Decree 333/2026/ND-CP detailing the Law on Cybersecurity

  • Summary
  • Content
  • Status
  • Vietnamese
  • Related documents
  • Diagram
  • Download
Bilingual Text

Please log in to your Advanced Package to view the full text. Do not have an account yet? Register here.

Save

Please log in to use this function

Send link to email

Please log in to use this function

Error message
  • Print
  • Share:
  • Text mode: Light | Dark
Font size:

ATTRIBUTE

Decree No. 333/2026/ND-CP dated August 19, 2026 of the Government detailing a number of articles and measures for implementation of the Law on Cybersecurity
Issuing body: GovernmentEffective date:
Known

Please log in to a subscriber account to use this function.

Don’t have an account? Register here

Official number:333/2026/ND-CPSigner:Pham Gia Tuc
Type:DecreeExpiry date:Updating
Issuing date:19/08/2026Effect status:
Known

Please log in to a subscriber account to use this function.

Don’t have an account? Register here

Fields:National Security, Information - Communications
For more details, click here.
Download files here.
LuatVietnam.vn is the SOLE distributor of English translations of Official Gazette published by the Vietnam News Agency
Effect status:
Known

The Effect status of this document is known.This feature is available to Advanced account holders. Please log in to a subscriber account to view Effect status. Don’t have an account? Register here

THE GOVERNMENT
__________

No. 333/2026/ND-CP

THE SOCIALIST REPUBLIC OF VIETNAM
Independence - Freedom - Happiness

______________________

Hanoi, August 19, 2026

 
DECREE

Detailing a number of articles and measures for implementation of the Law on Cybersecurity

 

Pursuant to Law No. 63/2025/QH15 on Organization of the Government;

Pursuant to Law No. 32/2004/QH11 on National Security;

Pursuant to Law No. 116/2025/QH15 on Cybersecurity;

At the proposal of the Minister of Public Security;

The Government promulgates the Decree detailing a number of articles and measures for implementation of the Law on Cybersecurity.

 

Chapter I

GENERAL PROVISIONS

 

Article 1. Scope of regulation

1. This Decree details Points a, b, c, d, dd, g, k, l and m, Clause 1, Article 5; Clause 4, Article 25; and Clause 5, Article 34 of the Law on Cybersecurity, covering the following contents:

a) Contents, order, procedures and competence for applying cybersecurity protection measures: cybersecurity appraisal; assessment of cybersecurity conditions; cybersecurity inspection; cybersecurity monitoring; response to and remediation of cybersecurity incidents; measures to combat and protect cybersecurity; use of cryptography to protect cyberinformation; request for the removal of unlawful information or false information and fake news in cyberspace that infringes upon national security, social order and safety or the lawful rights and interests of agencies, organisations and individuals; collection of electronic data related to activities infringing upon national security, social order and safety or the lawful rights and interests of agencies, organisations and individuals in cyberspace; termination, suspension, or request for cessation of operation of information systems, and revocation of domain names in accordance with law;

b) Assurance of cyberinformation security as prescribed in Clauses 2 and 3, Article 25 of the Law on Cybersecurity;

c) Standards for specialised cybersecurity knowledge and skills; programmes and contents of certification of intensive training in specialised cybersecurity knowledge and skills.

This Decree prescribes measures for implementation of the mechanism for the management of IP address identification applicable to enterprises providing telecommunications and Internet services.

Article 2. Subjects and principles of application

1. This Decree applies to Vietnamese agencies, organisations and individuals; foreign agencies, organisations and individuals in Vietnam, and persons of Vietnamese origin with undetermined nationality who reside in Vietnam and have been issued identity certificates; and foreign agencies, organisations and individuals directly participating in or related to cybersecurity protection activities in Vietnam.

2. The Ministry of National Defence shall perform cybersecurity management with respect to military and national defence tasks; the Ministry of Public Security shall perform cybersecurity management, according to its competence, with respect to civil and economic activities of military units; for overlapping matters (if any), the Ministry of Public Security and the Ministry of National Defence shall reach agreement thereon by a coordination regulation.

Article 3. Interpretation of terms

In this Decree, the terms below are construed as follows:

1. Service user means an organisation or individual participating in the use of services in cyberspace.

2. Service user in Vietnam means an organisation or individual using services in cyberspace in the territory of the Socialist Republic of Vietnam.

3. Services on telecommunications networks mean telecommunications services and telecommunications application services in accordance with law.

4. Services on the Internet mean Internet services and information content services on mobile telecommunications networks in accordance with law.

5. Value-added services in cyberspace mean value-added telecommunications services in accordance with law.

6. An act violating the law on cyberinformation security means an act violating the law on cybersecurity arising in activities of assurance of cyberinformation security, committed through cyberspace, information systems, information technology, electronic means or digital devices, and falling into the case specified in Article 7 or Article 13 of the Law on Cybersecurity.

7. Cybersecurity specialisations mean training specialisations in the groups of cybersecurity and information security disciplines, and the cybersecurity and prevention and combat of hi-tech crime discipline.

8. Security cryptography means cryptographic techniques and cryptographic products researched, built and developed by the Ministry of Public Security and used to secure or authenticate data under the management of the Ministry of Public Security.

Chapter II

ORDER AND PROCEDURES FOR APPLICATION OF A NUMBER OF CYBERSECURITY PROTECTION MEASURES

 

Article 4. Principles for application of cybersecurity protection measures

1. The application of cybersecurity protection measures must comply with the Constitution and law; and ensure the interests of the State and the lawful rights and interests of agencies, organisations and individuals.

2. Cybersecurity protection measures may only be applied for the proper purposes, to the proper subjects, within the proper competence and in the proper order and procedures in accordance with law; and may only be implemented after obtaining a written approval decision from a competent person.

Article 5. Order and procedures for cybersecurity appraisal of information systems critical to national security

1. Cybersecurity appraisal shall be conducted for designs, schemes, plans and options for new construction, upgrading and expansion of information systems critical to national security before approval, in order to consider and assess the satisfaction of cybersecurity requirements by such information systems.

2. In the case where the results of determination of the information system level have clarified the requirements, scope, contents and level of cybersecurity assurance for the information system, the competent agency shall inherit and use the contents already assessed and concluded; such contents shall not be re-appraised, except where there is a change affecting the information system level or the level of importance of the information system to national security.

3. Subjects of cybersecurity appraisal include:

a) Detailed design dossiers of investment projects for new construction, upgrading or expansion of information systems;

b) Schemes, plans and options for upgrading or expansion of information systems.

4. Contents of cybersecurity appraisal include:

a) Compliance with regulations, standards, technical regulations and cybersecurity conditions in the design, construction, upgrading or expansion of information systems;

b) The appropriateness of cybersecurity protection plans and plans for response to and remediation of cybersecurity incidents;

c) The arrangement of human resources, technical conditions and management measures for cybersecurity protection of information systems;

d) Other contents directly related to cybersecurity protection requirements for the information system being appraised.

5. Competence for cybersecurity appraisal is prescribed as follows:

a) The Ministry of Public Security shall conduct cybersecurity appraisal of information systems critical to national security, except the cases specified at Points b and c of this Clause;

b) The Ministry of National Defence shall conduct cybersecurity appraisal of military information systems;

c) The Government Cipher Committee shall conduct cybersecurity appraisal of cryptographic information systems under the Government Cipher Committee.

6. A dossier of request for cybersecurity appraisal comprises:

a) A written request for cybersecurity appraisal, made according to Form No. 01 in the Appendix promulgated together with this Decree;

b) Dossiers and documents concerning subjects of cybersecurity appraisal, including: detailed design dossiers of investment projects for new construction, upgrading or expansion of information systems; schemes, plans and options for upgrading or expansion of information systems;

c) Documents showing the results of determination of the cybersecurity level of the information system;

d) Other documents related to the contents requested for appraisal, if any.

7. The order and procedures for cybersecurity appraisal shall be carried out as follows:

a) After the information system level is determined in accordance with law, the information system manager shall submit 01 dossier of request for cybersecurity appraisal to the competent agency specified in Clause 5 of this Article;

b) Within 03 working days from the date of receipt of the dossier, the competent agency shall check the validity of the dossier. In the case where the dossier is valid, it shall issue a dossier receipt immediately after completion of the check. In the case where the dossier is invalid, it shall issue a written notice for the information system manager to supplement and complete the dossier;

c) Within a maximum period of 25 working days from the date of issuance of the receipt for a valid dossier, the competent agency shall organise the cybersecurity appraisal and notify in writing the appraisal results to the information system manager.

