DPO Radio

AesirX ComplianceOne | Decree 331 Vietnam Five-Level Classification

Overview Image

Decree 331/2026/NĐ-CP: Scope and Current Status

Decree 331/2026/NĐ-CP was issued by the Government on 19 August 2026 and took effect the same day. It runs to 40 articles across six chapters, with the Ministry of Public Security as lead authority. It is promulgated, in force, and not a proposal.

The decree details the Cybersecurity Law's delegated classification regime: the criteria for levels 1 through 5, the level-determination dossier and its appraisal and approval procedure, the national-security-critical system criteria, per-level protection duties, cloud and data-centre separation rules, the incident-reporting ladder, and the annual reporting cycle.

The level criteria carry real numbers. Between levels 2 and 3, the stated data-subject thresholds are 100,000 for basic personal data and 10,000 for sensitive personal data, and industrial control systems are graded on a construction-grade ladder. These thresholds are recorded as branches of the stated criteria, one input to a determination that runs through the statutory appraisal and approval procedure, not a formula that classifies a system on its own.

This instrument promulgates the priority draft tracked during the consultation period. The draft is retained as a legacy record so readiness history stays addressable, but it no longer states current law.

Overview Image

How Decree 331 Relates to the Vietnam Cybersecurity Law 2025

Cybersecurity Law 116/2025/QH15 grades information systems into five levels and left the criteria, competence and procedure to a Government decree. Decree 331 is that decree, detailing the Law's Articles 8(2), 9(5), 10(6) and 12(5).

The relationship with the earlier regime matters and is easy to overstate. The signed text of Decree 331 contains no repeal of Decree 85/2016/NĐ-CP. Under the Điều 39 transition, systems already under investment or construction before 1 July 2026 complete level appraisal and approval under Decree 85/2016 within 6 months of the Law's effective date, then meet this decree's per-level conditions within 12 months. Both regimes are therefore live in different roles, and a determination must name the instrument it was made under.

The decree prescribes no monetary fines of its own. Sanctions for its duty families run through Decree 330/2026/NĐ-CP, and any figure quoted from that instrument needs its individual-versus-organization attribution rule.

Technical Provisions and Compliance Obligations

ProvisionWhat It EstablishesOperational Implication
Điều 7, Điều 8Systems are identified and scoped by actual operation, without formalistic splitting or mergingScoping choices need a defensible operational rationale
Điều 9Classification of processed information into four secrecy classes and of each system into the stated kindsInformation classification precedes system classification
Điều 10Risk assessment in five prescribed cases with seven minimum contentsRisk assessments are triggered events with a stated table of contents, not free-form reviews
Điều 11–15The level 1–5 criteria, including the 100,000 basic and 10,000 sensitive data-subject thresholds between levels 2 and 3Data-subject counts become classification evidence
Điều 16, Điều 17National-security-critical system criteria, with every level-5 system automatically on the critical listA level-5 determination carries the critical-system regime with it
Điều 18–24The level-proposal dossier, its routing by proposed level, and the appraisal and approval authority ladderDossier quality drives the statutory clocks; the authority map depends on the proposed level
Điều 28, Điều 30The pre-operation condition assessment — an unqualified result blocks go-live — and the cybersecurity Regulation ordered before dossier approvalGo-live is gated; the internal Regulation is a prerequisite, not an afterthought
Điều 30 khoản 8, khoản 9Cloud and data-centre separation: logical for levels 3–4, physical for level 5 and critical systemsHosting architecture is a per-level compliance fact
Điều 31The incident ladder — immediate report for national-security signs, 24-hour initial notice for serious incidents, 72-hour cause/scope/remediation report — plus head-of-owner accountabilityIncident clocks need timestamped evidence per rung
Điều 35, Điều 36The annual reporting cycle with statutory dates and twelve contentsThe reporting calendar is fixed by decree, not by policy

ObligationTimelineReference
Decree takes effect19 August 2026Điều 38
Authority responds to an incomplete level-proposal dossier5 working daysĐiều 23 khoản 2
Appraisal of a level-3 dossier15 working daysĐiều 23 khoản 3 điểm a
Appraisal of a level-4 or level-5 dossier25 working daysĐiều 23 khoản 3 điểm b
Processing of the level-approval dossier7 working daysĐiều 24 khoản 2
Report incident cause, scope and remediation72 hours from detectionĐiều 31 khoản 2 điểm d
Initial notice of a serious incident24 hours from detectionĐiều 31 khoản 2 điểm d
Report incidents with national-security or serious-disruption signsImmediately on detectionĐiều 31 khoản 2 điểm d
Annual report data window15 December to 14 DecemberĐiều 35 khoản 3
Annual report to the system ownerBefore 20 December each yearĐiều 35 khoản 4 điểm a
Annual report to the Ministry of Public SecurityBefore 25 December each yearĐiều 35 khoản 4 điểm b
Ministry publishes the categorized system listBefore 15 January each yearĐiều 9 khoản 2 điểm e
Transitional appraisal under Decree 85/20166 months from the Law's effective dateĐiều 39 khoản 1
Transitional per-level compliance under this decree12 months from the Law's effective dateĐiều 39 khoản 1

Forms and Data Requirements

The decree's appendix prescribes eight official forms, Mẫu số 01 through Mẫu số 08, spanning the level-proposal dossier, appraisal and approval records and the annual report. All eight are carried from the signed source with their titles and section structure. Everything else ComplianceOne supplies for this instrument is an internal preparation template and is labelled as one.

