Based on the provided content, this is a section stipulating conditions and procedures related to the use of foreign certificates in Vietnam under the Decree. Specifically, it includes eligible users, scope of operation, validity period of permits, permit issuance conditions, permit application documents, permit review and issuance, changes and reissuance of permits, as well as obligations of organizations and individuals when using foreign certificates.
Đối tượng áp dụng
Vietnamese organizations and individuals who need to conduct electronic transactions with foreign partners where domestic certificates are not recognized in that country, and foreign organizations and individuals present in Vietnam.
Các điểm cốt lõi
- Conditions for using foreign certificates
- Scope of operation and validity period of permits for using foreign certificates in Vietnam
- Documents required for issuing permits to use foreign certificates in Vietnam
- Reviewing documents and issuing permits for using foreign certificates in Vietnam
- Changes and reissuance of permits for using foreign certificates in Vietnam
- Obligations of organizations and individuals using foreign certificates issued permits in Vietnam
🌐 Tác động xã hội từ văn bản này
- Enhancing international cooperation in the field of electronic transactions.
- Developing and expanding markets for digital signature certification services.
- Improving the business environment and attracting foreign investment.
❓ Câu hỏi thường gặp
Who can use foreign certificates in Vietnam?
Vietnamese organizations and individuals who need to conduct electronic transactions with foreign partners where domestic certificates are not recognized in that country, and foreign organizations and individuals present in Vietnam.
What is the validity period of permits for using foreign certificates in Vietnam?
The validity period of permits for using foreign certificates in Vietnam is five years but does not exceed the validity period of the certificate.
Toàn văn
|
| SOCIALIST REPUBLIC OF VIET NAM
|
DECREE
Regulations detailing the implementation of the Electronic Transactions Law on digital signatures and digital signature certification services
Decree No. 130/2018/NĐ-CP dated September 27, 2018, of the Government details the implementation of the Electronic Transactions Law on digital signatures and digital signature certification services, which took effect from November 15, 2018, and was amended and supplemented by:
Decree No. 48/2024/NĐ-CP dated May 9, 2024, of the Government amends and supplements certain provisions of Decree No. 130/2018/NĐ-CP dated September 27, 2018, of the Government detailing the implementation of the Electronic Transactions Law on digital signatures and digital signature certification services, which took effect from May 9, 2024.
Pursuant to the Law on Government Organization dated June 19, 2015;
Pursuant to the Electronic Transactions Law dated November 29, 2005;
Pursuant to the Law on Information Technology dated June 29, 2006;
Pursuant to the Law on Fees and Charges dated November 25, 2015;
At the proposal of the Minister of Information and Communications;
The Government promulgates this Decree detailing the implementation of the Electronic Transactions Law on digital signatures and digital signature certification services.[1]
Chapter I. GENERAL PROVISIONS
Article 1. Scope of Regulation
This Decree specifies detailed regulations on digital signatures and digital certificates; management, provision, and use of digital signatures, digital certificates, and digital signature certification services.
Article 2. Applicability
This Decree applies to agencies, organizations managing and providing digital signature certification services; agencies, organizations, and individuals using digital signatures, digital certificates, and digital signature certification services in electronic transactions.
Article 3. Explanation of Terms
In this Decree, the following terms are understood as follows:
1. "Key" is a binary number sequence (0 and 1) used in cryptographic systems.
2. "Asymmetric cryptographic system" is a cryptographic system capable of generating a key pair consisting of a private key and a public key.
3. "Private key" is a key in the key pair of an asymmetric cryptographic system, used to create digital signatures.
4. "Public key" is a key in the key pair of an asymmetric cryptographic system, used to verify digital signatures created by the corresponding private key in the key pair.
5. "Signing" is the process of inserting a private key into a software program to automatically generate and attach a digital signature to a data message.
6. "Digital signature" is an electronic signature generated by transforming a data message using an asymmetric cryptographic system, whereby those who obtain the original data message and the public key of the signer can accurately determine:
a) That the transformation mentioned above was created using the correct private key corresponding to the public key in the same key pair;
b) The integrity of the content of the data message since the transformation was performed.
7. "Digital certificate" is an electronic certificate issued by an organization providing digital signature certification services to provide identification information for the public key of an agency, organization, or individual, thereby confirming that the agency, organization, or individual is the signer of the digital signature by using the corresponding private key.
8. "Valid digital certificate" is a digital certificate that has not expired, is not suspended, or revoked.
9. "Public digital certificate" is a digital certificate issued by an organization providing public digital signature certification services.
10. "Foreign digital certificate" is a digital certificate issued by an organization providing foreign digital signature certification services.
11. "Subscriber" is an agency, organization, or individual granted a digital certificate, accepts the digital certificate, and retains the corresponding private key recorded on the issued digital certificate.
12. "Signer" is a subscriber who uses their own private key to sign a data message under their name.
13. "Recipient" is an organization or individual receiving a signed data message from the signer, using the signer's digital certificate to verify the digital signature in the received message.
14. "Application using digital signatures" refers to information technology applications that allow integration and use of digital signatures for authentication.
15. "Organization providing digital signature certification services" is an organization providing digital signature certification services that implements activities related to the provision of digital signature certification services.
16. "Organization providing public digital signature certification services" is an organization providing digital signature certification services for agencies, organizations, and individuals using such services in public activities. The provision of public digital signature certification services by organizations providing public digital signature certification services is a conditional business activity according to the law.
17. "Organization providing specialized digital signature certification services" is an organization providing digital signature certification services for agencies, organizations, and individuals using such services in specific professional or field activities with similar nature of work or purpose and linked together through operational charters or legal regulations defining common organizational structures or forms of collaboration and joint operations. The operation of an organization providing specialized digital signature certification services does not aim at profit-making. An organization providing specialized digital signature certification services includes:
a) Government specialized digital signature certification service provider supplying digital signature certification services to Party and State agencies;
b) Specialized digital signature certification service provider of agencies and organizations. The provision of specialized digital signature certification services by agencies and organizations must be registered with the competent state management agency for digital signature certification services according to the law.
18. "Agent for public digital signature certification services" is a trader assisting an organization providing public digital signature certification services in delivering digital signature certification services to subscribers under an agency agreement to earn remuneration.
19. "Certification rules" are the rules of organizations providing digital signature certification services regarding procedures and formalities for issuing, managing digital certificates, and using subscribers' digital certificates, as well as the relationship between the organization providing digital signature certification services and its agents and subscribers.
20. "Service fee for maintaining the status verification system of digital certificates" is the amount that service providers of digital signature authentication must pay when the national digital signature authentication service provider organization (as stipulated in Chapter VI of this Decree) maintains an online database of digital certificates and other information to serve the verification of the status of digital certificates and the validity of digital signatures of digital signature authentication service providers.
21. "Secret key storage device" is a physical device containing the digital certificate and secret key of the subscriber.
Article 4. Digital Signature Authentication Service
Digital signature authentication service is a type of electronic signature authentication service provided by a digital signature authentication service provider to subscribers to verify that the subscriber is the person who signed the data message digitally. The digital signature authentication service includes:
1. Creating a key pair or assisting in creating a key pair including the public key and the private key for the subscriber.
2. Issuing, extending, suspending, restoring, and revoking the digital certificate of the subscriber.
3. Maintaining an online database of digital certificates.
4. Providing necessary information to assist in verifying the digital signature of the subscriber on the data message.
Chapter II. DIGITAL SIGNATURES AND DIGITAL CERTIFICATES
Article 5. Contents of Digital Certificates
Digital certificates issued by the national digital signature authentication service provider organization, public digital signature authentication service provider organizations, government-specific digital signature authentication service provider organizations, and agency-specific digital signature authentication service provider organizations must include the following contents:
1. Name of the digital signature authentication service provider organization.
2. Name of the subscriber.
3. Certificate number.
4. Validity period of the digital certificate.
5. Public key of the subscriber.
6. Digital signature of the digital signature authentication service provider organization.
7. Restrictions on purpose and scope of use of the digital certificate.
8. Legal liability limitations of the digital signature authentication service provider organization.
9. Cryptographic algorithm.
10. Other necessary contents as prescribed by the Ministry of Information and Communications.
Article 6. Digital Certificates of Agencies, Organizations, and Authorized Persons of Agencies and Organizations
1. All agencies, organizations, state positions, and authorized persons of agencies and organizations as prescribed by laws on seal management and use have the right to be issued digital certificates with the value as stipulated in Clause 2 of Article 8 of this Decree..
2. Digital certificates issued to state positions and authorized persons of agencies and organizations must clearly state the position and name of the agency or organization of such person.
3. The issuance of digital certificates to agencies, organizations, state positions, and authorized persons of agencies and organizations must be based on the following documents:
a) A document from the agency or organization requesting the issuance of a digital certificate for the agency, organization, authorized person, or state position;
b) A valid copy of the decision establishing the agency or organization, the decision defining functions, tasks, powers, or a document confirming the position of the authorized person of the agency or organization or the state position.
Article 7. Use of Digital Signatures and Digital Certificates of Agencies, Organizations, and Authorized Persons of Agencies and Organizations
1. The digital signature of the entity issued a digital certificate as stipulated at Article 6 of this Decree shall only be used to conduct transactions within the authority of agencies, organizations, and positions that have been issued digital certificates.
2. The act of signing on behalf of another person or signing under delegation as prescribed by law shall be carried out by a person with the authority to use their own digital signature, understood based on the position of the signer recorded on the digital certificate.
Article 8. Legal value of digital signatures
1. In cases where the law stipulates that a document must bear a signature, the requirement for a data message to be considered met if such a data message is signed with a digital signature and the digital signature is secured in accordance with the provisions of Article 9 of this Decree.
2. In cases where the law stipulates that a document must bear the stamp of an agency or organization, the requirement for a data message to be considered met if such a data message is signed with a digital signature of the agency or organization and the digital signature is secured in accordance with the provisions of Article 9 of this Decree.
3. Foreign digital signatures and digital certificates granted permission for use in Vietnam in accordance with Chapter V of this Decree shall have the same legal value and effect as digital signatures and digital certificates issued by Vietnamese organizations providing public key infrastructure certification services.
Article 9. Conditions for ensuring security for digital signatures
A digital signature shall be deemed a secure electronic signature when it meets the following conditions:
1. The digital signature is created during the period when the digital certificate is valid and can be verified using the public key recorded on the digital certificate.
2. The digital signature is created using the private key corresponding to the public key recorded on the digital certificate issued by one of the following organizations:
a) An organization providing national public key infrastructure certification services;
b) An organization providing government-specific public key infrastructure certification services;
c) An organization providing public key infrastructure certification services;
d) An organization providing specific public key infrastructure certification services for agencies and organizations certified with a certificate of qualification to ensure security for specific digital signatures as provided for in Article 40 of this Decree.
3. The private key must be under the control of the signer at the time of signing.
Article 10. Provisions on the format of digital certificates
When issuing digital certificates, organizations providing public key infrastructure certification services and organizations providing specific public key infrastructure certification services for agencies and organizations certified with a certificate of qualification to ensure security for specific digital signatures must comply with the format regulations for digital certificates according to the certification rules of the organization providing national public key infrastructure certification services.
Chapter III. PUBLIC KEY INFRASTRUCTURE CERTIFICATION SERVICES
Section 1. LICENSE TO PROVIDE PUBLIC KEY INFRASTRUCTURE CERTIFICATION SERVICES
Article 11. Operating Conditions
An organization providing public key infrastructure certification services may provide services when meeting the following conditions:
1. Having a license to provide public key infrastructure certification services issued by the Ministry of Information and Communications.
2. Possessing a digital certificate issued by the organization providing national public key infrastructure certification services.
Article 12. Term of License
The license granted to an organization providing public key infrastructure certification services has a term of 10 years.
Article 13. Licensing Conditions
1. Subject Conditions:
Being a business established in accordance with Vietnamese law.
2. Financial conditions:
a) Depositing a guarantee fund of not less than five billion (5,000,000,000) Vietnamese dong at a commercial bank operating in Vietnam to address risks and compensation that may arise during the provision of services due to errors of the organization providing public key infrastructure certification services and to cover costs for receiving and maintaining the database of the enterprise in case the license is revoked;
b) Paying service fees for maintaining the system to check the status of digital certificates fully (in the case of reissuing the license).
3. Personnel conditions:
a) The enterprise must have personnel responsible for: System management, system operation, issuance of digital certificates, and ensuring the security of information in the system;
b) Personnel specified in point a of this clause must hold a bachelor's degree or higher in information security, information technology, or electronics and telecommunications.
4. Technical conditions:
a) Establishing technical equipment systems to meet the following requirements:
- Fully, accurately, and timely storing information about subscribers to serve the issuance of digital certificates throughout the validity period of the digital certificate;
- Fully, accurately, and timely storing lists of active, suspended, and expired digital certificates and allowing and guiding Internet users to access online 24 hours a day, seven days a week;
- Ensuring the creation of key pairs that are randomly generated and unique; having a feature to ensure that the private key cannot be detected when the corresponding public key is available;
- Having features to warn, prevent, and detect unauthorized network access;
- Designed to minimize direct contact with the Internet environment as much as possible;
- The key distribution system for subscribers must ensure the integrity and confidentiality of the key pair. If the key is distributed through a computer network, the key distribution system must use secure protocols to ensure that information is not exposed during transmission.
b) Having technical solutions to meet the requirements for ensuring the security of information systems and technical standards and mandatory standards applicable to digital signatures and certification services currently in force;
c) Having control measures for entering and exiting the headquarters, accessing the system, and entering and exiting locations where equipment for providing certification services is located;
d) Having backup plans to ensure continuous safe operation and to address incidents;
đ) Having plans to provide online subscriber information to the organization providing national public key infrastructure certification services, serving state management of certification services;
e) All equipment systems used to provide services must be located in Vietnam;
g) Having headquarters and equipment locations that comply with legal requirements for fire prevention and explosion protection; capable of resisting floods, earthquakes, electromagnetic interference, and illegal human intrusion;
h) Having a certification regulation according to the model prescribed in the certification regulation of the organization providing national public key infrastructure certification services.
Article 14. Application Documents
1. An application for a public digital signature authentication service license according to Form No. 01 the Appendix issued together with this Decree.
2. A bank guarantee certificate from a commercial bank operating in Vietnam. This certificate must include, but not be limited to, an unconditional and irrevocable commitment to pay any amount within the guarantee limit to the beneficiary to address risks and potential compensation during the provision of services due to errors of the public digital signature authentication service provider, and to cover costs for receiving and maintaining the enterprise's database in case the license is revoked.