8. In the case where it is necessary to determine the conformity between the current status of the information system and the dossier of request for appraisal, the competent agency shall conduct an on-site survey and assessment of the information system. The on-site survey and assessment must not affect the normal operation of the information system manager and the information system being appraised. The duration of the on-site survey and assessment must not exceed 07 working days and shall not be included in the appraisal time limit specified at Point c, Clause 7 of this Article.

9. Cybersecurity appraisal results shall serve as the basis for the information system manager to complete the cybersecurity assurance plan, submit it to the competent authority for approval, or carry out subsequent steps in accordance with law.

10. Dossiers, documents, information and cybersecurity appraisal results shall be managed and protected in accordance with the law on protection of state secrets, the law on cybersecurity and other relevant laws.

Article 6. Order and procedures for assessment of cybersecurity conditions for information systems critical to national security

1. Assessment of cybersecurity conditions means a procedure carried out by a competent agency to consider and determine the degree of satisfaction of cybersecurity conditions by an information system critical to national security before it is put into operation and use.

2. An information system critical to national security must be assessed and certified as satisfying cybersecurity conditions before being put into operation and use; the information system manager shall maintain the satisfaction of cybersecurity conditions throughout the process of management, operation and exploitation of the system.

3. An information system critical to national security shall be assessed as satisfying cybersecurity conditions when meeting the following requirements:

a) Having regulations, processes and plans for cybersecurity assurance in conformity with the law on cybersecurity, the law on protection of state secrets, cybersecurity standards and technical regulations, and relevant specialised technical standards;

b) Clearly identifying the information system, information, data, technical infrastructure and critical components requiring priority protection; processes for management, operation, exploitation, use and protection of the information system, data and technical infrastructure; and responsibilities of each unit and individual in the management, operation and use of the system;

c) Having a unit or personnel responsible for system operation and administration and cybersecurity protection; personnel performing such tasks must have appropriate professional qualifications in cybersecurity, information technology or relevant technical fields and shall keep confidential information related to the information system during the performance of their tasks and after termination of such tasks;

d) System operation and administration and cybersecurity protection activities shall have clearly defined functions, tasks, powers and responsibilities; ensure cross-checking, limit conflicts of duties and satisfy cybersecurity protection requirements;

dd) Equipment, hardware, software, databases, source code, application programs, development tools and other technical components of the system shall be inspected, managed, reviewed, updated, and have security weaknesses, vulnerabilities, malicious software, malicious hardware and cybersecurity risks remedied before being put into use and during operation;

e) Products, equipment, hardware and software for which specialised cybersecurity protection forces have issued warnings or notices of risks of compromising cybersecurity shall not be put into use, or may only be put into use after measures have been taken to handle and remedy such risks;

g) Having measures to manage, inspect and control the connection, use, transportation, storage, repair and destruction of information technology equipment, communication means, information carriers, mobile devices, and equipment and means for information storage serving the operation of the information system;

h) Having technical measures to monitor, detect, warn of, prevent, handle and remedy cybersecurity threats and incidents; separate the production environment from development, inspection and testing environments; and control the installation and use of software, services, tools and means on the system;

i) Having a data backup plan and testing data recovery capability; segmenting networks by users, purposes of use and levels of importance of system resources; and controlling connections and access between network segments and critical system resources;

k) Having solutions to detect and prevent untrusted access, unauthorised intrusion, denial-of-service attacks and other forms of cyberattack; and to scan for, detect, warn of and handle security weaknesses, technical vulnerabilities, connections, devices and software unlawfully installed in the system;

l) Recording, managing and storing logs of activities of the information system and users, arising errors and cybersecurity incidents in accordance with law, relevant standards and technical regulations, and cybersecurity protection requirements;

m) Having measures for account management, assignment of user privileges, access control, management of secret keys and authentication methods; controlling the creation, allocation, use and monitoring of accounts with administrative privileges; and reviewing, inspecting and re-approving users’ access rights;

n) Having measures to ensure physical security for locations where the system is installed, data centres, areas housing servers, network equipment, storage devices and critical technical areas; ensuring power supply and systems supporting continuous operation, controlling entry and exit, and preventing risks of intrusion and unlawful information collection using technical devices and means;

o) The processing, storage and transmission of information classified as state secrets on information systems must comply with the law on protection of state secrets, the law on cryptography, the law on cybersecurity and other relevant laws; information systems processing state secrets must be subject to protection measures appropriate to the secrecy level and cybersecurity protection requirements.

4. Contents of assessment of cybersecurity conditions include consideration and determination of the degree of satisfaction of the conditions specified in Clause 3 of this Article and other requirements directly related to cybersecurity assurance for the information system being assessed.

5. Competence for assessment and certification of satisfaction of cybersecurity conditions is prescribed as follows:

a) The Ministry of Public Security shall assess and certify satisfaction of cybersecurity conditions for information systems critical to national security, except the cases specified at Points b and c of this Clause;

b) The Ministry of National Defence shall assess and certify satisfaction of cybersecurity conditions for military information systems;

c) The Government Cipher Committee shall assess and certify satisfaction of cybersecurity conditions for cryptographic information systems under the Government Cipher Committee.

6. A dossier of request for assessment of cybersecurity conditions comprises:

a) A written request for certification of satisfaction of cybersecurity conditions, made according to Form No. 02 in the Appendix promulgated together with this Decree;

b) Feasibility study reports, technical design dossiers, construction drawing design dossiers or equivalent documents of investment projects for construction, upgrading or expansion of information systems;

c) Dossiers of cybersecurity assurance solutions for information systems critical to national security;

d) Documents showing cybersecurity appraisal results (if any);

dd) Other documents related to the contents requested for assessment (if any).

7. The order and procedures for assessment of cybersecurity conditions shall be carried out as follows:

a) The information system manager shall submit 01 dossier of request for assessment of cybersecurity conditions to the competent agency specified in Clause 5 of this Article;

b) Within a maximum period of 03 working days from the date of receipt of the dossier, the competent agency shall check the validity of the dossier. In the case where the dossier is valid, it shall issue a dossier receipt immediately after completion of the check. In the case where the dossier is invalid, it shall issue a written notice for the information system manager to supplement and complete the dossier;

c) Within a maximum period of 25 working days from the date of issuance of the receipt for a valid dossier, the competent agency shall organise the assessment of cybersecurity conditions;

d) In the case where the information system fully satisfies cybersecurity conditions, the head of the competent agency shall issue a certificate of satisfaction of cybersecurity conditions for the information system;

dd) In the case where the information system has not yet satisfied cybersecurity conditions, the competent agency shall issue a written notice clearly stating the unsatisfied contents and requiring the information system manager to supplement, complete, upgrade and remedy them before putting the information system into operation and use.

8. The information system manager shall supplement, complete, upgrade and remedy the unsatisfied contents as required by the competent agency specified at Point dd, Clause 7 of this Article and ensure that the information system satisfies cybersecurity conditions before putting it into operation and use.

9. The maintenance of cybersecurity conditions of the information system shall be inspected and subject to post-inspection in accordance with law. In the case where the information system manager fails to perform or fully perform the requirements specified in Clause 8 of this Article but puts the information system into operation and use, it shall be handled in accordance with law.

10. The certificate of satisfaction of cybersecurity conditions shall serve as the basis for the information system manager to put an information system critical to national security into operation and use in accordance with law.

11. Dossiers, documents, information and results of assessment of cybersecurity conditions shall be managed and protected in accordance with the law on protection of state secrets, the law on cybersecurity and other relevant laws.

Article 7. Order and procedures for cybersecurity monitoring

1. Cybersecurity monitoring means activities of collecting, receiving, analysing and processing information in order to detect and warn of cybersecurity threats, cybersecurity incidents, security weaknesses, vulnerabilities, malicious software and malicious hardware for timely prevention, stopping, handling and remediation.

2. The information system manager shall organise cybersecurity monitoring for information systems under its management; establish mechanisms for self-monitoring, self-warning and receipt of warnings of cybersecurity threats, cybersecurity incidents, security weaknesses and vulnerabilities; and maintain a cybersecurity monitoring system and a centralised malicious software prevention and combat system that satisfy requirements for connection and sharing of warning data on cybersecurity threats and incidents with competent agencies in accordance with law.

