DPO Radio

AesirX ComplianceOne | Decree 63/2026/NĐ-CP State Secrets Implementation

Overview Image

Decree 63/2026/NĐ-CP: Scope and Current Status

Decree 63/2026/NĐ-CP was issued by the Government of Vietnam on 28 February 2026 and took effect on 1 March 2026, the same day as the State Secrets Protection Law 117/2025/QH15 it implements. It governs classification determinations, reproduction, transfer, and the incoming/outgoing registers used to handle state-secret information. Decree 63 is represented according to its implemented legal role and is not promoted into a broader or more binding framework.

Operational themes include classification, reproduction, incoming and outgoing records, transfer, access, disclosure, and restricted audit history. Teams should confirm applicability and legal interpretation with qualified advisers.

Overview Image

How Decree 63 Relates to the Vietnam State Secrets Law

This instrument sits beneath the Vietnam State Secrets Law 2025 Security Overlay. The parent law establishes the broader legal baseline; classification, access, and lifecycle handling of state-secret information, while Decree 63 supplies the narrower operational layer beneath it and is the only instrument in the stack that carries verified official forms.

Cross-links preserve related evidence without duplicating parent obligations or changing the status of neighboring active, draft, guidance, or reference layers.

Explore the Vietnam State Secrets Law

Technical Provisions and Compliance Obligations

Operational AreaComplianceOne Support
ApplicabilityRecord scope decisions, owners, and review history.
Operational workAssign tasks, connect supporting evidence, and manage approvals.
ArtifactsSix verified records and registers – a classification determination record (Phụ lục I), a reproduction record and copying/reproduction register (Phụ lục II), and outgoing, incoming, and transfer registers (Phụ lục III) – are modeled with restricted, role-controlled, non-customer-facing visibility
Audit readinessPreserve contributor, reviewer, decision, and change history.
Overview Image

How ComplianceOne Supports Decree 63 Compliance

ComplianceOne connects structured records, supporting evidence, assigned owners, and human review. Authority-issued artifacts retain source labels; platform-prepared templates remain clearly identified as operational aids.

The platform helps prepare authority-ready or audit-ready packages where the implemented pack supports them. It does not guarantee compliance, legal validity, certification, or acceptance by an authority.

Related Modules

Data MappingData Mapping

Record where classified information is created, stored, transferred, and accessed across systems and responsible parties.

Explore Data Mapping

Data ClassificationData Classification

Manage classification decisions, review history, handling requirements, and changes to the status of protected information.

Expore Data Classification

Program GovernanceProgram Governance

Assign ownership, coordinate reviews, document approvals, and maintain governance over Decree 63 operational requirements.

Explore Program Governance

Compliance FormsCompliance Forms

Prepare and manage platform-supported records, registers, and evidence while clearly distinguishing authority-issued artifacts.

Explore Compliance Forms

Audit TrailAudit Trail

Preserve contributor, reviewer, approval, and evidence history to demonstrate how operational decisions were made over time.

Explore Audit Trail

Compliance Readiness Checklist

Confirm applicability and current instrument status.

Assign accountable owners and reviewers.

Select official artifacts only where source-verified.

Link supporting evidence and related framework records.

Record human review and approval.

Retain audit history for later inspection.

Background Image

See Decree 63 Compliance in Action

See how ComplianceOne helps structure evidence, ownership, and review for this framework.

Demo Image
Ronni K. Gothard Christiansen

Ronni K. Gothard Christiansen - Technical Privacy Engineer & CEO

Technical Compliance Expert, 32+ Years Open Source Advocate, X-BoD Open Source Matters Inc.

Or contact via

ronni@aesirx.io+84 909 500 760

Frequently Asked Questions

It is active; restricted and represented separately from draft, roadmap, or neighboring framework layers.

It implements the State Secrets Protection Law 117/2025/QH15, adding a narrower operational layer beneath it while retaining its own code, status, evidence, and review context.

Six, all source-verified and restricted: a classification determination record (Phụ lục I), a reproduction record and a copying/reproduction register (Phụ lục II), and outgoing, incoming, and transfer registers (Phụ lục III).

Six verified records and registers are modeled with restricted, role-controlled, non-customer-facing visibility. Platform-prepared templates and internal lifecycle records are labelled as operational working documents and are never presented as prescribed forms.

No. It structures evidence, ownership, workflow, and review; organizations remain responsible for legal interpretation.

Yes. Related records can be cross-linked while preserving their original framework ownership and audit history.

Next Steps

Icon Image

Start a Compliance Pilot

Test scoped workflows, evidence, and review with your compliance team.

Icon Image

Discuss Your Compliance Needs

Review applicability, evidence sources, and operating-model requirements.