DPO Radio

AesirX ComplianceOne | Decree 333/2026/NĐ-CP Cybersecurity Law Implementation

Overview Image

Decree Decree 333/2026/NĐ-CP: Scope and Current Status

Decree 333/2026/NĐ-CP was issued by the Government on 19 August 2026 and took effect the same day; no grace period between issuance and effect. It runs to 32 articles across six chapters, with the Ministry of Public Security as lead authority. It is promulgated, in force, and not a proposal.

The decree details the order and procedures for the cybersecurity protection measures; appraisal, condition assessment, monitoring, inspection, incident response, cryptography, information removal, electronic data collection, system suspension and domain-name revocation, the network-information-security duties of domestic and foreign service providers, the IP address identification regime for telecom and Internet providers, and the certified advanced cybersecurity training system.

One scope point deserves care before any obligation is assumed. The provider duties attach to services on telecom networks, the Internet and value-added services on cyberspace, and the decree defines that last category by cross-reference to value-added telecom services under telecom law, not by listing platform types. Whether a specific service falls inside the perimeter can therefore turn on how it classifies under telecom law in its actual deployment, and that is a legal analysis of the deployment, not a fact this page can assert for anyone.

This instrument promulgates the draft general implementing decree tracked during the consultation period. The draft is retained as a legacy record so readiness history stays addressable, but it no longer states current law.

Overview Image

How Decree 333P Relates to the Vietnam Cybersecurity Law 2025

Cybersecurity Law 116/2025/QH15, in force since 1 July 2026, is the parent instrument. Decree 333 supplies the procedures and numbers the Law delegated: how appraisal, condition assessment, monitoring, inspection and the other protection measures actually run; what the provider duty set contains and on which clocks; how IP addresses are identified; and how the certified training obligation rolls out.

The decree prescribes no monetary fines of its own. Sanctions for the duties it creates live in Decree 330/2026/NĐ-CP, and any fine figure quoted from that instrument must carry its individual-versus-organization attribution rule; cybersecurity amounts there are stated per individual, with organizations at twice the level.

It also does not stand alone among the 19 August instruments: the information-systems protection regime is Decree 331, violating-information handling procedure is Decree 327, and products-and-services licensing is Decree 332. Each carries its own duties; this decree is the general implementation layer.

Technical Provisions and Compliance Obligations

ProvisionWhat It EstablishesOperational Implication
Điều 5, Điều 6Cybersecurity appraisal of critical-system designs and pre-operation condition assessment and certification, each on a 3-working-day dossier check and a 25-working-day completion clockCritical-system projects need the dossier prepared before approval and go-live gates
Điều 8Self-inspection of critical systems with annual written results to the specialized force before 1 October each yearThe inspection report is a recurring dated obligation, not a one-off
Điều 13System suspension, cessation and domain-name revocation powers — an urgent demand made by phone, fax or email must be papered in writing within 24 hoursKeep the oral demand and the written confirmation on one record
Điều 16Provider duty set: user verification, user-information provision within 24 hours (3 in emergencies), removal within 24 hours (6 in national-security emergencies), account locking, and system logs retrievable for at least 12 monthsEvery clock needs timestamped evidence from request receipt to completion
Điều 16 khoản 4Account measures: temporary visibility restriction or locking up to 60 days for 3+ violating posts within 30 days, up to 180 days for 10+ within 90 days, three indefinite-lock cases, and restoration groundsLock decisions need the triggering counts and the restoration review recorded
Điều 18Infrastructure-layer duty: telecom, Internet, hosting, data-center and telecom-application providers block and remove within 24 hours of a request made in writing, by phone or by emailIntake must catch non-written request channels too
Điều 19, Điều 20Data localization for at least 24 months and branch or representative-office establishment on the statutory triggers, with 12 months from the ministerial decision to complyForeign providers should track the three-notification trigger threshold, not only the decision
Điều 21–23The IP address identification regime: mandated session logging, 12-month IP allocation log retention, and provision within 24 hours (3 in emergencies), never exploited commerciallyIP identification data is authority-facing evidence with its own retention floor
Điều 24–28Certified advanced cybersecurity training, with 24 months for incumbents in the Law's named positions and 36 months for level-3 to level-5 system owners' staffTraining review, budgeting and completion evidence run on decree-anchored deadlines
Điều 31Transitional rule: appraisal and condition-assessment dossiers pending under Decree 53/2022 are processed under Decree 53/2022In-flight dossiers keep their old procedure; new ones use this decree

ObligationTimelineReference
Decree takes effect19 August 2026Điều 30
Provide user information to the specialized force24 hours; 3 hours in emergenciesĐiều 16 khoản 3 điểm c
Block and remove information, services, applications24 hours; 6 hours in national-security emergenciesĐiều 16 khoản 4 điểm b
Infrastructure-layer blocking and removal24 hoursĐiều 18 khoản 2 điểm a
Keep system logs retrievableAt least 12 monthsĐiều 16 khoản 6 điểm c; Điều 20 khoản 3
Retain IP allocation and management logs12 monthsĐiều 22 khoản 3
Provide IP identification information24 hours; 3 hours in emergenciesĐiều 23 khoản 2 điểm c
Localize prescribed dataAt least 24 monthsĐiều 20 khoản 1
Comply with a localization and local-presence decision12 months from the decisionĐiều 19 khoản 6 điểm c
Authority checks an appraisal or assessment dossier3 working daysĐiều 5 khoản 7 điểm b; Điều 6 khoản 7 điểm b
Appraisal or condition assessment completed and notified25 working daysĐiều 5 khoản 7 điểm c, khoản 8; Điều 6 khoản 7 điểm c
Annual critical-system inspection reportBefore 1 October each yearĐiều 8 khoản 5 điểm b
Written papering of an urgent suspension demand24 hoursĐiều 13 khoản 4 điểm d
Certified training rollout24 months; 36 months for level-3 to level-5 system staffĐiều 24 khoản 8

Forms and Data Requirements

The decree's appendix prescribes three official forms: Mẫu số 01, the cybersecurity appraisal request; Mẫu số 02, the cybersecurity-condition certification request; and Mẫu số 03, the training-network registration. All three are carried from the signed source. Everything else ComplianceOne supplies for this instrument is an internal preparation template and is labelled as one.

