This Circular amends and supplements many contents related to the management of digital certificates in the banking system, including the responsibilities of certificate management organizations, registration procedures, information changes, suspension or revocation of digital certificates. The Circular also stipulates periodic and extraordinary reporting requirements for organizations using the State Bank's digital signature verification services.
적용 범위
This Circular applies to units under the State Bank, credit institutions, foreign bank branches, National Treasury, Deposit Insurance Corporation of Vietnam, Vietnam National Payment Corporation Joint Stock Company, and Asset Management Corporation of Credit Institutions of Vietnam.
핵심 사항
- Amending the responsibilities of certificate management organizations
- Provisions on registration, information changes, suspension or revocation of digital certificates
- Supplementing periodic and extraordinary reporting requirements for organizations using the State Bank's digital signature verification services
- Changing the name of the unit from 'Information Technology Center' to 'Information Technology Center'
- Issuing new forms to replace old forms
🌐 이 문서의 사회적 영향
- Enhancing the efficiency of digital certificate management and use in the banking system
- Reducing cyber security risks through strict management of information and storage devices for secret keys of digital certificates
❓ 자주 묻는 질문
When does this Circular take effect?
This Circular takes effect from January 1, 2021.
Which organizations must comply with this Circular?
This Circular applies to units under the State Bank, credit institutions, foreign bank branches, National Treasury, Deposit Insurance Corporation of Vietnam, Vietnam National Payment Corporation Joint Stock Company, and Asset Management Corporation of Credit Institutions of Vietnam.
What regulations does this Circular replace?
This Circular abolishes Clause 6 Article 1 and Clause 4 Article 2 of Circular No. 14/2019/TT-NHNN dated August 30, 2019 amending and supplementing certain provisions of Circulars concerning the periodic reporting regime of the State Bank.
전문
CIRCULAR
Amending and supplementing some articles of Circular No. 28/2015/TT-NHNN dated December 18, 2015, issued by the Governor of the State Bank of Vietnam on the management and use of digital signatures, digital certificates, and digital signature verification services of the State Bank of Vietnam.
Pursuant to the Law on the State Bank of Vietnam dated June 16, 2010;
Pursuant to the Law on Credit Institutions dated June 16, 2010 and the Law Amending and Supplementing Certain Articles of the Law on Credit Institutions dated November 20, 2017;
Pursuant to the Law on Information Technology dated June 29, 2006;
Pursuant to the Law on Electronic Transactions dated November 29, 2005;
Pursuant to Decree No. 130/2018/NĐ-CP dated September 27, 2018 of the Government detailing the implementation of the Law on Electronic Transactions regarding digital signatures and digital signature certification services;
Decree No. Decision No. 16/2017/NĐ-CP dated February 17, 2017, of the Government stipulating the functions, tasks, powers, and organizational structure of the State Bank of Vietnam;
At the proposal of the Director of the Department of Information Technology; information;
The Governor of the State Bank of Vietnam issues this Circular to amend and supplement some articles of Circular No. 28/2015/TT-NHNN dated December 18, 2015, issued by the Governor of the State Bank of Vietnam on the management and use of digital signatures, digital certificates, and digital signature verification services of the State Bank of Vietnam (hereinafter referred to as Circular 28/2015/TT-NHNN).
Article 1. Amending and supplementing certain articles of Circular 28/2015/TT-NHNN
Article 1 shall be amended and supplemented as follows:
"This Circular stipulates the management and use of digital signatures, digital certificates, and digital signature verification services of the State Bank of Vietnam (hereinafter referred to as the State Bank)."
Clause 1 of Article 2 shall be amended and supplemented as follows:
"Units under the State Bank; credit organizations; foreign bank branches; National Treasury; Deposit Insurance of Vietnam."
3. Adding Clauses 11, 12, 13, 14, and 15 to Article 3 as follows:
"11. 'Activation code' means information including reference number and authentication code used for authentication during the activation process of digital certificates.
12. 'Activation of digital certificate' refers to the process of generating a pair of digital certificate keys consisting of a private key and a public key and storing them in a private key storage device.
13. 'Authorized person' refers to the leadership of the State Bank, the leadership of units under the State Bank, or a legally authorized representative according to the law of the agencies and organizations specified in Article 2 of this Circular.
14. 'Public service system' refers to the electronic portal providing online public services of the State Bank.