3. Human resources file including: Curriculum vitae, diplomas, certificates of the technical staff involved in providing digital signature authentication services by the enterprise in compliance with Clause 3, Article 13 of this Decree..
4. Technical plan to ensure compliance with Clause 4, Article 13 of this Decree..
5. Authentication regulations according to the model prescribed in the Authentication Regulations of the National Digital Signature Authentication Organization.
Article 15. Reviewing Application Documents and Issuing License
Within 50 days from the date of receipt of valid application documents, the Ministry of Information and Communications shall take the lead and coordinate with the Ministry of Public Security, the Government Cryptographic Office, and relevant ministries and sectors to review the application documents and issue a license to enterprises that meet all licensing conditions stipulated in Article 13 of this Decree.The template for the public digital signature authentication service license is prescribed according to Form number 05 the Appendix issued together with this Decree.
In case of refusal, the Ministry of Information and Communications shall notify in writing and specify the reasons.
Article 16. Amending License Content and Reissuing License
1. Amending license content shall be carried out when the enterprise changes one of the following information: legal representative, headquarters address, trading name.
The enterprise submits an application for amending the license content to the Ministry of Information and Communications. The application for amending the license content includes: An application for amending the license content according to Form No. 02 the Appendix issued together with this Decree, a detailed report describing the proposed changes, and related documents.
Within 15 working days from the date of receipt of complete and valid application documents, the Ministry of Information and Communications shall review and reissue the license with amended contents to the enterprise; if refused, it must notify in writing and specify the reasons.
The validity period of the amended license is the remaining period of the previously issued license.
2. In case the license is lost or damaged, the enterprise sends an application for reissuing the license according to Implementation Report of Production Projects of Supporting Industry Products Confirmed with Incentives the Appendix issued together with this Decree, specifying the reason to the Ministry of Information and Communications. Within 7 working days from the date of receipt of the application, the Ministry of Information and Communications shall consider and reissue the license to the enterprise.
The validity period of the reissued license due to loss or damage is the remaining period of the previously issued license.
3. To ensure the continuity of service provision, enterprises wishing to continue providing services must submit an application for reissuing the license at least 90 days before the expiration date of the current license. The application for reissuing the license due to expiration includes:
a) An application for reissuing the public digital signature authentication service license of the enterprise due to the expiration of the old license according to Implementation Report of Production Projects of Supporting Industry Products Confirmed with Incentives the Appendix issued together with this Decree;
b) A bank guarantee certificate from a commercial bank operating in Vietnam according to Clause 2, Article 14 of this Decree;
c) Information on personnel and technical changes of the enterprise related to licensing conditions as stipulated in Clauses 3 and 4, Article 13 of this Decree. (if applicable).
Within 30 days from the date of receipt of valid application documents, the Ministry of Information and Communications shall take the lead and coordinate with the Ministry of Public Security, the Government Cryptographic Office, and relevant ministries and sectors to review the application documents and inspect whether the enterprise meets the licensing conditions in reality. If the enterprise meets all licensing conditions, the Ministry of Information and Communications shall reissue the license to the enterprise. In case of refusal, the Ministry of Information and Communications shall notify in writing and specify the reasons.
The validity period of the reissued license due to expiration is 10 years.
Article 17. Suspension of license, cessation of issuance of digital certificates
1. A public key infrastructure service provider shall have its license suspended for no more than six months if it falls under any of the following circumstances:
a) Providing services contrary to the content stated on the license;
b) Failing to meet any of the licensing conditions stipulated in this Law during the provision of services; Article 13 of this Decree. c) Failing to pay the full service fee for maintaining the status checking system of digital certificates for six months.
2. A public key infrastructure service provider must cease issuing new digital certificates to subscribers if it falls under any of the following circumstances:
a) Its license for providing public key infrastructure services has been suspended according to Clause 1 of this Article;
b) When discovering errors in its service system that may affect the interests of subscribers and recipients.
3. During the period of license suspension, if a public key infrastructure service provider remedies the cause of suspension, the Ministry of Information and Communications will allow the public key infrastructure service provider to continue providing services.
Article 18. Revocation of License
1. A public key infrastructure service provider shall have its license revoked if it occurs any of the following circumstances:
a) Failing to commence service provision within twelve months from the date of issuance without legitimate reasons;
b) Being dissolved or declared bankrupt in accordance with relevant laws;
c) The license for providing public key infrastructure services has expired;
d) Failing to pay the full service fee for maintaining the status checking system of digital certificates for twelve months;
đ) Failing to remedy the conditions for suspension stipulated in Clause 1 of Article 17 after the suspension period set by the competent authority;
e) The enterprise does not wish to continue providing services. 2. A public key infrastructure service provider whose license is revoked shall be responsible for negotiating and transferring all related databases and files concerning service provision activities and ensuring the continued use of services by subscribers to another active public key infrastructure service provider within thirty days from the date of receipt of the notice of license revocation. 3. The Ministry of Information and Communications shall supervise and guide the transfer between public key infrastructure service providers to ensure uninterrupted service use by subscribers.
In case of failure to reach an agreement with other organizations regarding the transfer of related databases and files concerning service provision activities and ensuring the continued use of services by subscribers, the Ministry of Information and Communications shall designate one or several public key infrastructure service providers to carry out this task. The receiving organization shall assume the rights and obligations towards subscribers and recipients according to the contract signed between the subscriber and the organization whose license was revoked.
4. Costs for receiving, maintaining related databases and files, and ensuring the continued use of services by subscribers shall be taken from the deposit at the bank of the public key infrastructure service provider whose license was revoked.
5. After three years from the date of license revocation except for the revocation specified in point c of Clause 1 of this Article, a public key infrastructure service provider shall have the right to request reissuance of the license. Conditions and procedures for reissuance shall be carried out in accordance with the provisions applicable to new issuance.
In the event that an agreement cannot be reached with other organizations regarding the transfer of databases and files related to service provision activities and ensuring the use of services by subscribers, the Ministry of Information and Communications shall designate one or more public digital signature certification service providers to carry out this task. The receiving organization shall assume the rights and obligations towards subscribers and recipients under the contracts signed between the subscribers and the revoked license provider.
4. The costs for receiving, maintaining databases and files related, and ensuring the use of services by subscribers shall be taken from the deposit account at the bank of the digital signature certification service provider whose license has been revoked.
5. After a period of three years from the date of license revocation, except for the revocation specified in point c, Clause 1, Article of this Law, the public digital signature certification service provider may request the issuance of a new license. The conditions and procedures for reissuance shall be carried out according to the provisions applicable to new issuances.
Article 19. Term of Digital Certificate Issued to Organizations Providing Public Key Infrastructure (PKI) Certification Services
The digital certificate issued to organizations providing public key infrastructure (PKI) certification services shall have a term of five years.
Article 20. Conditions for Issuing Digital Certificates to Organizations Providing Public Key Infrastructure (PKI) Certification Services
1. Possess a valid public key infrastructure (PKI) certification service provision license issued by the Ministry of Information and Communications.
2. The actual technical system must comply with the licensing application file.
3. The public key on the digital certificate will be unique and paired with the private key of the organization applying for the digital certificate.
Article 21. Application Documents for Issuing Digital Certificates to Organizations Providing Public Key Infrastructure (PKI) Certification Services
The application documents for issuing digital certificates to organizations providing public key infrastructure (PKI) certification services include:
1. A request form for the organization providing national PKI certification services to issue a digital certificate. Form number 04 the Appendix issued together with this Decree.
2. A copy of the public key infrastructure (PKI) certification service provision license.
3. Other documents as stipulated in the certification regulation of the organization providing national PKI certification services.
Article 22. Examination and Issuance of Digital Certificates to Organizations Providing Public Key Infrastructure (PKI) Certification Services
Within thirty working days from the date of receipt of a valid application for a digital certificate, the organization providing national PKI certification services shall examine the application:
1. The organization providing national PKI certification services shall conduct the following examinations:
a) Inspect the actual technical system of the organization providing public key infrastructure (PKI) certification services to ensure that it complies with the licensing application file.
b) Witness the creation of the private key and public key pair of the organization providing public key infrastructure (PKI) certification services to ensure that the key pair is created safely according to regulations.
2. In cases where the conditions for issuing a digital certificate are met, the organization providing national PKI certification services shall issue the digital certificate. If the conditions are not fully met, the organization providing national PKI certification services shall issue a refusal letter for the issuance of the digital certificate and specify the reasons.
3. The issuance of digital certificates by the organization providing national PKI certification services to organizations providing public key infrastructure (PKI) certification services must ensure the continuity of the services provided by these organizations to subscribers.
Section 2. ACTIVITIES OF ORGANIZATIONS PROVIDING PUBLIC KEY INFRASTRUCTURE (PKI) CERTIFICATION SERVICES
Article 23. Application Documents for Issuing Digital Certificates to Subscribers[2]
1. An application form for a digital certificate in paper or electronic format according to the model of the organization providing public key infrastructure (PKI) certification services.
2. Supporting documents and materials include:
a) For individuals: Citizen identification card or identity card or citizen identification certificate or passport or level 2 electronic identity account.
b) For organizations: Decision on establishment or decision on functions, tasks, powers, organizational structure or business registration certificate or investment certificate and citizen identification card or identity card or citizen identification certificate or passport of the legal representative of the organization; or using the electronic identity account of the organization.
3. Individuals and organizations have the right to choose to submit copies from original books, certified copies, or submit copies accompanied by original documents for verification, or provide electronic data for the organization providing public key infrastructure (PKI) certification services to use and exploit as stipulated in Clause 4 of this Article.
4. In cases where individuals or legal representatives of organizations provide information in the citizen identification card or identity card or citizen identification certificate or level 2 electronic identity account information of individuals or organization's electronic identity account information, the organization providing public key infrastructure (PKI) certification services (which has been approved to connect with the electronic identification and authentication system according to the law on electronic identification and authentication or has sufficient means to read electronic chip data, level 2 electronic identity account data) shall exploit data in the electronic chip, level 2 electronic identity account data of individuals, organization's electronic identity account without requiring individuals or legal representatives of organizations to submit documents and materials as stipulated in Clause 3 of this Article.
5. Organizations providing public key infrastructure (PKI) certification services shall be responsible for providing utilities or applications to implement electronic reception methods.
Article 24. Creation and Distribution of Keys for Subscribers
1. Organizations and individuals requesting issuance of digital certificates may create their own key pairs or request in writing that public service providers of digital signature authentication create key pairs for them.
2. In cases where organizations and individuals requesting issuance of digital certificates create their own key pairs, public service providers of digital signature authentication must ensure that such organizations and individuals have used equipment in accordance with prescribed standards to generate and store the key pairs.
3. In cases where public service providers of digital signature authentication create key pairs, such organizations must ensure the use of secure methods to transfer secret keys to organizations and individuals requesting issuance of digital certificates and may only retain copies of secret keys upon written request from such organizations and individuals.
Article 25. Issuance of Digital Certificates for Subscribers
1. Public service providers of digital signature authentication issue digital certificates to subscribers after verifying the following contents:
a) The information in the application file for digital certificate issuance by the subscriber is accurate;
b) The public key on the digital certificate to be issued will be unique and paired with the secret key of the organization or individual requesting issuance of the digital certificate.
2. Digital certificates shall only be issued to the applicant and must contain all the information prescribed in Article 5 of this Decree.
3. Public service providers of digital signature authentication may only publish the issued digital certificates of subscribers in their database of digital certificates after receiving confirmation from the subscriber regarding the accuracy of the information on the digital certificate; the publication period shall not exceed 24 hours after receipt of the subscriber's confirmation; except in cases of agreement otherwise.
4. Public service providers of digital signature authentication shall not refuse to issue digital certificates to organizations and individuals requesting issuance of digital certificates without justifiable reasons.
5. Public service providers of digital signature authentication must ensure security throughout the process of creating and transferring digital certificates to subscribers.
Article 26. Extension of Digital Certificates for Subscribers
1. At least 30 days before the expiration date of the digital certificate, the subscriber has the right to request an extension of the digital certificate.
2. Upon receiving a request for extension from the subscriber, the public service provider of digital signature authentication has the obligation to complete the extension procedures before the certificate expires.
3. In cases where there is a change in the public key on the extended digital certificate, the subscriber must clearly request it; the creation, distribution, and publication of the extended digital certificate shall be carried out in accordance with the provisions of Articles 24 and 25 of this Decree.
Article 27. Change of Key Pairs for Subscribers
In cases where subscribers have a need to change key pairs, the subscriber must submit a request for changing the key pair. The creation, distribution, and publication of digital certificates with new public keys shall be carried out in accordance with the provisions of Articles 24 and 25 of this Decree.
24 and 25 of this Decree
Article 28. Suspension and Restoration of Digital Certificates for Subscribers
1. The digital certificate of a subscriber shall be suspended in the following cases:
a) When the subscriber requests in writing and such request has been verified by the public service provider of digital signature authentication as accurate; 24 and 25 of this Decree b) When the public service provider of digital signature authentication has grounds to assert that the issued digital certificate does not comply with the provisions at
or when any errors affecting the rights of the subscriber and recipient are discovered;
c) When requested by judicial authorities, police agencies, or the Ministry of Information and Communications;
d) According to the conditions for suspending digital certificates stipulated in the contract between the subscriber and the public service provider of digital signature authentication.
2. Upon having grounds to suspend a digital certificate, the public service provider of digital signature authentication must immediately suspend it and notify the subscriber, and publish on the database of digital certificates the suspension, start time, and end time of the suspension.
Article 29. Revocation of Digital Certificates for Subscribers
1. The digital certificate of a subscriber shall be revoked in the following cases:
a) When the subscriber requests in writing and such request has been verified by the service provider organization to be accurate;
b) When the subscriber, being an individual, dies or is declared missing by a court, or when the subscriber, being an organization, is dissolved or declared bankrupt under the provisions of the law;
or when any errors affecting the rights of the subscriber and recipient are discovered;
d) In accordance with the conditions for revoking digital certificates that have been stipulated in the contract between the subscriber and the public key certification service provider organization.
2. When there is a basis for revoking the digital certificate, the public key certification service provider organization must revoke the digital certificate, simultaneously notify the subscriber, and publish on the database of digital certificates the revocation thereof.
Article 30. Time Stamping Service
1. The time stamping service is an added-value service to attach information about date, month, year, and time to data messages.
2. The time stamping service is provided by the public key certification service provider organization. The provision of the time stamping service must comply with technical standards and mandatory standards applicable to the time stamping service.
3. The date, month, year, and time attached to the data message are the date, month, year, and time when the time stamping service provider organization receives the data message and is certified by the time stamping service provider organization.
4. The source of time of the time stamping service provider organizations must comply with the provisions of the law regarding the national standard time source.
Article 31. Certification Rules of Public Key Certification Service Provider Organizations
1. The certification rules of public key certification service provider organizations are established according to the model prescribed in the certification rules of the National Public Key Certification Service Provider Organization.
2. The certification rules of public key certification service provider organizations must be made public in accordance with Clause 2 of Article 33 of this Decree. Clause 2 of Article 33 of this Decree.
3. When there is a change in information in the certification rules, the public key certification service provider organization must notify in writing to the National Public Key Certification Service Provider Organization and must obtain written consent from the National Public Key Certification Service Provider Organization for the changed contents.
Section 3. OBLIGATIONS OF PUBLIC KEY CERTIFICATION SERVICE PROVIDER ORGANIZATIONS
Article 32. Obligations of Public Key Certification Service Provider Organizations towards Subscribers
1. Ensure continuous and uninterrupted use of services by subscribers throughout the validity period of the digital certificate and continuously check the status of the subscriber's digital certificate.
2. Resolve risks and compensation claims arising for subscribers and recipients due to errors determined to be caused by the public key certification service provider organization.
3. Ensure the confidentiality, personal information security, and storage devices for subscribers' digital certificates in accordance with the laws on information security and other relevant laws.
4. Receive information:
Ensure that the information reception channel operates 24 hours a day, 7 days a week from subscribers related to the use of digital certificates.
5. Related to key management activities:
a) Immediately notify the subscriber and apply preventive measures and timely remedies in case signs of the subscriber's secret key being exposed, no longer intact, or any other errors that may adversely affect the subscriber's interests are detected;
b) Advise the subscriber to change the key pair when necessary to ensure the highest reliability and security of the key pair.
6. In the event of temporarily suspending issuance of new digital certificates:
During the suspension period, the public key certification service provider organization is responsible for maintaining the database system related to issued digital certificates.
7. Upon revocation of the license, the public key certification service provider organization must immediately notify the subscriber about the cessation of its services and provide information about the organization receiving its database to ensure the subscriber's service usage rights.
8. Develop a sample contract with subscribers including the following contents:
a) Scope, limitations of use, level of security, costs related to the issuance and use of digital certificates, and other information that may affect the subscriber's interests;
b) Requirements to ensure the safety in storing and using secret keys;
c) Complaint procedures and dispute resolution.
9. Perform the rights and obligations of the principal party according to the provisions of the commercial law.
Article 33. Obligations of organizations providing public digital signature certification services towards state management agencies for digital signatures and certification services
1. Disclosure of information:
Organizations providing public digital signature certification services must publicly disclose and maintain the following information on their electronic news websites 24 hours a day, 7 days a week:
a) Their certification regulations and digital certificates;
b) The list of active, suspended, and revoked digital certificates of subscribers;
c) Other necessary information as prescribed by law.
2. Updating information:
Organizations providing public digital signature certification services must update the information specified in Clause 1 of this Article within 24 hours when there are changes.
3. Providing information:
Organizations providing public digital signature certification services must provide in real-time online to the organization providing national digital signature certification services information about the number of active, suspended, and revoked digital certificates to serve state management of digital signature certification services.
4. Storing information:
All information related to the temporary suspension or revocation of licenses and subscriber databases, digital certificates must be stored for at least five years from the date of license suspension or revocation.
5. Paying service fees for maintaining the status check system according to regulations.
6. Reporting periodically and urgently as prescribed by the Ministry of Information and Communications and upon the request of competent state agencies.
Section 4. AGENTS OF PUBLIC DIGITAL SIGNATURE CERTIFICATION SERVICES
Article 34. Conditions for operation of agents of public digital signature certification services
1. Being a trader including legally established economic organizations, individuals independently and regularly engaged in commerce and registered for business.
2. Having a specific address for the trading office.
3. Having an agency contract with the organization providing public digital signature certification services.
Article 35. Rights and obligations of agents of public digital signature certification services
1. Implementing the rights and obligations of agents as prescribed by commercial laws.
2. Fully guiding the application procedures for digital certificates for subscribers.
3. Publicly posting the digital certificate issuance process at the agent's office.
4. Ensuring a 24-hour-a-day, 7-days-a-week information channel to receive requests from subscribers.
5. Bearing responsibility for reporting when requested by competent authorities to serve state management of digital signature certification services.
Chapter IV. SPECIALIZED DIGITAL SIGNATURE CERTIFICATION SERVICES FOR ORGANIZATIONS AND INSTITUTIONS
Section 1. ISSUANCE OF REGISTRATION ACTIVITY LICENSE FOR ORGANIZATIONS PROVIDING SPECIALIZED DIGITAL SIGNATURE CERTIFICATION SERVICES FOR ORGANIZATIONS AND INSTITUTIONS
Article 36. Conditions for operation and registration
1. Conditions for operation
Organizations and institutions can operate specialized digital signature certification services when they have a registration activity certificate issued by the Ministry of Information and Communications.
2. Conditions for registration
a) Organizations and institutions must have personnel responsible for: System administration; system operation and issuance of digital certificates; ensuring the security of the system. These personnel must hold a bachelor’s degree or higher in information security, information technology, or telecommunications;
b) Establishing technical equipment systems that meet the following requirements:
- Fully, accurately, and timely storing information about subscribers to serve the issuance of digital certificates throughout the validity period of the digital certificate;
- Ensuring the creation of key pairs that are randomly generated and unique; having a feature to ensure that the private key cannot be detected when the corresponding public key is available;
- Having features to warn, prevent, and detect unauthorized network access;
- Designed to minimize direct contact with the Internet environment as much as possible.
c) Having a plan to provide subscriber information online to the organization providing national digital signature certification services to serve state management of digital signature certification services;
d) The entire system equipment used to provide services must be located in Vietnam;
đ) Having headquarters and locations for machinery and equipment that comply with fire prevention and explosion protection legal requirements; capable of resisting floods, earthquakes, electromagnetic interference, and illegal human intrusion.
Article 37. Registration Documents
1. Application for issuance of registration certificate for operation of organizations providing specialized digital signature verification services. Form number 06 the Appendix issued together with this Decree.
2. Documents proving compliance with the conditions for registration of activities stipulated in Clause 2, Article 36 of this Decree..
3. Documents proving that the service users have the same nature of activities or work purposes and are linked to each other through their operational regulations or legal normative documents specifying the organizational structure or forms of cooperation and joint operations.
Article 38. Procedures for Issuance, Temporary Suspension, Revocation, Modification, and Reissuance of Registration Certificates for Operation
1. Issuance of Registration Certificate for Operation
a) Within thirty working days from the date of receipt of a valid registration application, the Ministry of Information and Communications shall examine the application and issue the registration certificate for operation if the application meets all the conditions for registration of activities stipulated at Clause 2, Article 36 of this Decree.. The model of the registration certificate for organizations providing specialized digital signature verification services is prescribed according to Form No. 09 the Appendix issued together with this Decree.
In case of refusal, the Ministry of Information and Communications shall notify in writing and specify the reasons;
b) The registration certificate for organizations providing specialized digital signature verification services of agencies and organizations has a validity period of five years.
2. Temporary Suspension of Registration Certificate for Operation
Organizations providing specialized digital signature verification services of agencies and organizations may be temporarily suspended from operating for no more than six months under one of the following circumstances:
a) Providing services contrary to the contents recorded on the registration certificate for operation;
b) Failing to meet one of the conditions for issuing the registration certificate for operation stipulated at Clause 2, Article 36 of this Decree. during the provision of services.
3. Restoration of Registration Certificate for Operation
During the period of temporary suspension of the registration certificate for operation, if the organization providing specialized digital signature verification services of agencies and organizations remedies the cause of temporary suspension, the Ministry of Information and Communications will allow the organization to continue providing services.
4. Revocation of Registration Certificate for Operation
Organizations providing specialized digital signature verification services of agencies and organizations will have their registration certificates for operation revoked under one of the following circumstances:
a) Not implementing service provision within twelve months from the date of issuance of the registration certificate for operation without legitimate reasons;
c) The license for providing public key infrastructure services has expired;
c) Unable to remedy the conditions for temporary suspension stipulated in Clause 2, Article 38 of this Decree; 3. The Ministry of Information and Communications shall supervise and guide the transfer between public key infrastructure service providers to ensure uninterrupted service use by subscribers.
d) Agencies and organizations do not wish to continue providing services.
5. Modification of Content of Registration Certificate for Operation
Modification of the content of the registration certificate for operation shall be carried out when the organization holding the certificate changes one of the following information: headquarters address, legal representative, scope and target of service provision, technical standards applied.
To modify the content of the registration certificate for operation, the organization providing specialized digital signature verification services of agencies and organizations shall submit an application for modification of the content of the registration certificate for operation at the Ministry of Information and Communications, which includes: an application for modification of the content of the registration certificate for operation according to Form No. 07 in the Appendix issued together with this Decree and related documents and materials serving as the basis for the request for modification.
Within fifteen working days from the date of receipt of a complete and valid application, the Ministry of Information and Communications shall examine and reissue the registration certificate for operation to the agency or organization with the modified content; in case of refusal to reissue, it must notify in writing and specify the reasons.
The validity period of the reissued registration certificate for operation is the remaining period of the previously issued certificate.
6. Reissuance of Registration Certificate for Operation Upon Expiry
At least thirty days before the expiry of the registration certificate for operation, the organization providing specialized digital signature verification services of agencies and organizations shall submit an application for reissuance of the registration certificate for operation due to expiry. The application for reissuance of the registration certificate for operation due to expiry includes:
a) An application for reissuance of the registration certificate for operation due to expiry, according to Form No. 08 the Appendix issued together with this Decree;
b) Changes in personnel and technical information of the organization related to the conditions for issuance of the certificate as stipulated at Clause 2, Article 36 of this Decree. (if applicable).
Within fifteen working days from the date of receipt of a valid application for reissuance of the registration certificate for operation due to expiry, the Ministry of Information and Communications shall examine the application.
If the application meets all the conditions, the Ministry of Information and Communications shall reissue the registration certificate for operation to the organization. In case of refusal, the Ministry of Information and Communications shall notify in writing and specify the reasons.
The validity period of the reissued registration certificate for operation due to expiry is five years.
Article 39. Rights and Obligations of Organizations Providing Special-Purpose Digital Signature Certification Services
1. Provide special-purpose digital signature certification services within the scope and objects of operation registered in the certificate of registration for activities issued by the Ministry of Information and Communications.
2. Specify the provision and use of special-purpose digital signature certification services within agencies and organizations within the scope and objects of operation registered.
3. Report periodically and urgently as prescribed by the Ministry of Information and Communications and upon the requirements of competent state agencies.
4. In cases where organizations providing special-purpose digital signature certification services for agencies and organizations have the need to use special-purpose digital signatures to transact with organizations and individuals to serve specialized activities under their functions and tasks, they must have a certificate of qualification conditions for ensuring the security of special-purpose digital signatures issued by the Ministry of Information and Communications pursuant to Articles 9, 40, and 41 of this Decree. Article 40. Conditions for Issuing Certificates of Qualification Conditions for Ensuring the Security of Special-Purpose Digital Signatures.
Section 2. ISSUANCE OF CERTIFICATES OF QUALIFICATION CONDITIONS FOR ENSURING THE SECURITY OF SPECIAL-PURPOSE DIGITAL SIGNATURES FOR AGENCIES AND ORGANIZATIONS
Article 40. Conditions for Issuing Certificates of Qualification Conditions for Ensuring the Security of Special-Purpose Digital Signatures
1. Have a certificate of registration for activities of organizations providing special-purpose digital signature certification services.
2. Meet the human resources and technical conditions prescribed in Clauses 3 and 4 of Article 13 of this Decree. Article 41. Documents for Requesting Issuance of Certificates of Qualification Conditions for Ensuring the Security of Special-Purpose Digital Signatures.
1. A request for issuance of certificates of qualification conditions for ensuring the security of special-purpose digital signatures according to the prescribed form.
2. A copy of the certificate of registration for activities of organizations providing special-purpose digital signature certification services. Form No. 10 the Appendix issued together with this Decree.
3. The decision on establishment and operational charter of the organization.
4. Human resource files including curriculum vitae, diplomas, and certificates of the staff participating in the provision of special-purpose digital signature certification services that meet the provisions at Clause 4 of Article 13 of this Decree.
5. Technical plans to ensure compliance with the provisions at Clause 4 of Article 13 of this Decree. Clause 3, Article 13 of this Decree..
6. Certification regulations according to the model prescribed in the national digital signature certification organization's certification regulations. Clause 4, Article 13 of this Decree..
Article 42. Procedures for Issuing, Temporarily Suspending, Revoking, Amending Content, and Reissuing Certificates of Qualification Conditions for Ensuring the Security of Special-Purpose Digital Signatures
1. Issuing Certificates of Qualification Conditions for Ensuring the Security of Special-Purpose Digital Signatures
a) Within sixty working days from the date of receipt of a valid application for issuance of certificates of qualification conditions for ensuring the security of special-purpose digital signatures, the Ministry of Information and Communications shall take the lead and coordinate with the Ministry of Public Security, the Government Cryptographic Office, and relevant ministries and sectors to examine the documents, conduct on-site inspections, and issue certificates of qualification conditions for ensuring the security of special-purpose digital signatures to organizations that meet all the conditions prescribed in Article 40 of this Decree.
The format of the certificate of qualification conditions for ensuring the security of special-purpose digital signatures is prescribed in accordance with the guidelines set forth in the national digital signature certification organization's regulations. If an organization does not meet the prescribed conditions, the Ministry of Information and Communications will notify in writing and specify the reasons.b) The certificate of qualification conditions for ensuring the security of special-purpose digital signatures has a validity period corresponding to the certificate of registration for activities of organizations providing special-purpose digital signature certification services but not exceeding five years. Model Number 13 the Appendix issued together with this Decree.
