Vietnam Civil Cryptography Licence Requirements and Applications

Updated: 23 September 2026

Civil cryptography is commonly abbreviated as MMDS in Vietnamese commercial and import dossiers. An encryption function alone does not settle the licensing question. From 1 September 2026, assess Decree No. 341/2026/ND-CP, its annexed lists and the actual functions of the product or service.

Scope of the business licence

Article 3 defines civil cryptography products and services; Article 4 requires a licence for business activities on the Annex I list. Read both the description and intended use. Cryptography protecting state secrets must not be conflated with civil cryptography.

A useful preparation step is to record cryptographic functions, intended use, customers, delivery method and technical documents. This supports classification but does not replace the legal dossier. A manufacturer's description of a network device, security software or cloud service does not determine classification by itself.

Conditions businesses must meet

Article 5 addresses management and technical personnel, facilities and technical plans. Requirements include at least two technical staff with university degrees or higher in electronics and telecommunications, IT, mathematics or information security; and one manager or executive with a university degree in those fields, or another degree plus training certification in security or information security.

The technical plan must match the proposed products and services. Qualifications alone, without a description of relevant control, delivery and protection processes, do not fully demonstrate operational capability.

Where to apply and which forms to use

Under Article 5, applications go to the Government Cipher Committee. The dossier includes Form No. 01 in Annex III, staffing evidence, a technical plan using Form No. 03 and other prescribed documents. Submission may be in person, by post or through the National Public Service Portal, with digital signature requirements for electronic dossiers.

The process allows one working day for validity checking and three working days for requested supplementation. The licence issuance period is 12 days from receipt of a complete valid dossier as prescribed. Preserve the distinction: 12 days must not be changed to 12 working days.

Products that also have cybersecurity functions

Article 4(5) provides for the Ministry of Public Security to issue cybersecurity product and service business licences for dual-use products with civil cryptography and cybersecurity functions. Before issuance, the Ministry obtains the Government Cipher Committee's written opinion on cryptographic functions. Classification therefore precedes selection of the receiving authority.

Do not assume that every product with both functions needs two independent licences. Equally, do not assume an existing licence covers every new product. Check the scope and coordination mechanism for the specific case.

Does a licence replace conformity certification

Article 4 sets a 10-year licence term and relevant conformity certification requirements before products are marketed, within the applicable scope. Business licences, export and import licences, and conformity certificates serve different purposes. Articles 6–8 address changes, additions and licence handling; Article 12 sets ongoing business responsibilities.

Licences issued before 1 July 2026 are assessed under the transitional provisions in Article 18 of Decree No. 341 and Article 45 of the Cybersecurity Law. Track expiry and scope rather than assume an earlier licence is invalid because a new decree exists.

Data encryption and cryptography licensing answer different questions

Article 12 of Decree No. 356 requires cloud personal data safeguards, including encryption in storage and transit. Decree No. 341 regulates civil cryptography products and services within its scope. A requirement to use safeguards does not turn every user into a cryptography business; a business licence does not prove that each customer's data protection configuration is adequate.

For a cloud project, clarify who supplies encryption, manages keys and can decrypt data. This informs contracts and risk assessments. If products are imported, assess Annex II and import documentation rather than stop at the business licence.

Frequently asked questions

Does internal encryption software use require a business licence? Distinguish use from the business of supplying products and services. Business obligations should not be applied merely because an organisation is a user.

Does a civil cryptography business licence permit importing every encryption device? No. Check the lists and procedures in Articles 9–10 and applicable quality duties separately.

Legal sources

Decree No. 341/2026/ND-CP on civil cryptography

Cybersecurity Law No. 116/2025/QH15

Decree No. 356/2025/ND-CP implementing personal data protection requirements

Sources checked through 23 September 2026.

Related articles

Article 13 Vietnam Cybersecurity Licences and the 2026 Transition from ATTTM

Article 15 Importing Civil Cryptography Products into Vietnam and Checking HS Codes

Article 19 Vietnam Cloud Service Notification and Data Protection Responsibilities

Similar Blog Posts

Vietnam Personal Data Protection Templates and How to Use Them

Request reference templates for Vietnam personal data protection and understand their scope and the review…

Vietnam and EU Data Protection and AI Laws Compared by Obligation

Compare Vietnam and EU data protection and AI duties, including DPIAs, 72-hour breach rules, territorial…

Vietnam Cloud Service Notification and Data Protection Responsibilities

Explore Vietnam cloud notification rules for domestic and overseas providers and the data protection responsibilities…

Vietnam Data Centre Services Registration and Licensing

Distinguish Vietnam data centre registration from telecommunications licensing, with provincial authority and processing changes under…
Designed by W.O.A.