Overview Image

How ComplianceOne Supports Decree 333 Compliance

The instrument is carried as an active framework whose every duty, clock and retention floor names the article it was read from, so a readiness record traces to the signed decree rather than to a summary of it.

The timed obligations are held as deadlines a programme can be measured against: the 24-hour and 3-hour information clocks, the 24-hour and 6-hour removal clocks, the infrastructure-layer window, the 12-month log floors, the 24-month localization floor and the training rollout dates each carry their citation.

Authority interactions can be recorded with the request, the verified receipt time, including phone and email demands that must be papered within 24 hours, the responsible owner, the response material and proof of completion.

The covered-provider question is presented as it stands in the text: a definitional cross-reference to telecom law, with edge cases marked as requiring deployment-specific legal analysis rather than resolved by assertion.

Built for Same-Day-Effective Implementation

The decree took effect on signing, so there was no runway between the draft era and live duties. Records carry dates that show which regime they were made under.

Every clock names its article. When counsel asks why a response window is 3 hours rather than 24, the answer is a citation to the signed decree, not a policy assumption.

Scope is not overstated. The covered-provider definition works by cross-reference, and unresolved edge cases are presented as needing legal analysis rather than silently included or excluded.

The draft is retained, not erased. Readiness history built during consultation keeps its identity, and the succession from draft to signed instrument is recorded on both records.

Related Modules

Program GovernanceProgram Governance

Assigns ownership for appraisal, assessment, training and localization readiness with dated obligations.

Explore Program Governance

Incident OperationsIncident Operations

Coordinates removal, suspension and authority-demand execution with a single evidence chain.

Explore Incident Operations

Incident ResponseIncident Response

Keeps incident plans and specialized-force notifications connected to the case record.

Explore Incident Response

Monitoring ProgramsMonitoring Programs

Tracks recurring self-inspection, log-retention and localization reviews.

Explore Monitoring Programs

Access AccountabilityAccess Accountability

Maintains the account-verification and locking evidence the provider duties test.

Explore Access Accountability

Compliance Readiness Checklist

Organizations operating under Decree 333 should confirm:

The covered-provider analysis for each service is documented, with unclear classifications referred to counsel.

User-information and IP-identification requests can be answered inside 24 hours, and 3 in emergencies, with timestamps.

Removal and blocking complete inside 24 hours, and 6 hours in national-security emergencies.

Intake catches requests made by phone or email, and urgent suspension demands are papered within 24 hours.

System logs and IP allocation logs are retrievable for at least 12 months.

Localization scope, the 24-month floor and any local-presence trigger exposure are assessed for foreign operations.

Account-locking decisions record the triggering counts, the case relied on, and the restoration review.

Critical systems have appraisal and condition-assessment dossiers, and the annual inspection report lands before 1 October.

Training review and budgeting for the 24-month and 36-month rollout clocks has started.

Dossiers pending under Decree 53/2022 are tracked under the transitional rule, not restarted.

Background Image

See Decree 333 Compliance in Action

See how ComplianceOne carries an in-force implementing decree with its provider clocks, retention floors, localization triggers and the evidence an inspection asks for.

Demo Image
Ronni K. Gothard Christiansen

Ronni K. Gothard Christiansen - Technical Privacy Engineer & CEO

Technical Compliance Expert, 32+ Years Open Source Advocate, X-BoD Open Source Matters Inc.

Or contact via

ronni@aesirx.io+84 909 500 760

Frequently Asked Questions

Yes. It was issued on 19 August 2026 and took effect the same day under Điều 30, with no grace period. Its procedures and provider duties are final law, subject to the Điều 31 transitional rule for dossiers already pending under Decree 53/2022.

Not automatically. The provider duties attach to services on telecom networks, the Internet and value-added services on cyberspace, and that last category is defined by cross-reference to value-added telecom services under telecom law rather than by listing platform types. Whether a specific service is covered depends on its classification in its actual deployment, a legal analysis, not a default assumption in either direction.

None of its own. It prescribes duties and procedures; monetary exposure for violating them runs through Decree 330/2026/NĐ-CP, whose cybersecurity amounts are stated per individual with organizations paying twice the level. No figure from that decree should be quoted without its attribution rule.

The signed text states no express repeal of Decree 53/2022. What it does state is the Điều 31 transition: appraisal and condition-assessment dossiers already pending under Decree 53/2022 are processed under that decree, while new work runs under Decree 333.

The prescribed data under Điều 19 must be stored in Vietnam from receipt of a storage request until the request ends, with a 24-month minimum. The branch or representative-office duty, once triggered, lasts while the enterprise operates in Vietnam or provides the regulated service, and a served decision allows 12 months to comply.

Next Steps

Icon Image

Start a Compliance Pilot

Test provider-response clocks, retention evidence, localization readiness and training rollout tracking against the signed decree.

Icon Image

Discuss Your Compliance Needs

Review your covered-provider analysis, your response-window readiness, and what changed between the draft and the signed instrument.