2. Temporarily Suspending Certificates of Qualification Conditions for Ensuring the Security of Special-Purpose Digital Signatures
Organizations providing special-purpose digital signature certification services for agencies and organizations may be temporarily suspended from holding certificates of qualification conditions for ensuring the security of special-purpose digital signatures for no more than six months if they fall into one of the following situations:
a) Being temporarily suspended from holding the certificate of registration for activities of organizations providing special-purpose digital signature certification services;
b) Not meeting one of the conditions for issuing certificates of qualification conditions for ensuring the security of special-purpose digital signatures prescribed in Clause 2 of Article 40 of this Decree.
3. Restoring Certificates of Qualification Conditions for Ensuring the Security of Special-Purpose Digital Signatures
During the period of temporary suspension of certificates of qualification conditions for ensuring the security of special-purpose digital signatures, if organizations providing special-purpose digital signature certification services for agencies and organizations can rectify the reasons for temporary suspension, the Ministry of Information and Communications will revoke the decision to temporarily suspend certificates of qualification conditions for ensuring the security of special-purpose digital signatures of such organizations. 4. Revoking Certificates of Qualification Conditions for Ensuring the Security of Special-Purpose Digital Signatures during the provision of services.
Organizations providing special-purpose digital signature certification services for agencies and organizations will have their certificates of qualification conditions for ensuring the security of special-purpose digital signatures revoked if they fall into one of the following situations:
a) Being revoked from holding the certificate of registration for activities of organizations providing special-purpose digital signature certification services;
b) Not being able to rectify the conditions for temporary suspension prescribed in Clause 2 of Article 42 of this Decree after the suspension period set by the competent authority.
5. Amending Contents of Certificates of Qualification Conditions for Ensuring the Security of Special-Purpose Digital Signatures
Amending contents of certificates of qualification conditions for ensuring the security of special-purpose digital signatures shall be carried out when organizations holding certificates of qualification conditions for ensuring the security of special-purpose digital signatures change one of the following information: office address, legal representative, scope and objects of service provision, technical standards applied.
To amend the contents of certificates of qualification conditions for ensuring the security of special-purpose digital signatures, organizations providing special-purpose digital signature certification services for agencies and organizations must submit an application for amending the contents of certificates of qualification conditions for ensuring the security of special-purpose digital signatures to the Ministry of Information and Communications, which includes: a request for amending the contents of certificates of qualification conditions for ensuring the security of special-purpose digital signatures according to the prescribed form. Within fifteen working days from the date of receipt of a valid application, the Ministry of Information and Communications shall examine and reissue certificates of qualification conditions for ensuring the security of special-purpose digital signatures with the amended contents; in case of refusal to issue, it must notify in writing and specify the reasons. after the temporary suspension period set by the competent authority.
5. Modification of the content of the certificate of qualification for ensuring the security of specialized digital signatures
The modification of the content of the certificate of qualification for ensuring the security of specialized digital signatures shall be carried out when the entity issued the certificate of qualification for ensuring the security of specialized digital signatures changes one of the following information: headquarters address, legal representative, scope and target of service provision, technical standards applied.
To modify the content of the certificate of qualification for ensuring the security of specialized digital signatures, the specialized digital signature certification service provider of government agencies and organizations shall submit an application for modification of the content of the certificate of qualification for ensuring the security of specialized digital signatures to the Ministry of Information and Communications, the application including: a request for modification of the content of the certificate of qualification for ensuring the security of specialized digital signatures in accordance with Form No. 11 in the Appendix issued together with this Decree and related documents and materials serving as the basis for the request for modification.
Within fifteen working days from the date of receipt of a valid application, the Ministry of Information and Communications shall review and issue a new certificate of qualification for ensuring the security of specialized digital signatures with the modified contents; in case of refusal, it must notify in writing and specify the reasons.
The validity period of the certificate of qualification for ensuring the safety of specialized digital signatures renewed shall be the remaining validity period of the previously issued certificate.
6. Renewal of the certificate of qualification for ensuring the safety of specialized digital signatures upon expiration
At least 45 days before the certificate of qualification for ensuring the safety of specialized digital signatures expires, the service provider organization must submit an application to renew the certificate due to expiration. The application for renewal of the certificate of qualification for ensuring the safety of specialized digital signatures due to expiration includes:
a) An application form for renewing the certificate of qualification for ensuring the safety of specialized digital signatures due to expiration, according to Form No. 12 the Appendix issued together with this Decree;
b) A copy of the registration certificate for the operation of the service provider organization for specialized digital signature certification;
c) Information on personnel and technical changes of the organization related to the conditions for issuing the certificate of qualification for ensuring the safety of specialized digital signatures as prescribed in 4. Revoking Certificates of Qualification Conditions for Ensuring the Security of Special-Purpose Digital Signatures.
Within 30 days from the date of receiving a valid application, the Ministry of Information and Communications shall lead and coordinate with relevant ministries and sectors to review the application and inspect the actual fulfillment of the conditions for issuing the certificate.
If the organization meets all the conditions for issuing the certificate, the Ministry of Information and Communications will renew the certificate of qualification for ensuring the safety of specialized digital signatures for the organization. In case of refusal, the Ministry of Information and Communications shall issue a notification letter specifying the reasons.
The validity period of the renewed certificate of qualification for ensuring the safety of specialized digital signatures due to expiration is five years.
Chapter V. FOREIGN DIGITAL CERTIFICATES AND SIGNATURES IN VIETNAM
Article 43. Conditions for Using Foreign Digital Certificates
1. The foreign digital certificate remains valid for use.
2. It has been granted a permit for use in Vietnam by the Ministry of Information and Communications or accepted in international transactions. In cases where foreign digital certificates are used for servers and software, no separate permit is required.
Article 44. Subjects Using Foreign Digital Certificates
1. Foreign organizations and individuals in Vietnam.
2. Vietnamese organizations and individuals who need to conduct electronic transactions with foreign partners where the digital certificates provided by domestic certification service organizations have not been recognized in that country.
Article 45. Scope of Operation and Validity Period of Permits for Using Foreign Digital Certificates in Vietnam
1. The scope of operation is the electronic transactions of subjects using foreign digital certificates as stipulated in Article 44 of this Decree.
2. The validity period of permits for using foreign digital certificates in Vietnam is five years but shall not exceed the validity period of the digital certificate.
Article 46. Conditions for Issuing Permits for Use
1. For subscribers using foreign digital certificates in Vietnam:
a) Belongs to the subject categories specified in Article 44 of this Decree;
b)[3] One of the following documents or level 2 e-identity account to verify information on the digital certificate:
- Business registration certificate, investment certificate, establishment decision, decision on functions, tasks, and powers for organizations; identity card, citizen identification card, passport for individuals;
- Level 2 e-identity account for individuals; e-identity account of organizations for organizations;
- Written authorization from competent authorities allowing foreign organizations and individuals to operate legally in Vietnam for subscribers who are foreign organizations and individuals;
- In cases of authorized use of digital certificates, there must be a lawful authorization for the use of digital certificates and the subscriber information on the digital certificate must match the information in the authorization letter.
2. For foreign digital signature certification service providers whose digital certificates are recognized in Vietnam
a) Established and operating legally in the country where the foreign digital signature certification service provider registers its activities;
b) Meeting the mandatory standards for digital signatures and digital signature certification services issued by the Ministry of Information and Communications or international standards for digital signatures recognized by the Ministry of Information and Communications as having equivalent levels of security;
c) Certified by an auditing firm that the business operations comply with credible international standards for digital signature certification services.
Article 47. Documents for Issuing a Permit to Use Foreign Digital Certificates in Vietnam
1. The application for issuing a permit to use foreign digital certificates in Vietnam from the subscriber. Model No. 14 the Appendix issued together with this Decree.
2. Explanatory and evidentiary documents demonstrating compliance with the conditions stipulated in Article 46 of this Decree..
3. A valid copy of the contract (or agreement) for using foreign digital certificates between the subscriber and the foreign digital certificate provider organization, or a document proving that the subscriber is a legitimate user of foreign digital certificates.
4. A commitment to comply with Vietnamese laws on digital signatures and digital signature certification services when using foreign digital certificates in Vietnam.
Article 48. Examination of Documents and Issuance of Permits to Use Foreign Digital Certificates in Vietnam
1. Within thirty working days from the date of receipt of complete and valid documents submitted by organizations and individuals requesting a permit to use foreign digital certificates in Vietnam, the Ministry of Information and Communications shall examine the documents.
2. If the documents meet the required conditions, the Ministry of Information and Communications shall issue a permit to use foreign digital certificates in Vietnam. The format of the permit to use foreign digital certificates in Vietnam is prescribed according to Model Number 15 the Appendix issued together with this Decree.
In cases where the conditions are not met, the Ministry of Information and Communications shall notify in writing and specify the reasons.
Article 49. Amendment and Reissue of Permits to Use Foreign Digital Certificates in Vietnam
1. Amendments to the contents of permits to use foreign digital certificates in Vietnam shall be made in cases where the permit holder changes their trading name, changes the legal representative for organizations, or changes the type of digital certificate they use.
The application for amending the contents of the permit includes an application for amendment, a detailed report describing the proposed amendments, and related documents (if any).
Within ten working days from the date of receiving all necessary documents, the Ministry of Information and Communications shall examine and amend the permit's contents for the applicant; if the request is denied, it must notify in writing and specify the reasons.
2. In cases where the permit is lost or damaged, the user of foreign digital certificates shall submit an application for reissuing the permit to the Ministry of Information and Communications, specifying the reason. Within seven working days from the date of receipt of the application, the Ministry of Information and Communications shall review and reissue the permit for the applicant.
3. The validity period of amended and reissued permits is the remaining validity period of the original issued permit.
Article 50. Obligations of Organizations and Individuals Using Foreign Digital Certificates Issued for Use in Vietnam
1. To use foreign digital certificates within the scope specified in the permit to use foreign digital certificates in Vietnam.
2. To report incidents or provide information about the use of foreign digital certificates in Vietnam upon request by the Ministry of Information and Communications.
Article 51. Acceptance of Foreign Digital Certificates in International Transactions
1. Foreign digital certificates accepted in international transactions are those foreign digital certificates used by subscribers who are not present in Vietnam and are valid for data messages sent to Vietnamese authorities and organizations.
2. Authorities, organizations, and individuals selecting and accepting foreign digital certificates for international transactions bear responsibility for such acceptance.
Chapter VI. ORGANIZATION OF PROVIDING NATIONAL DIGITAL SIGNATURE CERTIFICATION SERVICES
Article 52. Position, Functions, Tasks, and Authorities of the Organization Providing National Digital Signature Certification Services
1. The organization providing national digital signature certification services is a public service unit under the Ministry of Information and Communications, providing certification services for digital signatures to organizations providing public digital signature certification services, organizations providing specialized digital signature certification services for agencies and organizations that have been granted certificates confirming their qualification to ensure the security of specialized digital signatures, and agencies, organizations, and individuals using foreign digital certificates that have been permitted to be used in Vietnam. The organization providing national digital signature certification services is unique.
2. The organization providing national digital signature certification services has the following tasks and authorities:
a) Building, managing, maintaining, and operating technical systems to perform functions as prescribed in Clause 1 of this Article;
b) Issuing digital certificates to itself;
c) Studying and submitting to competent authorities for the construction and issuance of documents on the management and provision of certification services for digital signatures to organizations providing specialized digital signature certification services for agencies and organizations that have been granted certificates confirming their qualification to ensure the security of specialized digital signatures, and agencies, organizations, and individuals using foreign digital certificates that have been permitted to be used in Vietnam;
d) Announcing and updating on its electronic information website lists of organizations providing public digital signature certification services, organizations providing specialized digital signature certification services that have been granted operation certificates, foreign digital certificates that have been permitted to be used in Vietnam, and foreign digital certificates accepted in international transactions;
đ) Implementing activities to enable Vietnam's digital signature certification services to be recognized in other countries and international organizations.
Article 53. Activities of the Organization Providing National Digital Signature Certification Services
The issuance of digital certificates and digital signature certification services to organizations providing digital signature certification services is regulated in Chapters III and IV of this Decree:
1. The organization providing national digital signature certification services plays a role and has rights and obligations as an organization providing public digital signature certification services according to the provisions of Chapter III of this Decree. Organizations providing digital signature certification services play a role and have rights and obligations as subscribers according to the provisions of Chapter III of this Decree.
2. In addition to complying with the provisions of Clause 1 of this Article, the organization providing national digital signature certification services and organizations providing digital signature certification services must comply with the following provisions:
a) Key pairs as prescribed in Article 24 of this Decree shall be created by the organization providing digital signature certification services on its own system;
b) Content required to be checked before issuing digital certificates as prescribed in Clause 1 of Article 25 of this Decree, supplemented with checks on compliance with operational conditions prescribed in the Article 41. Documents for Requesting Issuance of Certificates of Qualification Conditions for Ensuring the Security of Special-Purpose Digital Signatures;
c) Public information as prescribed in Clause 2 of Article 33 of this Decree shall be announced on the electronic information website of the organization providing national digital signature certification services or the organization providing public digital signature certification services;
d) Organizations providing digital signature certification services using digital certificates issued by the organization providing national digital signature certification services must pay service fees for maintaining the system to check the status of digital certificates according to the Law on Fees and Charges.
Article 54. Regulations on Notarization of Organizations Providing National Digital Signature Notarization Services
1. The regulations on notarization of organizations providing national digital signature notarization services shall be issued by the Ministry of Information and Communications to guide procedures and processes for providing digital signature notarization services, including the following contents:
a) Model contract between the organization providing public digital signature notarization services and agents;
b) Model contract between the organization providing public digital signature notarization services and subscribers;
c) Model notarization regulations of the organization providing public digital signature notarization services and the organization providing specialized government digital signature notarization services with a certificate ensuring security for specialized government digital signatures.
2. Organizations providing digital signature notarization services, agents of public digital signature notarization services, and subscribers using foreign digital certificates permitted for use in Vietnam shall be responsible for implementing the provisions set forth in the regulations on notarization of organizations providing national digital signature notarization services.
Chapter VII. SPECIALIZED GOVERNMENT DIGITAL SIGNATURE NOTARIZATION SERVICES
Article 55. Position, Functions, Duties, and Authorities of Organizations Providing Specialized Government Digital Signature Notarization Services
1. An organization providing specialized government digital signature notarization services is an entity under the Government Cryptographic Bureau, providing specialized government digital signature notarization services to Party and State agencies.
