Decree 332/2026/ND-CP business in cybersecurity products and services

  • Summary
  • Content
  • Status
  • Vietnamese
  • Related documents
  • Diagram
  • Download
Bilingual Text

Please log in to your Advanced Package to view the full text. Do not have an account yet? Register here.

Save

Please log in to use this function

Send link to email

Please log in to use this function

Error message
  • Print
  • Share:
  • Text mode: Light | Dark
Font size:

ATTRIBUTE

Decree No. 332/2026/ND-CP dated August 18, 2026 of the Government on business in cybersecurity products and services
Issuing body: GovernmentEffective date:
Known

Please log in to a subscriber account to use this function.

Don’t have an account? Register here

Official number:332/2026/ND-CPSigner:Pham Gia Tuc
Type:DecreeExpiry date:Updating
Issuing date:19/08/2026Effect status:
Known

Please log in to a subscriber account to use this function.

Don’t have an account? Register here

Fields:Commerce - Advertising, National Security, Information - Communications
For more details, click here.
Download files here.
LuatVietnam.vn is the SOLE distributor of English translations of Official Gazette published by the Vietnam News Agency
Effect status:
Known

The Effect status of this document is known.This feature is available to Advanced account holders. Please log in to a subscriber account to view Effect status. Don’t have an account? Register here

THE GOVERNMENT
_______
No. 332/2026/ND-CP

THE SOCIALIST REPUBLIC OF VIETNAM
Independence - Freedom - Happiness

_______________________
Hanoi, August 19, 2026

 

DECREE

On business in cybersecurity products and services

 

Pursuant to the Law on Organization of the Government No. 63/2025/QH15;

Pursuant to the Law on Cybersecurity No. 116/2025/QH15;

Pursuant to the Law on Investment No. 143/2025/QH15;

Pursuant to the Law on Foreign Trade Management No. 05/2017/QH14;

At the proposal of the Minister of Public Security;

The Government hereby promulgates the Decree on business in cybersecurity products and services.

 

Chapter I

GENERAL PROVISIONS

 

Article 1. Scope of regulation

1. This Decree details Clause 3, Article 28 and Clause 3, Article 29 of the Law on Cybersecurity No. 116/2025/QH15, including:

a) Cybersecurity products and services;

b) Business in cybersecurity products and services: Conditions for doing business in cybersecurity products and services; issuance, modification, re-issuance, renewal, suspension and revocation of licences for doing business in cybersecurity products and services;

c) Import and export of cybersecurity products: Conditions for issuance and revocation of permits for importing and exporting cybersecurity products;

d) Inspection of business in cybersecurity products and services and export and import of cybersecurity products;

dd) Responsibilities of agencies, organisations, enterprises and individuals involved in business in cybersecurity products and services.

2. This Decree does not regulate business in civil cryptographic products and services.

Article 2. Subjects and scopes of application

1. This Decree applies to organisations and enterprises doing business in cybersecurity products and services; agencies licensing and managing business in cybersecurity products and services; and agencies, organisations and individuals involved in business in cybersecurity products and services.

2. The Ministry of National Defence shall manage cybersecurity in respect of military and national defence tasks; the Ministry of Public Security shall, within its competence, manage cybersecurity in respect of military units conducting civil and economic activities. For overlapping matters (if any), the Ministry of Public Security and the Ministry of National Defence shall agree on coordination regulations.

Article 3. Cybersecurity products

Cybersecurity products prescribed in this Decree include:

1. Cybersecurity inspection and assessment products, which are hardware devices and software having, or designed to integrate, the following functions: Scanning, inspecting and analysing the configurations, current status and log data of information systems and electronic devices; detecting vulnerabilities and weaknesses; and assessing cybersecurity risks.

2. Cybersecurity monitoring products, which are hardware devices and software having, or designed to integrate, the following functions: Monitoring and analysing data, network addresses and network traffic; collecting and analysing log data in real time; and detecting and issuing warnings of abnormal events that pose a risk to cybersecurity.

3. Anti-attack and anti-intrusion products, which are hardware devices and software having, or designed to integrate, functions for preventing attacks against, and intrusions into, information systems.