3. For information systems critical to national security, the information system manager shall regularly coordinate with specialised cybersecurity protection forces in organising cybersecurity monitoring; and ensure technical conditions, human resources and necessary information serving cybersecurity monitoring activities as required for national security protection.

4. Specialised cybersecurity protection forces under the Ministry of Public Security shall conduct cybersecurity monitoring of the following subjects, except military information systems and cryptographic information systems under the Government Cipher Committee:

a) National cyberspace;

b) Information systems critical to national security according to their assigned functions and tasks;

c) Information systems of agencies and organisations in the political system according to their assigned functions and tasks;

d) Other information systems where necessary as prescribed by the Law on Cybersecurity.

5. The order for conducting cybersecurity monitoring by specialised cybersecurity protection forces is prescribed as follows:

a) Before implementing cybersecurity monitoring measures, specialised cybersecurity protection forces shall notify the information system manager in writing of the reasons, scope, contents, duration and coordination requirements for monitoring, except in urgent cases for the protection of national security;

b) In an urgent case where prior notification cannot be made, specialised cybersecurity protection forces shall immediately implement cybersecurity monitoring measures and send a written notice to the information system manager within 24 hours from the time of implementation;

c) Specialised cybersecurity protection forces shall implement technical measures for cybersecurity monitoring within the scope and contents already notified or as required for handling an urgent situation;

d) Information collected during monitoring shall be analysed and assessed in order to promptly detect and warn of cybersecurity threats, cybersecurity incidents, security weaknesses, vulnerabilities, malicious software and malicious hardware;

dd) In the case where cybersecurity threats, cybersecurity incidents or signs affecting national security, social order and safety are detected, specialised cybersecurity protection forces shall promptly notify the information system manager for coordination in handling and remediation;

e) Cybersecurity monitoring results shall be consolidated and notified to the information system manager to the extent necessary, and reported to the competent agency in accordance with law.

6. During cybersecurity monitoring, the information system manager shall be responsible for:

a) Coordinating with specialised cybersecurity protection forces in implementing cybersecurity monitoring measures;

b) Ensuring necessary technical conditions serving cybersecurity monitoring activities as lawfully required by specialised cybersecurity protection forces;

c) Providing and updating information related to the configuration, connections and operation of the information system at the request of the competent agency;

d) Receiving and handling warnings of cybersecurity threats and cybersecurity incidents, and implementing remediation measures as required by specialised cybersecurity protection forces.

7. Telecommunications enterprises and enterprises providing Internet and information technology services shall coordinate, provide necessary technical information and data, and support specialised cybersecurity protection forces in cybersecurity monitoring activities in accordance with law.

8. Cybersecurity monitoring must ensure the proper competence, scope, purposes and cybersecurity protection requirements; and must not unlawfully affect the normal operation of agencies, organisations and individuals or the information systems being monitored.

9. Information, documents and data collected from cybersecurity monitoring activities shall be managed, used and protected in accordance with the law on protection of state secrets, the law on cybersecurity and other relevant laws.

Article 8. Order and procedures for cybersecurity inspection of information systems critical to national security

1. Cybersecurity inspection means activities of determining the actual cybersecurity status of information systems, information system infrastructure, and information stored, processed and transmitted in information systems in order to prevent, detect and handle cybersecurity threats and cybersecurity incidents, and propose measures to ensure the safe and continuous operation of information systems.

2. Information systems critical to national security shall be subject to cybersecurity inspection in the following cases:

a) When electronic means or cybersecurity services are put into use in the information system;

b) When there is a change in the current status of the information system affecting cybersecurity assurance requirements;

c) Annual periodic inspection;

d) Ad hoc inspection when a cybersecurity incident or an act infringing upon cybersecurity occurs; when required for state management of cybersecurity; or when the time limit for remediation of security weaknesses or vulnerabilities as required or recommended by specialised cybersecurity protection forces expires.

3. Subjects of cybersecurity inspection include:

a) Hardware systems, software, digital devices, network devices and other technical components of the information system;

b) Regulations, processes, plans and measures for cybersecurity assurance;

c) Information stored, processed and transmitted in the information system;

d) Plans and schemes for response to and remediation of cybersecurity incidents;

dd) Measures for protection of state secrets and prevention and combat of disclosure or loss of state secrets through technical channels;

e) Personnel participating in the administration, operation and cybersecurity protection of the information system.

4. Contents of cybersecurity inspection include:

a) Compliance with the law on cybersecurity assurance and protection of state secrets in cyberspace;

b) The implementation, maintenance and effectiveness of regulations, processes, plans and measures for cybersecurity assurance;

c) The implementation, maintenance and effectiveness of plans and schemes for response to and remediation of cybersecurity incidents;

d) Detection and assessment of security weaknesses, vulnerabilities, malicious software and malicious hardware, and testing of the capability to penetrate the system where necessary;

dd) Other contents appropriate to the inspection purposes and the nature and cybersecurity protection requirements of the information system.

5. The information system manager of an information system critical to national security shall be responsible for:

a) Organising self-inspection of cybersecurity for information systems under its management in the cases specified at Points a, b and c, Clause 2 of this Article;

b) Sending a written notice of the results of the annual periodic cybersecurity inspection to the competent specialised cybersecurity protection forces before October 01 every year;

c) Coordinating with specialised cybersecurity protection forces during ad hoc cybersecurity inspection;

d) Complying with requirements for remediation of cybersecurity threats and incidents, security weaknesses and vulnerabilities in accordance with the inspection conclusions of the competent agency.

6. Ad hoc cybersecurity inspection of information systems critical to national security is prescribed as follows:

a) Before the inspection is conducted, specialised cybersecurity protection forces shall notify the information system manager in writing at least 12 hours in advance in the case of a cybersecurity incident or an act infringing upon cybersecurity; and at least 72 hours in advance in the case of a state management requirement concerning cybersecurity or expiry of the time limit for remediation of security weaknesses or vulnerabilities as recommended by specialised cybersecurity protection forces;

b) Within 25 working days from the date of completion of the inspection, specialised cybersecurity protection forces shall notify the inspection results and set out requirements for the information system manager in the case where security weaknesses or vulnerabilities are detected; and provide guidance on or participate in remediation at the request of the information system manager;

c) Specialised cybersecurity protection forces under the Ministry of Public Security shall conduct ad hoc cybersecurity inspection of information systems critical to national security, except military information systems managed by the Ministry of National Defence, cryptographic information systems under the Government Cipher Committee, and cryptographic products provided by the Government Cipher Committee for protecting information classified as state secrets.

Specialised cybersecurity protection forces under the Ministry of National Defence shall conduct ad hoc cybersecurity inspection of military information systems.

The Government Cipher Committee shall conduct ad hoc cybersecurity inspection of cryptographic information systems under the Government Cipher Committee and cryptographic products provided by the Government Cipher Committee for protecting information classified as state secrets;

d) The information system manager of an information system critical to national security shall be responsible for coordinating with specialised cybersecurity protection forces in conducting ad hoc cybersecurity inspection.

7. The order and procedures for cybersecurity inspection conducted by specialised cybersecurity protection forces are prescribed as follows:

a) Notifying the information system manager of the inspection plan or cybersecurity inspection decision, except in the case of an ad hoc inspection for timely prevention of threats to national security, social order and safety;

b) Establishing an inspection team according to the assigned functions, tasks and competence;

c) Conducting cybersecurity inspection according to the inspection plan or decision; ensuring coordination with the information system manager and not disrupting the normal operation of the information system, except where necessary for the protection of national security;

d) Making a record of the process, contents and results of the cybersecurity inspection;

dd) Notifying the information system manager in writing of the cybersecurity inspection results within 03 working days from the date of completion of the inspection;

e) Requiring the information system manager to remedy cybersecurity threats, cybersecurity incidents, security weaknesses, vulnerabilities or violations of the law on cybersecurity detected through the inspection (if any).

8. In the case of an ad hoc inspection where prior notification cannot be made, specialised cybersecurity protection forces shall immediately conduct the inspection according to their competence and notify the information system manager in writing within 24 hours from the time the inspection commences.