2. The organization providing specialized government digital signature notarization services has the following duties and authorities:
a) Managing, maintaining, and operating technical systems to provide specialized government digital signature notarization services to Party and State agencies;
b) Issuing digital certificates to itself;
c) Building, submitting to competent authorities for issuance, and organizing guidance on operational procedures regarding the provision, management, and use of specialized government digital signature notarization services;
d) Annually guiding agencies, organizations, and individuals to report and organize summaries of management and implementation of digital certificates and digital signature notarization services within Party and State agencies;
đ) Being allocated and guaranteed personnel, funding, and office space by the State to implement tasks, manage, maintain operations, ensure the provision of digital certificates and digital signature notarization services according to the actual needs of Party and State agencies and security requirements based on the scale of operations.
Article 56. Specialized Government Digital Signature Notarization Services
The organization providing specialized government digital signature notarization services provides the following services:
1. Creating and distributing key pairs.
2. Issuing digital certificates.
3. Renewing digital certificates.
4. Changing information content in digital certificates.
5. Revoking digital certificates.
6. Restoring secret key storage devices.
7. Online publication and maintenance of databases on digital certificates.
8. Online verification service for digital certificates.
9. Issuing time stamps.
Article 57. Use of Specialized Government Digital Signature Notarization Services
Types of electronic transactions of Party and State agencies, if applying digital signatures, shall use digital signature notarization services provided by the organization providing specialized government digital signature notarization services.
Article 58. Creation and Distribution of Key Pairs
1. The organization providing specialized government digital signature certification services shall create key pairs for subscribers (public keys and private keys).
2. Public keys shall be attached to digital certificates and published online on the electronic information website of the organization providing specialized government digital signature certification services.
3. Private keys corresponding to each subscriber's digital certificate shall be stored on a secure key storage device and delivered to the subscriber through a secure method.
Article 59. Validity Period of Digital Certificates
1. The validity period of digital certificates issued by organizations providing specialized government digital signature certification services is twenty years.
2. For newly issued digital certificates for subscribers, the maximum validity period is five years.
3. For renewed digital certificates, the maximum extended validity period is three years.
Article 60. Conditions for Issuing New Digital Certificates
1. Conditions for issuing new digital certificates to individuals:
a) Must be civil servants or employees of Party or State agencies with a need for electronic transactions;
b) Must have a request letter and confirmation from the head of the direct managing agency or organization.
2. Conditions for issuing new digital certificates to authorized persons of agencies or organizations as stipulated by laws on seal management and use, and state officials:
a) Must be authorized persons of agencies or organizations under Party or State agencies as stipulated by laws on seal management and use, and state officials with a need for electronic transactions;
b) Must have a request letter and confirmation from the head of the direct managing agency or organization.
3. Conditions for issuing digital certificates to agencies or organizations:
a) Must be agencies or organizations with legal personality;
b) Must have a decision establishing the agency or organization or confirmation from the head of the direct superior agency or organization;
c) Must have a request letter from the person entrusted by the agency or organization to manage its digital certificate and confirmation from the head of the direct managing agency or organization.
4. Conditions for issuing new digital certificates to devices, services, and software:
a) Devices, services, and software must be owned or managed by agencies or organizations with legal personality;
b) The person managing the digital certificate of the device, service, or software must be an authorized person of the agency or organization as stipulated by laws on seal management and use;
c) Must have a request letter from the person entrusted by the agency or organization to manage the digital certificate of the device, service, or software and confirmation from the head of the direct managing agency or organization.
Article 61. Documents for Issuing Digital Certificates
1. Documents for issuing digital certificates to individuals: A request letter for a digital certificate from the individual with confirmation from the direct managing agency or organization.
2. Issuing digital certificates to authorized persons of agencies or organizations as stipulated by laws on seal management and use, and state officials: A request letter for a digital certificate from the authorized person of the agency or organization as stipulated by laws on seal management and use, and state officials, with confirmation from the direct managing agency or organization.
3. Issuing digital certificates to agencies or organizations: A request letter from the person entrusted by the agency or organization to manage its digital certificate and confirmation from the head of the direct managing agency or organization.
4. Issuing digital certificates to devices, services, and software: A request letter from the person entrusted by the agency or organization to manage the digital certificate of the device, service, or software, a confirmation of software copyright ownership from the agency or organization managing the software, and confirmation from the head of the direct managing agency or organization.
Article 62. Procedures for Issuing Digital Certificates
1. Application for Issuance of Digital Certificate:
a) Digital certificate for individuals:
Individuals must submit an application for issuance of digital certificate in accordance with Clause 1 of Article 61 of this Decree and send it to the organization providing specialized government digital signature authentication services. b) Digital certificate for persons authorized by agencies and organizations under the law on management and use of seals, and state officials:
Persons authorized by agencies and organizations under the law on management and use of seals, and state officials must submit an application for issuance of digital certificate confirmed by the directly managing agency or organization and dossier in accordance with
Clause 2 of Article 61 of this Decree to the organization providing specialized government digital signature authentication services. c) Digital certificate for agencies and organizations:
The person authorized by agencies and organizations under the law on management and use of seals, who is assigned by the agency or organization to manage its digital certificate, must submit an application for issuance of digital certificate confirmed by the directly managing agency or organization and dossier in accordance with
Clause 3 of Article 61 of this Decree d) Digital certificate for devices, services, software: c) Digital certificate for agencies and organizations:
The person authorized by agencies and organizations under the law on management and use of seals, who is assigned by the agency or organization to manage the digital certificate for devices, services, and software, must submit an application for issuance of digital certificate confirmed by the directly managing agency or organization to the organization providing specialized government digital signature authentication services.
2. Within three working days from the date of receiving a complete dossier, the organization providing specialized government digital signature authentication services shall be responsible for checking the dossier, organizing the creation of key pairs, issuing digital certificates, and ensuring the secure storage device for the private key of the subscriber. It shall notify the time and place for receiving the secure storage device for the private key to the directly managing agency or organization.
3. The directly managing agency or organization shall be responsible for receiving the secure storage device for the private key from the organization providing specialized government digital signature authentication services. After transferring the secure storage device for the private key to the subscriber, the directly managing agency or organization shall submit a request for the effective date of the digital certificate to the organization providing specialized government digital signature authentication services.
4. Within one working day from the date of receipt of the request for the effective date of the digital certificate, the organization providing specialized government digital signature authentication services shall be responsible for publishing the digital certificate of the subscriber on the electronic information website of the organization providing specialized government digital signature authentication services. The digital certificate of the subscriber shall take effect from the date it is published by the organization providing specialized government digital signature authentication services.
Article 63. Conditions for Renewal of Digital Certificates
1. A digital certificate can only be renewed once and must ensure at least 60 days remaining validity period.
2. Agencies, organizations, and individuals must submit a renewal request, approved by the directly managing authority, and apply for the renewal of the digital certificate.
Article 64. Procedures for Renewal of Digital Certificates
1. Application for Renewal of Digital Certificate:
a) Renewal of digital certificate for individuals:
Individuals must submit a renewal request for digital certificate confirmed by the directly managing agency or organization to the organization providing specialized government digital signature authentication services;
b) Renewal of digital certificate for persons authorized by agencies and organizations under the law on management and use of seals, and state officials:
Individuals authorized by agencies and organizations under the law on management and use of seals, and state officials must submit a renewal request for digital certificate (without accompanying documents specified in point b)
confirmed by the directly managing agency or organization to the organization providing specialized government digital signature authentication services. to the organization providing specialized government digital signature authentication services.c) Renewal of digital certificate for agencies and organizations:
The person authorized by agencies and organizations under the law on management and use of seals, who is assigned by the agency or organization to manage its digital certificate, must submit a renewal request for digital certificate (without accompanying documents specified in points b and c)
confirmed by the directly managing agency or organization to the organization providing specialized government digital signature authentication services; d) Digital certificate for devices, services, software:d) Renewal of digital certificate for devices, services, software:
The person authorized by agencies and organizations under the law on management and use of seals, who is assigned by the agency or organization to manage the digital certificate for devices, services, and software, must submit a renewal request for digital certificate confirmed by the directly managing agency or organization to the organization providing specialized government digital signature authentication services.
2. Within three working days from the date of receiving the renewal request for digital certificate, the organization providing specialized government digital signature authentication services shall be responsible for renewing the digital certificate for the subscriber and notifying the directly managing agency or organization.
In case of refusal to renew the digital certificate, the organization providing specialized government digital signature authentication services shall notify in writing the reasons to the directly managing agency or organization.
In the event that the extension of the digital certificate is not accepted, the specialized digital signature certification service provider for the Government shall notify in writing and specify the reasons to the directly managing agency or organization.
Article 65. Conditions for Changing the Content of Information in a Digital Certificate
1. A digital certificate that requires changes to its information content must still be valid for at least 60 days, and the validity period of the digital certificate after the change in information content shall remain the same as before the change.
2. The agency, organization, or individual must submit a written request to be confirmed by the directly managing agency or organization for the change in the information content of the digital certificate.
Article 66. Cases for Changing the Content of Information in a Digital Certificate
1. For personal digital certificates:
a) Change the information about the agency or organization where the person works if it does not match the information in the digital certificate;
b) Change the email address information.
2. For digital certificates of individuals who have authority according to the laws on management and use of seals and those with state positions:
Individuals change their authority according to the laws on management and use of seals and change their state position.
3. For digital certificates of agencies or organizations:
Agencies or organizations change their name or place of operation if the information does not match the information in the digital certificate.
4. For digital certificates of devices, services, or software:
Devices, services, or software change their name or upgrade their version, adding new features if the information does not match the information in the digital certificate.
Article 67. Procedures and Formalities for Changing the Content of Information in a Digital Certificate
1. Request to Change the Content of Information in a Digital Certificate
a) Changing the information content of a digital certificate for an individual:
The individual must submit a written request to change the information content of the digital certificate, confirmed by the directly managing agency or organization, to the organization providing specialized government digital signature certification services;
b) Changing the information content of a digital certificate for individuals with authority according to the laws on management and use of seals and those with state positions:
Individuals with authority according to the laws on management and use of seals and those with state positions must submit a written request to change the information content of the digital certificate and the required documentation as stipulated in to the organization providing specialized government digital signature authentication services. send to the organization providing specialized government digital signature certification services;
c) Changing the information content of a digital certificate for agencies or organizations:
The authorized individual of the agency or organization according to the laws on management and use of seals, designated by the agency or organization to manage the digital certificate of the agency or organization, must submit a written request to change the information content of the digital certificate, confirmed by the directly managing agency or organization, to the organization providing specialized government digital signature certification services;
d) Changing the information content of a digital certificate for devices, services, or software:
The authorized individual of the agency or organization according to the laws on management and use of seals, designated by the agency or organization to manage the digital certificate for devices, services, or software, must submit a written request to change the information content of the digital certificate, confirmed by the directly managing agency or organization, to the organization providing specialized government digital signature certification services.
2. Within three working days from the date of receiving the request to change the information content of the digital certificate, the organization providing specialized government digital signature certification services is responsible for changing the information content of the digital certificate for the subscriber and notifying the directly managing agency or organization.
In case of refusal to accept the request to change the information content of the digital certificate, the organization providing specialized government digital signature certification services must notify in writing, stating the reasons, to the directly managing agency or organization.
Article 68. Cases for Revoking Digital Certificates
1. For all types of digital certificates:
a) The digital certificate has expired;
b) At the written request from the subscriber, confirmed by the direct management agency or organization in cases where the secret key is disclosed or suspected to be disclosed; the secret key storage device is lost or other security breaches occur; the secret key storage device is damaged;
c) At the written request from agencies conducting litigation proceedings or public security agencies;
d) At the written request from the direct management agency or organization;
đ) The subscriber violates regulations on managing and using the secret key storage device as stipulated in Article 74 of this Decree.
2. For individual digital certificates:
a) The cases specified in Clause 1 of this Article;
b) The individual changes their job position and the new job position information does not match the information in the digital certificate;
c) The individual retires, resigns, or passes away.
3. For digital certificates of individuals with authority in agencies or organizations according to laws on seal management and use, and state officials:
a) The cases specified in Clauses 1 and 2 of this Article;
b) The individual changes the authority of the agency or organization according to laws on seal management and use, or changes their state official position.
4. For digital certificates of agencies or organizations:
a) The cases specified in Clause 1 of this Article;
b) The agency or organization is dissolved.
5. For digital certificates of devices, services, software:
a) The cases specified in Clause 1 of this Article;
b) The device, service, or software ceases operation.
Article 69. Authority to Request Revocation of Digital Certificates
1. The government specialized digital signature certification service provider automatically revokes the digital certificate when it expires, and simultaneously notifies the direct management agency or organization about the revocation of the secret key storage device.
2. In cases of revoking digital certificates that do not fall under the expiration case, a written request for revocation must be promptly sent to the direct management agency or organization.
3. When the subscriber is an individual who retires, resigns, transfers to another agency, or passes away, the direct management agency or organization has the authority to request the revocation of the digital certificate and send it to the government specialized digital signature certification service provider.
4. When the subscriber is an organization that is dissolved, the direct management agency or organization has the authority to request the revocation of the digital certificate and send it to the government specialized digital signature certification service provider.
5. Requests for revocation of digital certificates sent to the government specialized digital signature certification service provider must be done as quickly as possible in writing.
Article 70. Documentation, Procedure, and Formalities for Revoking Digital Certificates
1. Documentation for revoking digital certificates includes one of the following documents:
a) A written request for revocation of the digital certificate from an individual, confirmed by the direct management agency or organization;
b) A written request for revocation of the digital certificate from agencies conducting litigation proceedings or public security agencies.
2. Procedure and formalities for revoking digital certificates:
Within twelve hours from receiving the request for revocation of the digital certificate, the government specialized digital signature certification service provider must render the digital certificate ineffective and announce the revocation of the digital certificate on its electronic information website; simultaneously notify the direct management agency or organization about the revocation of the secret key storage device.
Article 71. Recovery of Secret Key Storage Devices After Expiration of Digital Certificates or Revocation of Digital Certificates
1. The subscriber shall be responsible for handing over the secret key storage device to the directly managing agency or organization when the digital certificate expires or is revoked.
2. The directly managing agency or organization of the subscriber shall be responsible for recovering the secret key storage device in cases where the subscriber is an individual who has retired, resigned, or passed away, or where the subscriber is an agency or organization that has been dissolved and transferred to the government-specific digital signature service provider organization.
