DPO Radio

Decree 331/2026/NĐ-CP was issued by the Government on 19 August 2026 and took effect the same day. It runs to 40 articles across six chapters, with the Ministry of Public Security as lead authority. It is promulgated, in force, and not a proposal.
The decree details the Cybersecurity Law's delegated classification regime: the criteria for levels 1 through 5, the level-determination dossier and its appraisal and approval procedure, the national-security-critical system criteria, per-level protection duties, cloud and data-centre separation rules, the incident-reporting ladder, and the annual reporting cycle.
The level criteria carry real numbers. Between levels 2 and 3, the stated data-subject thresholds are 100,000 for basic personal data and 10,000 for sensitive personal data, and industrial control systems are graded on a construction-grade ladder. These thresholds are recorded as branches of the stated criteria, one input to a determination that runs through the statutory appraisal and approval procedure, not a formula that classifies a system on its own.
This instrument promulgates the priority draft tracked during the consultation period. The draft is retained as a legacy record so readiness history stays addressable, but it no longer states current law.

Cybersecurity Law 116/2025/QH15 grades information systems into five levels and left the criteria, competence and procedure to a Government decree. Decree 331 is that decree, detailing the Law's Articles 8(2), 9(5), 10(6) and 12(5).
The relationship with the earlier regime matters and is easy to overstate. The signed text of Decree 331 contains no repeal of Decree 85/2016/NĐ-CP. Under the Điều 39 transition, systems already under investment or construction before 1 July 2026 complete level appraisal and approval under Decree 85/2016 within 6 months of the Law's effective date, then meet this decree's per-level conditions within 12 months. Both regimes are therefore live in different roles, and a determination must name the instrument it was made under.
The decree prescribes no monetary fines of its own. Sanctions for its duty families run through Decree 330/2026/NĐ-CP, and any figure quoted from that instrument needs its individual-versus-organization attribution rule.
| Provision | What It Establishes | Operational Implication |
|---|---|---|
| Điều 7, Điều 8 | Systems are identified and scoped by actual operation, without formalistic splitting or merging | Scoping choices need a defensible operational rationale |
| Điều 9 | Classification of processed information into four secrecy classes and of each system into the stated kinds | Information classification precedes system classification |
| Điều 10 | Risk assessment in five prescribed cases with seven minimum contents | Risk assessments are triggered events with a stated table of contents, not free-form reviews |
| Điều 11–15 | The level 1–5 criteria, including the 100,000 basic and 10,000 sensitive data-subject thresholds between levels 2 and 3 | Data-subject counts become classification evidence |
| Điều 16, Điều 17 | National-security-critical system criteria, with every level-5 system automatically on the critical list | A level-5 determination carries the critical-system regime with it |
| Điều 18–24 | The level-proposal dossier, its routing by proposed level, and the appraisal and approval authority ladder | Dossier quality drives the statutory clocks; the authority map depends on the proposed level |
| Điều 28, Điều 30 | The pre-operation condition assessment — an unqualified result blocks go-live — and the cybersecurity Regulation ordered before dossier approval | Go-live is gated; the internal Regulation is a prerequisite, not an afterthought |
| Điều 30 khoản 8, khoản 9 | Cloud and data-centre separation: logical for levels 3–4, physical for level 5 and critical systems | Hosting architecture is a per-level compliance fact |
| Điều 31 | The incident ladder — immediate report for national-security signs, 24-hour initial notice for serious incidents, 72-hour cause/scope/remediation report — plus head-of-owner accountability | Incident clocks need timestamped evidence per rung |
| Điều 35, Điều 36 | The annual reporting cycle with statutory dates and twelve contents | The reporting calendar is fixed by decree, not by policy |
| Obligation | Timeline | Reference |
|---|---|---|
| Decree takes effect | 19 August 2026 | Điều 38 |
| Authority responds to an incomplete level-proposal dossier | 5 working days | Điều 23 khoản 2 |
| Appraisal of a level-3 dossier | 15 working days | Điều 23 khoản 3 điểm a |
| Appraisal of a level-4 or level-5 dossier | 25 working days | Điều 23 khoản 3 điểm b |
| Processing of the level-approval dossier | 7 working days | Điều 24 khoản 2 |
| Report incident cause, scope and remediation | 72 hours from detection | Điều 31 khoản 2 điểm d |
| Initial notice of a serious incident | 24 hours from detection | Điều 31 khoản 2 điểm d |
| Report incidents with national-security or serious-disruption signs | Immediately on detection | Điều 31 khoản 2 điểm d |
| Annual report data window | 15 December to 14 December | Điều 35 khoản 3 |
| Annual report to the system owner | Before 20 December each year | Điều 35 khoản 4 điểm a |
| Annual report to the Ministry of Public Security | Before 25 December each year | Điều 35 khoản 4 điểm b |
| Ministry publishes the categorized system list | Before 15 January each year | Điều 9 khoản 2 điểm e |
| Transitional appraisal under Decree 85/2016 | 6 months from the Law's effective date | Điều 39 khoản 1 |
| Transitional per-level compliance under this decree | 12 months from the Law's effective date | Điều 39 khoản 1 |
The decree's appendix prescribes eight official forms, Mẫu số 01 through Mẫu số 08, spanning the level-proposal dossier, appraisal and approval records and the annual report. All eight are carried from the signed source with their titles and section structure. Everything else ComplianceOne supplies for this instrument is an internal preparation template and is labelled as one.

The five-level scheme is carried with its per-tier criteria transcribed from the signed articles, the data-subject thresholds recorded as branches of the stated criteria, and a determination caveat naming the statutory appraisal and approval procedure, so a level is a defended conclusion, not a dropdown choice.
The procedure clocks are held as deadlines: the 5, 15, 25 and 7 working-day windows, the incident ladder's three rungs, and the annual cycle's four statutory dates each carry their citation.
The two five-level regimes stay distinguishable. A determination made under Decree 85/2016 keeps that identity through the transitional window, beside the levels this decree defines, so nothing silently converts one scale into the other.
Incident, assessment and reporting evidence links to the system record, its approved level and its hosting-separation facts, which is the shape an inspection under this decree asks about.
A level is only as strong as its dossier. Criteria, counts and the appraisal opinion stay attached to the determination, so the conclusion can be defended when it is re-examined.
Both five-level regimes keep their identity. The transitional window runs on Decree 85/2016 while new duties run on this decree, and no record pretends the two scales are interchangeable.
Every clock names its article. The working-day windows, the incident rungs and the annual dates are citations, not house conventions.
The no-stated-limit fact for level-1 and level-2 dossiers is presented honestly, rather than papered over with a number the text does not contain.
Assigns level-determination, dossier and transitional work with dated obligations.
Explore Program GovernanceRuns the five trigger cases with the seven minimum contents recorded.
Explore Risk AssessmentKeeps the information-classification evidence that level criteria depend on.
Explore Data ClassificationRuns the immediate, 24-hour and 72-hour reporting rungs with timestamps.
Explore Incident ResponseTracks the annual cycle, re-determination triggers and recurring reviews.
Explore Monitoring ProgramsOrganizations operating under Decree 331 should confirm:
See how ComplianceOne carries a classification decree with its level criteria, dossier clocks, incident ladder and the evidence an appraisal asks for.

Yes. It was issued on 19 August 2026 and took effect the same day under Điều 38. The level criteria, procedures and duty families are final law, with the Điều 39 transition governing systems that predate the Law.
No. The signed text contains no repeal clause for Decree 85/2016, and the Điều 39 transition expressly runs the appraisal of pre-existing systems under it. The earlier regime remains the transitional-window reference while this decree's duties phase in, and each determination should name its instrument.
No. Each threshold is one branch of one stated criterion between levels 2 and 3. The level itself is determined through the dossier, appraisal and approval procedure of the decree, and other criteria, including the construction-grade ladder for industrial control systems, can drive the outcome.
On a three-rung ladder: immediately on detection where an incident shows national-security or serious-disruption signs, an initial notice within 24 hours for serious incidents, and a cause, scope and remediation report within 72 hours of detection. Systems managed by the Ministry of National Defence report to its counterpart agency.
Systems under investment or construction before 1 July 2026 complete level appraisal and approval under Decree 85/2016 within 6 months of the Law's effective date, then meet this decree's per-level conditions, standards and measures within 12 months of it.

Test level determination, dossier preparation, incident-clock evidence and the annual cycle against the signed decree.

Review your system inventory, your proposed levels, your hosting separation and your transitional-track exposure.