Updated: 23 September 2026
A proposed security level dossier requires more than an application letter. It must explain system scope, classification grounds and the cybersecurity plan. Articles 18–23 of Decree No. 331/2026/ND-CP govern contents, procedure and authority.
Distinguishing the system owner from the operator
Articles 4–5 of Decree No. 331 distinguish the system owner from the operating unit. The owner organises implementation of requirements within its responsibility; the operator prepares, implements and cooperates as assigned. Outsourcing decisions and contracts must clearly identify these roles.
An agency or business hiring an infrastructure operator does not thereby make the provider the security level approving authority. Providers can assist with surveys, documentation and technical measures, but the decision must be issued by the proper authorised party.
Main components of the dossier
Article 21 specifies the system overview, design documents, evidence supporting the proposed level, cybersecurity plan and expert opinions required for Levels 4 and 5. Article 22 details the contents.
The overview must match the system scope, and design diagrams must reflect relevant zones, connections and components. The level justification must cite the correct criteria rather than simply say the system is important and therefore Level 3. The protection plan should cover management and technical measures linked to risks and level requirements.
Who appraises and approves Levels 1 to 3
Under Article 18, the owner's dedicated cybersecurity unit appraises and approves Levels 1 and 2 and reports to the owner. For Level 3, the dedicated unit appraises and the system owner approves.
If the dedicated unit also operates the system, Article 18(4) requires arrangements to ensure proper appraisal, such as assigning another capable unit or forming an independent appraisal council. Do not simply have one team prepare and validate its own dossier while overlooking these organisational requirements.
Authority for Levels 4 and 5
The Ministry of Public Security conducts appraisal under Article 18, subject to specified exceptions within the Ministry of National Defence's and Government Cipher Committee's remits. The owner approves Level 4. For Level 5, distinguish the Prime Minister's approval of the list of systems critical to national security from the owner's approval of the cybersecurity plan.
This distinction helps avoid misdirected filings or calling every result a security level certificate. Dossiers and decisions should use the correct names, authorities and legal grounds.
New systems and operating systems
Article 19 integrates level classification and cybersecurity into investment, upgrades and service procurement; Article 20 addresses operating systems. Article 37 encourages level approval before investment plan approval. Preserve its advisory nature rather than turn it into a universal mandatory deadline.
For systems predating transitional milestones, check Article 45 of the Cybersecurity Law and Article 39 of Decree No. 331. Approval does not end responsibility: the plan must be implemented and updated when scope, risks or architecture change as prescribed.
Information that can support several dossiers
System inventories, connection diagrams, data locations, providers and access rights can support both level dossiers and personal data impact assessments. Each document must nevertheless answer its own procedure's questions, identify the correct responsible party and go to the correct recipient. Shared survey information does not make one decision a substitute for another.
When using cloud services, include connections, remote administration and protection assignments within the appropriate assessment scope. If a plan relies on provider support, the contract must reflect that work. A diagram showing isolated systems while operations use a shared administrator account requires correction in both documents and configuration.
After approval, establish who checks that measures have been implemented. The cloud responsibility and incident response articles help convert an approved plan into operational work.
Frequently asked questions
Must all security level dossiers go to the Ministry of Public Security? No. Authority differs by level and system owner.
Is it appropriate to buy all equipment before preparing the dossier? Follow the procedure applicable to the project. Identifying requirements early helps avoid designs that cannot meet the plan.
Does hiring a consultant replace implementation? No. Documentation and operating measures must be consistent; owners and operators must still discharge their duties.
Legal sources
Cybersecurity Law No. 116/2025/QH15
Decree No. 331/2026/ND-CP on cybersecurity assurance by security level
Personal Data Protection Law No. 91/2025/QH15
Decree No. 356/2025/ND-CP implementing personal data protection requirements
Sources checked through 23 September 2026.
Related articles
Article 04 Vietnam Personal Data Processing Impact Assessment Requirements
Article 06 Personal Data Breaches and Vietnam 72 Hour Notification Rules
Article 11 How Vietnam Classifies Information Systems from Security Level 1 to 5
Article 19 Vietnam Cloud Service Notification and Data Protection Responsibilities