3. Procedure for recovering the secret key storage device:
a) Within five working days from the date of revoking the digital certificate, the directly managing agency or organization shall be responsible for recovering the secret key storage device of the expired digital certificate or the revoked digital certificate and transferring it to the government-specific digital signature service provider organization;
b) The process of delivering and receiving the secret key storage device must be documented in a record.
Article 72. Issuance of New Digital Certificates After Expiration or Revocation of Old Digital Certificates
1. If the subscriber needs to obtain a new digital certificate after the old digital certificate expires or is revoked and meets the conditions set forth in Article 63 of this Decree, they will be considered for issuance of a new digital certificate. 2. The application procedures and formalities are the same as those for the initial issuance of digital certificates.
Article 73. Restoration of Secret Key Storage Devices
1. In cases requiring restoration of the secret key storage device:
a) The secret key storage device will be locked if the password is entered incorrectly more than the number of times established by the government-specific digital signature service provider organization;
b) To restore the operation of the secret key storage device, the restoration procedure for the secret key storage device must be carried out;
c) Only the government-specific digital signature service provider organization and organizations authorized by the government-specific digital signature service provider organization have the right to restore the secret key storage device;
d) The list of organizations authorized by the government-specific digital signature service provider organization to restore the secret key storage device is published on the electronic information website of the government-specific digital signature service provider organization.
2. Documents for restoring the secret key storage device:
A request for restoration of the secret key storage device from the subscriber, confirmed by the directly managing agency or organization.
3. Procedure for restoring the secret key storage device:
a) The subscriber requesting restoration of the secret key storage device, with confirmation from the directly managing agency, sends the request to the government-specific digital signature service provider organization;
b) Within twenty-four hours from the time of receiving the request for restoration of the secret key storage device, the government-specific digital signature service provider organization or the authorized organization for restoration of the secret key storage device performs the restoration and informs the subscriber requesting restoration of the secret key storage device and the directly managing agency or organization.
Article 74. Management of Secret Key Storage Devices
1. Secret key storage devices must be managed in accordance with current laws.
2. No tools, programs, or other means may be used to alter data or damage the secret key storage device.
2. It is prohibited to use any tools, programs, or any other form to alter data or damage devices storing secret keys.
Chapter VIII. RIGHTS AND OBLIGATIONS OF SUBSCRIBERS, SIGNERS, RECIPIENTS, ORGANIZATIONS AND INDIVIDUALS DEVELOPING APPLICATIONS AND PROVIDING DIGITAL SIGNATURE SOLUTIONS
Article 75. Rights and obligations of subscribers using public digital signature certification services
1. Has the right to request organizations providing public digital signature certification services to provide in writing the information prescribed in Clause 8, Article 32 of this Decree.
2. Has the right to request organizations providing their own digital signature certification services to temporarily suspend, revoke issued digital certificates and bear full responsibility for such requests.
3. Provide information truthfully and accurately as required to organizations providing public digital signature certification services.
4. In case of self-generating key pairs, subscribers must ensure that the key pair generation devices comply with technical standards and mandatory requirements. This provision does not apply to cases where subscribers lease key pair generation devices from organizations providing public digital signature certification services.
5. Safeguard and use their secret keys securely and confidentially throughout the period during which their digital certificates are valid and suspended.
6. Notify the organization providing their digital signature certification service within 24 hours if they discover signs indicating that their secret key has been exposed, stolen, or used improperly so that appropriate measures can be taken.
7. When agreeing to have the organization providing public digital signature certification services publicly announce their digital certificate according to the provisions of Clause 3, Article 25 of this Decree or when providing that digital certificate to others for transaction purposes, the subscriber shall be deemed to have committed to the recipient that the subscriber is the lawful holder of the secret key corresponding to the public key on that digital certificate and that the information on the digital certificate related to the subscriber is true, and must fulfill the obligations arising from that digital certificate.
8. Shall be liable under the law if they violate the provisions of Clauses 3, 4, 5, 6, and 7 of this Article and other relevant laws.
Article 76. Rights and obligations of subscribers using specialized digital signature certification services of agencies and organizations
1. Use the service within the scope prescribed in the certification regulations of the organization providing their digital signature certification service.
2. Safeguard and use their secret keys securely and confidentially throughout the period during which their digital certificates are valid and suspended.
3. Notify the organization providing their digital signature certification service within 24 hours if they discover signs indicating that their secret key has been exposed, stolen, or used improperly so that timely measures can be taken.
Article 77. Rights and obligations of subscribers using foreign digital certificates licensed for use in Vietnam
1. Have rights and obligations similar to those of subscribers using public digital signature certification services within the scope and purpose specified in the license for using foreign digital certificates in Vietnam.
2. Notify the organization providing their digital signature certification service and the Ministry of Information and Communications within 24 hours if they discover signs indicating that their secret key has been exposed, stolen, or used improperly so that timely measures can be taken.
Article 78. Obligations of the Signatory before Digital Signing
Before digital signing, the signatory must perform the following procedures to check the status of their digital certificate as follows:
1. Check the status of their own digital certificate on the technical system of the service provider that issued the digital certificate.
2. In case the signatory uses a digital certificate provided by a public key certification service provider: Check the status of the digital certificate of the certification service provider for themselves on the technical system of the National Certification Service Provider Organization.
3. If the results of checks under paragraphs 1 and 2 of this Article are simultaneously valid, the signatory shall proceed with digital signing. If the result of the check under paragraph 1 or paragraph 2 of this Article is not valid, the signatory shall not proceed with digital signing.
Article 79. Obligation to Verify the Validity of Digital Certificates and Digital Signatures when Receiving Digitally Signed Data Messages
1. Prior to accepting the digital signature of the signatory, the recipient must verify the following information:
a) The status of the digital certificate, scope of use, liability limits, and other information on the digital certificate of the signatory;
b) The digital signature must be created using the private key corresponding to the public key on the digital certificate of the signatory;
c) For digital signatures created using foreign digital certificates licensed for use in Vietnam, the recipient must verify the validity of the digital certificate on both the system of the National Certification Service Provider Organization and the system of the foreign certification service provider issuing the digital certificate.
2. The recipient must follow the verification procedure as follows:
a) Check the status of the digital certificate at the time of signing, scope of use, liability limits, and other information on the digital certificate according to the provisions of Article 5 of this Decree on the technical system of the service provider that issued the digital certificate;
b) In case the signatory uses a digital certificate provided by a public key certification service provider: Check the status of the digital certificate of the certification service provider that issued the digital certificate at the time of signing on the technical system of the National Certification Service Provider Organization;
c) The digital signature on the data message is only valid if the results of the checks under paragraphs 1 and 2 of this Article are simultaneously valid.
3. The recipient shall be responsible in the following cases:
a) Failure to comply with the provisions of paragraphs 1 and 2 of this Article;
b) Knowing or being informed about the untrustworthiness of the digital certificate and the private key of the signatory.
Article 80. Responsibilities of Organizations and Individuals Developing Applications Using Digital Signatures
1. Comply with existing mandatory technical standards and standards regarding digital signatures and certification services.
2. Ensure technological neutrality, not using technical barriers to limit the use of digital signatures from one or several certification service providers.
3. Update digital certificates of certification service providers in applications upon request of such organizations or upon request of competent authorities as prescribed by law to ensure accurate authentication results.
4. Adhere to the procedures for checking the status of digital certificates as stipulated at Article 78 and Clause 2 of Article 79 of this Decree.
Article 81. Responsibilities of organizations and individuals providing digital signature solutions
1. Provide solutions that meet technical standards and mandatory standards regarding digital signatures and digital signature certification services currently in effect.
2. Encourage the provision of solutions that comply with widely recognized and advanced digital signature standards worldwide.
Chapter IX. IMPLEMENTATION PROVISIONS[4]
Article 82. Transitional Provisions
For organizations providing digital signature certification services that are legally operating, within two years from the date this Decree takes effect, they must meet the service provision conditions stipulated in this Decree.
Article 83. Effective Date
1. This Decree shall take effect from November 15, 2018.
2. This Decree replaces Decree No. 26/2007/NĐ-CP dated February 15, 2007 of the Government detailing the implementation of the Law on Electronic Transactions concerning digital signatures and digital signature certification services, Decree No. 106/2011/NĐ-CP dated November 23, 2011 of the Government amending and supplementing certain articles of Decree No. 26/2007/NĐ-CP, and Decree No. 170/2013/NĐ-CP dated November 13, 2013 of the Government amending and supplementing certain articles of Decree No. 26/2007/NĐ-CP and Decree No. 106/2011/NĐ-CP.
Article 84. Implementation Organization and Responsibility for Enforcement
1. Ministries, ministerial-level agencies, government agencies, provinces, centrally governed cities, and organizations related to the application of information technology in state administrative activities and the provision of online public services to citizens and businesses have the responsibility to promote the application and use of digital signatures and digital signature certification services in accordance with the provisions of this Decree to ensure the security of electronic transactions between state agencies and citizens and businesses.
2. Ministers, heads of ministerial-level agencies, heads of government agencies, Chairmen of People's Committees of provinces and centrally governed cities, and relevant organizations and individuals are responsible for enforcing this Decree./.
| MINISTRY OF INFORMATION AND COMMUNICATION Number: 06/VBHN-BTTTT
Place of Receipt: | CERTIFIED CONSOLIDATED DOCUMENT
Hanoi, July 22, 2024
THE MINISTER |
ANNEX
(Attached to Decree No. 130/2018/NĐ-CP dated September 27, 2018 of the Government)
| Form No. 01 | Application for Issuance of License for Providing Public Digital Signature Certification Services |
| Form No. 02 | Application for Change of Content of License for Providing Public Digital Signature Certification Services |
| Implementation Report of Production Projects of Supporting Industry Products Confirmed with Incentives | Application for Reissuance of License for Providing Public Digital Signature Certification Services |
| Form number 04 | Application for Issuance of Digital Certificate |
| Form number 05 | License for Providing Public Digital Signature Certification Services |
| Form number 06 | Application for Issuance of Registration Certificate for Organizations Providing Specialized Digital Signature Certification Services |
| Form No. 07 | Application for Change of Content of Registration Certificate for Organizations Providing Specialized Digital Signature Certification Services |
| Form No. 08 | Application for Reissuance of Registration Certificate for Organizations Providing Specialized Digital Signature Certification Services |
| Form No. 09 | Registration Certificate for Organizations Providing Specialized Digital Signature Certification Services |
| Form No. 10 | Application for Issuance of Certificate of Qualification for Ensuring Security of Specialized Digital Signatures |
| Form No. 11 | Application for Change of Content of Certificate of Qualification for Ensuring Security of Specialized Digital Signatures |
| Form No. 12 | Application for Reissuance of Certificate of Qualification for Ensuring Security of Specialized Digital Signatures |
| Model Number 13 | Certificate of Qualification for Ensuring Security of Specialized Digital Signatures |
| Model No. 14 | Application for Issuance of License for Using Foreign Digital Certificates in Vietnam |
| Model Number 15 | License for Using Foreign Digital Certificates in Vietnam |
Form No. 01
| (Enterprise Name) | SOCIALIST REPUBLIC OF VIET NAM |
| Number: ……. | …., day ….. month ….. year ….. |
APPLICATION FOR ISSUANCE OF LICENSE FOR PROVIDING PUBLIC DIGITAL SIGNATURE CERTIFICATION SERVICES
Respectfully submitted to: Ministry of Information and Communications.
Pursuant to the Electronic Transactions Law dated November 29, 2005;
Pursuant to Decree No. /2018/NĐ-CP dated month year 2018 of the Government detailing the implementation of the Law on Electronic Transactions concerning digital signatures and digital signature certification services;
(Name of enterprise) requests the Ministry of Information and Communications to issue a license for providing public digital signature certification services with the following contents:
1. Information about the enterprise requesting the license
Vietnamese trading name: …
Vietnamese abbreviated name: …
English trading name: …
English abbreviated name: …
Business registration certificate number …issued by …on... month... year...
Address: …
Telephone: …Fax: …
Email: …Website: …
Name and contact address of the person responsible for managing the system: …
2. Documents for applying for a license to provide public digital signature certification services
| Serial number | Name of document | Quantity | Remarks |
| 1 |
|
|
|
| 2 |
|
|
|
| 3 |
|
|
|
| … |
|
|
|
3. Commitment
(Name of enterprise) commits to being responsible for the accuracy of the above-provided information and accompanying documents and commits to complying with laws on digital signatures, digital signature certification services, and related laws./.
|
| LEGAL REPRESENTATIVE |
Form No. 02
| (Enterprise Name) | SOCIALIST REPUBLIC OF VIET NAM |
| Number: ……. | …., day …. month ….. year ….. |
APPLICATION FOR CHANGE OF CONTENT OF LICENSE FOR PROVIDING PUBLIC DIGITAL SIGNATURE CERTIFICATION SERVICES
Respectfully submitted to: Ministry of Information and Communications.
Pursuant to the Law on Electronic Transactions dated November 29, 2005;
Pursuant to Decree No.../2018/NĐ-CP dated... month... year 2018 of the Government detailing the implementation of the Law on Electronic Transactions concerning digital signatures and digital signature certification services;
Pursuant to the License for Providing Public Digital Signature Certification Services No…/GP-BTTTT issued by the Ministry of Information and Communications on... month... year...;
(Name of enterprise) requests the Ministry of Information and Communications to change the content of the License for Providing Public Digital Signature Certification Services No……./GP-BTTTT as follows:
1. Reason for changing the content of the license
………………………………………………………………………………………………………….
………………………………………………………………………………………………………
………………………………………………………………………………………………………
………………………………………………………………………………………………………
………………………………………………………………………………………………………
2. Content of the license requested to be changed
……………………………………………………………………………………………………….
………………………………………………………………………………………………………
………………………………………………………………………………………………………
………………………………………………………………………………………………………
………………………………………………………………………………………………………
3. Documents for changing the content of the license
| Serial number | Name of document | Quantity | Remarks |
| 1 |
|
|
|
| 2 |
|
|
|
| 3 |
|
|
|
| … |
|
|
|
4. Commitment
(Name of enterprise) commits to being responsible for the accuracy of the above-provided information and accompanying documents and commits to complying with laws on digital signatures, digital signature certification services, and related laws./.
|
| LEGAL REPRESENTATIVE |
Implementation Report of Production Projects of Supporting Industry Products Confirmed with Incentives
| (Enterprise Name) | SOCIALIST REPUBLIC OF VIET NAM |
| No.:……… | ……., day ….. month …… year ….. |
APPLICATION FOR REISSUANCE OF LICENSE FOR PROVIDING PUBLIC DIGITAL SIGNATURE CERTIFICATION SERVICES
Respectfully submitted to: Ministry of Information and Communications.
