qualifying earlier licences until their recorded expiry, and gives qualifying products, services, solutions, and technical means already in use a separate twelve-month conformance period.

They are provider action windows under Article 25(2)(b). An in-scope provider has up to 24 hours after a request from the Ministry of Public Security's specialist cybersecurity force to block sharing, delete unlawful information, or remove the affected service or application. The six-hour window applies only to the stated emergency threat to national security; neither period is a universal incident-report deadline.

No. Article 38(1) names state bodies, state enterprises, political and socio-political organizations, and publicly funded service units, and applies the minimum to qualifying digital-transformation and IT investment programmes, schemes, and projects. It should not be presented as a universal private-sector percentage.

Yes. Law 116/2025/QH15 Điều 45 khoản 1 preserves a level already determined under the earlier stack, and gives twelve months from 1 July 2026 to 30 June 2027 to meet the new Law's conditions, standards and protection measures for that level. ComplianceOne keeps the determination readable alongside that date.

Yes. The cluster was promulgated on 19 August 2026: the general implementing decree (333), the information-systems protection decree (331), the violating-information handling decree (327) and the products-and-services business decree (332) are in force from that date, and the false-information decree (328) is signed final law taking effect on 5 October 2026. The two consultation drafts are retained as legacy records for lineage. Two further decrees followed in September 2026; the civil-cryptography decree (341), in force since 1 September, and the signed cyber-conflict response decree (343), issued and effective on 3 September.

The Incident Operations module manages the full incident lifecycle: detection, triage, escalation based on severity classification, authority notification through defined channels, investigation with evidence collection, remediation tracking, and case closure. Evidence chain of custody is maintained throughout, with tamper-evident records of every action.

 

Yes. The Monitoring Programs module manages all types of authority requests – information requests, system access requests, operational data requests – through a structured workflow with verification, legal review, management approval, response execution, and closure. Every interaction is logged in a centralized disclosure register.

 

Data localization readiness is managed through the Program Governance module with governance workflows that document in-scope determination (based on service type, user count, and data types), localization assessment, compliance status, and ongoing review schedules. Evidence of compliant storage and retention practices is maintained with audit trail coverage.

 

Yes. ComplianceOne supports Vietnam regulatory frameworks within a shared workflow engine. Organizations subject to both the Cybersecurity Law and the PDPL manage all obligations from a single platform. When a cybersecurity incident also involves a personal data breach, both the cybersecurity incident workflow and the PDPL breach notification workflow operate in coordination with consistent evidence production.

 

Next Steps

Icon Image

Start a Compliance Pilot

Test incident, authority-response, and transition-readiness workflows with your team.

Icon Image

Discuss Your Compliance Needs

Talk to our team about cybersecurity compliance operations, multi-framework coverage, and deployment for your organization.