4. Other cybersecurity products falling into any of the following categories:

a) Covert information collection products, including: Hardware devices and software having functions for covertly collecting information in cyberspace and from electronic means and devices;

b) Cyberinformation suppression products, including: Specialised hardware devices and software for blocking, intercepting, jamming or disrupting wireless Internet connections in areas or at targets requiring protection;

c) Digital forensics and digital investigation products, including: Specialised hardware devices and software for collecting, extracting, recovering and analysing electronic data and conducting digital forensic examinations using electronic data sources;

d) Network system suppression products, including: Specialised hardware devices and software for suppressing or altering the operation of telecommunications networks, the Internet, computer networks, information systems, information processing and control systems, databases and electronic means;

dd) IP address concealment products, which connect devices to cyberspace through remote servers in order to conceal the devices’ actual IP addresses in cyberspace.

Article 4. Cybersecurity services

Cybersecurity services prescribed in this Decree include:

1. Cybersecurity inspection and assessment services, which involve scanning, inspecting and analysing the configurations, current status and log data of information systems; detecting vulnerabilities and weaknesses; and assessing risks to cybersecurity.

2. Information security services not using civil cryptography, which assist users in ensuring the confidentiality of information and information systems without using civil cryptographic products.

3. Cybersecurity consultancy services, which provide support in consulting on, inspecting, assessing, implementing, designing and developing solutions to ensure cybersecurity.

4. Cybersecurity monitoring services, which involve monitoring and analysing data traffic transmitted through information systems; collecting and analysing log data in real time; and detecting and issuing warnings of abnormal events that pose a risk to cybersecurity.

5. Cybersecurity incident response services, which involve the timely handling and remediation of incidents compromising the cybersecurity of information systems.

6. Data recovery services, which involve recovering data that have been deleted from or damaged in electronic devices or information systems.

7. Cyberattack prevention and combat services, which involve preventing attacks against, and intrusions into, information systems by monitoring, collecting and analysing events occurring in such information systems.

8. Other cybersecurity services include:

a) Cybersecurity protection connectivity platform services, which connect experts and communities in cyberspace to participate in cybersecurity and data security protection tasks;

b) Cybersecurity protection training and exercise services;

c) IP address concealment services in cyberspace, which provide network connections between devices and cyberspace through remote servers in order to conceal the devices’ actual IP addresses in cyberspace;

d) Security vulnerability hunting and reporting services, which provide platforms for receiving reports from security experts and the cybersecurity community on security vulnerabilities detected in information systems of agencies, organisations and individuals.

Article 5. Business in cybersecurity products and services

1. Organisations and enterprises doing business in cybersecurity products and services specified in Articles 3 and 4 of this Decree must possess a licence for doing business in cybersecurity products and services.

2. A licence for doing business in cybersecurity products and services shall be valid for 10 years.

3. Organisations and enterprises submitting dossiers of application for licences for doing business in cybersecurity products and services shall pay charges in accordance with the law on charges and fees.

 

Chapter II

CONDITIONS FOR DOING BUSINESS IN CYBERSECURITY PRODUCTS AND SERVICES

 

Article 6. General conditions for doing business in cybersecurity products and services

An organisation or enterprise doing business in cybersecurity products and services shall be granted a licence for doing business in cybersecurity products and services if it fully satisfies the following conditions:

1. It is established in accordance with Vietnamese law and has not violated the law on business in cybersecurity products and services. For foreign-invested economic organisations, the remaining investment term in Vietnam must exceed 05 years from the date of grant of the licence for doing business in cybersecurity products and services.

2. Personnel conditions:

a) The at-law representative, manager or person authorised by the at-law representative or manager does not fall into any of the following cases:

A Vietnamese citizen against whom criminal proceedings have been initiated and who is under investigation, prosecution or trial by Vietnamese or foreign proceeding-conducting agencies; who has a previous conviction for an offence infringing upon national security; who has been determined by a competent agency to have engaged in activities infringing upon national security; or who has an unspent conviction for another intentionally committed offence; who is subject to a postponement of serving a prison sentence; who is subject to probation, residence ban, prohibition from holding a position or prohibition from conducting a business line subject to security and order conditions under a court decision; who is subject to the measure of education in a commune, ward or special zone; or who is subject to a postponement or suspension of the execution of a decision on placement in a compulsory educational establishment or compulsory rehabilitation centre.

An overseas Vietnamese holding a foreign passport or a foreigner who has not been granted permission to reside and work in Vietnam by a competent Vietnamese agency;

b) The organisation or enterprise must have technical personnel responsible for matters appropriate to the types of products and services in which it conducts business. Such personnel must possess a university or higher degree or a professional certificate in cybersecurity, information security, information technology, electronics or telecommunications.

