{"id":2556,"date":"2026-09-23T23:55:38","date_gmt":"2026-09-23T16:55:38","guid":{"rendered":"https:\/\/kmunion.vn\/en\/?p=2556"},"modified":"2026-09-23T23:55:38","modified_gmt":"2026-09-23T16:55:38","slug":"vietnam-cybersecurity-law-2026-business-changes","status":"publish","type":"post","link":"https:\/\/kmunion.vn\/en\/vietnam-cybersecurity-law-2026-business-changes.html","title":{"rendered":"Vietnam Cybersecurity Law Changes for Businesses in 2026"},"content":{"rendered":"<p class=\"km-updated\">Updated: 23 September 2026<\/p>\n<p>Vietnam&#x27;s central cybersecurity legal framework changed on 1 July 2026. Under Article 44, Cybersecurity Law No. 116\/2025\/QH15 replaces the Law on Cyberinformation Security No. 86\/2015\/QH13 and Cybersecurity Law No. 24\/2018\/QH14. Businesses reviewing policies, contracts and licences must read both the new rules and transitional provisions.<\/p>\n<h2>Obligations to reassess<\/h2>\n<p>The Law addresses cybersecurity for information systems, information and data protection, cybersecurity products and services, and parties&#x27; responsibilities. Article 8 establishes five information system security levels; Article 9 concerns information systems critical to national security. These are related concepts but are not interchangeable.<\/p>\n<p>Articles 25\u201326 address information and data protection; Articles 28\u201329 regulate cybersecurity products and the business of supplying products and services. Ordinary businesses should focus on their systems and data activities. Security service providers must additionally check business conditions, licence scope and specific products.<\/p>\n<h2>Who is responsible for the system<\/h2>\n<p>Article 40 establishes system owners&#x27; responsibilities; Article 41 concerns service providers within scope; and Article 42 addresses users. Assigning an operator does not remove the owner&#x27;s role. Outsourcing contracts should clearly set out tasks, incident cooperation and evidence of compliance.<\/p>\n<p>An organisation outsourcing all infrastructure and operations must still identify who decides the system&#x27;s objectives, scope and protection requirements. A provider&#x27;s certification or monitoring centre does not replace the system&#x27;s security level decision or cybersecurity plan.<\/p>\n<h2>Must existing security level approvals be redone immediately<\/h2>\n<p>Article 45 provides transitional rules for systems with established levels. Existing decisions may continue under the Law&#x27;s conditions, while protective measures must be adjusted within 12 months of its effective date. This does not mean every system must resubmit a dossier on 1 July 2026.<\/p>\n<p>Decree No. 331\/2026\/ND-CP, effective from 19 August 2026, details levels, authority and plans. Article 39 contains specific rules for certain systems under investment or construction before 1 July 2026. Transitional planning should distinguish operating systems, systems under construction and new systems.<\/p>\n<h2>Can existing cyberinformation security and civil cryptography licences still be used<\/h2>\n<p>Article 45 allows licences for cyberinformation security products and services and civil cryptography issued before the Law took effect to remain usable until their stated expiry, subject to the rules. It is therefore incorrect to claim all earlier licences became invalid on 1 July 2026.<\/p>\n<p>New applications, scope changes and renewals require assessment under Decree No. 332\/2026\/ND-CP or Decree No. 341\/2026\/ND-CP as appropriate. An unexpired licence does not automatically cover new activities outside its authorised scope.<\/p>\n<h2>Regulators and business preparation<\/h2>\n<p>Article 39 allocates state management responsibilities, with the Ministry of Public Security holding the general role and the Ministry of National Defence and Government Cipher Committee acting within assigned remits. Authority for a specific procedure may rest with the system owner, a dedicated unit or another body under the Law and decrees.<\/p>\n<p>Start with an inventory of systems, existing level decisions, protection plans, current licences and provider contracts. Compare each against the new rules to identify immediate changes, transitional treatment and who must complete the work.<\/p>\n<h2>Where cybersecurity meets personal data protection<\/h2>\n<p>A well-controlled database may still be used for an improper purpose, while processing with a valid basis may lack system safeguards. The Cybersecurity Law and Personal Data Protection Law address related aspects without replacing each other. IT teams must work with those deciding data purposes within the same project.