DPO Radio

Measure Value, Not Just Traffic Explore new features in AesirX Analytics

Vietnam Cybersecurity Law 24/2018

Overview Image

Law 24/2018/QH14: Scope and Current Status

Law 24/2018/QH14 (the Vietnam Cybersecurity Law 2018) was enacted on June 12, 2018, and entered into force on January 1, 2019. Administered by the Ministry of Public Security (MPS), it established Vietnam's foundational cybersecurity regulatory framework, covering cybersecurity obligations for organizations operating information systems, online platforms, and digital infrastructure within Vietnam. It was the first comprehensive cybersecurity statute in Vietnam and created the primary obligations for incident response and notification, authority cooperation, data localization, and in-scope determination that have shaped cybersecurity compliance practice in the country.

Law 24 remained in force from January 1, 2019 until it was replaced by Law 116/2025/QH15 on July 1, 2026. While no longer the governing cybersecurity framework, organizations that operated during the Law 24 period remain responsible for maintaining historical compliance records, evidence, and documentation created under its requirements. These records continue to support inspections, audits, and transition assessments under the current framework.

The practical significance of Law 24 today extends beyond its historical role as Vietnam's foundational cybersecurity framework. Organizations subject to Law 24 built compliance programs, completed in-scope determinations, established incident response procedures, implemented data localization measures, and created authority cooperation protocols under its requirements. Understanding those requirements remains necessary to assess the completeness of historical compliance programs, correctly scope evidence retention for the Law 24 period, and understand the transition from Law 24 to Law 116/2025/QH15.

Overview Image

How Law 24/2018 Relates to the Vietnam Cybersecurity Law 2025

The Vietnam Cybersecurity Law 2025 (Law 116/2025/QH15) replaced Law 24/2018 on July 1, 2026, becoming Vietnam's current cybersecurity framework. For organizations managing current cybersecurity obligations, see the Vietnam Cybersecurity Law 2025 (Law 116/2025/QH15) compliance page.

Law 24 is the predecessor framework on which Law 116 builds. Organizations that operated under Law 24 retain historical compliance records, evidence, and governance documentation that remain relevant for inspections, audits, and transition assessments. Understanding the relationship between the two laws helps organizations distinguish legacy obligations from current requirements while maintaining an accurate compliance history.

Organizations should retain historical compliance evidence and clearly attribute it to the framework that applied at the time. Incident records, authority cooperation logs, in-scope determinations, data localization documentation, and other compliance evidence created under Law 24 should remain identifiable as legacy records alongside current compliance activities under Law 116. Maintaining this distinction supports inspections, audits, evidence continuity, and an accurate historical compliance record.

Technical Provisions and Compliance Obligations Under Law 24

ObligationRequirementImplementing Reference
In-scope determinationOrganizations providing domestic online services, storing or processing data affecting national security, social order, or economic rights must determine their in-scope statusLaw 24, Article 26; Decree 13/2022
Data localizationIn-scope organizations must store "important data" domestically; foreign organizations must maintain a local representative or officeLaw 24, Article 26
Cybersecurity incident notificationOrganizations must notify MPS of cybersecurity incidents that affect information systems, with notification to authority through defined channelsLaw 24, Article 18
Authority cooperationOrganizations must cooperate with MPS cybersecurity investigations, provide system access when required, and respond to information requestsLaw 24, Articles 23, 24
Cybersecurity condition complianceOrganizations operating important information systems must maintain prescribed cybersecurity conditions, conduct periodic security reviews, and submit to MPS auditsLaw 24, Articles 22, 23
Content removalPlatforms must respond to MPS requests to remove unlawful content within prescribed windowsLaw 24, Article 16
User data provisionIn-scope organizations must provide user data to MPS upon request in accordance with legal requirementsLaw 24, Article 26

In-scope determination was one of the foundational compliance obligations under Law 24. Decree 13/2022/ND-CP specified the following criteria.

CriterionThresholdImplication
Service typeDomestic online services (telecommunications, internet, payment, e-commerce, social networking, search, email, and others)All major digital service categories are potentially in-scope
User count or data volumeMOrganizations with significant user bases or data volumes affecting national interestsThreshold assessment required; no single published number – assessment based on service and data type
Data typeData affecting national security, social order, public health, or economic rightsData classification assessment required to identify qualifying data
Regulatory designationCritical information infrastructure operators as designated by sector regulatorsCheck applicable sector regulatory designation

ObligationTimelineReference
Cybersecurity incident notification to MPSWithin prescribed window based on incident severityLaw 24, Article 18
Response to MPS information requestsWithin the window specified in the MPS requestLaw 24, Article 23
Content removal upon MPS orderWithin 24 hours of MPS notificationLaw 24, Article 16
Cybersecurity condition complianceOngoing; periodic review requiredDecree 13/2022

Why Organizations Must Still Understand Law 24/2018

Law 24/2018 remains operationally relevant for organizations maintaining historical cybersecurity compliance records and evidence.

Historical compliance records

Law 24 governed Vietnam's cybersecurity framework from January 1, 2019 until June 30, 2026. Organizations that operated during this period created compliance records under its requirements, including incident notifications, authority cooperation records, in-scope determinations, and data localization documentation. These records remain part of an organization's historical compliance evidence and should continue to be retained and accessible.

Evidence continuity for the Law 24 period

Historical compliance evidence created under Law 24 reflects the legal requirements that applied at the time. Regulators conducting inspections or audits may review activities undertaken during the Law 24 period, making it important that incident records, authority cooperation logs, governance decisions, and supporting documentation remain complete, accessible, and clearly attributed to the correct legal framework. Evidence created under Law 24 should remain distinct from records produced under Law 116.

