top of page

Vietnam Cybersecurity Law Now in Effect: Compliance Guide

  • 20 hours ago
  • 4 min read

Vietnam's new Law on Cybersecurity No. 116/2025/QH15 entered into force on 1 July 2026, establishing a single national framework for cybersecurity and network information security. The National Assembly passed the Law on 10 December 2025, and it was signed by National Assembly Chairman Trần Thanh Mẫn. The instrument consolidates and replaces two earlier laws, the Law on Cybersecurity No. 24/2018/QH14 (2018) and the Law on Network Information Security No. 86/2015/QH13 (2015) both of which ceased to have effect on the same date.

The lead authority for the new regime is the Ministry of Public Security (MPS), which now oversees information system classification, incident response, content takedown cooperation, and the licensing of cybersecurity products and services.


What the Vietnam Cybersecurity Law Changes


The Law is a consolidation and expansion instrument rather than a wholly new departure. It carries forward the core principles, prohibited acts framework, and five tier information system classification from the 2015 and 2018 laws, while adding industry responsive obligations that reflect newer digital economy risks. Key elements include:


  • Extraterritorial scope. The Law applies to both Vietnamese and foreign agencies, organizations, and individuals. For foreign entities, it reaches those present in Vietnam or otherwise involved in cybersecurity protection activities or the business of cybersecurity products and services in Vietnam.

  • Five-tier information-system classification (Levels 1–5). Classification is based on the potential harm to national security and social order if an incident occurs. A refined category of "information system critical for national security" is determined by a list decided by the Prime Minister, with criteria to be detailed by the Government.

  • Expanded prohibited acts. The list now expressly addresses online fraud and asset misappropriation, impersonation and digital identity offenses, and misuse of artificial intelligence or new technologies (including deepfake video, voice, and images).

  • Content and data response timelines. Covered service providers must block or remove violating information within 24 hours of an MPS request (6 hours in urgent national security cases), and must provide user information within 24 hours (3 hours in urgent cases).

  • Data localization and local presence. The Law retains the 2018 data localization requirement for covered service providers operating in Vietnam and the requirement for certain foreign enterprises to establish a branch or representative office in Vietnam.

  • Child and vulnerable group protection. Platform operators must control, prevent, and promptly remove harmful or rights infringing content involving children, and cooperate with MPS forces.

  • Cybersecurity standards, products, and services. A dedicated chapter governs cybersecurity technical regulations and the products and services regime, including a licensing requirement discussed below.


An infographic breaking down Vietnam's Law No. 116/2025/QH15, which consolidates prior cybersecurity laws into a single framework taking effect on 1 July 2026. The chart outlines key provisions such as extraterritorial scope, a 5-tier system classification, strict content removal timelines, and data localization rules. It highlights the new Business Licence requirement from the Ministry of Public Security for cryptography and security vendors while noting that standard RF and telecom device approvals remain unchanged under the separate QCVN regime.

Cybersecurity products and services: the licensing hook


This is the provision with the most direct relevance to product and certification teams. The Law defines two regulated categories:


  • Cybersecurity products including civil cryptography products, cybersecurity testing and assessment tools, monitoring solutions, products designed to prevent cyberattacks and unauthorized intrusions, and other cybersecurity products.

  • Cybersecurity services including cybersecurity testing and assessment, civil and non civil cryptography information security services, security consultancy, monitoring, incident response, data recovery, and cyberattack prevention services.


Enterprises engaged in the business of cybersecurity products and services in Vietnam must hold a Business Licence for Cybersecurity Products and Services. Detailed procedures and eligibility conditions are to be issued through Government implementing guidance.


What This Means for Manufacturers


For most companies pursuing type approval or equipment authorization for radio, EMC, or general ICT devices in Vietnam, this Law is not a type approval change. Radio frequency and telecom equipment approval, conformity marking, and import certification continue to run through Vietnam's separate technical regulation (QCVN) regime administered by the national telecommunications authority a track that is legally distinct from this cybersecurity instrument. Manufacturers of ordinary consumer or industrial wireless devices should not expect a new device authorization obligation to arise from Law No. 116/2025/QH15 itself.

The Law does, however, create real obligations for specific business profiles:


  • Cybersecurity product and cryptography vendors. If your product is a civil cryptography product, a monitoring or intrusion prevention solution, or a security testing/assessment tool sold into Vietnam, you fall within the products and services regime and will need the Business Licence for Cybersecurity Products and Services once implementing rules are in force.

  • Covered service providers. Telecommunications, internet, and value added service providers face data localization, local presence, user verification, log retention, and rapid content/data response duties.

  • Owners and operators of information systems (Level 3 and above, or critical to national security). These parties must designate qualified cybersecurity personnel, connect monitoring and malware prevention systems to MPS designated centres, and report incidents promptly.


The practical takeaway: scope your product and your legal role before assuming the Law does or does not apply. A device that is "just hardware" for RF purposes may still fall inside the cybersecurity product perimeter if it performs cryptographic or security monitoring functions.


Certification Impact Summary


Area

Impact under Law No. 116/2025/QH15

Who is affected

RF / EMC / telecom device type approval

No direct change; separate QCVN regime continues to apply

Radio and telecom device manufacturers, importers, test labs

Cybersecurity products (civil cryptography, monitoring, intrusion prevention, testing tools)

New Business Licence for Cybersecurity Products and Services required to trade in Vietnam

Security product and cryptography vendors

Cybersecurity services (assessment, incident response, consultancy, monitoring)

Business Licence required; conditions set by implementing guidance

Service providers operating in Vietnam

Data localization and local presence

Retained from 2018 law; branch/representative office required for certain foreign providers

Covered telecom / internet / value added service providers

Information system classification duties

Level 3+ and national security critical systems face staffing, monitoring connectivity, and reporting duties

Owners and operators of in-scope systems

Standards and technical regulations

Consolidated chapter; product standards intended to remove cybersecurity risk from the design stage

Product developers within the cybersecurity perimeter


Timeline and Required Actions


Date

Milestone

Action for certification and market access teams

10 Dec 2025

Law No. 116/2025/QH15 passed by the National Assembly

Confirm which of your product lines and legal roles fall within the cybersecurity product/service perimeter

1 Jul 2026

Law in force; 2018 Cybersecurity Law and 2015 Network Information Security Law repealed

Treat obligations as live; do not rely on the repealed instruments

In force now

Business Licence requirement for cybersecurity products and services

Determine licence applicability; prepare for application once procedures are published

Pending

Government implementing decrees/circulars (classification criteria, licence procedures, data-retention durations, penalties)

Monitor for issuance; map obligations to each SKU and entity

Ongoing

Data localization, local presence, and rapid response duties for covered service providers

Verify Vietnam data storage posture and local entity status; document 24h/3h/6h response readiness


bottom of page