3. Technical conditions: Having equipment systems, physical facilities and technologies appropriate to its investment and business activities and the types of cybersecurity products and services registered for business.

Article 7. Conditions for the manufacture, purchase, sale, exchange, import and export of cybersecurity products

1. Organisations and enterprises manufacturing cybersecurity products shall satisfy the conditions prescribed in Article 6 of this Decree and the following conditions:

a) The product categories and scale of production are consistent with the cybersecurity industry development strategy;

b) Having an appropriate business plan covering the following matters: The scope and intended recipients of the products; the types of products to be manufactured; compliance with standards and technical regulations applicable to each type of product; and the principal technical features of the products;

c) Having appropriate means and equipment for inspecting and monitoring technical specifications for product quality inspection during the manufacturing process, ensuring compliance with cybersecurity protection standards and technical regulations;

d) Only organisations and enterprises of the Ministry of Public Security or the Ministry of National Defence that have received written task assignments or orders, or organisations and enterprises that have entered into contracts with competent agencies of the Ministry of Public Security or the Ministry of National Defence and fully satisfy the prescribed conditions, may manufacture the cybersecurity products specified at Points a, b, c and d, Clause 4, Article 3 of this Decree for the performance of national security protection tasks.

2. Organisations and enterprises purchasing, selling, exchanging, importing or exporting cybersecurity products shall satisfy the conditions prescribed in Article 6 of this Decree and the following conditions:

a) The product categories and scale are consistent with the cybersecurity industry development strategy;

b) Having an appropriate business plan covering the following matters: The purpose of import; the scope and intended recipients of the products; compliance with standards and technical regulations applicable to each type of product; and details of the principal technical features of the products;

c) Having appropriate means and equipment for preserving and ensuring the quality of cybersecurity products in accordance with cybersecurity protection standards and technical regulations;

d) Only the organisations and enterprises specified at Point d, Clause 1 of this Article may purchase, sell, exchange, import or export the cybersecurity products specified at Points a, b, c and d, Clause 4, Article 3 of this Decree;

dd) The purpose of exporting or importing cybersecurity products and their intended users must be clearly identified, and a commitment must be made that such export or import will not prejudice national security.

Article 8. Conditions for provision of cybersecurity services

Organisations and enterprises providing cybersecurity services shall satisfy the conditions prescribed in Article 6 of this Decree and the following conditions:

1. For cybersecurity inspection services and cybersecurity consultancy services, the technical personnel must include at least 05 persons possessing a university or higher degree or a certificate in cybersecurity and having a specific residential address in Vietnam; the at-law representative must be a Vietnamese citizen.

2. For cybersecurity monitoring services, the personnel must include at least 12 persons possessing a university or higher degree or a certificate in cybersecurity, as well as personnel responsible for system administration and information security; the at-law representative must be a Vietnamese citizen.

3. Having a technical plan that satisfies the cybersecurity protection requirements applicable to the type of service provided, made according to Form No. 07 in Appendix I to this Decree.

4. Having a contingency plan to ensure safe and continuous operation and remediation in the event of an incident.

5. Having an overall description of the technical features of the cybersecurity monitoring system and the cybersecurity monitoring operation process.

6. Having an appropriate business plan covering the following matters: The scope and intended recipients of the services; the types of services to be provided; the plan for protecting the confidentiality of customer information; and the plan for ensuring service quality.

Article 9. Grant of licences for doing business in cybersecurity products and services

1. Organisations and enterprises shall be granted licences for doing business in cybersecurity products and services if they satisfy the conditions prescribed in Articles 6, 7 and 8 of this Decree.

2. A dossier of application for a licence for doing business in cybersecurity products and services comprises:

a) An application made according to Form No. 03 in Appendix I to this Decree;

b) Personal history declarations accompanied by the personal identification documents of the at-law representative and managers of the organisation or enterprise, where their information cannot be retrieved from the information system, including: Copies of valid identity cards, citizen identity cards or passports, permanent residence cards, temporary residence cards or visas permitting residence in Vietnam; and personnel declarations of the organisation or enterprise made according to Forms No. 05 and 06 in Appendix I to this Decree;

c) Degrees, certificates or documents of equivalent validity under the law on education and training, proving satisfaction of the personnel conditions;

d) Documents explaining equipment systems, physical facilities and technologies appropriate to the activities and products or services registered for business;

dd) Technical plans and business plans made according to Forms No. 07 and 08 in Appendix I to this Decree;

e) An organisation or enterprise manufacturing the cybersecurity products specified at Points a, b, c and d, Clause 4, Article 3 of this Decree for the performance of national security protection tasks must possess a written task assignment or order, or have entered into a contract with a competent agency of the Ministry of Public Security or the Ministry of National Defence.

