Vietnam Cybersecurity Law Now in Effect: Compliance Guide
- 20 hours ago
- 4 min read
Vietnam's new Law on Cybersecurity No. 116/2025/QH15 entered into force on 1 July 2026, establishing a single national framework for cybersecurity and network information security. The National Assembly passed the Law on 10 December 2025, and it was signed by National Assembly Chairman Trần Thanh Mẫn. The instrument consolidates and replaces two earlier laws, the Law on Cybersecurity No. 24/2018/QH14 (2018) and the Law on Network Information Security No. 86/2015/QH13 (2015) both of which ceased to have effect on the same date.
The lead authority for the new regime is the Ministry of Public Security (MPS), which now oversees information system classification, incident response, content takedown cooperation, and the licensing of cybersecurity products and services.
What the Vietnam Cybersecurity Law Changes
The Law is a consolidation and expansion instrument rather than a wholly new departure. It carries forward the core principles, prohibited acts framework, and five tier information system classification from the 2015 and 2018 laws, while adding industry responsive obligations that reflect newer digital economy risks. Key elements include:
Extraterritorial scope. The Law applies to both Vietnamese and foreign agencies, organizations, and individuals. For foreign entities, it reaches those present in Vietnam or otherwise involved in cybersecurity protection activities or the business of cybersecurity products and services in Vietnam.
Five-tier information-system classification (Levels 1–5). Classification is based on the potential harm to national security and social order if an incident occurs. A refined category of "information system critical for national security" is determined by a list decided by the Prime Minister, with criteria to be detailed by the Government.
Expanded prohibited acts. The list now expressly addresses online fraud and asset misappropriation, impersonation and digital identity offenses, and misuse of artificial intelligence or new technologies (including deepfake video, voice, and images).
Content and data response timelines. Covered service providers must block or remove violating information within 24 hours of an MPS request (6 hours in urgent national security cases), and must provide user information within 24 hours (3 hours in urgent cases).
Data localization and local presence. The Law retains the 2018 data localization requirement for covered service providers operating in Vietnam and the requirement for certain foreign enterprises to establish a branch or representative office in Vietnam.
Child and vulnerable group protection. Platform operators must control, prevent, and promptly remove harmful or rights infringing content involving children, and cooperate with MPS forces.
Cybersecurity standards, products, and services. A dedicated chapter governs cybersecurity technical regulations and the products and services regime, including a licensing requirement discussed below.

Cybersecurity products and services: the licensing hook
This is the provision with the most direct relevance to product and certification teams. The Law defines two regulated categories:
Cybersecurity products including civil cryptography products, cybersecurity testing and assessment tools, monitoring solutions, products designed to prevent cyberattacks and unauthorized intrusions, and other cybersecurity products.
Cybersecurity services including cybersecurity testing and assessment, civil and non civil cryptography information security services, security consultancy, monitoring, incident response, data recovery, and cyberattack prevention services.
Enterprises engaged in the business of cybersecurity products and services in Vietnam must hold a Business Licence for Cybersecurity Products and Services. Detailed procedures and eligibility conditions are to be issued through Government implementing guidance.
What This Means for Manufacturers
For most companies pursuing type approval or equipment authorization for radio, EMC, or general ICT devices in Vietnam, this Law is not a type approval change. Radio frequency and telecom equipment approval, conformity marking, and import certification continue to run through Vietnam's separate technical regulation (QCVN) regime administered by the national telecommunications authority a track that is legally distinct from this cybersecurity instrument. Manufacturers of ordinary consumer or industrial wireless devices should not expect a new device authorization obligation to arise from Law No. 116/2025/QH15 itself.
The Law does, however, create real obligations for specific business profiles:
Cybersecurity product and cryptography vendors. If your product is a civil cryptography product, a monitoring or intrusion prevention solution, or a security testing/assessment tool sold into Vietnam, you fall within the products and services regime and will need the Business Licence for Cybersecurity Products and Services once implementing rules are in force.
Covered service providers. Telecommunications, internet, and value added service providers face data localization, local presence, user verification, log retention, and rapid content/data response duties.
Owners and operators of information systems (Level 3 and above, or critical to national security). These parties must designate qualified cybersecurity personnel, connect monitoring and malware prevention systems to MPS designated centres, and report incidents promptly.
The practical takeaway: scope your product and your legal role before assuming the Law does or does not apply. A device that is "just hardware" for RF purposes may still fall inside the cybersecurity product perimeter if it performs cryptographic or security monitoring functions.
Certification Impact Summary
Area | Impact under Law No. 116/2025/QH15 | Who is affected |
RF / EMC / telecom device type approval | No direct change; separate QCVN regime continues to apply | Radio and telecom device manufacturers, importers, test labs |
Cybersecurity products (civil cryptography, monitoring, intrusion prevention, testing tools) | New Business Licence for Cybersecurity Products and Services required to trade in Vietnam | Security product and cryptography vendors |
Cybersecurity services (assessment, incident response, consultancy, monitoring) | Business Licence required; conditions set by implementing guidance | Service providers operating in Vietnam |
Data localization and local presence | Retained from 2018 law; branch/representative office required for certain foreign providers | Covered telecom / internet / value added service providers |
Information system classification duties | Level 3+ and national security critical systems face staffing, monitoring connectivity, and reporting duties | Owners and operators of in-scope systems |
Standards and technical regulations | Consolidated chapter; product standards intended to remove cybersecurity risk from the design stage | Product developers within the cybersecurity perimeter |
Timeline and Required Actions
Date | Milestone | Action for certification and market access teams |
10 Dec 2025 | Law No. 116/2025/QH15 passed by the National Assembly | Confirm which of your product lines and legal roles fall within the cybersecurity product/service perimeter |
1 Jul 2026 | Law in force; 2018 Cybersecurity Law and 2015 Network Information Security Law repealed | Treat obligations as live; do not rely on the repealed instruments |
In force now | Business Licence requirement for cybersecurity products and services | Determine licence applicability; prepare for application once procedures are published |
Pending | Government implementing decrees/circulars (classification criteria, licence procedures, data-retention durations, penalties) | Monitor for issuance; map obligations to each SKU and entity |
Ongoing | Data localization, local presence, and rapid response duties for covered service providers | Verify Vietnam data storage posture and local entity status; document 24h/3h/6h response readiness |
