DPO Radio

AesirX ComplianceOne | Decree 85/2016/NĐ-CP Information System Security Levels

Overview Image

Decree 85/2016/NĐ-CP: Scope and Current Status

Decree 85/2016/NĐ-CP sets out how an information system is assigned a security level from 1 to 5, and what the system owner must do at each level. Điều 6 classifies systems by what they serve; internal operations, citizens and enterprises, information infrastructure, or industrial control. Điều 7 to Điều 11 give the criteria for each level. Điều 5 khoản 2 states the rule for composite systems: where a system is made of component systems at different levels, the system's level is the highest of them. It is detailed by Circular 12/2022/TT-BTTTT of the Ministry of Information and Communications.

Levels ascend. Cấp độ 1 is the lowest (a system serving an agency's internal operations and processing only public information) and cấp độ 5 the highest. This is the opposite of some informal four-tier scales in circulation, and getting it backwards inverts every obligation that hangs off it.

The decree was made under the Law on Network Information Security 86/2015/QH13. Law 116/2025/QH15 Điều 44 khoản 2 ended that parent law on 1 July 2026. Điều 45 khoản 1 of the same Law preserves a level already determined under this decree and allows twelve months from 1 July 2026 to 30 June 2027 to meet the new Law's conditions, standards and protection measures for that level. Organisations should confirm applicability and interpretation with qualified advisers.

Overview Image

How Decree 85 Relates to the Vietnam Cybersecurity Law

This instrument is presented beneath the Vietnam Cybersecurity Law 2025 as transition context, not as one of its implementing decrees. Its own legal parent is Law 86/2015/QH13, a Ministry of Information and Communications stack, and its criteria are not the Cybersecurity Law's criteria.

That distinction matters operationally. Law 116/2025/QH15 Điều 8 also sets five levels, but it grades them by the degree of harm an incident or a violation would cause, and Điều 8 khoản 2 leaves the detailed determination criteria, the competence and the procedure to a Government decree. Decree 85 grades a system by what it serves and what information it processes. The two scales share their numbering and answer different questions, so a determination must name which one it was made under. Điều 9 of the new Law is a third thing again: the designation of a system as important to national security, which is a decision of the Prime Minister on the Ministry of Public Security's proposal, and is not a level at all.

Cross-links preserve related evidence without promoting a superseded stack into current law or collapsing two scales into one.

Operational Provisions and Evidence

AreaComplianceOne Support
Level determinationRecord the level determined for each system with the criteria relied on and a written rationale (Điều 5, Điều 6, Điều 7–11).
Composite systemsDeclare component systems and their levels; the highest component level is applied because Điều 5 khoản 2 states that rule, and the record shows when a component raised the result.
Proposal dossierTrack preparation and maintenance of the level-proposal dossier (Điều 14, Điều 15).
Appraisal and approvalTrack the appraisal and the approval decision by the body competent under Điều 12, Điều 16 and Điều 17.
Security-assurance planMaintain the plan matching the approved level (Điều 19) and evidence its measures.
OwnershipAssign system-owner and information-security unit responsibilities (Điều 20, Điều 21).
TransitionKeep the determined level readable alongside the 30 June 2027 conformance date under Law 116/2025/QH15 Điều 45 khoản 1.
Overview Image

How ComplianceOne Supports Decree 85/2016/NĐ-CP

The five levels are carried as regulatory content, with each level's text transcribed from the article that defines it and an English rendering prepared by AesirX, Decree 85 has no official English translation. Regulatory Classification, the Subject Register leaf under Data Mapping, offers those levels for any system in your inventory once the framework is installed.

An operator records the system's kind under Điều 6, the level they have determined and their reasoning, and any component systems with their own levels. Where components are declared, the highest component level is applied and the record states that it was a component that raised the result rather than the system's own answers.

The determination is the operator's, and the approval is the authority's. The decree fixes a system's level through a process: the system owner lodges a level-proposal dossier, it is appraised, and it is approved by the competent body. ComplianceOne records the determination, the rationale and the reviewer who signed it off. It does not determine the level and nothing in it substitutes for the approval decision.

Approving a determination instantiates the protective measures that follow from it, drawn from the requirements of the installed frameworks that attach duties to a classification of that kind, the framework that publishes the scheme, and any framework that declares it places obligations on the result, rather than from any control catalogue of ours. The instrument that publishes a scheme and the instrument that says what to do about landing on a level are routinely two different documents, and both contribute. This is not legal advice, and it does not guarantee compliance, certification, or acceptance by an authority.

Built for Information System Security Operations

A level is only useful if you can say how you arrived at it. Each determination keeps the system kind, the criteria relied on, the rationale, the reviewer and the date in one record.

The composite-system rule is applied because the decree states it, and the record shows when it changed the answer, so a reviewer can see that a component drove the level rather than having to reconstruct it.

Two five-level scales are now in force in Vietnam and they are not the same scale. Every determination names which instrument it was made under, which keeps the transition legible instead of merging the two.

Compliance Readiness Checklist

List every information system and confirm which are in scope.

Classify each system by kind under Điều 6 before determining a level.

Record the determined level with the criteria and rationale relied on.

Declare component systems where a system is composite.

Confirm the level-proposal dossier exists and is current.

Record the appraisal and approval decision and its date.

Plan conformance with the new Law's measures for that level by 30 June 2027.