How Vietnam Classifies Information Systems from Security Level 1 to 5

Updated: 23 September 2026

Information security by level remains a familiar expression in many dossiers. Under the current framework, consult Cybersecurity Law No. 116/2025/QH15 and Decree No. 331/2026/ND-CP on cybersecurity assurance for information systems by level. The level follows legal criteria and impact, not a label chosen by a provider.

What the five levels represent

Article 8 of the Cybersecurity Law and Articles 8–15 of Decree No. 331 establish Levels 1 to 5. Levels increase according to nature, scope, impact and specific criteria. They are neither product quality ratings nor counts of security devices to purchase.

Before classification, define system scope under Article 7, type under Article 9 and risk under Article 10. A system may include multiple components, connected services and shared data. Arbitrarily splitting it to obtain a lower level can distort the assessment.

How Levels 1 and 2 differ

Article 11 sets Level 1 criteria for internal systems processing only public information and meeting the corresponding impact conditions. Not every internal system is Level 1.

Article 12 sets Level 2 criteria, including internal systems handling private or personal information but not state secrets, and other categories subject to specific conditions. For certain online service systems, thresholds are below 100,000 subjects for basic personal data or below 10,000 subjects for sensitive personal data. Read these thresholds with the system type and other criteria; a single number cannot decide every case.

When to consider Level 3

Article 13 lists systems including online services in conditional business sectors, administrative procedures, information infrastructure within specified scopes and systems meeting corresponding data thresholds. For the online services identified there, at least 100,000 basic-data subjects or 10,000 sensitive-data subjects are relevant thresholds.

For example, a platform collecting many people's sensitive data cannot rely only on monthly logged-in accounts. Determine the correct number of subjects and data scope under the rules, alongside the service type. Where several criteria apply, the proposal must reflect the higher applicable criterion under the Decree's principles.

Are Levels 4 and 5 only for large systems

Articles 14–15 impose stricter criteria concerning scope, continuity and effects on protected interests. Large server capacity or revenue does not automatically establish Level 4 or 5. Conversely, a system with few users but a particularly important function must still be assessed against the proper criteria.

The concept of an information system critical to national security under Article 9 of the Law must also be distinguished from a company's informal description of an important system. Authority, lists and duties for this category are separately regulated.

Information needed for classification

Inputs should include system objectives, services, users served, data categories, subject numbers, connection diagrams, continuity needs and impacts of disruption or compromise. These support the proposed level and corresponding protection plan.

System levels differ from data and AI classifications

Sensitive personal data is a data classification; Levels 1–5 classify systems; and high, medium and low risk are classifications under the Artificial Intelligence Law. There is no automatic conversion between them. A system may have to meet several requirements after each scope has been assessed properly.

For example, an AI-enabled platform processing health data needs assessment of data type, system level criteria and AI purpose. The 100,000-subject threshold for exemptions from certain personal data obligations must not replace the classification thresholds in Decree No. 331; the mechanisms have different subjects and application rules.

Only after classification should the plan and approving party be identified. Advanced measures such as continuous monitoring centres or dedicated key management technology should reflect applicable requirements and risks, rather than be presented as a uniform mandatory toolkit for every system.

Frequently asked questions

Does every business website need the same dossier? No. First check Article 2 of Decree No. 331 and the system's actual characteristics.

Does ISO certification replace security level approval? No. Certification has its own scope and purpose; classification, appraisal and approval must follow applicable law.

Can a consultant issue Level 3 certification? Not merely by being a consultant. Article 18 of Decree No. 331 allocates appraisal and approval authority.

Legal sources

Cybersecurity Law No. 116/2025/QH15

Decree No. 331/2026/ND-CP on cybersecurity assurance by security level

Personal Data Protection Law No. 91/2025/QH15

Decree No. 356/2025/ND-CP implementing personal data protection requirements

Artificial Intelligence Law No. 134/2025/QH15

Sources checked through 23 September 2026.

Related articles

Article 07 Vietnam Data Law and the Classification of Core and Important Data

Article 12 Vietnam Information System Security Level Dossiers and Approval Authorities

Article 16 Vietnam AI Law and System Risk Classification in 2026

Article 18 Vietnam Data Centre Services Registration and Licensing

Similar Blog Posts

Vietnam Personal Data Protection Templates and How to Use Them

Request reference templates for Vietnam personal data protection and understand their scope and the review…

Vietnam and EU Data Protection and AI Laws Compared by Obligation

Compare Vietnam and EU data protection and AI duties, including DPIAs, 72-hour breach rules, territorial…

Vietnam Cloud Service Notification and Data Protection Responsibilities

Explore Vietnam cloud notification rules for domestic and overseas providers and the data protection responsibilities…

Vietnam Data Centre Services Registration and Licensing

Distinguish Vietnam data centre registration from telecommunications licensing, with provincial authority and processing changes under…
Designed by W.O.A.