3. A dossier of application for a licence for doing business in cybersecurity products and services shall comprise 01 set and be submitted directly, by post or through the online public service system to the Ministry of Public Security. The dossier shall be made in Vietnamese and comprise 01 original set. In case of direct or postal submission, the original dossier must bear all required signatures and certification seals of the organisation or enterprise. Documents prepared by organisations, enterprises or individuals that consist of 02 or more pages must bear an overlapping seal across the pages. The entity and person submitting the dossier shall be responsible for the legality of the documents contained therein. In case of submission through the online public service system, the organisation or enterprise shall digitally sign the dossier in accordance with the law on digital signatures.

4. The time of receipt of a dossier is the time when the officer receives it from the submitting organisation or enterprise, in case of direct submission; when it is delivered by a postal employee, in case of postal submission; or the date on which the receiving officer records the dossier on the public service portal system and confirms its receipt to the submitting organisation or enterprise, in case of submission through the public service portal. Within 03 working days from the time of receipt of a dossier, the receiving agency shall examine the dossier and notify the organisation or enterprise of its validity:

a) In case of a valid dossier: To accept and process the dossier and confirm its acceptance and processing in writing, through the organisation’s or enterprise’s account on the public service portal, or via its email address (if any), using Form No. 10 in Appendix I to this Decree;

b) In case the dossier requires supplementation: To provide instructions to the organisation or enterprise on supplementing the dossier and issue a notice in writing, through the organisation’s or enterprise’s account on the public service portal, or via its email address (if any), using Form No. 11 in Appendix I to this Decree. Within 10 working days from the date of receipt of the notice of dossier supplementation, the enterprise shall complete and submit the full dossier to the receiving agency as requested in the notice. If the enterprise fails to submit the full dossier within the above time limit, the dossier shall be deemed invalid;

c) In case of an invalid dossier: To refuse to accept and process the dossier and notify the organisation or enterprise of such refusal in writing, through its account on the public service portal, or via its email address (if any), using Form No. 11 in Appendix I to this Decree, clearly stating the reason for the refusal.

5. Within 28 working days from the date of receipt of a complete and valid dossier, the Ministry of Public Security shall appraise the dossier of application for a licence for doing business in cybersecurity products and services and consider granting such licence, using Form No. 01 in Appendix I to this Decree, if the dossier contains sufficient information to establish that the prescribed conditions under this Decree have been satisfied. If the prescribed conditions are not satisfied, the Ministry of Public Security shall issue a written refusal to grant the licence for doing business in cybersecurity products and services to the organisation or enterprise, using Form No. 12 in Appendix I to this Decree, clearly stating the reason.

Article 10. Modification of licences for doing business in cybersecurity products and services

1. An organisation or enterprise shall apply for modification of its licence for doing business in cybersecurity products and services in case of a change to the name of the organisation or enterprise or its at-law representative; an addition or change to cybersecurity products or services; or the loss of or damage to a valid licence for doing business in cyberinformation security products and services.

2. A dossier of application for modification of the licence for doing business in cybersecurity products and services comprises all of the following documents:

a) An application made according to Form No. 03 in Appendix I to this Decree;

b) A personal history declaration accompanied by the personal identification documents of the at-law representative;

c) A detailed description of the contents subject to modification;

d) Documents proving satisfaction of the conditions applicable to the relevant type of business in cybersecurity products and services corresponding to the enterprise’s application for modification, in case of a change to the name of the organisation or enterprise or its at-law representative, or an addition or change to cybersecurity products or services.

3. Cyberinformation security products and services shall be converted into cybersecurity products and services as follows:

a) Cyberinformation security inspection and assessment products shall be converted into cybersecurity inspection and assessment products;

b) Cyberinformation security monitoring products shall be converted into cybersecurity monitoring products;

c) Anti-attack and anti-intrusion products shall remain unchanged;

d) Other cyberinformation security products shall be removed;

dd) Cyberinformation security monitoring services shall be converted into cybersecurity monitoring services;

e) Cyberattack prevention and combat services shall remain unchanged;

g) Cyberinformation security consultancy services shall be converted into cybersecurity consultancy services;

h) Cyberinformation security incident response services shall be converted into cybersecurity incident response services;

i) Cyberinformation security inspection and assessment services shall be converted into cybersecurity inspection and assessment services;

k) Data recovery services shall remain unchanged;

l) Information security services not using civil cryptography shall remain unchanged;

m) Other cyberinformation security services shall be removed.

4. Dossiers of application for modification of licences for doing business in cybersecurity products and services shall be submitted by the methods prescribed in Clause 3, Article 9 of this Decree.

5. The Ministry of Public Security shall examine the validity of the dossier in accordance with Clause 4, Article 9 of this Decree.

6. Within 05 working days from the date of receipt of a valid application, the Ministry of Public Security shall consider and modify the licence for doing business in cybersecurity products and services of the organisation or enterprise. In case of refusal, it shall issue a written notice, clearly stating the reason.

7. The term of the modified licence for doing business in cybersecurity products and services shall remain the same as that of the licence initially granted.

Article 11. Re-issuance of licences for doing business in cybersecurity products and services

1. An organisation or enterprise shall apply for re-issuance of its licence for doing business in cybersecurity products and services if the valid licence is lost or damaged.

2. A dossier of application for re-issuance of the licence for doing business in cybersecurity products and services comprises all of the following documents:

a) An application made according to Form No. 03 in Appendix I to this Decree;

b) A personal history declaration accompanied by the personal identification documents of the at-law representative;

c) A detailed description of the contents subject to re-issuance.

3. Dossiers of application for re-issuance of licences for doing business in cybersecurity products and services shall be submitted by the methods prescribed in Clause 3, Article 9 of this Decree.

4. The Ministry of Public Security shall examine the validity of the dossier in accordance with Clause 4, Article 9 of this Decree.

5. Within 05 working days from the date of receipt of a valid application, the Ministry of Public Security shall consider and re-issue the licence for the organisation or enterprise. In case of refusal, it shall issue a written notice, clearly stating the reason.

6. The term of the modified licence for doing business in cybersecurity products and services shall remain the same as that of the licence initially granted.

Article 12. Renewal of licences for doing business in cybersecurity products and services

1. An organisation or enterprise that has not violated the law on business in cybersecurity products and services may have its licence for doing business in cybersecurity products and services extended once for a period not exceeding 03 years. A dossier of application for renewal of the licence shall be submitted to the Ministry of Public Security no later than 60 days before the licence expires.

2. A dossier of application for renewal of the licence for doing business in cybersecurity products and services comprises:

a) An application made according to Form No. 03 in Appendix I to this Decree;

b) A report on the operations of the organisation or enterprise during the preceding 02 years.

3. Dossiers of application for renewal of licences for doing business in cybersecurity products and services shall be submitted by the methods prescribed in Clause 3, Article 9 of this Decree.

4. The Ministry of Public Security shall examine the validity of the dossier in accordance with Clause 4, Article 9 of this Decree.

5. Within 10 working days from the date of receipt of a valid application, the Ministry of Public Security shall consider and renew the licence for the organisation or enterprise. In case of refusal, it shall issue a written notice, clearly stating the reason.

Article 13. Conditions for grant of permits for importing and exporting cybersecurity products;

1. When exporting or importing cybersecurity products on the List of cybersecurity products subject to export or import permits in the Appendix to this Decree, organisations and enterprises shall obtain permits for export or import of cybersecurity products granted by the Ministry of Public Security. A permit for export or import of cybersecurity products shall be granted for each export or import consignment and shall be valid for 02 years. An organisation or enterprise applying for a permit for export or import of cybersecurity products shall possess a licence for doing business in cybersecurity products and services and pay the prescribed fee.

2. Conditions for grant of permits for export or import of cybersecurity products

a) An organisation or enterprise applying for a permit for export or import of cybersecurity products shall possess a valid licence for doing business in cybersecurity products and services;

b) Imported cybersecurity products shall conform to international standards or Vietnamese standards in the field of cybersecurity in accordance with the law on standards and technical regulations;

c) The purposes and intended users of cybersecurity products shall be specified and shall not be prejudicial to national security.