9. In the case where it is necessary to preserve the current status of the information system for investigation, verification, handling of violations of law, handling of cybersecurity incidents, or remediation of security weaknesses or vulnerabilities, specialised cybersecurity protection forces shall issue a written request for the information system manager to implement one or several necessary measures, including temporarily preserving the configuration, technical status, data and system logs; restricting, adjusting or temporarily suspending part of the operation of the information system. The written request must clearly state the reasons, purposes, scope, applicable measures and implementation period.

10. Cybersecurity inspection must ensure the proper competence, grounds, purposes, scope and inspection contents; and must not unlawfully affect the normal operation of agencies, organisations and individuals or the information systems being inspected.

11. Inspection records, inspection results, information, documents and data collected during cybersecurity inspection shall be managed, used and protected in accordance with the law on protection of state secrets, the law on cybersecurity and other relevant laws.

Article 9. Order and procedures for response to and remediation of cybersecurity incidents involving information systems critical to national security

1. Response to and remediation of cybersecurity incidents means activities of detecting, identifying, preventing, limiting, handling and remedying cybersecurity incidents and restoring the operation of information systems when cybersecurity incidents occur.

2. Activities of response to and remediation of cybersecurity incidents include:

a) Detecting and identifying cybersecurity incidents;

b) Protecting the scene, collecting and preserving information, data, documents and evidence related to cybersecurity incidents;

c) Containing, isolating and limiting the scope of impact of cybersecurity incidents;

d) Analysing, assessing, classifying and determining the severity of cybersecurity incidents;

dd) Implementing measures for response, remediation and restoration of the normal operation of information systems;

e) Verifying the causes and tracing the origins of cybersecurity incidents.

3. The information system manager shall be responsible for:

a) Developing, promulgating, organising the implementation of and maintaining a plan for response to and remediation of cybersecurity incidents for information systems under its management;

b) Promptly detecting, identifying and classifying cybersecurity incidents and implementing the plan for response to and remediation of cybersecurity incidents;

c) Immediately notifying the competent specialised cybersecurity protection forces when a cybersecurity incident exceeds its handling capability or a dangerous cybersecurity situation arises;

d) Coordinating and providing information, documents, data and necessary technical conditions for specialised cybersecurity protection forces to perform tasks of coordination, response to and remediation of cybersecurity incidents;

dd) Reporting the results of handling and remediation of cybersecurity incidents to the competent specialised cybersecurity protection forces as prescribed.

4. The notification and reporting of cybersecurity incidents specified at Points c and dd, Clause 3 of this Article shall not apply to military information systems and cryptographic information systems under the Government Cipher Committee. The notification and reporting of cybersecurity incidents involving military information systems and cryptographic information systems under the Government Cipher Committee shall comply with regulations of the Ministry of National Defence and the law on cryptography.

5. Upon receipt of information on a cybersecurity incident, the competent specialised cybersecurity protection forces shall perform the following tasks:

a) Guiding the information system manager in applying temporary measures to prevent and limit damage;

b) Assessing the nature, severity and scope of impact of the cybersecurity incident;

c) Deciding on or proposing a plan for coordination, response to and remediation of the cybersecurity incident according to their competence;

d) Directing and monitoring activities of response to and remediation of the cybersecurity incident where necessary;

dd) Consolidating, reporting and assessing the results of handling the cybersecurity incident as prescribed.

6. In an urgent case for the protection of national security, social order and safety, the competent specialised cybersecurity protection forces may immediately apply necessary measures for coordination, response to and remediation of cybersecurity incidents in accordance with law; and shall concurrently notify the information system manager for coordinated implementation.

7. The order for coordination, response to and remediation of cybersecurity incidents shall be carried out as follows:

a) The information system manager shall detect, identify and classify the cybersecurity incident and immediately implement initial response measures;

b) In the case where the incident exceeds its handling capability or a dangerous cybersecurity situation arises, the information system manager shall notify the competent specialised cybersecurity protection forces;

c) Specialised cybersecurity protection forces shall assess the incident and provide guidance on or decide on a plan for coordination, response to and remediation of the cybersecurity incident according to their competence;

d) The information system manager shall implement measures for response to and remediation of the cybersecurity incident according to the determined plan or the guidance of specialised cybersecurity protection forces;

dd) Related agencies, organisations, enterprises and individuals shall coordinate, provide information, and provide necessary technical support and resources serving activities of coordination, response to and remediation of cybersecurity incidents as required by the competent agency;

e) After completion of the response to and remediation of the incident, the information system manager shall consolidate the handling results, assess the causes, consequences and measures applied, and send a report to the competent specialised cybersecurity protection forces.

8. Response to and remediation of cybersecurity incidents shall be carried out through the National Cybersecurity Incident Response and Remediation Network, under the unified coordination of the Ministry of Public Security, ensuring coordination among specialised cybersecurity protection forces, ministries, sectors, localities, agencies, organisations, enterprises and related individuals in accordance with law.

9. Telecommunications enterprises, enterprises providing Internet services, and information technology enterprises shall be responsible for coordinating, providing information and technical data, and arranging necessary technical conditions for specialised cybersecurity protection forces to perform tasks of coordination, response to and remediation of cybersecurity incidents in accordance with law.

10. Information, documents, data and evidence collected during response to and remediation of cybersecurity incidents shall be managed, used and protected in accordance with the law on protection of state secrets, the law on cybersecurity and other relevant laws.

Article 10. Order and procedures for implementation of the measure of using cryptography to protect cyberinformation

1. Specialised cybersecurity protection forces shall use encryption measures employing cryptography of the cryptographic sector to protect cyberinformation when storing and transmitting information and documents containing contents classified as state secrets in cyberspace. The use of cryptography of the cryptographic sector must comply with the law on cryptography, the law on protection of state secrets and the law on cybersecurity.

2. For data and information under the management of the Ministry of Public Security, specialised cybersecurity protection forces may use security cryptography to implement measures to secure or authenticate data for the purposes of national security protection, ensuring social order and safety, and cybersecurity assurance.

3. In the case where necessary for reasons of national security, social order and safety, or protection of the lawful rights and interests of agencies, organisations and individuals, specialised cybersecurity protection forces shall send a written request to related agencies, organisations and individuals to encrypt information not classified as state secrets before storing or transmitting it on the Internet. The written request must clearly state the reasons, scope, contents of information to be encrypted and applicable encryption measures.

Article 11. Order and procedures for implementation of the measure of requesting the removal of unlawful information or false information and fake news in cyberspace that infringes upon national security, social order and safety or the lawful rights and interests of agencies, organisations and individuals

1. Cases of application of the measure:

a) When information in cyberspace is determined by a competent agency to contain contents that infringe upon national security, propagandise against the State of the Socialist Republic of Vietnam; incite riots, disrupt security, or disturb public order in accordance with law;

b) When there are legal grounds for determining that information in cyberspace contains contents that insult or slander; infringe upon economic management order; or are fabricated or false, causing public confusion and serious damage to socio-economic activities to an extent that requires removal of the information;

c) Other information in cyberspace having contents specified in Clause 2, Article 7 of the Law on Cybersecurity in accordance with law.

2. Specialised cybersecurity protection forces under the Ministry of Public Security shall:

a) Decide on the application of the measure of requesting the removal of unlawful information or false information and fake news in cyberspace that infringes upon national security, social order and safety or the lawful rights and interests of agencies, organisations and individuals as specified in Clause 1 of this Article;

b) Send a written request to enterprises providing services on telecommunications networks, services on the Internet or value-added services in cyberspace, and information system managers to remove unlawful information or false information and fake news in cyberspace that infringes upon national security, social order and safety or the lawful rights and interests of agencies, organisations and individuals as specified in Clause 1 of this Article;

c) Inspect compliance with the implementation of the measure by related subjects to which the request is made;

d) Exchange and share information on the implementation of this measure, except where the contents fall within the scope of state secrets or professional requirements of the Ministry of Public Security.

3. Specialised cybersecurity protection forces under the Ministry of National Defence shall, according to their assigned functions, tasks and powers, decide on the application of the measure of requesting the removal of unlawful information or false information and fake news in cyberspace that infringes upon national security or military security as specified in Clause 1 of this Article with respect to military information systems.

Article 12. Order and procedures for implementation of the measure of collecting electronic data related to activities infringing upon national security, social order and safety or the lawful rights and interests of agencies, organisations and individuals in cyberspace

1. Electronic data means symbols, writings, numbers, images, sounds or similar forms created, stored, transmitted or received by electronic means.

2. Competence to decide on the implementation of the measure of collecting electronic data:

a) Specialised cybersecurity protection forces under the Ministry of Public Security shall decide on the implementation of the measure of collecting electronic data for investigation and handling of acts infringing upon national security, social order and safety or the lawful rights and interests of agencies, organisations and individuals in cyberspace;

b) Specialised cybersecurity protection forces under the Ministry of National Defence shall decide on the application of the measure of collecting electronic data for investigation of violations and crimes causing insecurity or unsafety or infringing upon national security or military security in cyberspace.

3. Activities of collecting electronic data related to activities infringing upon national security, social order and safety or the lawful rights and interests of agencies, organisations and individuals in cyberspace shall be carried out in accordance with law, ensuring the following principles and requirements:

a) Electronic data must not be interfered with or altered;

b) Data collection activities must be approved by a competent person specified in Clause 2 of this Article, carried out in accordance with the prescribed process, using recognised and verifiable equipment and software, and ensuring the integrity of electronic data stored in electronic means;

c) Persons conducting electronic data collection must possess adequate professional competence and be assigned by a competent person specified in Clause 2 of this Article to perform the task of collecting electronic data in accordance with law;

d) The process of collecting electronic data must be recorded in minutes and images and, where necessary, may be repeated to obtain similar results. Where necessary, an independent third party may be invited to witness and certify this process.

4. Seizure of means for storing, transmitting or processing electronic data related to activities infringing upon national security, social order and safety or the lawful rights and interests of agencies, organisations and individuals in cyberspace shall be carried out in accordance with law.

Article 13. Order and procedures for implementation of the measure of termination, suspension or request for cessation of operation of information systems, and revocation of domain names

1. Cases of application:

a) There are documents proving that the operation of an information system violates the law on national security or the law on cybersecurity;

b) The information system is being used for the purpose of infringing upon national security, social order and safety.

2. The Minister of Public Security shall directly decide on the termination, suspension or request for cessation of operation of information systems, or the suspension or revocation of domain names involving activities in violation of the law on cybersecurity.

3. Specialised cybersecurity protection forces under the Ministry of Public Security shall be responsible for implementing decisions on the termination, suspension or request for cessation of operation of information systems, or the suspension or revocation of domain names.

4. The order and procedures for implementation of the measure are as follows:

a) Reporting on the application of the measure of termination, suspension or request for cessation of operation of information systems, or suspension or revocation of domain names;

b) Deciding on the termination, suspension or request for cessation of operation of information systems, or suspension or revocation of domain names;

c) Sending a written request to related agencies, organisations and individuals to implement the termination, suspension or request for cessation of operation of information systems, or sending a written request to the Ministry of Science and Technology for suspension or revocation of domain names according to the order and procedures prescribed by law; the written request shall clearly state the reasons, duration, contents and recommendations;

d) In an urgent case where it is necessary to promptly prevent the operation of an information system from causing harm to national security or to prevent potentially harmful consequences, the Ministry of Public Security shall make a direct request or send a written request by fax or email to require agencies, organisations and individuals to terminate, suspend or request cessation of operation of the information system;

Within 24 hours at the latest from the time of the request, the Ministry of Public Security must send a written request for termination, suspension or request for cessation of operation of the information system. In the case where the above time limit expires without a written decision, the information system may continue its operation. Depending on the nature, severity and consequences arising from the delay in sending the written request, the responsible officer and related persons shall bear responsibility in accordance with law;

dd) The termination, suspension or request for cessation of operation of the information system must be recorded in minutes. The minutes must clearly state the time, place and grounds and be made in 02 copies. The competent functional agency shall retain one copy, and the agency, organisation or individual owning or managing the information system shall retain one copy;

e) For the suspension or revocation of domain names in the cases specified in Clause 1 of this Article, the competent functional agency shall send a written request to the Ministry of Science and Technology for suspension or revocation of the domain names according to the order and procedures prescribed by law.

5. Where the termination, suspension or request for cessation of operation of an information system is made without the grounds specified in Clause 2 of this Article, the head, deputy head of the competent functional agency and related officers shall bear responsibility before law; if damage is caused to related agencies, organisations or individuals, compensation must be made in accordance with law.

Article 14. Responsibilities of agencies, organisations and individuals in implementing cybersecurity protection measures

1. Specialised cybersecurity protection forces shall be responsible for providing specific guidance to related agencies, organisations and individuals on the implementation of provisions on the order and procedures for applying a number of cybersecurity protection measures.

2. Agencies, organisations and individuals shall, within the scope of their respective responsibilities and powers, promptly coordinate with and support specialised cybersecurity protection forces in implementing provisions on the order and procedures for applying a number of cybersecurity protection measures.

3. In the case where an enterprise providing cross-border services is publicly announced by a competent agency as having violated Vietnamese law, Vietnamese organisations and enterprises shall be responsible for coordinating with competent functional agencies in preventing and handling violations of law by enterprises providing cross-border services.

4. Any act of taking advantage of or abusing cybersecurity protection measures to violate law shall, depending on the nature and severity of the violation, be handled in accordance with law; in the case where damage is caused to the lawful rights and interests of organisations or individuals, compensation must be made in accordance with law.

5. For information systems not included in the List of information systems critical to national security, the Ministry of Public Security and the Ministry of National Defence shall coordinate synchronously in cybersecurity protection according to their assigned functions and tasks:

a) The Ministry of Public Security shall act as the focal-point agency in charge of civil and economic activities, activities of national security protection, maintenance of social order and safety, cybersecurity protection, prevention and combat of cybercrime, cyber-terrorism and cyber-espionage;

b) The Ministry of National Defence shall act as the focal-point agency in charge of activities for protection of the Fatherland in cyberspace.

 

Chapter III

ASSURANCE OF CYBERINFORMATION SECURITY

 

Article 15. Principles of assurance of cyberinformation security

1. Activities of assurance of cyberinformation security in the provision of services on telecommunications networks, the Internet and value-added services in cyberspace in Vietnam must ensure national sovereignty in cyberspace; protect national security, social order and safety; and ensure the lawful rights and interests of agencies, organisations and individuals in accordance with law.

2. The application of measures for assurance of cyberinformation security must be implemented synchronously in terms of state management and technical measures; and be appropriate to the nature, scale and scope of operation of the services provided by organisations and individuals and the level of risk to cyberinformation security.

3. The collection, storage, processing, use and provision of information and data in the course of providing services in cyberspace must comply with the law on cybersecurity, the law on personal data protection and other relevant laws of Vietnam.

Article 16. Activities of assurance of cyberinformation security

1. Domestic enterprises and foreign enterprises, when providing services on telecommunications networks, the Internet and value-added services in cyberspace in Vietnam, must carry out activities of assurance of cyberinformation security in accordance with this Article and other relevant laws of Vietnam.

2. Activities of authentication and protection of information and accounts of service users include:

a) Authenticating user information at the time of registration of a digital account in accordance with law;

b) Authenticating accounts by mobile phone numbers in Vietnam; in the case where a user does not have a mobile phone number in Vietnam, authentication shall be carried out using the personal identification number or another lawful electronic identification method in accordance with the law on electronic identification and authentication;

c) In the case where a service user uses the livestream feature for commercial purposes, the account must be authenticated using the personal identification number in accordance with law;

d) Applying necessary state management and technical measures to ensure the safety and confidentiality of users’ information and accounts; allowing only authenticated accounts to post and share information and use interactive features on the system.

3. Activities of providing information serving the protection of cyberinformation security include:

a) Providing information of service users to specialised cybersecurity protection forces under the Ministry of Public Security upon a valid request, based on the provisions of Vietnamese law, for verification, investigation and handling of violations of law;

b) Requests for and provision of information shall be made in writing, by electronic means or in another form, ensuring authentication of the requesting entity and confidentiality of the information provided in accordance with law;

c) The time limit for provision of information shall be no later than 24 hours from the time of receipt of the request; in an urgent case threatening infringement upon national security or threatening human life, the time limit for provision of information shall be no later than 03 hours.