Overview Image

How ComplianceOne Supports Decree 331 Compliance

The five-level scheme is carried with its per-tier criteria transcribed from the signed articles, the data-subject thresholds recorded as branches of the stated criteria, and a determination caveat naming the statutory appraisal and approval procedure, so a level is a defended conclusion, not a dropdown choice.

The procedure clocks are held as deadlines: the 5, 15, 25 and 7 working-day windows, the incident ladder's three rungs, and the annual cycle's four statutory dates each carry their citation.

The two five-level regimes stay distinguishable. A determination made under Decree 85/2016 keeps that identity through the transitional window, beside the levels this decree defines, so nothing silently converts one scale into the other.

Incident, assessment and reporting evidence links to the system record, its approved level and its hosting-separation facts, which is the shape an inspection under this decree asks about.

Built for Defensible Level Determinations

A level is only as strong as its dossier. Criteria, counts and the appraisal opinion stay attached to the determination, so the conclusion can be defended when it is re-examined.

Both five-level regimes keep their identity. The transitional window runs on Decree 85/2016 while new duties run on this decree, and no record pretends the two scales are interchangeable.

Every clock names its article. The working-day windows, the incident rungs and the annual dates are citations, not house conventions.

The no-stated-limit fact for level-1 and level-2 dossiers is presented honestly, rather than papered over with a number the text does not contain.

Related Modules

Program GovernanceProgram Governance

Assigns level-determination, dossier and transitional work with dated obligations.

Explore Program Governance

Risk AssessmentRisk Assessment

Runs the five trigger cases with the seven minimum contents recorded.

Explore Risk Assessment

Data ClassificationData Classification

Keeps the information-classification evidence that level criteria depend on.

Explore Data Classification

Incident ResponseIncident Response

Runs the immediate, 24-hour and 72-hour reporting rungs with timestamps.

Explore Incident Response

Monitoring ProgramsMonitoring Programs

Tracks the annual cycle, re-determination triggers and recurring reviews.

Explore Monitoring Programs

Compliance Readiness Checklist

Organizations operating under Decree 331 should confirm:

Every information system is identified and scoped by actual operation, with the rationale recorded.

Data-subject counts for basic and sensitive personal data are known where the level 2/3 thresholds may bite.

Level-proposal dossiers are complete before filing; the statutory clocks run from a valid dossier.

The cybersecurity Regulation is issued before dossier approval, and the pre-operation assessment gate is in the project plan.

Hosting separation matches the level: logical for levels 3–4, physical for level 5 and critical systems.

Incident reporting can hit all three rungs (immediate, 24 hours, 72 hours) with timestamped evidence.

The annual cycle dates are calendared: data cut 14 December, owner report before 20 December, ministry report before 25 December.

Systems under investment or construction before 1 July 2026 are on the 6-month and 12-month transitional tracks.

Determinations name the instrument they were made under, this decree or Decree 85/2016.

Level-5 candidates are reviewed against the critical-system criteria and their automatic listing.

Background Image

See Decree 331 Compliance in Action

See how ComplianceOne carries a classification decree with its level criteria, dossier clocks, incident ladder and the evidence an appraisal asks for.

Demo Image
Ronni K. Gothard Christiansen

Ronni K. Gothard Christiansen - Technical Privacy Engineer & CEO

Technical Compliance Expert, 32+ Years Open Source Advocate, X-BoD Open Source Matters Inc.

Or contact via

ronni@aesirx.io+84 909 500 760

Frequently Asked Questions

Yes. It was issued on 19 August 2026 and took effect the same day under Điều 38. The level criteria, procedures and duty families are final law, with the Điều 39 transition governing systems that predate the Law.

No. The signed text contains no repeal clause for Decree 85/2016, and the Điều 39 transition expressly runs the appraisal of pre-existing systems under it. The earlier regime remains the transitional-window reference while this decree's duties phase in, and each determination should name its instrument.

No. Each threshold is one branch of one stated criterion between levels 2 and 3. The level itself is determined through the dossier, appraisal and approval procedure of the decree, and other criteria, including the construction-grade ladder for industrial control systems, can drive the outcome.

On a three-rung ladder: immediately on detection where an incident shows national-security or serious-disruption signs, an initial notice within 24 hours for serious incidents, and a cause, scope and remediation report within 72 hours of detection. Systems managed by the Ministry of National Defence report to its counterpart agency.

Systems under investment or construction before 1 July 2026 complete level appraisal and approval under Decree 85/2016 within 6 months of the Law's effective date, then meet this decree's per-level conditions, standards and measures within 12 months of it.

Next Steps

Icon Image

Start a Compliance Pilot

Test level determination, dossier preparation, incident-clock evidence and the annual cycle against the signed decree.

Icon Image

Discuss Your Compliance Needs

Review your system inventory, your proposed levels, your hosting separation and your transitional-track exposure.