Pursuant to the Electronic Transactions Law dated November 29, 2005;
Pursuant to Decree No.../2018/NĐ-CP dated…..month…..year 2018 of the Government detailing the implementation of the Law on Electronic Transactions concerning digital signatures and digital signature certification services;
Pursuant to the License for Providing Public Digital Signature Certification Services No…/GP-BTTTT issued by the Ministry of Information and Communications on... month... year...;
(Name of enterprise) requests the Ministry of Information and Communications to reissue License No…../GP-BTTTT with the following contents:
1. Trading name of the organization providing public digital signature certification services requesting reissuance of the license
………………………………………………………………………………………………………
………………………………………………………………………………………………………
………………………………………………………………………………………………………
2. Reason for requesting reissuance of the license
………………………………………………………………………………………………………
………………………………………………………………………………………………………
………………………………………………………………………………………………………
………………………………………………………………………………………………………
3. Documents for reissuing the license
| Serial number | Name of document | Quantity | Remarks |
| 1 |
|
|
|
| 2 |
|
|
|
| 3 |
|
|
|
| … |
|
|
|
4. Commitment
(Name of enterprise) commits to being responsible for the accuracy of the above-provided information and accompanying documents and commits to complying with laws on digital signatures, digital signature certification services, and related laws./.
|
| LEGAL REPRESENTATIVE |
Form number 04
| (Enterprise Name) | SOCIALIST REPUBLIC OF VIET NAM |
| No.:... | …, day …… month ….. year … |
APPLICATION FOR ISSUANCE OF DIGITAL CERTIFICATE
Respected National Electronic Certification Center,
Pursuant to the Law on Electronic Transactions dated November 29, 2005;
Pursuant to Decree No.../2018/NĐ-CP dated month year 2018 of the Government detailing the implementation of the Law on Electronic Transactions regarding digital signatures and digital signature certification services;
Pursuant to Public Digital Signature Certification Service License No…./GP-BTTTT issued by the Ministry of Information and Communications on... month... year...;
(Name of the organization providing public digital signature certification service) hereby requests the National Electronic Certification Center to issue a digital certificate with the following content:
1. Information about the enterprise requesting issuance of the digital certificate
Trade name of the organization providing public digital signature certification service:
English trading name:
Public Digital Signature Certification Service License No…./GP-BTTTT issued by the Ministry of Information and Communications on... month... year...
Address: …
Telephone: …Fax: …
Email: …Website: …
2. Documents accompanying the request for issuance of the digital certificate
| Serial number | Name of document | Quantity | Remarks |
| 1 |
|
|
|
| ... |
|
|
|
3. Commitment
(Name of the organization providing public digital signature certification service) hereby undertakes responsibility for the accuracy of the information provided above and accompanying documents, and commits to comply with laws related to digital signatures, digital signature certification services, and relevant laws./.
|
| LEGAL REPRESENTATIVE |
Form number 05
| MINISTRY OF INFORMATION AND COMMUNICATION | SOCIALIST REPUBLIC OF VIET NAM |
| No.: /GP-BTTTT | Hanoi, on... day... month... year... |
LICENSE
PROVIDING PUBLIC DIGITAL SIGNATURE CERTIFICATION SERVICE
(Valid until.../.../…)
MINISTER OF INFORMATION AND COMMUNICATIONS
Pursuant to the Electronic Transactions Law dated November 29, 2005;
Pursuant to Decree No.../2018/NĐ-CP dated... month... year 2018 of the Government detailing the implementation of the Law on Electronic Transactions concerning digital signatures and digital signature certification services;
Upon reviewing the application for a license to provide public digital signature certification service dated... month... year... submitted by (Name of the enterprise);
At the proposal of the Director of the National Electronic Certification Center,
NOW PERMITS
Article 1. (NAME OF THE ENTERPRISE), English trade name: (ENGLISH NAME), headquartered at…, holding Business Registration Certificate No:…issued by……on... month... year..., is granted the provision of public digital signature certification service with the specific contents as follows:
1. Trade name of the organization providing public digital signature certification service: …
…………………………………………………………………………………………………………
2. Scope and target of service provision
The organization providing public digital signature certification service (Name of the organization providing public digital signature certification service) is authorized to provide digital signature certification service to agencies, organizations, and individuals using it in public activities.
3. Types of digital certificates
The organization providing public digital signature certification service (Name of the organization providing public digital signature certification service) is authorized to provide the following types of digital certificates:
…………………………………………………………………………………………………………
…………………………………………………………………………………………………………
4. Method of storing the private key of the subscriber
The method of storing the private key of the subscriber of the organization providing public digital signature certification service (Name of the organization providing public digital signature certification service) is as follows:
…………………………………………………………………………………………………………
…………………………………………………………………………………………………………
5. Technical standards and applicable standards
The technical system providing service of the organization providing public digital signature certification service (Name of the organization providing public digital signature certification service) must comply with mandatory technical standards and standards applicable to digital signatures and digital signature certification services currently in effect.
Article 2. In addition to the provisions of Article 1, (Name of the enterprise) shall be responsible for complying with laws related to digital signatures, digital signature certification services, and relevant laws.
Article 3. This license takes effect from the date of signing./.
|
| THE MINISTER |
Form number 06
| (Name of the agency, organization) | SOCIALIST REPUBLIC OF VIET NAM |
| No.:... | …, on ….. day…. month…. year….. |
APPLICATION FOR ISSUANCE OF BUSINESS REGISTRATION CERTIFICATE FOR ORGANIZATION PROVIDING SPECIALIZED DIGITAL SIGNATURE CERTIFICATION SERVICE
Respectfully submitted to: Ministry of Information and Communications.
Pursuant to the Law on Electronic Transactions dated November 29, 2005;
Pursuant to Decree No /2018/NĐ-CP dated... month... year 2018 of the Government detailing the implementation of the Law on Electronic Transactions regarding digital signatures and digital signature certification services;
(Name of the agency, organization) requests the Ministry of Information and Communications to approve the registration of the organization providing specialized digital signature certification service with the following contents:
1. Information about the agency, organization
Vietnamese trade name:
English trading name:
Decision on establishment/Decision on functions and responsibilities No …issued by …on... month... year... (if any)
Business License No …issued by …on... month... year... (if any)
Address: …
………………………………………………………………………………………………………..
Telephone: …Fax: …
Email: …Website: …
Name of the legal representative of the agency/organization:
Name of the person responsible for managing the system:
2. Documents sent along with the application
| Serial number | Name of document | Quantity | Remarks |
| 1 |
|
|
|
| 2 |
|
|
|
| 3 |
|
|
|
| … |
|
|
|
3. Commitment
(Agency, organization) hereby undertakes responsibility for the accuracy of the information provided above and accompanying documents, and commits to comply with laws related to digital signatures, digital signature certification services, and relevant laws./.
|
| LEGAL REPRESENTATIVE |
Form No. 07
| (Name of the agency, organization) | SOCIALIST REPUBLIC OF VIET NAM |
| No.: … | …, on …day…. month…. year….. |
APPLICATION FOR AMENDMENT OF CONTENTS OF BUSINESS REGISTRATION CERTIFICATE FOR ORGANIZATION PROVIDING SPECIALIZED DIGITAL SIGNATURE CERTIFICATION SERVICE
Respectfully submitted to: Ministry of Information and Communications.
Pursuant to the Law on Electronic Transactions dated November 29, 2005;
Pursuant to Decree No... dated... month... year 2018 of the Government detailing the implementation of the Law on Electronic Transactions regarding digital signatures and digital signature certification services;
Pursuant to Specialized Digital Signature Certification Service Business Registration Certificate No…/GCN-BTTTT issued by the Ministry of Information and Communications on... month... year...;
(Name of the agency, organization) requests the Ministry of Information and Communications to amend the contents of Specialized Digital Signature Certification Service Business Registration Certificate No …/GCN-BTTTT, specifically as follows:
1. Reason for amending the contents of the business registration certificate
……………………………………………………………………………………………………….
………………………………………………………………………………………………………..
………………………………………………………………………………………………………..
2. Contents of the business registration certificate to be amended
………………………………………………………………………………………………………...
…………………………………………………………………………………………………………
…………………………………………………………………………………………………………
3. Documents accompanying the request for amendment of the business registration certificate
| Serial number | Name of document | Quantity | Remarks |
| 1 |
|
|
|
| 2 |
|
|
|
| 3 |
|
|
|
| … |
|
|
|
4. Commitment
(Agency, organization) hereby undertakes responsibility for the accuracy of the information provided above and accompanying documents, and commits to comply with laws related to digital signatures, digital signature certification services, and relevant laws./.
|
| LEGAL REPRESENTATIVE |
Form No. 08
| (Name of the agency, organization) | SOCIALIST REPUBLIC OF VIET NAM |
| No.: ... | ………, on ….. day…. month…. year….. |
APPLICATION FOR REISSUANCE OF BUSINESS REGISTRATION CERTIFICATE FOR ORGANIZATION PROVIDING SPECIALIZED DIGITAL SIGNATURE CERTIFICATION SERVICE
Respectfully submitted to: Ministry of Information and Communications.
Pursuant to the Electronic Transactions Law dated November 29, 2005;
Pursuant to Decree No.../2018/NĐ-CP dated month year 2018 of the Government detailing the implementation of the Law on Electronic Transactions regarding digital signatures and digital signature certification services;
Pursuant to Specialized Digital Signature Certification Service Business Registration Certificate No…/GCN-BTTTT issued by the Ministry of Information and Communications on... month... year...;
(Name of the agency, organization) requests the Ministry of Information and Communications to reissue Specialized Digital Signature Certification Service Business Registration Certificate No…/GCN-BTTTT with the following contents:
1. Trade name of the organization providing specialized digital signature certification service requesting reissuance of the business registration certificate
………………………………………………………………………………………………………
………………………………………………………………………………………………………
………………………………………………………………………………………………………
2. Reason for requesting reissuance of the business registration certificate
………………………………………………………………………………………………………
………………………………………………………………………………………………………
………………………………………………………………………………………………………
3. Documents accompanying the request for reissuance of the business registration certificate
| Serial number | Name of document | Quantity | Remarks |
| 1 |
|
|
|
| 2 |
|
|
|
| ... |
|
|
|
4. Commitment
(Agency, organization) hereby undertakes responsibility for the accuracy of the information provided above and accompanying documents, and commits to comply with laws related to digital signatures, digital signature certification services, and relevant laws./.
|
| LEGAL REPRESENTATIVE |
Form No. 09
| MINISTRY OF INFORMATION AND COMMUNICATION | SOCIALIST REPUBLIC OF VIET NAM |
| No: /GCN-BTTTT | Hanoi, on ….. day…. month…. year….. |
BUSINESS REGISTRATION CERTIFICATE FOR ORGANIZATION PROVIDING SPECIALIZED DIGITAL SIGNATURE CERTIFICATION SERVICE
(Valid until.../.../…)
MINISTER OF INFORMATION AND COMMUNICATIONS
Pursuant to the Electronic Transactions Law dated November 29, 2005;
Pursuant to Decree No.../2018/NĐ-CP dated... month... year 2018 of the Government detailing the implementation of the Law on Electronic Transactions concerning digital signatures and digital signature certification services;
CONSIDERING the application for issuance of the certificate of operation of the organization providing specialized digital signature authentication services on... day... month... year... of (Name of agency/company);
At the proposal of the Director of the National Electronic Certification Center,
NOW CERTIFY
Article 1. (NAME OF THE ORGANIZATION), English trading name: (ENGLISH NAME), with its headquarters at..., established by Decision No... issued on... day... month... year... (if applicable) or has Business Registration Certificate No:... issued by... on... day... month... year... (if applicable), is granted the service of providing specialized digital signature authentication with the following specific contents:
1. Trading name of the organization providing specialized digital signature authentication service: ……
………………………………………………………………………………………………………
2. Scope and target of service provision
The organization providing specialized digital signature authentication service (Name of the organization providing specialized digital signature authentication service) is authorized to provide digital signature authentication services to agencies, organizations, and individuals using them in specialized activities or fields with similar nature or purpose of work.
Article 2. In addition to the provisions of Article 1, the organization providing specialized digital signature authentication service (Name of the organization providing specialized digital signature authentication service) shall be responsible for complying with the laws on digital signatures, digital signature authentication services, and related laws.
Article 3. This certificate takes effect from the date of signing./.
|
| THE MINISTER |
Form No. 10
| (Name of the agency, organization) | SOCIALIST REPUBLIC OF VIET NAM |
| No.:... | ………, day …… month ……. year … |
APPLICATION FOR ISSUANCE OF CERTIFICATE MEETING THE REQUIREMENTS FOR SECURING SPECIALIZED DIGITAL SIGNATURES
Respectfully submitted to: Ministry of Information and Communications.
Pursuant to the Electronic Transactions Law dated November 29, 2005;
Pursuant to Decree No.../2018/NĐ-CP dated... month... year 2018 of the Government detailing the implementation of the Law on Electronic Transactions concerning digital signatures and digital signature certification services;
Based on the certificate of registration for operation of the organization providing specialized digital signature authentication service (name of the organization) No…../GCN-BTTTT issued by the Ministry of Information and Communications on... day... month... year...;
(Name of the organization providing specialized digital signature authentication service) requests the Ministry of Information and Communications to issue a certificate meeting the requirements for securing specialized digital signatures with the following contents:
1. Information about the agency, organization
Vietnamese trading name: …
English trading name: …
Establishment Decision/Decision specifying functions and tasks No ……… issued by ……… on... day... month... year... (if applicable)
Business License No... issued by... on... day... month... year... (if applicable)
Address: …
Telephone: …Fax: …
Email: …Website: …
Name of the person responsible for managing the system:
…………………………………………………………………………………………………………
…………………………………………………………………………………………………………
2. Application for issuance of certificate meeting the requirements for securing specialized digital signatures
| Serial number | Name of document | Quantity | Remarks |
| 1 |
|
|
|
| 2 |
|
|
|
| … |
|
|
|
3. Commitment
(Name of the organization providing specialized digital signature authentication service) commits to being responsible for the accuracy of the information provided above and accompanying documents, and commits to comply with the laws on digital signatures, digital signature authentication services, and related laws./.
|
| LEGAL REPRESENTATIVE |
Form No. 11
| (Name of the agency, organization) | SOCIALIST REPUBLIC OF VIET NAM |
| No.:... | …., day ….. month ….. year …… |
APPLICATION FOR AMENDMENT OF CONTENTS OF THE CERTIFICATE MEETING THE REQUIREMENTS FOR SECURING SPECIALIZED DIGITAL SIGNATURES
Respectfully submitted to: Ministry of Information and Communications.
Pursuant to the Electronic Transactions Law dated November 29, 2005;
Based on Decree No.../2018/NĐ-CP dated day month year 2018 of the Government detailing the implementation of the Law on Electronic Transactions regarding digital signatures and digital signature authentication services;
Based on the certificate meeting the requirements for securing specialized digital signatures No …/GCN-BTTTT issued by the Ministry of Information and Communications on... day... month... year...;
(Name of the organization providing specialized digital signature authentication service) requests the Ministry of Information and Communications to amend the contents of the certificate meeting the requirements for securing specialized digital signatures No …./GCN-BTTTT, specifically as follows:
1. Reason for amending the contents of the business registration certificate
………………………………………………………………………………………………………
………………………………………………………………………………………………………
………………………………………………………………………………………………………
2. Contents of the certificate to be amended
………………………………………………………………………………………………………
………………………………………………………………………………………………………
………………………………………………………………………………………………………
3. Application for amendment of contents of the certificate meeting the requirements for securing specialized digital signatures
| Serial number | Name of document | Quantity | Remarks |
| 1 |
|
|
|
| 2 |
|
|
|
| … |
|
|
|
4. Commitment
(Name of the organization providing specialized digital signature authentication service) commits to being responsible for the accuracy of the information provided above and accompanying documents, and commits to comply with the laws on digital signatures, digital signature authentication services, and related laws./.
|
| LEGAL REPRESENTATIVE |
Form No. 12
| (Name of the agency, organization) | SOCIALIST REPUBLIC OF VIET NAM |
| No.:... | ……, day …… month ….. year ….. |
APPLICATION FOR REISSUE OF THE CERTIFICATE MEETING THE REQUIREMENTS FOR SECURING SPECIALIZED DIGITAL SIGNATURES
Respectfully submitted to: Ministry of Information and Communications.
Pursuant to the Electronic Transactions Law dated November 29, 2005;
Based on Decree No.../2018/NĐ-CP dated day month year 2018 of the Government detailing the implementation of the Law on Electronic Transactions regarding digital signatures and digital signature authentication services;
Based on the certificate meeting the requirements for securing specialized digital signatures No …/GCN-BTTTT issued by the Ministry of Information and Communications on... day... month... year...;
(Name of the organization providing specialized digital signature authentication service requests the Ministry of Information and Communications to reissue Certificate No …/GCN-BTTTT with the following contents:
1. Trading name of the organization providing specialized digital signature authentication service requesting reissuance of the certificate meeting the requirements for securing specialized digital signatures
………………………………………………………………………………………………………
………………………………………………………………………………………………………
2. Reason for requesting reissuance of the business registration certificate
………………………………………………………………………………………………………
………………………………………………………………………………………………………
3. Application for reissuance of the certificate ensuring security for specialized digital signatures
| Serial number | Name of document | Quantity | Remarks |
| 1 |
|
|
|
| 2 |
|
|
|
| 3 |
|
|
|
| … |
|
|
|
4. Commitment
(Name of the organization providing specialized digital signature authentication service) commits to being responsible for the accuracy of the information provided above and accompanying documents, and commits to comply with the laws on digital signatures, digital signature authentication services, and related laws./.
|
| LEGAL REPRESENTATIVE |
Model Number 13
| MINISTRY OF INFORMATION AND COMMUNICATION | SOCIALIST REPUBLIC OF VIET NAM |
| No: /GCN-BTTTT | Hanoi, day ….. month …. year …. |
CERTIFICATE OF INSURANCE OR OTHER FINANCIAL SECURITY
MEETING THE REQUIREMENTS FOR SECURING SPECIALIZED DIGITAL SIGNATURES
(Valid until.../.../…)
MINISTER OF INFORMATION AND COMMUNICATIONS
Pursuant to the Electronic Transactions Law dated November 29, 2005;
Based on Decree No …/2018/NĐ-CP dated day month year 2018 of the Government detailing the implementation of the Law on Electronic Transactions regarding digital signatures and digital signature authentication services;
CONSIDERING the application for issuance of the certificate meeting the requirements for securing specialized digital signatures on... day... month... year... of (Name of agency/company);
At the proposal of the Director of the National Electronic Certification Center,
NOW CERTIFY
Article 1. (NAME OF AUTHORITY/ORGANIZATION), English trade name: (ENGLISH NAME), headquartered at..., holds Certificate of Operation Registration for Digital Signature Service Providers No. .../GCN-BTTTT dated... month... year... issued by the Ministry of Information and Communications, certified to meet the security requirements for specialized digital signatures with the following specific contents:
1. Trading name of the organization providing specialized digital signature authentication service: ……
………………………………………………………………………………………………………
2. Scope and target of service provision
The organization providing specialized digital signature authentication service (Name of the organization providing specialized digital signature authentication service) is authorized to provide digital signature authentication services to agencies, organizations, and individuals using them in specialized activities or fields with similar nature or purpose of work.
3. Method of storing the subscriber's secret key
The method of storing the subscriber's secret key of the Digital Signature Service Provider Organization (Name of Digital Signature Service Provider Organization) is as follows:
………………………………………………………………………………………………………
………………………………………………………………………………………………………
………………………………………………………………………………………………………
4. Technical standards and applicable standards
The technical system providing services of the Digital Signature Service Provider Organization (Name of Digital Signature Service Provider Organization) must comply with the mandatory technical standards and standards on digital signatures and digital signature certification services currently in effect.
Article 2. In addition to the provisions of Article 1, (Name of Digital Signature Service Provider Organization) is responsible for complying with the laws on digital signatures, digital signature certification services, and related laws.
Article 3. The certificate of meeting the security requirements for specialized digital signatures is effective from the date of signing./.
|
| THE MINISTER |
Model No. 14
| (Name of the agency, organization) | SOCIALIST REPUBLIC OF VIET NAM |
| Number:... | ..., day.... month.... year..... |
APPLICATION FOR ISSUANCE OF LICENSE TO USE FOREIGN DIGITAL CERTIFICATES IN VIETNAM
Respectfully submitted to: Ministry of Information and Communications.
Pursuant to the Electronic Transactions Law dated November 29, 2005;
Pursuant to Decree No.../2018/NĐ-CP dated... month... year 2018 of the Government detailing the implementation of the Law on Electronic Transactions regarding digital signatures and digital signature certification services,
(Name of organization/person) requests the Ministry of Information and Communications to issue a license to use foreign digital certificates in Vietnam with the following contents:
1. Information about individual/organization
Vietnamese trading name/Full name:...
Decision on establishment/Business license (for organizations) No... issued by... on... month... year...
Identity card/Passport (for individuals) No... issued by... on... month... year...
Address: …
Telephone:... Fax (for organizations):...
Email:... Website (for organizations):...
Type of digital certificate:... issued by the organization (name of foreign digital signature certification service provider organization).
Serial Number (SN):...
Common Name (CN):...
Validity period of use from... to...
2. Application dossier for issuance of license to use foreign digital certificates accepted in Vietnam
| Serial number | Name of document | Quantity | Remarks |
| 1 |
|
|
|
| 2 |
|
|
|
| … |
|
|
|
3. Commitment
(Name of organization/person) commits to be responsible for the accuracy of the information provided above and accompanying documents, and commits to comply with the laws on digital signatures, digital signature certification services, and related laws./.
|
| (INDIVIDUAL/LEGAL REPRESENTATIVE OF THE ORGANIZATION) |
Model Number 15
| MINISTRY OF INFORMATION AND COMMUNICATION | SOCIALIST REPUBLIC OF VIET NAM |
| No.: /GP-BTTTT | Hanoi, day.... month.... year..... |
LICENSE
USE OF FOREIGN DIGITAL CERTIFICATES IN VIETNAM
(Valid until.../.../…)
MINISTER OF INFORMATION AND COMMUNICATIONS
Pursuant to the Electronic Transactions Law dated November 29, 2005;
Pursuant to Decree No.../2018/NĐ-CP dated... month... year 2018 of the Government detailing the implementation of the Law on Electronic Transactions concerning digital signatures and digital signature certification services;
Considering the application dossier for issuance of license to use foreign digital certificates in Vietnam dated... month... year... submitted by (Name of organization/person);
At the proposal of the Director of the National Electronic Certification Center,
NOW PERMITS
Article 1. (NAME OF ORGANIZATION/PERSON), English trade name: (ENGLISH NAME FOR ORGANIZATIONS), located at..., holds Decision on Establishment/Business License/Identity Card/Passport:... issued by... on... month... year..., is allowed to use foreign digital certificates in Vietnam with the following specific contents:
1. Information on foreign digital certificates
Type of digital certificate:... issued by the organization (name of foreign digital signature certification service provider organization).
Serial Number:...
Validity Period of Use:...
2. Scope of Use
………………………………………………………………………………………………………
………………………………………………………………………………………………………
Article 2. In addition to the provisions of Article 1, (Name of organization/person) is responsible for complying with Vietnamese laws, fully performing the rights and obligations of organizations/individuals using foreign digital certificates in Vietnam as stipulated in the Law on Electronic Transactions, Decree No.../2018/NĐ-CP dated... month... year 2018 of the Government detailing the implementation of the Law on Electronic Transactions regarding digital signatures and digital signature certification services, and other relevant legal documents issued by state management agencies./.
|
| THE MINISTER |
___________________________
[1] Decree No. 48/2024/NĐ-CP dated May 9, 2024 of the Government amending and supplementing some articles of Decree No. 130/2018/NĐ-CP dated September 27, 2018 of the Government detailing the implementation of the Law on Electronic Transactions regarding digital signatures and digital signature certification services has the following basis for promulgation:
"Pursuant to the Law on Organization of the Government dated June 19, 2015; the Law Amending and Supplementing Certain Articles of the Law on Organization of the Government and the Law on Organization of Local Administration dated November 22, 2019;
Pursuant to the Law on Electronic Transactions dated November 29, 2005;
Pursuant to the Law on Information Technology dated June 29, 2006;
At the proposal of the Minister of Information and Communications;
The Government promulgates this Decree to amend and supplement some articles of Decree No. 130/2018/NĐ-CP dated September 27, 2018 of the Government detailing the implementation of the Law on Electronic Transactions regarding digital signatures and digital signature certification services.”
[2] Điều này được sửa đổi, bổ sung theo quy định tại khoản 1 Điều 1 của Nghị định số 48/2024/NĐ-CP ngày 09 tháng 5 năm 2024 của Chính phủ sửa đổi, bổ sung một số điều của Nghị định số 130/2018/NĐ-CP ngày 27 tháng 9 năm 2018 của Chính phủ quy định chi tiết thi hành Luật Giao dịch điện tử về chữ ký số và dịch vụ chứng thực chữ ký số, có hiệu lực kể từ ngày 09 tháng 5 năm 2024.
[3] Điểm này được sửa đổi, bổ sung theo quy định tại khoản 2 Điều 1 của Nghị định số 48/2024/NĐ-CP ngày 09 tháng 5 năm 2024 của Chính phủ sửa đổi, bổ sung một số điều của Nghị định số 130/2018/NĐ-CP ngày 27 tháng 9 năm 2018 của Chính phủ quy định chi tiết thi hành Luật Giao dịch điện tử về chữ ký số và dịch vụ chứng thực chữ ký số, có hiệu lực kể từ ngày 09 tháng 5 năm 2024.
[4] Điều 2 và Điều 3 của Nghị định số 48/2024/NĐ-CP ngày 09 tháng 5 năm 2024 của Chính phủ sửa đổi, bổ sung một số điều của Nghị định số 130/2018/NĐ-CP ngày 27 tháng 9 năm 2018 của Chính phủ quy định chi tiết thi hành Luật Giao dịch điện tử về chữ ký số và dịch vụ chứng thực chữ ký số, có hiệu lực kể từ ngày 09 tháng 5 năm 2024 quy định như sau:
“Điều 2. Điều khoản thi hành
1. Nghị định này có hiệu lực thi hành kể từ ngày ký ban hành.
2. Bộ trưởng, Thủ trưởng cơ quan ngang bộ, Thủ trưởng cơ quan thuộc Chính phủ, Chủ tịch Ủy ban nhân dân các cấp và các cơ quan, tổ chức, cá nhân có liên quan chịu trách nhiệm thi hành Nghị định này.
Điều 3. Điều khoản chuyển tiếp
1. Đối với hồ sơ cấp chứng thư số của thuê bao đã nộp cho Tổ chức cung cấp dịch vụ chứng thực chữ ký số công cộng nhưng đến ngày Nghị định này có hiệu lực thi hành chưa được cấp chứng thư số thì tiếp tục thực hiện theo quy định của Nghị định số 130/2018/NĐ-CP ngày 27 tháng 9 năm 2018 của Chính phủ quy định chi tiết thi hành Luật Giao dịch điện tử về chữ ký số và dịch vụ chứng thực chữ ký số, trừ trường hợp các bên lựa chọn áp dụng quy định của Nghị định này.
2. Đối với hồ sơ cấp giấy phép sử dụng chứng thư số nước ngoài tại Việt Nam đã nộp cho cơ quan nhà nước có thẩm quyền nhưng đến ngày Nghị định này có hiệu lực thi hành chưa được cấp giấy phép sử dụng chứng thư số nước ngoài tại Việt Nam thì tiếp tục thực hiện theo quy định của Nghị định số 130/2018/NĐ-CP ngày 27 tháng 9 năm 2018 của Chính phủ quy định chi tiết thi hành Luật Giao dịch điện tử về chữ ký số và dịch vụ chứng thực chữ ký số.”
Văn bản gốc (PDF)
Bản đồ quan hệ
Bấm vào một văn bản để mở. Viền đỏ = quan hệ làm thay đổi hiệu lực.
Bản dịch
Văn bản này có sẵn ở các ngôn ngữ sau: