Updated: 23 September 2026
Vietnam's central cybersecurity legal framework changed on 1 July 2026. Under Article 44, Cybersecurity Law No. 116/2025/QH15 replaces the Law on Cyberinformation Security No. 86/2015/QH13 and Cybersecurity Law No. 24/2018/QH14. Businesses reviewing policies, contracts and licences must read both the new rules and transitional provisions.
Obligations to reassess
The Law addresses cybersecurity for information systems, information and data protection, cybersecurity products and services, and parties' responsibilities. Article 8 establishes five information system security levels; Article 9 concerns information systems critical to national security. These are related concepts but are not interchangeable.
Articles 25–26 address information and data protection; Articles 28–29 regulate cybersecurity products and the business of supplying products and services. Ordinary businesses should focus on their systems and data activities. Security service providers must additionally check business conditions, licence scope and specific products.
Who is responsible for the system
Article 40 establishes system owners' responsibilities; Article 41 concerns service providers within scope; and Article 42 addresses users. Assigning an operator does not remove the owner's role. Outsourcing contracts should clearly set out tasks, incident cooperation and evidence of compliance.
An organisation outsourcing all infrastructure and operations must still identify who decides the system's objectives, scope and protection requirements. A provider's certification or monitoring centre does not replace the system's security level decision or cybersecurity plan.
Must existing security level approvals be redone immediately
Article 45 provides transitional rules for systems with established levels. Existing decisions may continue under the Law's conditions, while protective measures must be adjusted within 12 months of its effective date. This does not mean every system must resubmit a dossier on 1 July 2026.
Decree No. 331/2026/ND-CP, effective from 19 August 2026, details levels, authority and plans. Article 39 contains specific rules for certain systems under investment or construction before 1 July 2026. Transitional planning should distinguish operating systems, systems under construction and new systems.
Can existing cyberinformation security and civil cryptography licences still be used
Article 45 allows licences for cyberinformation security products and services and civil cryptography issued before the Law took effect to remain usable until their stated expiry, subject to the rules. It is therefore incorrect to claim all earlier licences became invalid on 1 July 2026.
New applications, scope changes and renewals require assessment under Decree No. 332/2026/ND-CP or Decree No. 341/2026/ND-CP as appropriate. An unexpired licence does not automatically cover new activities outside its authorised scope.
Regulators and business preparation
Article 39 allocates state management responsibilities, with the Ministry of Public Security holding the general role and the Ministry of National Defence and Government Cipher Committee acting within assigned remits. Authority for a specific procedure may rest with the system owner, a dedicated unit or another body under the Law and decrees.
Start with an inventory of systems, existing level decisions, protection plans, current licences and provider contracts. Compare each against the new rules to identify immediate changes, transitional treatment and who must complete the work.
Where cybersecurity meets personal data protection
A well-controlled database may still be used for an improper purpose, while processing with a valid basis may lack system safeguards. The Cybersecurity Law and Personal Data Protection Law address related aspects without replacing each other. IT teams must work with those deciding data purposes within the same project.
Decree No. 333/2026/ND-CP further implements the Cybersecurity Law; Decree No. 330/2026/ND-CP sets penalties for cybersecurity and personal data protection violations. Both took effect on 19 August 2026. First identify the obligated party and applicable conditions, then consider the corresponding sanction; do not infer a universal requirement from a penalty amount.
Online service providers should next examine provider responsibilities and cooperation mechanisms. Businesses outsourcing services for internal operations will usually start with system scope, security level and the allocation of responsibilities with the operator.
Frequently asked questions
Can contracts still use the older term cyberinformation security, or ATTTM? Read it in context and against transitional rules. Describe current procedures using the new legislation's terminology, explaining older names where needed.
Does every business need a cybersecurity licence? No. Licensing arises from regulated business activities and differs from the duty to protect systems a business uses.
Legal sources
Cybersecurity Law No. 116/2025/QH15
Decree No. 331/2026/ND-CP on cybersecurity assurance by security level
Decree No. 332/2026/ND-CP on cybersecurity products and services businesses
Decree No. 341/2026/ND-CP on civil cryptography
Personal Data Protection Law No. 91/2025/QH15
Decree No. 333/2026/ND-CP implementing the Cybersecurity Law
Decree No. 330/2026/ND-CP on penalties for cybersecurity and personal data protection violations
Sources checked through 23 September 2026.
Related articles
Article 02 Vietnam Personal Data Protection Law and Business Responsibilities in 2026
Article 06 Personal Data Breaches and Vietnam 72 Hour Notification Rules
Article 11 How Vietnam Classifies Information Systems from Security Level 1 to 5
Article 12 Vietnam Information System Security Level Dossiers and Approval Authorities
Article 13 Vietnam Cybersecurity Licences and the 2026 Transition from ATTTM