15. 'Digital certificate transaction' refers to transactions on information systems where subscribers can use digital certificates to approve or authenticate. A digital certificate may be used to approve or authenticate one or more transactions on one or more information systems. Information systems using State Bank digital certificates include:
a) Public service system;
b) Inter-bank electronic payment system;
c) State Bank reporting system;
d) Tendering system and open market operations business comprising sub-businesses:
- Tenders and open market operations;
- Issuance of State Bank bills;
d) The information system supporting management, supervision, and prevention of fraud risks in payment activities;
đ) Deposit Insurance Corporation of Vietnam reporting system;
e) Other systems determined by the Governor of the State Bank."
4. Adding Article 4a as follows:
"Article 4a. Methods of submitting and receiving applications, documents, reports related to digital signature verification services and processing results
1. The managing organization of subscribers submits applications, documents, and reports related to digital certificates and digital signature verification services to the State Bank (Information Technology Department) through one of the following methods:
a) Electronic method via the Public Service System;
b) Paper documents submitted directly at the One-Stop Service Center or sent via postal service. The State Bank (Information Technology Department) will only accept and process paper documents in the following cases:
- The public service system encounters technical issues preventing it from operating;
- The managing organization of subscribers has not been issued a digital certificate with public service transactions or the digital certificate has expired or the subscriber's private key storage device is damaged.
2. Applications, documents, and reports related to digital certificates and digital signature verification services, the State Bank and the managing organization of subscribers have the right to choose to submit original copies or scanned copies of original documents (PDF format files) signed digitally using a State Bank CA digital certificate or certified copies issued from original records or copies with certification or copies accompanied by presentation of original documents for comparison.
3. The Information Technology Department sends notifications of processing results and reasons for rejection in cases where applications are not approved to the managing organization of subscribers via the public service system electronically. In case the public service system encounters technical issues, notifications will be sent to: (i) the managing organization of subscribers via postal service or (ii) the email address of the subscriber and the individual or department responsible for managing digital certificates of the managing organization of subscribers."
5. Adding Article 4b as follows:
"Article 4b. Subscriber Private Key Storage Devices
1. The Information Technology Department is responsible for guiding the types and technical specifications of subscriber private key storage devices that are compatible with the State Bank's digital signature verification system and technological developments.
2. The Information Technology Department provides private key storage devices to administrative units under the State Bank. Other managing organizations of subscribers equip themselves with private key storage devices in accordance with the guidance of the Information Technology Department.
3. The sending and receiving of private key storage devices between the Information Technology Department and administrative units under the State Bank shall be carried out either directly or through postal service."
6. Article 5 shall be amended and supplemented as follows:
"Article 5. Issuance of Digital Certificates
1. When there is a need to issue a digital certificate or supplement functions, the subscriber management organization submits one set of application materials including:
a) Issuing and supplementing digital certificate transactions for individuals who are authorized persons:
- Application for issuance and supplementation of digital certificate transactions according to Appendix 01 issued together with this Circular;
- Application for issuance and supplementation of digital certificate transactions for individuals according to Appendix 02 issued together with this Circular;
- Documents proving the legal representative status of the authorized person of the agency or organization as follows:
+ Business registration certificate or cooperative registration certificate or equivalent documents for enterprises and credit organizations, foreign bank branches;
+ Appointment decision of the person applying for issuance and supplementation of digital certificate transactions (for state agencies).
b) Issuing and supplementing functions for a digital certificate for an individual who is authorized by an authorized person:
- Application for issuance and supplementation of digital certificate transactions according to Appendix 01 issued together with this Circular;
- Application for issuance and supplementation of digital certificate transactions for individuals according to Appendix 02 issued together with this Circular;
- Authorization letter from the authorized person allowing the authorized representative to sign off on applications, documents, reports, and transactions on corresponding information systems for the proposed digital certificate transactions. The authorized representative cannot delegate this authority to another person.
- Confirmation document of the position of the person applying for issuance and supplementation of digital certificate transactions.
c) Issuing and supplementing functions for a digital certificate for an organization:
- Application for issuance and supplementation of digital certificate transactions for organizations according to Appendix 02a issued together with this Circular;
- Decision on establishment or decision specifying functions, tasks, powers, organizational structure or business registration certificate or cooperative registration certificate or equivalent documents.
2. In cases where the digital certificate number has been issued and remains valid, upon request from the subscriber management organization to supplement digital certificate services, the Information Technology Department shall implement the supplementation of services for the existing digital certificate of the subscriber.
3. Time limit for processing and results
Within five working days from the date of receipt of the application for issuance of a digital certificate, the Information Technology Department will conduct a review of the application, issue the digital certificate or supplement digital certificate services for the subscriber, and send a notification of the issuance of the digital certificate and the activation code to the subscriber's email address and mobile phone number. For organizational digital certificates, the Information Technology Department sends the notification of the issuance of the digital certificate and the activation code to the email address and mobile phone number of the responsible officer of the subscriber management organization as stipulated in Clause 1, Article 14 of this Circular.