4. Activities of preventing and handling information, services and applications violating the law on cyberinformation security include:

a) Restricting or blocking access, removing information, and removing services and applications in Vietnam with respect to information, services and applications violating the law on cyberinformation security at the request of specialised cybersecurity protection forces under the Ministry of Public Security;

b) Implementation of the request specified at Point a of this Clause must be completed no later than 24 hours from the time of receipt of the request; in an urgent case threatening infringement upon national security, it must be completed no later than 06 hours from the time of receipt of the request;

c) Applying state management measures and technical measures to restrict, suspend or cease the provision of services to organisations and individuals that repeatedly post information violating the law on cyberinformation security at the request of a competent agency and in accordance with law;

d) Restricting display in Vietnam or temporarily locking personal accounts, pages, community groups or content channels used to post information violating the law on cyberinformation security in the following cases:

Within a period of 30 days, if information violating the law on cyberinformation security is posted 03 times or more, display in Vietnam shall be restricted or the account, page, community group or content channel shall be temporarily locked for a maximum period of 60 days, depending on the nature and severity of the violation;

Within a period of 90 days, if information violating the law on cyberinformation security is posted 10 times or more, display in Vietnam shall be restricted or the account, page, community group or content channel shall be temporarily locked for a maximum period of 180 days, depending on the nature and severity of the violation;

dd) Indefinitely restricting display in Vietnam or indefinitely locking personal accounts, pages, community groups or content channels used to commit, continue committing, disseminate, organise, direct or support the commission of acts violating the law on cybersecurity in the following cases:

Posting or disseminating information infringing upon the national security of the Socialist Republic of Vietnam;

Having been temporarily locked 03 times or more at the request of a competent agency but continuing to be used to commit acts violating the law on cybersecurity;

There are grounds to determine that the personal account, page, community group or content channel continues to be used as a tool or means for committing acts violating the law on cybersecurity and that the application of the measure of indefinite account locking is necessary and appropriate to the nature and severity of the violation;

e) An account subject to the measure of indefinite account locking shall be considered for restoration in the following cases: the grounds for application of the measure no longer exist; there was an error in the verification or handling process; new circumstances arise that change the grounds for application of the measure; the competent agency determines that the account was not used to commit acts violating the law on cybersecurity.

5. Activities of suspension or cessation of service provision to ensure cyberinformation security include not providing or suspending or ceasing the provision of services to organisations or individuals that post information falling into the cases specified in Clauses 1, 2 and 3, Article 13 and Clause 2, Article 14 of the Law on Cybersecurity at the request of specialised cybersecurity protection forces under the Ministry of Public Security; the suspension or cessation of service provision must ensure the proper scope, subjects and duration and conform to relevant laws.

6. Activities of storage and management of system logs include:

a) Storing and managing system logs serving state management, assurance of cyberinformation security and handling of violations of law;

b) System logs must include at least information on service users’ accounts, login and logout times, IP addresses, source ports upon login and logout, and logs of processing of posted information;

c) The system log retention period must ensure that data can be retrieved for at least 12 months, satisfying requirements for verification, investigation and handling of violations of law.

Article 17. Measures for assurance of cyberinformation security

1. Measures for assurance of cyberinformation security include state management measures, technical measures and professional measures in accordance with law.

2. Competent state agencies shall, based on the nature, severity and scope of impact of threats and violations, require the application of one or more measures for assurance of cyberinformation security to enterprises, organisations and individuals providing and using services in cyberspace.

3. The application of measures for assurance of cyberinformation security must ensure compliance with the principles specified in Article 15 of this Decree and must not unlawfully infringe upon the lawful rights and interests of agencies, organisations and individuals.

Article 18. Responsibilities for assurance of cyberinformation security

1. Enterprises, organisations and individuals providing and using services in cyberspace shall be responsible for coordinating with specialised cybersecurity protection forces and competent state agencies in implementing activities and measures for assurance of cyberinformation security.

2. Telecommunications enterprises, enterprises providing Internet services, web hosting services, data centre services and enterprises providing telecommunications application services shall be responsible for:

a) Blocking and removing unlawful contents, services and applications on networks no later than 24 hours from the time of receipt of a request in writing, by telephone or by email from specialised cybersecurity protection forces under the Ministry of Public Security;

b) Refusing to provide or suspending the provision of telecommunications services, Internet services or other services to organisations and individuals using services to post unlawful information on networks upon a valid request from specialised cybersecurity protection forces under the Ministry of Public Security;

c) Telecommunications enterprises and enterprises providing Internet services shall connect to and receive requests for coordination in blocking and removing harmful and unlawful information, report results through the technical system, and implement other handling measures as required by the Ministry of Public Security;

d) Telecommunications enterprises and enterprises providing Internet services shall be responsible for ensuring technical infrastructure, connection systems, processing capacity, transmission and sharing of information and data, and other necessary conditions in the course of service provision in order to satisfy requirements for assurance of cyberinformation security and serve the implementation of cybersecurity protection solutions and measures in accordance with law and valid requests of specialised cybersecurity protection forces under the Ministry of Public Security.

3. Agencies, organisations and individuals, upon detecting acts violating the law on cyberinformation security, shall be responsible for notifying and coordinating with competent agencies in accordance with law.

Article 19. Data storage and establishment of a branch or representative office bearing legal responsibility in Vietnam

1. Data to be stored in Vietnam:

a) Personal information of service users in Vietnam;

b) Data created by service users in Vietnam: service account names, service usage time, credit card information, email addresses, most recent login and logout Internet Protocol (IP) addresses, and registered telephone numbers associated with accounts or data.

2. Domestic enterprises shall store the data specified in Clause 1 of this Article in Vietnam.

3. Data storage and establishment of a branch or representative office bearing legal responsibility in Vietnam by foreign enterprises:

a) Foreign enterprises conducting business activities in Vietnam in any of the following fields: telecommunications services; storage and sharing of data in cyberspace; provision of domain name registration and maintenance services for service users in Vietnam; e-commerce; online payment; payment intermediary services; transport connection services via cyberspace; social networks and social media; online video games; online applications; other services of providing, managing or operating information in cyberspace in the form of messages, voice calls, video calls, emails or online chats must store the data specified in Clause 1 of this Article and establish a branch or representative office bearing legal responsibility in Vietnam in the case where the services provided by such enterprises are used to commit acts violating the law on cybersecurity, the enterprises have been notified thereof by specialised cybersecurity protection forces under the Ministry of Public Security and requested in writing to coordinate in preventing, investigating and handling such acts 03 times over a maximum period of 06 months, but the foreign enterprises fail to provide remedial solutions; fail to comply; fail to fully comply in terms of the scope or quantity of each matter required to be complied with in the written request; or prevent, obstruct, neutralise or render ineffective cybersecurity protection measures implemented by specialised cybersecurity protection forces;

b) In the case of force majeure where compliance by a foreign enterprise with requirements of the law on cybersecurity cannot be carried out, the foreign enterprise shall notify specialised cybersecurity protection forces under the Ministry of Public Security within 03 working days for verification of the authenticity of the force majeure event. In this case, the enterprise shall have 25 working days to find a remedial solution.

4. In the case where the data collected, exploited, analysed or processed by an enterprise is not complete as specified in Clause 1 of this Article, the enterprise shall coordinate with specialised cybersecurity protection forces under the Ministry of Public Security to confirm and proceed with storage of the types of data currently being collected, exploited, analysed or processed.

In the case where an enterprise additionally collects, exploits, analyses or processes the types of data specified in Clause 1 of this Article, the enterprise shall be responsible for coordinating with specialised cybersecurity protection forces under the Ministry of Public Security to supplement, publicly notify users of, and update the list of data required to be stored in Vietnam.

5. The form of data storage in Vietnam shall be decided by enterprises themselves, ensuring the capability to retrieve and promptly provide data at the request of a competent agency and ensuring information security in accordance with national standards and technical regulations.

6. The order and procedures for requiring foreign enterprises to store data and establish a branch or representative office in Vietnam:

a) The Minister of Public Security shall issue a decision requiring data storage and establishment of a branch or representative office in Vietnam;

b) Specialised cybersecurity protection forces under the Ministry of Public Security shall notify, guide, monitor, supervise and urge enterprises to comply with requirements for data storage and establishment of a branch or representative office in Vietnam; and concurrently notify related agencies for performance of their state management functions according to their competence;

c) Within 12 months from the date the Minister of Public Security issues the decision, the enterprises specified at Point a, Clause 3 of this Article must complete data storage and establishment of a branch or representative office in Vietnam.