<\/p>\n<p>Decree No. 333\/2026\/ND-CP further implements the Cybersecurity Law; Decree No. 330\/2026\/ND-CP sets penalties for cybersecurity and personal data protection violations. Both took effect on 19 August 2026. First identify the obligated party and applicable conditions, then consider the corresponding sanction; do not infer a universal requirement from a penalty amount.<\/p>\n<p>Online service providers should next examine provider responsibilities and cooperation mechanisms. Businesses outsourcing services for internal operations will usually start with system scope, security level and the allocation of responsibilities with the operator.<\/p>\n<h2>Frequently asked questions<\/h2>\n<p><strong>Can contracts still use the older term cyberinformation security, or ATTTM? Read it in context and against transitional rules. Describe current procedures using the new legislation&#x27;s terminology, explaining older names where needed.<\/strong><\/p>\n<p><strong>Does every business need a cybersecurity licence? No. Licensing arises from regulated business activities and differs from the duty to protect systems a business uses.<\/strong><\/p>\n<h2>Legal sources<\/h2>\n<p><a href=\"https:\/\/vanban.chinhphu.vn\/?docid=216499&amp;pageid=27160\">Cybersecurity Law No. 116\/2025\/QH15<\/a><\/p>\n<p><a href=\"https:\/\/congbao.chinhphu.vn\/van-ban\/nghi-dinh-so-331-2026-nd-cp-470334.htm\">Decree No. 331\/2026\/ND-CP on cybersecurity assurance by security level<\/a><\/p>\n<p><a href=\"https:\/\/congbao.chinhphu.vn\/van-ban\/nghi-dinh-so-332-2026-nd-cp-470329.htm\">Decree No. 332\/2026\/ND-CP on cybersecurity products and services businesses<\/a><\/p>\n<p><a href=\"https:\/\/congbao.chinhphu.vn\/van-ban\/nghi-dinh-so-341-2026-nd-cp-470382.htm\">Decree No. 341\/2026\/ND-CP on civil cryptography<\/a><\/p>\n<p><a href=\"https:\/\/vanban.chinhphu.vn\/?docid=214590&amp;pageid=27160\">Personal Data Protection Law No. 91\/2025\/QH15<\/a><\/p>\n<p><a href=\"https:\/\/congbao.chinhphu.vn\/van-ban\/nghi-dinh-so-333-2026-nd-cp-470335.htm\">Decree No. 333\/2026\/ND-CP implementing the Cybersecurity Law<\/a><\/p>\n<p><a href=\"https:\/\/vanban.chinhphu.vn\/?docid=219266&amp;pageid=27160\">Decree No. 330\/2026\/ND-CP on penalties for cybersecurity and personal data protection violations<\/a><\/p>\n<p><em>Sources checked through 23 September 2026.<\/em><\/p>\n<h2>Related articles<\/h2>\n<p><a href=\"https:\/\/kmunion.vn\/en\/vietnam-personal-data-protection-business-responsibilities.html\">Article 02  Vietnam Personal Data Protection Law and Business Responsibilities in 2026<\/a><\/p>\n<p><a href=\"https:\/\/kmunion.vn\/en\/vietnam-data-breach-72-hour-notification.html\">Article 06  Personal Data Breaches and Vietnam 72 Hour Notification Rules<\/a><\/p>\n<p><a href=\"https:\/\/kmunion.vn\/en\/vietnam-information-system-security-levels.html\">Article 11  How Vietnam Classifies Information Systems from Security Level 1 to 5<\/a><\/p>\n<p><a href=\"https:\/\/kmunion.vn\/en\/vietnam-system-security-level-dossier-approval.html\">Article 12  Vietnam Information System Security Level Dossiers and Approval Authorities<\/a><\/p>\n<p><a href=\"https:\/\/kmunion.vn\/en\/vietnam-cybersecurity-licence-atttm-2026.html\">Article 13  Vietnam Cybersecurity Licences and the 2026 Transition from ATTTM<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Understand Vietnam&#8217;s 2026 Cybersecurity Law, replacement of earlier laws, transitional licences and information system owner responsibilities.<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":[],"categories":[78],"tags":[],"_links":{"self":[{"href":"https:\/\/kmunion.vn\/en\/wp-json\/wp\/v2\/posts\/2556"}],"collection":[{"href":"https:\/\/kmunion.vn\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/kmunion.vn\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/kmunion.vn\/en\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/kmunion.vn\/en\/wp-json\/wp\/v2\/comments?post=2556"}],"version-history":[{"count":1,"href":"https:\/\/kmunion.vn\/en\/wp-json\/wp\/v2\/posts\/2556\/revisions"}],"predecessor-version":[{"id":2589,"href":"https:\/\/kmunion.vn\/en\/wp-json\/wp\/v2\/posts\/2556\/revisions\/2589"}],"wp:attachment":[{"href":"https:\/\/kmunion.vn\/en\/wp-json\/wp\/v2\/media?parent=2556"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/kmunion.vn\/en\/wp-json\/wp\/v2\/categories?post=2556"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/kmunion.vn\/en\/wp-json\/wp\/v2\/tags?post=2556"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}