Vietnam Cybersecurity Law Changes for Businesses in 2026

Updated: 23 September 2026

Vietnam's central cybersecurity legal framework changed on 1 July 2026. Under Article 44, Cybersecurity Law No. 116/2025/QH15 replaces the Law on Cyberinformation Security No. 86/2015/QH13 and Cybersecurity Law No. 24/2018/QH14. Businesses reviewing policies, contracts and licences must read both the new rules and transitional provisions.

Obligations to reassess

The Law addresses cybersecurity for information systems, information and data protection, cybersecurity products and services, and parties' responsibilities. Article 8 establishes five information system security levels; Article 9 concerns information systems critical to national security. These are related concepts but are not interchangeable.

Articles 25–26 address information and data protection; Articles 28–29 regulate cybersecurity products and the business of supplying products and services. Ordinary businesses should focus on their systems and data activities. Security service providers must additionally check business conditions, licence scope and specific products.

Who is responsible for the system

Article 40 establishes system owners' responsibilities; Article 41 concerns service providers within scope; and Article 42 addresses users. Assigning an operator does not remove the owner's role. Outsourcing contracts should clearly set out tasks, incident cooperation and evidence of compliance.

An organisation outsourcing all infrastructure and operations must still identify who decides the system's objectives, scope and protection requirements. A provider's certification or monitoring centre does not replace the system's security level decision or cybersecurity plan.

Must existing security level approvals be redone immediately

Article 45 provides transitional rules for systems with established levels. Existing decisions may continue under the Law's conditions, while protective measures must be adjusted within 12 months of its effective date. This does not mean every system must resubmit a dossier on 1 July 2026.

Decree No. 331/2026/ND-CP, effective from 19 August 2026, details levels, authority and plans. Article 39 contains specific rules for certain systems under investment or construction before 1 July 2026. Transitional planning should distinguish operating systems, systems under construction and new systems.

Can existing cyberinformation security and civil cryptography licences still be used

Article 45 allows licences for cyberinformation security products and services and civil cryptography issued before the Law took effect to remain usable until their stated expiry, subject to the rules. It is therefore incorrect to claim all earlier licences became invalid on 1 July 2026.

New applications, scope changes and renewals require assessment under Decree No. 332/2026/ND-CP or Decree No. 341/2026/ND-CP as appropriate. An unexpired licence does not automatically cover new activities outside its authorised scope.

Regulators and business preparation

Article 39 allocates state management responsibilities, with the Ministry of Public Security holding the general role and the Ministry of National Defence and Government Cipher Committee acting within assigned remits. Authority for a specific procedure may rest with the system owner, a dedicated unit or another body under the Law and decrees.

Start with an inventory of systems, existing level decisions, protection plans, current licences and provider contracts. Compare each against the new rules to identify immediate changes, transitional treatment and who must complete the work.

Where cybersecurity meets personal data protection

A well-controlled database may still be used for an improper purpose, while processing with a valid basis may lack system safeguards. The Cybersecurity Law and Personal Data Protection Law address related aspects without replacing each other. IT teams must work with those deciding data purposes within the same project.

Decree No. 333/2026/ND-CP further implements the Cybersecurity Law; Decree No. 330/2026/ND-CP sets penalties for cybersecurity and personal data protection violations. Both took effect on 19 August 2026. First identify the obligated party and applicable conditions, then consider the corresponding sanction; do not infer a universal requirement from a penalty amount.

Online service providers should next examine provider responsibilities and cooperation mechanisms. Businesses outsourcing services for internal operations will usually start with system scope, security level and the allocation of responsibilities with the operator.

Frequently asked questions

Can contracts still use the older term cyberinformation security, or ATTTM? Read it in context and against transitional rules. Describe current procedures using the new legislation's terminology, explaining older names where needed.

Does every business need a cybersecurity licence? No. Licensing arises from regulated business activities and differs from the duty to protect systems a business uses.

Legal sources

Cybersecurity Law No. 116/2025/QH15

Decree No. 331/2026/ND-CP on cybersecurity assurance by security level

Decree No. 332/2026/ND-CP on cybersecurity products and services businesses

Decree No. 341/2026/ND-CP on civil cryptography

Personal Data Protection Law No. 91/2025/QH15

Decree No. 333/2026/ND-CP implementing the Cybersecurity Law

Decree No. 330/2026/ND-CP on penalties for cybersecurity and personal data protection violations

Sources checked through 23 September 2026.

Related articles

Article 02 Vietnam Personal Data Protection Law and Business Responsibilities in 2026

Article 06 Personal Data Breaches and Vietnam 72 Hour Notification Rules

Article 11 How Vietnam Classifies Information Systems from Security Level 1 to 5

Article 12 Vietnam Information System Security Level Dossiers and Approval Authorities

Article 13 Vietnam Cybersecurity Licences and the 2026 Transition from ATTTM

Similar Blog Posts

Vietnam Personal Data Protection Templates and How to Use Them

Request reference templates for Vietnam personal data protection and understand their scope and the review…

Vietnam and EU Data Protection and AI Laws Compared by Obligation

Compare Vietnam and EU data protection and AI duties, including DPIAs, 72-hour breach rules, territorial…

Vietnam Cloud Service Notification and Data Protection Responsibilities

Explore Vietnam cloud notification rules for domestic and overseas providers and the data protection responsibilities…

Vietnam Data Centre Services Registration and Licensing

Distinguish Vietnam data centre registration from telecommunications licensing, with provincial authority and processing changes under…
Designed by W.O.A.