Historical baseline for Law 116

Law 24 provides the historical baseline from which organizations transitioned to Law 116/2025/QH15. Understanding what was implemented under Law 24, including in-scope determinations, data localization measures, incident response procedures, and governance controls, helps demonstrate how cybersecurity compliance evolved over time. Maintaining that baseline supports structured governance, evidence continuity, and an accurate historical compliance record.

Overview Image

How ComplianceOne Supports Law 24/2018 Compliance

ComplianceOne supports organizations managing Law 24 compliance records through its cybersecurity incident operations, authority cooperation, and program governance capabilities, with evidence continuity features that preserve historical compliance records alongside the current Law 116 framework.

The Incident Response module manages cybersecurity incident case records created under Law 24's notification requirements. Each case captures the incident discovery timestamp, assessment timeline, notification to MPS, and any authority follow-up, preserving the evidence chain of custody that demonstrates compliance with the notification obligation. Incident cases can be attributed to the applicable legal framework based on the incident date, ensuring that historical Law 24 records remain clearly distinguished from records created under Law 116.

The Monitoring Programs module manages authority cooperation records under Law 24, including MPS information requests, system access requests, and user data provision requests, through a structured workflow with verification, legal review, approval, and disclosure logging. Each authority interaction is captured in the centralized disclosure register with the legal basis, scope, approving authority, and response details. This register preserves historical evidence of Law 24 authority cooperation and supports future inspections and audits.

For in-scope determination and data localization documentation, the Program Governance module records the in-scope assessment, the criteria applied under Decree 13/2022, the determination outcome, and the data localization measures implemented. These records provide the historical evidence of an organization's Law 24 compliance program and remain part of its long-term compliance archive.

Related Modules

Incident ResponseIncident Response

Manages cybersecurity incident notification workflows under Law 24's notification requirements with timestamp-based compliance evidence.

Explore Incidents

Monitoring ProgramsMonitoring Programs

Handles MPS authority cooperation workflows (information requests, system access, user data provision) with centralized disclosure logging.

Explore Monitoring Programs

Program GovernanceProgram Governance

Documents in-scope determination, data localization compliance, and cybersecurity condition compliance reviews under Decree 13/2022.

Explore Program Governance

Audit TrailAudit Trail

Maintains tamper-evident historical records for the full Law 24 compliance period, supporting post-transition inspection readiness.

Explore Audit Trail

Compliance Readiness Checklist

Organizations maintaining Law 24/2018 compliance records should confirm:

In-scope determination has been conducted and documented per Decree 13/2022 criteria.

Data localization compliance has been implemented and documented for qualifying data categories.

Cybersecurity incident notification workflows are configured per Law 24's notification requirements.

MPS authority cooperation workflows are in place with verification gates, approval chains, and disclosure logging.

Historical incident notification records are retained and accessible in their original form.

Authority cooperation records from the Law 24 era are retained in the centralized disclosure register.

A transition gap analysis against Law 116/2025/QH15 has been initiated.

Dual-track compliance management is in place for the transition period (active Law 24 compliance + Law 116 preparation).

Evidence pack generation has been tested for Law 24-era compliance records.

Background Image

See Law 24/2018 Compliance Records in Action

Ready to see how ComplianceOne manages Law 24/2018 compliance records, preserves historical evidence, and maintains continuity alongside Law 116? Request a demo tailored to your organization's cybersecurity compliance needs.

Demo Image
Ronni K. Gothard Christiansen

Ronni K. Gothard Christiansen - Technical Privacy Engineer & CEO

Technical Compliance Expert, 32+ Years Open Source Advocate, X-BoD Open Source Matters Inc.

Or contact via

ronni@aesirx.io+84 909 500 760

Frequently Asked Questions

Law 24/2018/QH14 remained the governing cybersecurity framework until July 1, 2026, when it was replaced by Law 116/2025/QH15 (the Vietnam Cybersecurity Law 2025). Organizations that operated in Vietnam during the Law 24 period should retain compliance records and evidence created under that framework as part of their historical compliance record.

The most significant consideration is maintaining a complete historical compliance record. Organizations should retain Law 24 compliance records, evidence, and governance documentation while clearly distinguishing them from records created under Law 116. ComplianceOne's Program Governance module supports framework-specific record management and evidence continuity.

In-scope determination under Decree 13/2022 requires assessment against four primary criteria: service type (whether the organization provides one of the designated domestic online service categories), user count or data volume (whether the scale of operations affects national interests), data type (whether the data processed affects national security, social order, or economic rights), and regulatory designation (whether the organization has been designated as critical information infrastructure). The assessment must be documented with the criteria applied, data gathered, and determination reached.

Law 24 compliance records must be retained per applicable retention schedules even after Law 116 takes effect. Regulators may examine historical compliance conduct under the framework applicable at the time, meaning Law 24 records remain relevant for any inspection covering periods before July 1, 2026. These records should be maintained in accessible form and clearly attributed to the Law 24 compliance period.

Next Steps

Icon Image

Start a Compliance Pilot

Test Law 24/2018 incident operations, authority cooperation, and in-scope determination workflows with your team – including transition readiness assessment.

Icon Image

Discuss Your Compliance Needs

Talk to our team about Law 24/2018 compliance management, transition planning to Law 116, and dual-track cybersecurity compliance for your organization.