7. The order and procedures for establishment of a branch or representative office in Vietnam shall be carried out in accordance with the laws on business, commerce and enterprises and other relevant laws.

8. Enterprises that fail to comply with this Article shall, depending on the nature and severity of their violations, be handled in accordance with law.

Article 20. Periods of data storage and establishment of a branch or representative office in Vietnam

1. The period of data storage specified in Article 19 of this Decree shall commence from the time an enterprise receives the data storage request and end when the request terminates. The minimum storage period is 24 months.

2. The period of establishment of a branch or representative office in Vietnam as specified in Article 19 of this Decree shall commence from the time an enterprise receives the request to establish a branch or representative office in Vietnam and end when the enterprise no longer operates in Vietnam or the specified service is no longer provided in Vietnam.

3. System logs serving investigation and handling of acts violating the law on cybersecurity as specified at Point b, Clause 2, Article 25 of the Law on Cybersecurity shall be stored for at least 12 months.

 

Chapter IV

MANAGEMENT OF IP ADDRESS IDENTIFICATION

 

Article 21. Principles of IP address identification

1. The management of IP address identification must ensure accuracy, integrity and unique traceability to organisations and individuals registering for use of services, addresses at which Internet connection lines are installed for fixed broadband networks, and registered telephone numbers for mobile telecommunications networks.

2. Enterprises providing telecommunications services and enterprises providing Internet services shall be responsible for establishing and maintaining technical systems to record, store and manage information serving IP address identification associated with subscriber information, time of service use and information on related services in accordance with law.

3. IP address identification shall be carried out throughout the stages of allocation, use and revocation of IP addresses, ensuring continuity, consistency and the capability to serve state management requirements and cybersecurity protection measures.

Article 22. Contents and technical requirements for IP address identification

1. Enterprises providing telecommunications and Internet services, when allocating IP addresses to organisations and individuals, must apply technical measures to accurately identify subscriber information at the time of IP address allocation.

2. System log data on IP address allocation and management shall be synchronised according to the national time standard and include at least the following information:

a) Source IP address, source port, destination IP address, destination port and connection protocol;

b) In the case where Network Address Translation (NAT) is used, complete IP address mapping information must be stored;

c) Start time and end time of the connection session, synchronised according to the national time standard;

d) Identifier of the public IP allocation gateway (Gateway ID); connection session identifier (Session ID);

dd) Subscriber information and account using the IP address at the corresponding time.

3. The system log data specified in Clause 2 of this Article must be stored fully and continuously for at least 12 months; the data storage system must ensure integrity, safety and confidentiality, prevent modification and deletion, and ensure the extraction and provision of data to specialised cybersecurity protection forces for implementation of cybersecurity protection measures in real time.

Article 23. Provision of IP address identification information to specialised cybersecurity protection forces

1. Enterprises providing telecommunications and Internet services shall be responsible for establishing and maintaining an appropriate technical mechanism to ensure the capability to connect to and provide information serving IP address identification to the technical system of specialised cybersecurity protection forces under the Ministry of Public Security in accordance with law.

2. Specific requests for provision of IP address identification information shall be carried out according to the following order and procedures:

a) On the basis of a lawful written request or a valid electronic request of specialised cybersecurity protection forces for implementation of cybersecurity protection measures, verification, investigation and handling of acts violating the law on cybersecurity;

b) Enterprises providing telecommunications and Internet services must provide complete and accurate IP address identification information (including: full name of the individual, organisation information, personal identification number, subscriber name/code, registered address for installation of the Internet connection line for fixed broadband networks, and registered telephone number for mobile telecommunications networks) at the corresponding time as requested by specialised cybersecurity protection forces;

c) The time limit for provision of information shall be no later than 24 hours from the time of receipt of the request; in an urgent case related to national security, prevention and combat of cyber-terrorism, cyberattacks or particularly serious crimes, the time limit for provision of information must not exceed 03 hours.

3. The use, disclosure or exploitation of IP address identification information for commercial purposes is strictly prohibited, except where otherwise provided by law.

 

Chapter V

INTENSIVE TRAINING IN SPECIALISED CYBERSECURITY KNOWLEDGE AND SKILLS

Article 24. Requirements for specialised cybersecurity knowledge and skills

1. The subjects specified in Clause 1, Article 34 of the Law on Cybersecurity shall be determined as satisfying the requirements for specialised cybersecurity knowledge and skills when satisfying one of the following criteria:

a) Having received university-level or higher training in a cybersecurity specialisation;

b) Having received university-level or higher training in information technology disciplines or disciplines closely related to information technology and possessing a professional cybersecurity certificate specified in Clause 5 of this Article;

c) Having received university-level or higher training in information technology disciplines or disciplines closely related to information technology and having at least 5 years of experience in cybersecurity protection and prevention and combat of hi-tech crime;

d) Having received university-level or higher training in information technology disciplines or disciplines closely related to information technology and having undergone intensive training in specialised cybersecurity knowledge and skills specified in Clause 2 of this Article.

2. Based on their job positions and assigned functions and tasks, the subjects specified in Clause 2, Article 34 of the Law on Cybersecurity must undergo training in foundational cybersecurity knowledge and skills specified in Clause 3 of this Article and at least one area of specialised cybersecurity knowledge and skills specified in Clause 4 of this Article, except individuals who have received training in a cybersecurity specialisation.

3. Foundational cybersecurity knowledge and skills include:

a) Knowledge of laws, policies and strategies on cybersecurity, including the Law on Cybersecurity and guiding documents for its implementation; regulations on personal data protection and protection of state secrets in the cyber environment; rights, obligations and responsibilities of agencies, organisations and individuals in cybersecurity protection; and treaties on cybersecurity to which Vietnam is a contracting party;

b) General knowledge of cybersecurity, including concepts, scope and subjects of protection; common cybersecurity threats; principles for cybersecurity assurance; system security architecture; international standards and norms, and trends in the development of cybersecurity technology.

4. Specialised cybersecurity knowledge and skills include:

a) Cybersecurity governance, policies and law;

b) Cybersecurity incident response and handling, and digital forensics;

c) Inspection and assessment of cybersecurity weaknesses and vulnerabilities, and software security;

d) Cybersecurity monitoring, analysis and early warning of cybersecurity risks and threats;

dd) Research and development of cybersecurity products and systems;

e) Cybersecurity design and architecture;

g) Deployment, operation and security assurance of information systems;

h) Cloud security, OT/IoT systems and emerging technologies;

i) Data security, privacy and information management.

5. Individuals possessing valid cybersecurity certificates issued by foreign organisations and recognised by the Ministry of Public Security as equivalent to the specialised cybersecurity knowledge and skills specified in Clause 4 of this Article shall only be required to participate in training in the foundational knowledge and skills specified in Clause 3 of this Article.

6. The Minister of Public Security shall promulgate the training programme framework and standards for knowledge and skills specified in Clauses 3 and 4 of this Article as a uniform basis for organising training, assessing results and issuing certificates nationwide, except for subjects under the management of the Ministry of National Defence and the Government Cipher Committee.

7. The Minister of National Defence shall promulgate the training programme framework and standards for specialised cybersecurity knowledge and skills as a uniform basis for organising training, assessing results and issuing certificates for cybersecurity protection forces under its management.

8. The application of the requirements for specialised cybersecurity knowledge and skills specified in Clause 1 of this Article shall be carried out according to the following roadmap:

a) State agencies, organisations and enterprises shall be responsible for reviewing persons currently holding the positions specified in Clause 1, Article 34 of the Law on Cybersecurity, allocating funds and organising training within 24 months from the effective date of this Decree;

b) Information system managers of level-3, level-4 and level-5 information systems in state agencies, organisations and enterprises shall be responsible for reviewing persons under their management who are currently holding the positions specified in Clause 2, Article 34 of the Law on Cybersecurity, allocating funds and organising training within 36 months from the effective date of this Decree.

Article 25. Intensive training in specialised cybersecurity knowledge and skills

1. An institution may organise intensive training in specialised cybersecurity knowledge and skills for the subjects specified in Article 34 of the Law on Cybersecurity when it fully satisfies the following conditions:

a) Being lawfully established and operating in accordance with Vietnamese law;

b) Having physical facilities, technical infrastructure, classrooms, practice rooms, simulation and exercise systems, and teaching materials appropriate to the training contents;

c) Having a team of trainers satisfying the standards for specialised knowledge and skills corresponding to the knowledge and skills standards specified in Article 24 and satisfying the requirements in Article 27 of this Decree;

d) Having curricula, materials and teaching contents appropriate to the training programme framework and standards for specialised cybersecurity knowledge and skills.