3. A dossier of application for a permit for export or import of cybersecurity products specified in Article 3 of this Decree shall comprise:

a) An application for the permit for export or import of cybersecurity products, made according to Form No. 04 in Appendix I to this Decree;

b) Documents certifying conformity with international standards or Vietnamese standards in the field of cybersecurity;

c) Documents evidencing the import purposes and intended users, including a commercial contract with the end user and documents evidencing that the import serves research or warranty purposes.

4. The List of cybersecurity products subject to export or import, together with their HS codes, is provided in Appendix II to this Decree.

5. Dossiers of application for permits for export or import of cybersecurity products shall be submitted by the methods prescribed in Clause 3, Article 9 of this Decree.

6. The Ministry of Public Security shall examine the validity of the dossier in accordance with Clause 4, Article 9 of this Decree.

7. Within 05 working days from the date of receipt of a valid application, the Ministry of Public Security shall consider and grant permit for the organisation or enterprise. In case of refusal, it shall issue a written notice, clearly stating the reason according to Form No. 12 provided in Appendix I to this Decree.

Article 14. Suspension and revocation of licences for doing business in cybersecurity products and services

1. Cases of permanent revocation:

a) Forging a dossier or providing false information in documents to apply for a licence for doing business in cybersecurity products and services; or being granted a licence for doing business in cybersecurity products and services by an authority other than that prescribed in this Decree;

b) Failing to satisfy the business conditions prescribed in Articles 6, 7 and 8 of this Decree and, after such failure is detected by a competent agency and rectification is required, failing to rectify it within 40 days from the date of receipt of the rectification request;

c) Failing to commence operations within 06 months from the date of grant of the licence for doing business in cybersecurity products and services;

d) Having its operations suspended or being dissolved or declared bankrupt in accordance with law, or having its establishment registration documents revoked by a competent agency; or requesting revocation of its licence for doing business in cybersecurity products and services;

dd) Lending, leasing, purchasing or selling a licence for doing business in cybersecurity products and services.

2. Cases of suspension of the use of a licence for doing business in cybersecurity products and services for a period of between 03 months and 06 months:

a) Failing to carry out procedures for modification of the licence for doing business in cybersecurity products and services when the organisation or enterprise changes its name or at-law representative;

b) Failing to carry out procedures for re-issuance of the lost or damaged licence for doing business in cybersecurity products and services;

c) Failing to cease or suspend the provision of cybersecurity products or services at the request of a competent agency;

d) Failing to report to the Ministry of Public Security on the business, export and import of cybersecurity products and services as prescribed;

dd) Committing violations of regulations on business in cybersecurity products and services for which administrative penalties have been imposed on 02 or more occasions within a period of 12 months.

3. If, during an inspection, an organisation or enterprise is found to fall into any of the cases subject to revocation or suspension of its licence for doing business in cybersecurity products and services specified in Clause 1 or 2 of this Article, the inspecting agency shall make a written record thereof and submit it to the Ministry of Public Security. Within 15 working days from the date of receipt of the written record, the Ministry of Public Security shall consider and decide on the revocation or suspension of the licence for doing business in cybersecurity products and services. The revocation or suspension decision shall be sent to the business registration agency and the customs office.

4. If a licence for doing business in cybersecurity products and services is revoked or suspended, the permit for export or import of cybersecurity products shall cease to be valid.

Article 15. Revocation of permits for importing and exporting cybersecurity products

1. An organisation or enterprise shall have its permit for export or import of cybersecurity products revoked in any of the following cases:

a) Forging a dossier of application for a permit for export or import of cybersecurity products, or altering or erasing the permit so as to change its contents;

b) Being granted a permit for export or import of cybersecurity products by an authority other than the competent authority, or without compliance with the dossier and procedural requirements prescribed in this Decree;

c) The importer has its business registration certificate or investment registration certificate revoked or suspended; ceases its operations; is no longer authorised by the owner or manufacturer of the cybersecurity products and the right to import such products has not been transferred to a replacement organisation; or is dissolved or declared bankrupt in accordance with law;

d) The imported cybersecurity products have reached the end of their circulation period according to a notice from the manufacturer, owner or competent agency or organisation, or products currently circulating on the market contain defects that cause consequences for users and cannot be remedied.