If the application is not in compliance, the Information Technology Department will reject the application and specify the reasons. Feedback information and the results of the application processing will be carried out according to the provisions of Clause 3, Article 4a of this Circular.
4. The activation code for the digital certificate has a maximum validity period of thirty days from the date of issuance of the digital certificate. For newly issued digital certificates, subscribers must activate the digital certificate before the expiration of the activation code's validity period. Guidelines for activating and renewing digital certificates issued by the State Bank are published on the State Bank's electronic portal. For digital certificates with supplemented services, subscribers do not need to activate the digital certificate.
5. The validity period of the digital certificate of the subscriber, as requested by the subscriber management organization, but not exceeding five years from the date of activation of the digital certificate.
7. Article 6 is amended and supplemented as follows:
"Article 6. Renewal and change of information in digital certificates
1. Digital certificates requested for renewal or change of information must still be valid.
2. Validity period of the digital certificate:
a) After renewal, the digital certificate will have a validity period starting from the successful renewal date but not exceeding five years;
b) Changing the content of information in the digital certificate does not alter its validity period.
3. In cases of renewal or change of information in digital certificates:
a) The managing organization must request the renewal of the subscriber's digital certificate at least ten days before the expiry date of the digital certificate;
b) The subscriber management organization requests changes to the content of information in the digital certificate within five working days from the date of the following changes:
- The subscriber changes their position, rank, or department;
- The subscriber changes their identification card/residence card information;
- The subscriber changes their address, email, or telephone information.
4. The subscriber management organization submits one set of application documents for renewal or change of information in the digital certificate, including the Application for Renewal and Change of Information in Digital Certificates as specified in Appendix 03 attached to this Circular.
5. Time limit for processing and results of implementation
Within five working days from the date of receipt of the application for renewal or change of information in the digital certificate, the Information Technology Department will review the application, renew or change the information in the digital certificate for the subscriber. If the application is not in compliance, the Information Technology Department will reject the application and specify the reasons. Feedback information and the results of the application processing will be carried out according to the provisions of Clause 3, Article 4a of this Circular.
Upon receiving the approval notice for renewal of the digital certificate, the subscriber will carry out the renewal process according to the guidelines for activating and renewing digital certificates published on the State Bank's electronic portal.
8. Article 7 is amended and supplemented as follows:
“Article 7. Suspension of digital certificates
1. A subscriber's digital certificate is suspended when one of the following situations occurs:
a) The management organization sends the application for suspending the digital certificate to the Department of Information Technology.
b) At the written request of judicial authorities, police agencies, or the Ministry of Information and Communications;
c) The Information Technology Department discovers any errors or incidents that may affect the subscriber's interests or the security of the digital signature service system.
2. The period of suspension of the digital certificate as provided for in point a, Clause 1 of this Article shall be based on the request of the management organization. The period of suspension of the digital certificate as provided for in point b, Clause 1 of this Article shall be based on the request of the investigative agency, the police agency, or the Ministry of Information and Communications. The period of suspension of the digital certificate as provided for in point c, Clause 1 of this Article shall continue until the errors and incidents have been resolved.
3. The managing organization shall submit one set of application files for suspending the digital certificate, including the Application for Suspension of Digital Certificate according to Appendix 04 issued together with this Circular.
4. Time Limit for Processing and Results
a) Within three working days from the date of receipt of the application for suspending the digital certificate as provided for in point a, Clause 1 of this Article, the Department of Information Technology shall examine the file, suspend the digital certificate of the subscriber, and notify the result of the processing to the management organization. In case the file is not valid, the Department of Information Technology shall refuse to process the file and clearly state the reasons. Feedback information and the results of the file processing shall be carried out in accordance with the provisions of Clause 3, Article 4a of this Circular.
b) Within three working days from the date of receipt of the information as provided for in points b and c, Clause 1 of this Article, the Department of Information Technology shall suspend the digital certificate and notify in writing the time and reason for the suspension of the digital certificate to the management organization.
9. Point d, Clause 2, Clause 3, and Clause 4 of Article 8 are amended and supplemented as follows:
“d) The digital certificate is suspended according to the provisions of point c, Clause 1 of this Circular, and the errors and incidents have been resolved.”
“3. The management organization sends one set of files requesting to restore the digital certificate including the Application for Restoring the Digital Certificate as stipulated in Appendix 05 issued together with this Circular.