2. An institution organising intensive training in specialised cybersecurity knowledge and skills shall be responsible for:

a) Organising training in accordance with the training programme framework and knowledge and skills standards; assessing results and issuing certificates as prescribed;

b) Retaining dossiers and documents related to training courses for at least 05 years; and sending reports on training results to the Ministry of Public Security within 25 working days from the date of completion of the course;

c) Fully updating information on the institution, trainees and trainers on the management system as prescribed;

d) Implementing periodic or ad hoc reporting regimes as required by the state management agency for cybersecurity.

3. Training institutions wishing to receive guidance and support from the Ministry of Public Security on training programmes, contents and methods may register to participate in the Network of Institutions for Intensive Training in Specialised Cybersecurity Knowledge and Skills managed by the Ministry of Public Security.

4. Training institutions under the management of the Ministry of National Defence shall submit reports in accordance with regulations of the Ministry of National Defence.

Article 26. Network of Institutions for Intensive Training in Specialised Cybersecurity Knowledge and Skills

1. The Ministry of Public Security shall establish and manage the Network of Institutions for Intensive Training in Specialised Cybersecurity Knowledge and Skills for the following purposes:

a) Supporting and guiding institutions in developing training programmes, curricula and training materials;

b) Sharing experience, materials and tools serving training;

c) Organising refresher training and capacity building for trainers;

d) Monitoring and assessing the quality of training activities;

dd) Strengthening connections and coordination among training institutions.

2. An institution wishing to participate in the Network shall register with the Ministry of Public Security; the registration dossier comprises:

a) An application for participation in the Network, made according to Form No. 03 in the Appendix promulgated together with this Decree;

b) Documents proving its lawful establishment and operation;

c) Information on physical facilities, trainers, curricula and teaching materials and contents proving its capacity to organise training.

3. The Ministry of Public Security shall review the dossier and approve the institution’s participation in the Network within 15 working days from the date of receipt of a complete and valid dossier; approval for participation in the Network is not a mandatory condition for an institution to organise training.

4. An institution participating in the Network shall have the following rights:

a) Accessing materials, tools and platforms supporting training provided by the Ministry of Public Security;

b) Participating in refresher training and capacity-building activities organised by the Ministry of Public Security;

c) Receiving professional and technical support and guidance;

d) Other rights in accordance with law.

5. An institution participating in the Network shall be responsible for:

a) Organising training in accordance with the training programme framework and knowledge and skills standards promulgated by the Ministry of Public Security;

b) Periodically reporting the results of training activities;

c) Participating in common activities of the Network;

d) Complying with inspection and monitoring by the Ministry of Public Security.

6. An institution shall be suspended from or have its participation in the Network terminated in the following cases:

a) Serious violation of regulations on organisation of training;

b) Issuance of certificates not in accordance with regulations;

c) Failure to fully perform the responsibilities of a Network member;

d) Submission of a written request for withdrawal from the Network.

Article 27. Requirements for trainers participating in intensive training in specialised cybersecurity knowledge and skills

1. Trainers participating in teaching and intensive training in specialised cybersecurity knowledge and skills must possess a university degree or higher qualification in cybersecurity, information technology, electronics and telecommunications, or another relevant specialisation appropriate to the teaching contents.

2. Trainers participating in intensive training in specialised cybersecurity knowledge and skills must satisfy one of the following conditions:

a) Having at least 03 years of practical experience in the field of cybersecurity;

b) Possessing a professional or technical certificate in cybersecurity appropriate to the field of teaching.

3. Trainers participating in intensive training in specialised cybersecurity knowledge and skills must possess pedagogical competence, knowledge communication skills and practical instruction skills satisfying the requirements of training activities.

Article 28. Conditions for issuance of certificates of intensive training in specialised cybersecurity knowledge and skills

1. An individual shall be issued a training certificate when fully satisfying the following conditions:

a) Attending at least 80% of the duration of the training course;

b) Fully completing exercises and practical exercises during the training;

c) Satisfying the requirements of the end-of-course test and assessment as prescribed.

2. A certificate of intensive training in specialised cybersecurity knowledge and skills:

a) Shall be signed and stamped by the head of the institution organising the training;

b) Shall clearly state the full name of the certificate holder; the knowledge and skills components completed; the training duration; and the date of issuance.

3. The institution organising the training shall be responsible for sending information on issued certificates to the Ministry of Public Security for updating and management as prescribed. For institutions organising training under the management of the Ministry of National Defence and the Government Cipher Committee, the sending of information and management of certificates shall comply with regulations of the Ministry of National Defence and the Government Cipher Committee.

4. State agencies, organisations and enterprises shall be responsible for periodically reviewing, organising and assigning officers to participate in updating and refresher training of knowledge in order to ensure satisfaction of the requirements of their job positions as specified in Clauses 1 and 2, Article 34 of the Law on Cybersecurity.

Article 29. Responsibilities of the Ministry of Public Security in management of cybersecurity training activities

1. Promulgating the training programme framework and standards for specialised cybersecurity knowledge and skills for uniform application nationwide.

2. Developing, maintaining, updating and managing the database on training institutions, trainees and cybersecurity trainers.

3. Providing detailed guidance on training programmes and contents; standards and procedures for assessment of learning results; training certificate forms; procedures for registration for participation in the Network; and standards for physical facilities and equipment serving training.

4. Organising support, refresher training and capacity-building activities for training institutions and trainers.

5. Conducting inspection and monitoring and handling violations in activities of intensive training in specialised cybersecurity knowledge and skills in accordance with law.

 

Chapter VI

IMPLEMENTATION PROVISIONS

 

Article 30. Effect

This Decree takes effect on August 19, 2026.

Article 31. Transitional provisions

Dossiers of request for cybersecurity appraisal and dossiers of request for assessment of cybersecurity conditions that have been validly received by competent agencies in accordance with Decree No. 53/2022/ND-CP before the effective date of this Decree but for which no settlement results have been issued shall continue to be settled in accordance with Decree No. 53/2022/ND-CP.

Article 32. Responsibility for implementation

Ministers, heads of ministerial-level agencies, chairpersons of People’s Committees of provinces and centrally run cities, and related agencies, organisations and individuals shall be responsible for implementing this Decree.

On behalf of the Government
For the Prime Minister
The Deputy Prime Minister

PHAM GIA TUC

* All Appendices are not translated herein.

This feature is available to English or Advanced account holders. Please log in to a subscriber account to see the full text. Don’t have an account? Register here
Please log in to a subscriber account to see the full text. Don’t have an account? Register here
Processing, please wait...

You are not logged in.

This feature is available to Advanced account holders. Please log in to access detailed information on Related documents.

If you do not have an account, please register here!

Processing, please wait...
LuatVietnam.vn is the SOLE distributor of English translations of Official Gazette published by the Vietnam News Agency

VIETNAMESE DOCUMENTS

download
Decree 333/2026/NĐ-CP PDF (Original)

This utility is available to subscribers only. Please log in to a subscriber account to download. Don’t have an account? Register here

download
Decree 333/2026/NĐ-CP (Word)

This utility is available to subscribers only. Please log in to a subscriber account to download. Don’t have an account? Register here

Appendix 1 (Word)

This utility is available to subscribers only. Please log in to a subscriber account to download. Don’t have an account? Register here

Appendix 2 (Word)

This utility is available to subscribers only. Please log in to a subscriber account to download. Don’t have an account? Register here

Appendix 3 (Word)

This utility is available to subscribers only. Please log in to a subscriber account to download. Don’t have an account? Register here

ENGLISH DOCUMENTS

LuatVietnam's translation
download
Decree 333/2026/NĐ-CP (PDF)

This utility is available to subscribers only. Please log in to a subscriber account to download. Don’t have an account? Register here

download
Decree 333/2026/NĐ-CP (Word)

This utility is available to subscribers only. Please log in to a subscriber account to download. Don’t have an account? Register here

* Note: To view documents downloaded from LuatVietnam.vn, please install DOC, DOCX and PDF file readers
For further support, please call 19006192

SAME CATEGORY

loading