2. If, during an inspection, an organisation or enterprise is found to fall into any of the cases subject to revocation of its permit for export or import of cybersecurity products specified in Clause 1 of this Article, the inspecting agency shall make a written record thereof and submit it to the public security agency competent to grant the permit. Within 05 working days from the date of receipt of the written record, the Ministry of Public Security shall consider and decide on the revocation of the permit for export or import of cybersecurity products. The revocation decision shall be sent to the customs office. After a decision on revocation of the permit for export or import of cybersecurity products is issued, the organisation or enterprise shall recall the cybersecurity products specified in the revocation decision and shall not continue to import or export such products.

 

Chapter III

RESPONSIBILITIES OF MINISTRIES, MINISTERIAL-LEVEL AGENCIES, PROVINCIAL-LEVEL PEOPLE’S COMMITTEES, ORGANISATIONS AND ENTERPRISES

 

Article 16. Responsibilities of organisations and enterprises

1. To regularly and continuously maintain the required conditions throughout the course of business in cybersecurity products and services. Enterprises providing cybersecurity monitoring services shall maintain connections and exchange monitoring information with the Ministry of Public Security’s national cybersecurity protection system throughout the provision of cybersecurity monitoring services. Cybersecurity products specified at Points a, b, c and d, Clause 4, Article 3 of this Decree shall be destroyed when they are damaged or are no longer used for the performance of tasks of the Ministry of Public Security or the Ministry of National Defence.

2. To pay fees for the grant of licences for doing business in cybersecurity products and services and charges for the grant of licences for export or import of cybersecurity products in accordance with law.

3. Organisations and enterprises granted licences for doing business in cybersecurity products and services shall submit ad hoc reports upon request and annual reports on their business in cybersecurity products and services to the Ministry of Public Security, according to Form No. 09 in Appendix I to this Decree. Data for periodic reports shall cover the period from January 01 to December 31. Such reports shall be submitted before January 31 of the subsequent year.

4. If an organisation or enterprise suspends its operations, it shall, within 10 working days from the date of suspension, notify in writing the agency competent to grant licences for doing business in cybersecurity products and services.

5. To comply with inspections and the handling of violations by public security agencies and competent state management agencies.

Article 17. Responsibilities of the Ministry of Public Security

The Minister of Public Security shall be responsible before the Government for the unified state management of business in cybersecurity products and services and shall:

1. Assume the prime responsibility for, and coordinate with ministries and sectors in, managing business in cybersecurity products and services in accordance with this Decree and relevant legal documents; decentralise and delegate powers to manage business in cybersecurity products and services in accordance with law.

2. Publish standards and prescribe technical regulations in the field of cybersecurity; develop an electronic information database system for management and performance of administrative procedures related to business in cybersecurity products and services.

3. Assume the prime responsibility for, and coordinate with ministries and sectors in, conducting and providing guidance on inspections in accordance with Article 19 of this Decree; settle complaints and denunciations; and prevent, detect, combat and handle violations relating to business in cybersecurity products and services in accordance with law.

Article 18. Responsibilities of ministries, ministerial-level agencies and provincial-level People’s Committees

Within the ambit of their functions, tasks, and powers, ministries, ministerial-level agencies, and provincial-level People’s Committees shall coordinate with the Ministry of Public Security in performing state management of business in cybersecurity products and services.

Article 19. Inspection

1. A competent agency shall conduct a comprehensive inspection of compliance with regulations on business in cybersecurity products and services no more than once a year, including interdisciplinary inspections, except where there are clear indications of violations.

An ad hoc inspection shall be conducted when a business establishment is found to have committed or show indications of committing a violation of law relating to business in cybersecurity products and services; when a complaint or denunciation is filed by an organisation or individual concerning a violation of law relating to business in cybersecurity products and services by an organisation or enterprise; or to enhance the maintenance of security and order under a written direction of a competent agency.

2. Contents of inspection:

a) Inspecting documents in the legal dossier; and comparing the business contents stated in the licence for doing business in cybersecurity products and services and the permit for export or import of cybersecurity products granted to the organisation or enterprise against its actual operations;

b) Inspecting compliance with this Decree and other relevant legal documents;

c) Upon completion of an inspection, a written record shall be made according to the uniform form prescribed by the Minister of Public Security, clearly stating the inspection results and any outstanding issues or violations.

