DPO Radio

Decree 63/2026/NĐ-CP was issued by the Government of Vietnam on 28 February 2026 and took effect on 1 March 2026, the same day as the State Secrets Protection Law 117/2025/QH15 it implements. It governs classification determinations, reproduction, transfer, and the incoming/outgoing registers used to handle state-secret information. Decree 63 is represented according to its implemented legal role and is not promoted into a broader or more binding framework.
Operational themes include classification, reproduction, incoming and outgoing records, transfer, access, disclosure, and restricted audit history. Teams should confirm applicability and legal interpretation with qualified advisers.

This instrument sits beneath the Vietnam State Secrets Law 2025 Security Overlay. The parent law establishes the broader legal baseline; classification, access, and lifecycle handling of state-secret information, while Decree 63 supplies the narrower operational layer beneath it and is the only instrument in the stack that carries verified official forms.
Cross-links preserve related evidence without duplicating parent obligations or changing the status of neighboring active, draft, guidance, or reference layers.
| Operational Area | ComplianceOne Support |
|---|---|
| Applicability | Record scope decisions, owners, and review history. |
| Operational work | Assign tasks, connect supporting evidence, and manage approvals. |
| Artifacts | Six verified records and registers – a classification determination record (Phụ lục I), a reproduction record and copying/reproduction register (Phụ lục II), and outgoing, incoming, and transfer registers (Phụ lục III) – are modeled with restricted, role-controlled, non-customer-facing visibility |
| Audit readiness | Preserve contributor, reviewer, decision, and change history. |

ComplianceOne connects structured records, supporting evidence, assigned owners, and human review. Authority-issued artifacts retain source labels; platform-prepared templates remain clearly identified as operational aids.
The platform helps prepare authority-ready or audit-ready packages where the implemented pack supports them. It does not guarantee compliance, legal validity, certification, or acceptance by an authority.
Record where classified information is created, stored, transferred, and accessed across systems and responsible parties.
Explore Data MappingManage classification decisions, review history, handling requirements, and changes to the status of protected information.
Expore Data ClassificationAssign ownership, coordinate reviews, document approvals, and maintain governance over Decree 63 operational requirements.
Explore Program GovernancePrepare and manage platform-supported records, registers, and evidence while clearly distinguishing authority-issued artifacts.
Explore Compliance FormsPreserve contributor, reviewer, approval, and evidence history to demonstrate how operational decisions were made over time.
Explore Audit TrailSee how ComplianceOne helps structure evidence, ownership, and review for this framework.

It is active; restricted and represented separately from draft, roadmap, or neighboring framework layers.
It implements the State Secrets Protection Law 117/2025/QH15, adding a narrower operational layer beneath it while retaining its own code, status, evidence, and review context.
Six, all source-verified and restricted: a classification determination record (Phụ lục I), a reproduction record and a copying/reproduction register (Phụ lục II), and outgoing, incoming, and transfer registers (Phụ lục III).
Six verified records and registers are modeled with restricted, role-controlled, non-customer-facing visibility. Platform-prepared templates and internal lifecycle records are labelled as operational working documents and are never presented as prescribed forms.
No. It structures evidence, ownership, workflow, and review; organizations remain responsible for legal interpretation.
Yes. Related records can be cross-linked while preserving their original framework ownership and audit history.

Test scoped workflows, evidence, and review with your compliance team.

Review applicability, evidence sources, and operating-model requirements.