DPO Radio

Decree 333/2026/NĐ-CP was issued by the Government on 19 August 2026 and took effect the same day; no grace period between issuance and effect. It runs to 32 articles across six chapters, with the Ministry of Public Security as lead authority. It is promulgated, in force, and not a proposal.
The decree details the order and procedures for the cybersecurity protection measures; appraisal, condition assessment, monitoring, inspection, incident response, cryptography, information removal, electronic data collection, system suspension and domain-name revocation, the network-information-security duties of domestic and foreign service providers, the IP address identification regime for telecom and Internet providers, and the certified advanced cybersecurity training system.
One scope point deserves care before any obligation is assumed. The provider duties attach to services on telecom networks, the Internet and value-added services on cyberspace, and the decree defines that last category by cross-reference to value-added telecom services under telecom law, not by listing platform types. Whether a specific service falls inside the perimeter can therefore turn on how it classifies under telecom law in its actual deployment, and that is a legal analysis of the deployment, not a fact this page can assert for anyone.
This instrument promulgates the draft general implementing decree tracked during the consultation period. The draft is retained as a legacy record so readiness history stays addressable, but it no longer states current law.

Cybersecurity Law 116/2025/QH15, in force since 1 July 2026, is the parent instrument. Decree 333 supplies the procedures and numbers the Law delegated: how appraisal, condition assessment, monitoring, inspection and the other protection measures actually run; what the provider duty set contains and on which clocks; how IP addresses are identified; and how the certified training obligation rolls out.
The decree prescribes no monetary fines of its own. Sanctions for the duties it creates live in Decree 330/2026/NĐ-CP, and any fine figure quoted from that instrument must carry its individual-versus-organization attribution rule; cybersecurity amounts there are stated per individual, with organizations at twice the level.
It also does not stand alone among the 19 August instruments: the information-systems protection regime is Decree 331, violating-information handling procedure is Decree 327, and products-and-services licensing is Decree 332. Each carries its own duties; this decree is the general implementation layer.
| Provision | What It Establishes | Operational Implication |
|---|---|---|
| Điều 5, Điều 6 | Cybersecurity appraisal of critical-system designs and pre-operation condition assessment and certification, each on a 3-working-day dossier check and a 25-working-day completion clock | Critical-system projects need the dossier prepared before approval and go-live gates |
| Điều 8 | Self-inspection of critical systems with annual written results to the specialized force before 1 October each year | The inspection report is a recurring dated obligation, not a one-off |
| Điều 13 | System suspension, cessation and domain-name revocation powers — an urgent demand made by phone, fax or email must be papered in writing within 24 hours | Keep the oral demand and the written confirmation on one record |
| Điều 16 | Provider duty set: user verification, user-information provision within 24 hours (3 in emergencies), removal within 24 hours (6 in national-security emergencies), account locking, and system logs retrievable for at least 12 months | Every clock needs timestamped evidence from request receipt to completion |
| Điều 16 khoản 4 | Account measures: temporary visibility restriction or locking up to 60 days for 3+ violating posts within 30 days, up to 180 days for 10+ within 90 days, three indefinite-lock cases, and restoration grounds | Lock decisions need the triggering counts and the restoration review recorded |
| Điều 18 | Infrastructure-layer duty: telecom, Internet, hosting, data-center and telecom-application providers block and remove within 24 hours of a request made in writing, by phone or by email | Intake must catch non-written request channels too |
| Điều 19, Điều 20 | Data localization for at least 24 months and branch or representative-office establishment on the statutory triggers, with 12 months from the ministerial decision to comply | Foreign providers should track the three-notification trigger threshold, not only the decision |
| Điều 21–23 | The IP address identification regime: mandated session logging, 12-month IP allocation log retention, and provision within 24 hours (3 in emergencies), never exploited commercially | IP identification data is authority-facing evidence with its own retention floor |
| Điều 24–28 | Certified advanced cybersecurity training, with 24 months for incumbents in the Law's named positions and 36 months for level-3 to level-5 system owners' staff | Training review, budgeting and completion evidence run on decree-anchored deadlines |
| Điều 31 | Transitional rule: appraisal and condition-assessment dossiers pending under Decree 53/2022 are processed under Decree 53/2022 | In-flight dossiers keep their old procedure; new ones use this decree |
| Obligation | Timeline | Reference |
|---|---|---|
| Decree takes effect | 19 August 2026 | Điều 30 |
| Provide user information to the specialized force | 24 hours; 3 hours in emergencies | Điều 16 khoản 3 điểm c |
| Block and remove information, services, applications | 24 hours; 6 hours in national-security emergencies | Điều 16 khoản 4 điểm b |
| Infrastructure-layer blocking and removal | 24 hours | Điều 18 khoản 2 điểm a |
| Keep system logs retrievable | At least 12 months | Điều 16 khoản 6 điểm c; Điều 20 khoản 3 |
| Retain IP allocation and management logs | 12 months | Điều 22 khoản 3 |
| Provide IP identification information | 24 hours; 3 hours in emergencies | Điều 23 khoản 2 điểm c |
| Localize prescribed data | At least 24 months | Điều 20 khoản 1 |
| Comply with a localization and local-presence decision | 12 months from the decision | Điều 19 khoản 6 điểm c |
| Authority checks an appraisal or assessment dossier | 3 working days | Điều 5 khoản 7 điểm b; Điều 6 khoản 7 điểm b |
| Appraisal or condition assessment completed and notified | 25 working days | Điều 5 khoản 7 điểm c, khoản 8; Điều 6 khoản 7 điểm c |
| Annual critical-system inspection report | Before 1 October each year | Điều 8 khoản 5 điểm b |
| Written papering of an urgent suspension demand | 24 hours | Điều 13 khoản 4 điểm d |
| Certified training rollout | 24 months; 36 months for level-3 to level-5 system staff | Điều 24 khoản 8 |
The decree's appendix prescribes three official forms: Mẫu số 01, the cybersecurity appraisal request; Mẫu số 02, the cybersecurity-condition certification request; and Mẫu số 03, the training-network registration. All three are carried from the signed source. Everything else ComplianceOne supplies for this instrument is an internal preparation template and is labelled as one.

The instrument is carried as an active framework whose every duty, clock and retention floor names the article it was read from, so a readiness record traces to the signed decree rather than to a summary of it.
The timed obligations are held as deadlines a programme can be measured against: the 24-hour and 3-hour information clocks, the 24-hour and 6-hour removal clocks, the infrastructure-layer window, the 12-month log floors, the 24-month localization floor and the training rollout dates each carry their citation.
Authority interactions can be recorded with the request, the verified receipt time, including phone and email demands that must be papered within 24 hours, the responsible owner, the response material and proof of completion.
The covered-provider question is presented as it stands in the text: a definitional cross-reference to telecom law, with edge cases marked as requiring deployment-specific legal analysis rather than resolved by assertion.
The decree took effect on signing, so there was no runway between the draft era and live duties. Records carry dates that show which regime they were made under.
Every clock names its article. When counsel asks why a response window is 3 hours rather than 24, the answer is a citation to the signed decree, not a policy assumption.
Scope is not overstated. The covered-provider definition works by cross-reference, and unresolved edge cases are presented as needing legal analysis rather than silently included or excluded.
The draft is retained, not erased. Readiness history built during consultation keeps its identity, and the succession from draft to signed instrument is recorded on both records.
Assigns ownership for appraisal, assessment, training and localization readiness with dated obligations.
Explore Program GovernanceCoordinates removal, suspension and authority-demand execution with a single evidence chain.
Explore Incident OperationsKeeps incident plans and specialized-force notifications connected to the case record.
Explore Incident ResponseTracks recurring self-inspection, log-retention and localization reviews.
Explore Monitoring ProgramsMaintains the account-verification and locking evidence the provider duties test.
Explore Access AccountabilityOrganizations operating under Decree 333 should confirm:
See how ComplianceOne carries an in-force implementing decree with its provider clocks, retention floors, localization triggers and the evidence an inspection asks for.

Yes. It was issued on 19 August 2026 and took effect the same day under Điều 30, with no grace period. Its procedures and provider duties are final law, subject to the Điều 31 transitional rule for dossiers already pending under Decree 53/2022.
Not automatically. The provider duties attach to services on telecom networks, the Internet and value-added services on cyberspace, and that last category is defined by cross-reference to value-added telecom services under telecom law rather than by listing platform types. Whether a specific service is covered depends on its classification in its actual deployment, a legal analysis, not a default assumption in either direction.
None of its own. It prescribes duties and procedures; monetary exposure for violating them runs through Decree 330/2026/NĐ-CP, whose cybersecurity amounts are stated per individual with organizations paying twice the level. No figure from that decree should be quoted without its attribution rule.
The signed text states no express repeal of Decree 53/2022. What it does state is the Điều 31 transition: appraisal and condition-assessment dossiers already pending under Decree 53/2022 are processed under that decree, while new work runs under Decree 333.
The prescribed data under Điều 19 must be stored in Vietnam from receipt of a storage request until the request ends, with a 24-month minimum. The branch or representative-office duty, once triggered, lasts while the enterprise operates in Vietnam or provides the regulated service, and a served decision allows 12 months to comply.

Test provider-response clocks, retention evidence, localization readiness and training rollout tracking against the signed decree.

Review your covered-provider analysis, your response-window readiness, and what changed between the draft and the signed instrument.