3. Inspecting competence:

a) The Ministry of Public Security may conduct annual inspections or ad hoc inspections in accordance with Clause 1 of this Article;

b) Provincial-level people’s Committees or higher-level authorities may inspect organisations and enterprises within their management areas upon detecting that such organisations or enterprises have committed or show indications of committing violations of law relating to business in cybersecurity products and services, or upon receiving complaints or denunciations from organisations or individuals relating to security and order at organisations or enterprises within their management areas. After an inspection, a written notice of the inspection results and the handling of violations shall be sent to the Ministry of Public Security.

4. Violations detected during inspections shall be handled in accordance with law.

 

Chapter IV

IMPLEMENTATION PROVISIONS

 

Article 20. Effect

This Decree takes effect from August 19, 2026.

Article 21. Transitional provisions

1. Enterprises may continue to perform contracts for business in cybersecurity products and services concluded and valid before the effective date of this Decree.

2. Dossiers of application for issuance, modification, re-issuance or renewal that have been received before July 01, 2026, but not yet processed shall comply with the order, procedures and conditions specified in this Decree.

Article 22. Implementation responsibilities

1. The Minister of Public Security shall urge, inspect and guide the implementation of this Decree.

2. Ministers, heads of ministerial-level agencies, Chairpersons of provincial-level People's Committees shall implement this Decree.

 

 

ON BEHALF OF THE GOVERNMENT
FOR THE PRIME MINISTER
DEPUTY PRIME MINISTER


Pham Gia Tuc

 

This feature is available to English or Advanced account holders. Please log in to a subscriber account to see the full text. Don’t have an account? Register here
Please log in to a subscriber account to see the full text. Don’t have an account? Register here
Processing, please wait...

You are not logged in.

This feature is available to Advanced account holders. Please log in to access detailed information on Related documents.

If you do not have an account, please register here!

Processing, please wait...
LuatVietnam.vn is the SOLE distributor of English translations of Official Gazette published by the Vietnam News Agency

VIETNAMESE DOCUMENTS

download
Decree 332/2026/NĐ-CP PDF (Original)

This utility is available to subscribers only. Please log in to a subscriber account to download. Don’t have an account? Register here

download
Decree 332/2026/NĐ-CP (Word)

This utility is available to subscribers only. Please log in to a subscriber account to download. Don’t have an account? Register here

Appendix 1 (Word)

This utility is available to subscribers only. Please log in to a subscriber account to download. Don’t have an account? Register here

Appendix 2 (Word)

This utility is available to subscribers only. Please log in to a subscriber account to download. Don’t have an account? Register here

Appendix 3 (Word)

This utility is available to subscribers only. Please log in to a subscriber account to download. Don’t have an account? Register here

Appendix 4 (Word)

This utility is available to subscribers only. Please log in to a subscriber account to download. Don’t have an account? Register here

Appendix 5 (Word)

This utility is available to subscribers only. Please log in to a subscriber account to download. Don’t have an account? Register here

Appendix 6 (Word)

This utility is available to subscribers only. Please log in to a subscriber account to download. Don’t have an account? Register here

Appendix 7 (Word)

This utility is available to subscribers only. Please log in to a subscriber account to download. Don’t have an account? Register here

Appendix 8 (Word)

This utility is available to subscribers only. Please log in to a subscriber account to download. Don’t have an account? Register here

Appendix 9 (Word)

This utility is available to subscribers only. Please log in to a subscriber account to download. Don’t have an account? Register here

Appendix 10 (Word)

This utility is available to subscribers only. Please log in to a subscriber account to download. Don’t have an account? Register here

Appendix 11 (Word)

This utility is available to subscribers only. Please log in to a subscriber account to download. Don’t have an account? Register here

Appendix 12 (Word)

This utility is available to subscribers only. Please log in to a subscriber account to download. Don’t have an account? Register here

Appendix 13 (Word)

This utility is available to subscribers only. Please log in to a subscriber account to download. Don’t have an account? Register here

ENGLISH DOCUMENTS

LuatVietnam's translation
download
Decree 332/2026/NĐ-CP (PDF)

This utility is available to subscribers only. Please log in to a subscriber account to download. Don’t have an account? Register here

download
Decree 332/2026/NĐ-CP (Word)

This utility is available to subscribers only. Please log in to a subscriber account to download. Don’t have an account? Register here

* Note: To view documents downloaded from LuatVietnam.vn, please install DOC, DOCX and PDF file readers
For further support, please call 19006192

SAME CATEGORY

loading