4. Time Limit for Processing and Results
a) Within three working days from the date of receipt of the application for restoring the digital certificate as provided for in points a and b, Clause 2 of this Article, the Department of Information Technology shall examine the file, restore the digital certificate for the subscriber. In case the file is not valid, the Department of Information Technology shall refuse to process the file and clearly state the reasons. Feedback information and the results of the processing shall be carried out in accordance with the provisions of Clause 3, Article 4a of this Circular;
b) Within three working days from the date of receipt of the information as provided for in points c and d, Clause 2 of this Article, the Department of Information Technology shall automatically restore the digital certificate for the subscriber.”
10. Article 9 is amended and supplemented as follows:
“Article 9. Revocation of digital certificates
1. The management organization may propose the revocation of the digital certificate or the cancellation of some operations of the digital certificate of the subscriber. In case of revoking the digital certificate, all operations of the digital certificate of the subscriber will be revoked.
2. The electronic signature certificate of the subscriber shall be revoked in the following cases:
a) At the request of a competent investigative body, a police agency, or the Ministry of Information and Communications in writing;
b) At the proposal of the organization managing subscribers to revoke the electronic signature certificate;
c) The subscriber management organization has a decision to revoke the operating license, split, merge, dissolve, or declare bankruptcy according to the law;
d) There is sufficient evidence to determine that the subscriber has violated regulations on the management and use of secret keys and key storage devices;
đ) The electronic signature certificate has expired.
3. The management organization sends one set of files requesting to revoke the digital certificate including the Application for Revoking and Canceling Operations of the Digital Certificate as stipulated in Appendix 06 issued together with this Circular.
4. Time Limit for Processing and Results
a) Within one working day from the date of receipt of the application for revoking the digital certificate as provided for in points a and b, Clause 2 of this Article, the Department of Information Technology shall examine the file, revoke or cancel the operations of the digital certificate for the subscriber. In case the file is not valid, the Department of Information Technology shall refuse to process the file and clearly state the reasons. Feedback information and the results of the processing shall be carried out in accordance with the provisions of Clause 3, Article 4a of this Circular;
b) Within one working day from the date of receipt of the information as provided for in points c, d, and đ, Clause 2 of this Article, the Department of Information Technology shall automatically revoke the digital certificate of the subscriber.”
11. Clause 2 of Article 10 is amended and supplemented as follows:
“2. The subscriber must create a key pair before the expiration date of the activation code as stated in the issuance notification of the digital certificate. In case the activation code is exposed or suspected to be exposed, or if it exceeds the activation deadline specified in the issuance notification of the digital certificate and the subscriber has not created the key pair and wishes to continue using the digital certificate, the management organization sends one set of files including the Application for Changing the Activation Code of the Digital Certificate as stipulated in Appendix 08 issued together with this Circular.”
12. Clause 2 and Clause 3 of Article 11 are amended and supplemented as follows:
“2. The management organization sends one set of files requesting to change the key pair including the Application for Changing the Key Pair of the Digital Certificate as stipulated in Appendix 07 issued together with this Circular.
3. Within five working days from the date of receipt of the application for changing the key pair, the Department of Information Technology shall examine the file, change the key pair, send the notification of changing the key pair and the activation code of the digital certificate to the email address and SMS to the mobile phone number of the subscriber. For the digital certificate of organizations, the Department of Information Technology shall send the notification of changing the key pair and the activation code of the digital certificate to the email address and SMS to the mobile phone number of the focal point responsible for the digital certificate of the management organization as stipulated in Clause 1 of Article 14 of this Circular.
If the application is not in compliance, the Information Technology Department will reject the application and specify the reasons. Feedback information and the results of the application processing will be carried out according to the provisions of Clause 3, Article 4a of this Circular.
Upon receiving the activation code of the digital certificate, the subscriber shall activate the digital certificate to create a new key pair before the expiration date of the activation code according to the guidance on activating and renewing the digital certificate published on the State Bank of Vietnam's electronic portal.
13. Article 14 is amended and supplemented as follows:
“Article 14. Responsibilities of the organization managing subscribers
1. Designate an individual or department to be responsible for registration, management of files, documents, and reports related to digital certificates and subscriber lists of the organization; notify the Department of Information Technology initially and whenever there is a change in the individual or department.
2. Register and bear full responsibility for the accuracy of all information contained in documents, files, and reports related to subscribers' digital certificates submitted to the Department of Information Technology.
3. Manage, statistically analyze, and update the list of subscribers within the organization. At least once every six months, conduct a review and comparison of the list of digital certificates issued by the State Bank with the actual needs and information at the subscriber management organization. For digital certificates that do not match the information, the subscriber management organization must immediately carry out procedures to change information, suspend, recover, or cancel the certificate transaction.
4. Report periodically and urgently as prescribed in this Circular.
5. Guide, inspect, and facilitate conditions for subscribers under its management to use digital certificates and secret keys in accordance with the provisions of this Circular.
6. Promptly notify the Department of Information Technology to suspend or revoke the digital certificate of a subscriber in the following cases:
- The secret key of a suspected leaked, leaked, stolen, or improperly used subscriber;
- The storage device of a lost secret key of a subscriber;
- A subscriber who changes their work position without needing to use a digital certificate for work purposes;
- A subscriber on temporary leave, resignation, retirement, or death;
- A subscriber belonging to a branch/unit of the subscriber management organization whose bank code has been canceled;
- Other cases arising from the needs of the subscriber management organization.
7. Digital certificates issued to organizations must be handed over to individuals for management and use. The handover must be documented in writing, clearly defining the roles and responsibilities of the individual receiving the management. The individual receiving the management must fulfill the roles and responsibilities of the subscriber as stipulated in this Circular.
8. The subscriber management organization, which is an administrative unit under the State Bank, must promptly recover storage devices of keys of subscribers who no longer use them for reuse by other subscribers.
14.Clause 2 of Article 15 is amended and supplemented as follows:
“2. Safeguard and use access codes for devices and data within the storage device of secret keys securely and confidentially throughout the period when the digital certificate is valid and suspended; do not share or lend access codes for devices or storage devices of digital certificates. When leaving the job, transferring positions, or changing work positions, if the job requirements no longer require the use of a digital certificate, the storage device of the secret key must be handed over to the subscriber management organization.”
15.Add Clause 3 to Article 16 as follows:
"3. The signer is responsible for the authenticity of the information they digitally sign and shall only perform digital signing on information systems when the system indicates that their digital certificate is valid."
16.Article 17 is amended and supplemented as follows:
“Article 17. Reporting System
The subscriber management organization is responsible for sending reports to the State Bank as follows:
1. Periodic reports
a) Report name: Report on reconciling the list of digital certificates issued by the State Bank;
b) Content of the report:
- Statistics on digital certificates and usage status;
- Reconcile the list of digital certificates issued by the Department of Information Technology with the actual needs and information at the subscriber management organization and report the list of digital certificates that do not match.
c) Implementing entity: Units under the State Bank, credit institutions, foreign bank branches, National Treasury, Deposit Insurance Corporation of Vietnam, Vietnam National Payment Corporation, Asset Management Corporation of Credit Institutions of Vietnam, and other agencies and organizations using the State Bank's digital signature certification service;
d) Receiving agency/unit: Department of Information Technology - State Bank;
đ) Method of sending and receiving reports:
- Sending and receiving reports shall be carried out according to the provisions of Clause 3 of Article 4a of this Circular;
- The subscriber management organization sends the reconciliation report on digital certificates through the Public Service System according to the report outline in Appendix 09 attached to this Circular.
e) Frequency and deadline for submitting reports: quarterly, latest by June 20th and December 20th of the reporting year;
g) Time to finalize report data:
- The time to finalize data for the first half-year report is from December 15th of the previous reporting year to June 14th of the current reporting year;
- The time to finalize data for the second half-year report is from June 15th to December 14th of the current reporting year.
2. Submit an urgent report when requested by the provider of the State Bank's digital signature certification service.”
Article 2.
1. Replace the term “Department of Computer Science” with the term “Department of Information Technology”.
2. Replace Model Forms 01, 02, 03, 04, 05, 06, 07, 08, 09 issued together with Circular 28/2015/TT-NHNN with Appendices 01, 02, 03, 04, 05, 06, 07, 08, 09 respectively issued together with this Circular.
3. Add Appendix 02a issued together with this Circular.
This Circular takes effect from December 25, 2025/.
Heads of units under the State Bank, credit institutions, foreign bank branches, National Treasury, Deposit Insurance Corporation of Vietnam, Vietnam National Payment Corporation, Asset Management Corporation of Credit Institutions of Vietnam are responsible for organizing the implementation of this Circular.
Article 4. Implementation provisions
1. This Circular takes effect from January 1, 2021
2. This Circular abolishes Clause 6 of Article 1 and Clause 4 of Article 2 of Circular 14/2019/TT-NHNN dated August 30, 2019, amending and supplementing certain articles in Circulars concerning the State Bank’s periodic reporting regulations./.
원본 문서(PDF)
관계도
문서를 클릭하면 열립니다. 빨간 테두리=효력을 변경하는 관계.
번역본
이 문서는 다음 언어로 제공됩니다: