LAW ON CYBER SECURITY NUMBER 116/2025/QH15

The Law on Cyber Security provides detailed regulations on aspects of cyber security protection in state agencies, political organizations, and political-social organizations at central and local levels. The Law also addresses the protection of cyber security for national cyberspace infrastructure, international network gateways, ensuring cyber information security and data.

Số hiệu116/2025/QH15
Loại văn bảnLaw
Cơ quan ban hànhMinistry of Public Security
Người kýTrần Thanh Mẫn — Chủ tịch Quốc hội
Cập nhật11/06/2026
Ngày ban hành10/12/2025
Ngày áp dụng01/07/2026
Ngày hết hiệu lực
Tình trạngIn effect
✦ Tóm lược thông minh

The Law on Cyber Security provides detailed regulations on aspects of cyber security protection in state agencies, political organizations, and political-social organizations at central and local levels. The Law also addresses the protection of cyber security for national cyberspace infrastructure, international network gateways, ensuring cyber information security and data.

Đối tượng áp dụng

This Law applies to state agencies, political organizations, and political-social organizations at central and local levels; domestic and foreign enterprises providing services on telecommunications networks, the Internet, and additional services on cyberspace in Vietnam.

Các điểm cốt lõi

  • Implementing cyber security protection activities includes establishing internal computer network usage regulations, contingency plans for cyber security incidents; organizing training on cyber security knowledge for officials, civil servants, and employees.
  • Protection of cyber security for national cyberspace infrastructure and international network gateways must ensure a tight integration between cyber security protection requirements and economic and social development requirements.
  • Enterprises providing services on telecommunications networks, the Internet have the responsibility to verify user information, prevent the posting of information violating cyber security laws, and store data in Vietnam.
  • Ensuring data security includes establishing data protection policies, using encryption to protect data, and strictly controlling personnel involved in data processing.
  • Technical standards and specifications for cyber security are applied to information systems, hardware, software, and cybersecurity products and services.

🌐 Tác động xã hội từ văn bản này

  • Enhance awareness of cyber security protection in the community.
  • Encourage investment in building national cyberspace infrastructure.
  • Strengthen the ability to respond to cyber security incidents.

❓ Câu hỏi thường gặp

What does the Law on Cyber Security stipulate regarding the responsibilities of enterprises?

Enterprises providing services on telecommunications networks, the Internet have the responsibility to verify user information, prevent the posting of information violating cyber security laws, and store data in Vietnam.

What does the Law on Cyber Security stipulate regarding ensuring data security?

Ensuring data security includes establishing data protection policies, using encryption to protect data, and strictly controlling personnel involved in data processing.

To which entities are technical standards for cyber security applied?

Technical standards for cyber security are applied to information systems, hardware, software, and cybersecurity products and services.

Toàn văn

OF THE NATIONAL ASSEMBLY

Law number: 116/2025/QH15

SOCIALIST REPUBLIC OF VIETNAM INDEPENDENT AND UNITED

Independence - Freedom - Happiness

 LAW

ON CYBER SECURITY 

Pursuant to the Constitution of the Socialist Republic of Vietnam amended and supplemented by Resolution No. 203/2025/QH15;

The National Assembly enacts the Cyber Security Law. 

PART I

GENERAL PROVISIONS 

Article 1. Scope of Regulation and Applicability

1. This Law stipulates on cyber security, protection of cyber security; rights, obligations, responsibilities of agencies, organizations, individuals related to cyber security.

2. This Law applies to:

a) Agencies, organizations, and individuals of Vietnam;

b) Agencies, organizations, individuals from foreign countries in Vietnam and Vietnamese-origin persons who have not been identified with nationality but are residing in Vietnam and have been issued identity cards.

c) Agencies, organizations, individuals from foreign countries directly participating or related to activities protecting cyber security, operating cyber security products and services in Vietnam.

Article 2. Interpretation of Terms

In this Law, the following terms shall be understood as follows:

1. Cyber security means stability, security, safety of cyberspace; protection of information systems and ensuring that information, data, activities on cyberspace do not harm national security, social order and safety, rights and legitimate interests of agencies, organizations, individuals.

2. Information security in cyberspace means ensuring the integrity, confidentiality, availability of information in cyberspace, preventing unauthorized access, use, disclosure, modification, destruction or other acts threatening or harming national security, social order and safety.

3. Data security means ensuring the quality of data and activities processing, using data in cyberspace for economic and social development, national digital transformation, preventing unauthorized access, use, disclosure, modification, destruction or other acts threatening or harming national security, social order and safety.

4. Protection of cyber security means prevention, detection, blocking, handling acts infringing upon cyber security.

5. Cyberspace is an environment formed by the network system connecting infrastructure of information technology, including telecommunications networks, the Internet, computer networks, information systems, information processing and control systems, databases; it is where people carry out social behaviors without being limited by space and time.

6. National cyberspace is the part of cyberspace under the sovereignty, jurisdiction, and control of the Socialist Republic of Vietnam.

7. Information system is a set of hardware, software, and data established to serve the purpose of creating, providing, transmitting, collecting, processing, storing, and exchanging information in cyberspace.

8. Manager of information system is the agency, organization, individual having direct management authority over the information system.

9. Malicious software is software capable of causing abnormal operation of a part or all of the information system or performing unauthorized copying, modifying, deleting stored information in the information system.

10. Malicious hardware are physical components designed intentionally or added outside the standard hardware configuration to collect information, data illegally or interfere, disrupt, paralyze, destroy computer systems, information systems.

11. System log is a collection of records reflecting time, user, activity, status of the system serving management, monitoring, and securing the system.

12. Cybercrime is a socially dangerous act prescribed in the Penal Code, carried out by individuals or organizations on cyberspace through the use of information technology or electronic means.

13. Cyber Attack is an act carried out on cyberspace through the use of information technology or electronic means to seize information, cause disruption, interruption, paralysis of operations, destruction or control of telecommunications networks, the Internet, computer networks, information systems, information processing and control systems, databases, electronic devices.

14. Cyber terrorism is an act carried out on cyberspace through the use of information technology or electronic means aimed at causing public panic or political instability.

15. Cyber espionage is an act carried out on cyberspace through the use of secret information technology or electronic means to secretly infiltrate and seize, collect, copy information within the scope of state secrets, important data of agencies, organizations, individuals with the aim of harming national security, social order and safety..

16. Threat to cyber security is a state of cyberspace showing signs of threats to national security, causing serious harm to social order and safety, rights and legitimate interests of agencies, organizations, individuals.

17. Cyber security incident is an unexpected event occurring in cyberspace infringing upon national security, social order and safety, rights and legitimate interests of agencies, organizations, individuals.

18. Dangerous situation regarding cyber security is a state or development in cyberspace when there are elements of attack, intrusion, incitement, exposure, loss of information or other acts threatening serious infringement upon national security, social order and safety, rights and legitimate interests of agencies, organizations, individuals.

19. Digital account is information used to authenticate, verify, authorize the use of applications, services on cyberspace.

20. Civil cryptographyis cryptographic techniques and cryptographic products used to secure or authenticate information not within the scope of state secrets to ensure information security for agencies, organizations, individuals.

21. Cyber security product is hardware, software with functions to protect cyber security, information security in cyberspace, data security, information, data, information systems, information technology infrastructure.

22. Cyber security service is a service provided to protect cyber security, information security in cyberspace, data security, information, data, information systems, information technology infrastructure.

23. Critical information system is an information system using critical cryptography to protect information within the scope of state secrets to serve specialized professional activities managed and operated directly by critical organizations.

Article 3. State policy on cyber security

1. Building a healthy cyberspace that does not harm national security, public order, social safety, rights and legitimate interests of agencies, organizations, and individuals.

2. Prioritizing the protection of cyber security in fields such as defense, security, cryptography, economic and social development, science, technology, and foreign affairs.

3. Prioritizing the allocation of resources to build and develop specialized forces for cyber security protection, ensuring a high-quality human resource to serve cyber security protection; enhancing the capacity of cyber security protection forces and individuals participating in cyber security protection; prioritizing investment in research and development activities of modern science and technology to serve cyber security protection; having special mechanisms and preferential policies to mobilize, attract, train, and utilize talents in the field of cyber security.

4. Promoting collaboration and investment through public-private partnership models in cyber security protection; encouraging and creating conditions for agencies, organizations, and individuals to participate in cyber security protection, handling threats to cyber security; researching and developing technology, products, services, applications aimed at protecting cyber security; using domestic cyber security products and services.

5. Expanding international cooperation on cyber security to enhance the ability to protect cyber security; preventing and combating cybercrime and cross-border cyber security threats; adopting advanced technology to improve national cyber security autonomy capabilities.

Article 4. Principles of cyber security protection

1. Adhering to the Constitution and laws; ensuring security, sovereignty, and national interests in cyberspace.

2. Placing under the leadership of the Communist Party of Vietnam; unified management by the State; mobilizing the comprehensive strength of the political system and the entire nation; giving full play to the core role of specialized forces for cyber security protection.

3. Closely combining cyber security protection with economic and social development, ensuring human rights, citizens' rights, protecting personal data, providing conditions for agencies, organizations, and individuals to operate legally in cyberspace.

4. Applying measures to protect the national cyberspace; proactively preventing, detecting, blocking, and fighting to defeat all activities in cyberspace that infringe upon national security, public order, social safety, rights, and legitimate interests of agencies, organizations, and individuals; promptly and strictly dealing with violations of cyber security laws.

5. Continuously implementing cyber security protection activities for national cyberspace infrastructure; proactively applying measures to protect important information systems related to national security.

Article 5. Measures for cyber security protection

1. Cyber security protection measures include:

a) Cyber security assessment;

b) Evaluation of cyber security conditions;

c) Cyber security inspection;

d) Cyber security monitoring;

đ) Response and remediation of cyber security incidents;

e) Struggle to protect cyber security;

g) Using encryption to protect network information;

h) Using technical solutions to protect information security networks, data security, information systems; preventing illegal information;

i) Preventing, temporarily suspending, or stopping the provision of network information; suspending, temporarily suspending, or stopping the establishment, provision, and use of telecommunications networks, the Internet, production, and use of radio wave transmission devices according to the provisions of the law;

k) Requesting removal, accessing and removing illegal or false information, fake news on cyberspace that infringes upon national security, public order, social safety, rights, and legitimate interests of agencies, organizations, and individuals;

l) Collecting electronic data related to activities infringing upon national security, public order, social safety, rights, and legitimate interests of agencies, organizations, and individuals on cyberspace;

m) Sealing off, limiting the operation of information systems; suspending, temporarily suspending, or requesting cessation of operations of information systems, reclaiming domain names according to the provisions of the law;

n) Initiating prosecution, investigation, prosecution, and trial according to the provisions of the Criminal Procedure Code;

o) Other measures prescribed by laws on national security and administrative violation handling laws.

2. The Government shall provide detailed regulations on the content, procedures, formalities, and authority for applying cyber security protection measures, except for the measures prescribed in points n and o of Clause 1 of this Article.

Article 6. International Cooperation on Cybersecurity

1. International cooperation on cybersecurity shall be carried out based on respecting independence, sovereignty, territorial integrity, non-interference in each other's internal affairs, equality, mutual benefit, and compliance with the Constitution and laws of Vietnam, international treaties to which the Socialist Republic of Vietnam is a member.

2. The contents of international cooperation on cybersecurity include:

a) Sharing information, data, and early warnings about cyber risks, incidents, and attacks that affect cybersecurity;

b) Establishing legal frameworks, policies, and cooperation mechanisms for protecting cybersecurity; negotiating, signing, and implementing international treaties and agreements on cybersecurity;

c) Training, consulting, sharing experiences, and enhancing professional and technical capabilities in the field of cybersecurity;

d) Preventing and combating cybercrime, high-tech crime; coordinating investigations and handling violations of the law, cybercrime, and high-tech crime;

đ) Researching, developing, transferring technology, products, and technical solutions to serve cybersecurity work;

e) Organizing international conferences and seminars and implementing international cooperation programs and projects on cybersecurity;

g) Other activities of international cooperation on cybersecurity.

3. Responsibilities for international cooperation on cybersecurity are defined as follows:

a) The Ministry of Public Security is responsible before the Government for leading and coordinating the implementation of international cooperation on cybersecurity;

b) The Ministry of National Defense is responsible before the Government for implementing international cooperation on cybersecurity within its management scope;

c) The Ministry of Foreign Affairs has the responsibility to coordinate with the Ministry of Public Security and the Ministry of National Defense in international cooperation activities on cybersecurity;

d) In cases where international cooperation on cybersecurity involves the responsibilities of multiple ministries and sectors, it shall be decided by the Prime Minister;

đ) International cooperation activities on cybersecurity of other ministries, sectors, and localities must have a participation opinion document from the Ministry of Public Security before implementation.the entity must have a document reflecting the opinion of the Ministry of Public Security before implementation.

Article 7. Prohibited Acts Concerning Cybersecurity

1. Posting or disseminating information containing the following content on cyberspace:

a) Propaganda against the Socialist Republic of Vietnam including: distorting, slandering the people's government; psychological warfare, inciting war of aggression, dividing, causing hatred among ethnic groups, religions, and people of different countries; insulting nationalities, national flags, state emblems, national anthems, great men, leaders, celebrities, national heroes;

b) Distorting history, denying revolutionary achievements, undermining the unity of the entire nation, insulting religions, discriminating against gender, racial discrimination;

c) Fabricating, defaming, spreading false information, infringing upon the dignity, reputation, and credibility of others or causing damage to the legitimate rights and interests of other agencies, organizations, and individuals;

d) Spreading false information causing public panic, damaging economic and social activities, hindering the normal operation of state agencies or public servants, infringing upon the legitimate rights and interests of other agencies, organizations, and individuals; fabricating and spreading false information about products, goods, money, bonds, promissory notes, treasury bills, checks, and other negotiable instruments; spreading false information in the fields of finance, banking, e-commerce, business operationshthrough multi-level marketing, securities.

2. Committing the following acts on cyberspace:

a) Organizing, operating, colluding, inciting, bribing, deceiving, recruiting, training, and instructing people to oppose the Socialist Republic of Vietnam;

b) Inciting, calling for, mobilizing, inciting, threatening, dividing, conducting armed activities or using violence against the people's government; calling for, mobilizing, inciting, threatening, and recruiting large gatherings of people to cause disturbances, opposing public officials, obstructing the activities of agencies and organizations, causing instability in security and order;

c) Stealing, buying, selling, holding, intentionally leaking state secrets, work-related secrets, business secrets; stealing, buying, selling, holding, intentionally leaking personal secrets, family secrets, and private lives affecting the reputation, credibility, dignity, rights, and legitimate interests of agencies, organizations, and individuals; intentionally eavesdropping, recording conversations illegally on cyberspace; disclosing information about civilian cryptographic products, customer information legally using such productscryptographic products; using and trading civilian cryptographic products of unknown origin;

d) Engaging in prostitution, social evils, trafficking in persons, body parts; promoting obscene, pornographic cultural products; inciting and advocating violence, decadent lifestyles, deviant behaviors, destroying traditional customs, morals, social ethics, and community health;

đ) Fraudulent acquisition of property; organizing gambling, online gambling; international telecommunications fraud over the Internet; promoting, advertising, buying, and selling goods and services prohibited by law; violating copyright and intellectual property on cyberspace;

e) Impersonating websites of agencies, organizations, and individuals; forging, circulating, stealing, buying, selling, and illegally exchanging credit card information, bank accounts, encrypted assets, digital assets of others; issuing, providing, and using illegal payment means; forging official documents of agencies and organizations;

g) Using artificial intelligence or new technologies to forge videos, images, voices of others contrary to the law; creating, posting, and disseminating information as stipulated in Clause 1 of this Article;

h) Collecting, using, disseminating, trading, transferring, and engaging in illegal business activities involving personal information of others;

i) Guiding, inciting, recruiting, and stirring up others to commit crimes or violate the law;

k) Committing other acts on cyberspace by using information technology and electronic means to violate laws concerning national security, public order, and safety.

3. Committing cyber attacks, cyber terrorism, cyber espionage, cyber crimes, high-tech crimes; causing incidents, attacking, infiltrating, taking control, distorting, interrupting, paralyzing, or damaging information systems.

4. Producing, putting into use tools, means, software, or engaging in acts that obstruct, disrupt, or disseminate spam emails, spam messages, spam calls, harmful computer programs affecting the operation of telecommunications networks, the Internet, computer networks, information systems, information processing and control systems, electronic devices.

5. Illegally accessing telecommunications networks, computer networks, information systems, information processing and control systems, databases, or electronic devices of others.

6. Resisting or obstructing the activities of cybersecurity protection forces; illegally attacking or rendering ineffective cybersecurity measures, thereby nullifying their protective effects.

7. Exploiting or misusing cybersecurity protection activities to infringe upon national sovereignty, interests, national security, social order and safety, lawful rights and interests of agencies, organizations, individuals, or for personal gain.

8. Other acts violating the provisions of this Law.

Chapter II

PROTECTION OF CYBERSECURITY FOR INFORMATION SYSTEMS

Article 8. Classification of Information System Levels

1. Information systems are classified into five levels based on the degree of harm to national security, social order and safety, the lawful rights and interests of organizations and individuals, public interest when incidents occur or violations of cybersecurity laws take place, as follows:

a) Level 1 may cause harm to the lawful rights and interests of organizations and individuals;

b) Level 2 may cause serious harm to the lawful rights and interests of organizations and individuals or cause harm to public interest;

c) Level 3 may cause particularly serious harm to the lawful rights and interests of organizations and individuals; serious harm to public interest; harm or serious harm to social order and safety, or cause harm to national security;

d) Level 4 may cause particularly serious harm to public interest, social order and safety, or serious harm to national security;

đ) Level 5 may cause particularly serious harm to national security.

2. The Government shall specify detailed criteria for determining the level of information systems; define the authority, procedures, and processes for determining the level of information systems and measures, responsibilities, obligations to ensure cybersecurity according to each level of the information system.

Article 9. National Security-Critical Information Systems

1. National security-critical information systems are information systems with strategic importance, particularly critical to politics, defense, security, diplomacy, economy, and society when incidents occur or violations of cybersecurity laws take place, which can cause harm to national security, serious harm to social order and safety, listed in the directory decided by the Prime Minister.

2. National security-critical information systems belong to the following fields:

a) Military, security, diplomatic, and confidential information systems;

b) Information systems storing and processing state secrets;

c) Information systems serving the preservation and storage of particularly important items and documents;

d) Information systems serving the storage and handling of materials and substances particularly dangerous to humans and the environment;

đ) Information systems serving the storage, production, and management of other particularly important facilities related to national security;

e) Important information systems serving the operations of central agencies and organizations;

g) National information systems in energy, finance, banking, telecommunications, transportation, agriculture, natural resources and environment, chemicals, health, culture sectors;

h) Automatic control and surveillance systems at important projects related to national security, important targets regarding national security.

3. National security-critical information systems must undergo cybersecurity assessment and certification before being put into operation and use; regularly check and monitor cybersecurity during use and promptly respond to and rectify cybersecurity incidents.

4. The Ministry of Public Security shall lead and coordinate with relevant ministries, agencies, organizations, and individuals to establish and submit to the Prime Minister for consideration and decision the list of national security-critical information systems.

5. The Government shall specify detailed criteria for determining national security-critical information systems.

Article 10. Tasks and Measures for Protecting Cybersecurity of Information Systems

1. The tasks for protecting cybersecurity of information systems include:

a) Determining the cybersecurity level of information systems and important national security information systems;

b) Assessing and managing cybersecurity risks of information systems;

c) Urging, supervising, and inspecting cybersecurity protection work of information systems;

d) Organizing the implementation of cybersecurity protection measures for information systems;

đ) Implementing reporting regimes as prescribed;

e) Organizing propaganda and raising awareness about cybersecurity.

2. The measures for protecting cybersecurity of information systems include:

a) Issuing regulations on ensuring cybersecurity in the design, construction, management, operation, use, upgrading, and decommissioning of information systems;

b) Reviewing cybersecurity for the files and designs of information systems;

c) Evaluating cybersecurity conditions for information systems;

d) Applying management measures according to cybersecurity technical standards and norms, researching and building a national firewall system to prevent and mitigate cybersecurity threats;

đ) Organizing the implementation of storage and backup measures to protect cybersecurity and the security of components constituting information systems;

e) Inspecting and monitoring compliance with regulations and evaluating the effectiveness of applied management and technical measures;

g) Conducting cybersecurity surveillance;

h) Responding to and mitigating cybersecurity incidents in information systems.

3. Managers of information systems at Level 1 and Level 2 shall fully perform the tasks prescribed in Clause 1 of this Article and, based on actual needs and capabilities, select and apply the measures prescribed in Clause 2 of this Article.

4. Managers of information systems at Level 3 and Level 4 that do not belong to the list of important national security information systems shall fully perform the tasks prescribed in Clause 1 of this Article, the measures prescribed in Points a, d, đ, e, g, and h of Clause 2 of this Article, and, based on actual needs and capabilities, select and apply the measures prescribed in Points b and c of Clause 2 of this Article.

5. Managers of information systems listed in the important national security information systems shall fully implement the tasks and measures prescribed in Clauses 1 and 2 of this Article. 

6. The Government shall provide detailed regulations for Clause 1 and Clause 2 of this Article.

Article 11. Responsibilities for Protecting Cybersecurity of Important National Security Information Systems

1. Managers of important national security information systems have the following responsibilities:

a) Implementing the provisions of Clause 5 of Article 10 of this Law;

b) When establishing, expanding, or upgrading important national security information systems, they must conduct cybersecurity inspections before operation and exploitation; annually self-inspect cybersecurity, evaluate the cybersecurity conditions of important national security information systems, and report the inspection results in writing before October each year to the specialized forces responsible for cybersecurity with authority;

c) Taking the lead and coordinating with the specialized forces responsible for cybersecurity with authority in regularly conducting cybersecurity surveillance; building mechanisms for self-warning and receiving warnings about cybersecurity threats; formulating emergency response plans;

d) Formulating emergency response plans for cybersecurity incidents; implementing these plans when cybersecurity incidents occur and promptly reporting to the specialized forces responsible for cybersecurity with authority;

đ) Cooperating with the specialized forces responsible for cybersecurity in conducting sudden cybersecurity inspections.

2. The Ministry of Public Security has the following responsibilities for important national security information systems, except military information systems and cryptographic information systems under the Government Cryptographic Office as prescribed by law:

a) Reviewing cybersecurity for important national security information systems;

b) Evaluating and certifying that important national security information systems meet cybersecurity conditions;

c) Conducting sudden cybersecurity inspections of important national security information systems;

d) Conducting cybersecurity surveillance; warning and coordinating with managers of information systems to address and handle cybersecurity threats and incidents in important national security information systems;

đ) Taking the lead in coordinating emergency response activities for cybersecurity incidents occurring in important national security information systems; notifying managers of information systems when cyber attacks or cybersecurity incidents are detected;

e) Taking the lead and coordinating with the Government Cryptographic Office in implementing measures to protect important national security information systems using cryptographic solutions and products provided by the Government Cryptographic Office to protect state secrets.

3. The Ministry of Defense takes the lead in reviewing cybersecurity, evaluating cybersecurity conditions, conducting sudden cybersecurity inspections, conducting cybersecurity surveillance, and coordinating emergency response activities for cybersecurity incidents in military information systems managed by the Ministry of Defense.

4. The Government Cryptographic Office leads in organizing the implementation of cryptographic solutions to protect classified information in important national security information systems; reviewing cybersecurity, evaluating cybersecurity conditions, conducting sudden cybersecurity inspections, conducting cybersecurity surveillance, and coordinating emergency response activities for cybersecurity incidents in cryptographic information systems under the Government Cryptographic Office.

Article 12. Cybersecurity inspection for information systems of agencies and organizations not included in the list of important information systems concerning national security

1. Cybersecurity inspections shall be conducted for information systems of agencies and organizations not included in the list of important information systems concerning national security in the following cases:

a) When there are acts prescribed in Clauses 12, 13, 14, and 15 of Article 2 of this Law;

b) Upon request of the management body of the information system.

2. The objects of cybersecurity inspection include:

a) Hardware, software, digital devices used in the information system;

b) Information stored, processed, and transmitted within the information system;

c) Measures to protect state secrets and prevent the leakage and loss of state secrets through technical channels.

3. The management body of the information system shall notify the specialized force responsible for cybersecurity under the Ministry of Public Security when discovering violations of laws on cybersecurity in the managed information system.

4. The specialized force responsible for cybersecurity under the Ministry of Public Security shall conduct cybersecurity inspections for information systems of agencies and organizations in the cases stipulated in Clause 1 of this Article. The results of cybersecurity inspections shall be kept confidential in accordance with the provisions of the law.

5. The Government shall prescribe the procedures and formalities for cybersecurity inspections as provided for in this Article.

Chapter III

PREVENTION AND HANDLING OF ACTS VIOLATING CYBERSECURITY

Article 13. Information and acts using information technology and electronic means to violate national security and public order and safety on cyberspace

1. Information containing content that propagandizes against the Socialist Republic of Vietnam, incites riots, disrupts public security, and causes public disorder includes:

a) Propagating information and materials that distort, defame, and slander the people's administration;

b) Psychological warfare, inciting aggressive war, dividing, and causing hatred among ethnic groups, religions, and peoples of different countries;

c) Insulting the nation, national flag, emblem, anthem, great men, leaders, and national heroes;

d) Calling for, mobilizing, inciting, threatening, dividing, and conducting armed activities or using violence against the people's administration;

đ) Calling for, mobilizing, inciting, threatening, and gathering crowds to cause disturbances, opposing public officials, and obstructing the normal operations of agencies and organizations, thereby disrupting national security and public order;

e) Distorting and inaccurately reflecting the national border, sovereignty of the Socialist Republic of Vietnam; posting, transmitting distorted, inaccurate, and incomplete images of the map of Vietnam or incorrectly representing the sovereignty of the Socialist Republic of Vietnam.

2. Information containing content that undermines policies of unity and socio-economic policies of the Socialist Republic of Vietnam includes:

a) Causing conflicts and divisions among the people, between the people and the people's administration, the people's armed forces, or political-social organizations;

b) Inciting hatred, discrimination, division, secessionism among ethnic groups, and infringing upon the equality rights of ethnic communities in Vietnam;

c) Inciting conflicts and divisions between religious followers and non-religious individuals, among followers of different religions, and dividing religious followers from the people's administration, the people's armed forces, or political-social organizations;

d) Undermining and obstructing the implementation of international solidarity policies;

đ) Propagandizing to directly or indirectly harm the legitimate rights and interests of the State in politics, economy, society, and international reputation;

e) Calling for and inciting the destruction of the implementation of socio-economic policies, obstructing the enforcement of such policies;

g) Calling for and inciting the destruction of material and technical infrastructure of the Socialist Republic of Vietnam.

3. Information containing content that violates the legitimate rights and interests of organizations and individuals includes:

a) Spreading false, fabricated, and misleading information that affects the reputation and normal operations of organizations;

b) Calling for, mobilizing, and inciting boycotts of products, services, goods, brands, and trademarks of organizations and enterprises, causing material losses and damage to the reputation of organizations and enterprises;

c) Impersonating, fabricating information, and imitating products, brand names, and trademarks of organizations and enterprises using technological tools, affecting the reputation of organizations and enterprises;

d) Insulting the dignity, reputation, and personality of others;

đ) Distorting the truth and affecting the dignity, reputation, and personality of others;

e) Fabricating or spreading information known to be false, causing damage to the legitimate rights and interests of others;

g) Fabricating criminal charges against others and reporting them to competent authorities;

h) Impersonating, fabricating information, and voices of individuals, affecting the reputation, dignity, and personality of individuals.

4. Acts carried out on cyberspace using information technology and electronic means to violate national security and public order and safety include:

a) Posting and disseminating information on cyberspace with content prescribed in Clauses 1, 2, and 3 of this Article;

b) Committing acts prescribed in Clause 1 of Article 15 of this Law;

c) Stealing property; organizing gambling, online gambling; stealing international telecommunications charges over the Internet; infringing copyrights and intellectual property on cyberspace;

d) Impersonating websites of agencies, organizations, and individuals; forging, circulating, stealing, buying, selling, collecting, and illegally exchanging credit card information, bank accounts of others; issuing, providing, and using illegal payment instruments; forging seals, documents, or other papers of agencies and organizations;

đ) Propagandizing, advertising, and illegally trading weapons, explosives, support tools, fireworks; narcotics, precursor chemicals, addictive substances, psychotropic substances; endangered wild animals, rare, precious, and valuable species, and other goods and services prohibited by law; brokering prostitution; spreading pornographic cultural products; sexually abusing children; sexual harassment.

e) Establishing, providing services, or supporting the operation, business, transactions, buying and selling, online marketing for illegal trading platforms, websites, applications on cyberspace, including: electronic commerce platforms, information websites, sales applications, commercial electronic service providers; index-based trading platforms for various goods; digital asset trading platforms, multi-level marketing businesses;

g) Using false identities, fake documents, or improperly using others' information to establish enterprises, set up bank accounts, securities accounts, insurance accounts, tax accounts, and other digital accounts; collecting, storing, exchanging, buying, selling, giving away, or publicly disclosing illegally bank account data, bank cards, e-wallet accounts, securities accounts, insurance accounts, tax accounts, and other types of digital accounts;

h) Advertising, selling counterfeit goods, smuggled goods, goods of unknown origin, goods circulating domestically subject to emergency measures; expired goods;

i) Guiding others to commit acts violating the law;

k) Other acts committed on cyberspace through the use of information technology that violate the law;, electronic means concerning national security, public order, social safety.

Article 14. Prevention and handling of information and acts using information technology and electronic means that infringe upon national security, public order, and social safety on cyberspace

1. System administrators, domestic and foreign enterprises providing telecommunications network services, Internet services, and additional services on cyberspace shall be responsible for implementing technical measures to prevent, detect, block, and remove information containing the contents specified in Clauses 1, 2, and 3 of Article 13 of this Law from the information systems under their management or when requested by specialized forces protecting cybersecurity.

2. Specialized forces protecting cybersecurity and competent authorities shall apply the measures prescribed in Clause 1 of Article 5 of this Law to handle information on cyberspace containing the contents specified in Clauses 1, 2, and 3 of Article 13 of this Law and combat, prevent, and control acts using information technology, electronic means that infringe upon national security, public order, and social safety on cyberspace.

3. Domestic and foreign enterprises providing telecommunications network services, Internet services, and additional services on cyberspace and system administrators shall cooperate with specialized forces protecting cybersecurity to handle information on cyberspace containing the contents specified in Clauses 1, 2, and 3 of Article 13 of this Law and prevent and control acts using information technology, electronic means that infringe upon national security, public order, and social safety on cyberspace.

4. Organizations and individuals drafting, posting, disseminating information on cyberspace containing the contents specified in Clauses 1, 2, and 3 of Article 13 of this Law must remove such information when requested by specialized forces protecting cybersecurity and bear responsibility according to the law.

5. The Government shall provide detailed regulations on this matter.

Article 15. Prevention and combating cyber espionage; protection of information classified as state secrets, work secrets, business secrets, personal secrets, family secrets, and private life on cyberspace

1. Acts of cyber espionage; infringement upon state secrets, work secrets, business secrets, personal secrets, family secrets, and private life on cyberspace include:

a) Seizing, buying, confiscating, intentionally leaking information classified as state secrets, work secrets, business secrets; seizing, buying, confiscating, intentionally leaking personal secrets, family secrets, and private life causing damage to the reputation, credibility, dignity, rights, and legitimate interests of agencies, organizations, and individuals;

b) Intentionally deleting, damaging, losing, or changing information classified as state secrets, work secrets, business secrets, personal secrets, family secrets, and private life transmitted or stored on cyberspace;

c) Intentionally altering, canceling, or rendering ineffective technical measures established and applied to protect information classified as state secrets, work secrets, business secrets, personal secrets, family secrets, and private life;

d) Uploading information classified as state secrets, work secrets, business secrets, personal secrets, family secrets, and private life to cyberspace contrary to the provisions of the law;

đ) Intentionally listening, recording audio, or filming conversations without permission;

e) Other intentional acts infringing upon state secrets, work secrets, business secrets, personal secrets, family secrets, and private life.

2. System administrators have the following responsibilities:

a) Conducting cybersecurity checks to identify and eliminate malicious codes, harmful hardware, address weaknesses, and security vulnerabilities; detecting, blocking, and handling unauthorized access activities or other threats to cybersecurity;

b) Implementing management and technical measures to prevent, detect, and block acts of cyber espionage, infringement upon state secrets, work secrets, business secrets, personal secrets, family secrets, and private life on information systems and promptly removing related information;

c) Cooperating and implementing requests from specialized forces protecting cybersecurity regarding prevention and combating cyber espionage, protection of information classified as state secrets, work secrets, business secrets, personal secrets, family secrets, and private life on information systems.

3. Agencies and organizations drafting, storing information, documents classified as state secrets have the responsibility to protect state secrets drafted, retained on computers, other devices, or exchanged on cyberspace in accordance with the law on protecting state secrets.

4. The Ministry of Public Security has the following responsibilities, except forthe cases provided for in Clause 5 and Clause 6 of this Article:

a) Conducting cybersecurity checks on important national security information systems to identify and eliminate malicious codes, harmful hardware, address weaknesses, and security vulnerabilities; detecting, blocking, and handling unauthorized access activities;

b) Conduct cybersecurity checks on devices, telecommunications products and services, digital equipment, electronic equipment before they are put into use in important information systems related to national security;

c) Monitor cybersecurity for important information systems related to national security with the aim of detecting and handling illegal activities involving the collection of state secrets;

d) Detect and handle acts of posting, storing, and exchanging illegally information and documents containing state secrets on cyberspace;

đ) Participate in researching and producing products for storing and transmitting information and documents containing state secrets in accordance with the provisions of the law, and encrypted information products on cyberspace within their assigned functions and tasks;

e) Inspect and check the work of protecting state secrets on cyberspace of state agencies and the protection of cybersecurity of the managers of important information systems related to national security;

g) Organize training and instruction to enhance awareness and knowledge about protecting state secrets on cyberspace, preventing cyber attacks, and protecting cybersecurity for the cybersecurity forces specified in Clause 4, Article 30 of this Law;

5. The Ministry of National Defense shall be responsible for implementing the contents stipulated in Clause 4 of this Article for military information systems;

6. The Government Cryptographic Office shall be responsible for implementing the contents stipulated in Clause 4 of this Article for cryptographic information systems under the Government Cryptographic Office; it shall also be responsible for organizing the implementation of legal regulations regarding the use of encryption to protect state secrets stored and exchanged on cyberspace;

Article 16. Prevention and combating child abuse on cyberspace

1. Children have the right to access information, participate in social activities, play, and entertain, protect personal privacy, private life, and other rights on cyberspace in accordance with the law;

2. When children use value-added services on cyberspace, parents or guardians must, in accordance with civil regulations, register accounts using their own information and are responsible for monitoring and managing the content that children access, post, and share on these service platforms;provisions of 1. The Legal Affairs Department shall be the focal point, coordinating with relevant units to advise and assist the Minister in monitoring the implementation of legal normative documents within the scope of the Ministry of Industry and Trade's management; drafting and submitting to the Minister for issuance a plan to monitor the implementation of legal normative documents of the Ministry of Industry and Trade within fifteen days from the date the Prime Minister issues the central and inter-sectoral plan, to be sent to the Ministry of Justice for monitoring and consolidation; preparing annual reports on the organization of legal implementation to be submitted to the Minister for consolidation by the Ministry of Justice. for civil law register accounts using the information of parents or guardians and are responsible for monitoring and managing the content that children access, post, and share on these service platforms;

3. Managers of information systems, enterprises providing services over telecommunications networks, the Internet, and value-added services on cyberspace shall have the following responsibilities:

a) Control the content of information on the information system or on the service provided by the enterprise so as not to harm children or infringe upon children's rights;

b) Prevent the sharing and removal of information containing content that harms children or infringes upon children's rights;

c) Develop and implement technical systems to support activities aimed at blocking harmful content targeting children on cyberspace;

d) Coordinate with relevant authorities, organizations, and enterprises to block sources disseminating harmful information targeting children on cyberspace;

đ) Timely report and coordinate with specialized cybersecurity forces under the Ministry of Public Security to handle such matters;

4. Organizations, individuals participating in activities on cyberspace shall be responsible for coordinating with competent authorities to ensure children's rights on cyberspace; prevent and combat child abuse on cyberspace;

5. Organizations, parents, guardians, teachers, caregivers, and other related individuals shall be responsible for ensuring children's rights and protecting children when they participate in cyberspace in accordance with the law on children and this Law;

6. Specialized cybersecurity forces and competent authorities shall be responsible for applying measures to prevent, detect, block, and strictly handle acts of using cyberspace to harm children, infringe upon children's rights, and violate children's rights.

Article 17. Prevention, detection, blocking, and handling of malicious software

1. Agencies, organizations, and individuals have the responsibility to proactively prevent, detect, block malicious software and implement according to the guidance and requirements of competent state agencies.

2. Managers of important information systems related to national security shall deploy technical systems to prevent, detect, block, and promptly handle malicious software.

3. Organizations and enterprises providing email services, data transmission, and information storage must have a system to filter out malicious software during the sending, receiving, and storing of information on their own systems and report to competent state agencies as prescribed by law.

4. Enterprises providing Internet services must take measures to manage, prevent, detect, block the dissemination of malicious software and handle according to the requirements of competent state agencies.

5. The Ministry of Public Security shall take the lead and coordinate with the Ministry of National Defense andBrelevant ministries and sectors to organize prevention, detection, blocking, and handling of malicious software that harms national security.

Article 18. Prevention and Counteraction against Cyber Attacks       

1. Acts of cyber attacks and acts related to cyber attacks include:

a) Disseminating harmful computer programs affecting telecommunications networks, the Internet, computer networks, information systems, information processing and control systems, databases, electronic devices;

b) Causing hindrance, disruption, paralysis, interruption, cessation of operations, illegal obstruction of data transmission in cyberspace;

c) Intruding, damaging, or appropriating data stored or transmitted through telecommunications networks, the Internet, computer networks, information systems, information processing and control systems, databases, electronic devices;

d) Intruding, creating, or exploiting vulnerabilities and security holes in system services to appropriate information for illicit gain;

e) Producing, buying, trading, giving away tools, equipment, software with features harmful to telecommunications networks, the Internet, computer networks, information systems, information processing and control systems, databases, electronic devices for unlawful purposes;

f) Other acts affecting the normal operation of telecommunications networks, the Internet, computer networks, information systems, information processing and control systems, databases, electronic devices.

2. Managers of information systems are responsible for applying technical measures to prevent and block the acts specified in points a, b, c, d, and e of Clause 1 of this Article within the scope of their management.

3. When a cyber attack occurs or threatens to infringe upon sovereignty, interests, national security, causing serious harm to social order and safety, specialized forces responsible for cybersecurity shall take the lead and coordinate with managers of information systems and related organizations and individuals to apply measures to determine the origin of the cyber attack, collect evidence; request enterprises providing services on telecommunications networks, the Internet, and additional services in cyberspace to block and filter information to prevent and eliminate cyber attacks and provide full and timely information and documents related thereto.

4. Responsibilities for preventing and counteracting cyber attacks are stipulated as follows:

a) The Ministry of Public Security shall take the lead and coordinate with relevant ministries, sectors, and localities to carry out preventive work, detect, and handle acts specified in Clause 1 of this Article that infringe upon or threaten to infringe upon sovereignty, interests, national security, causing serious harm to social order and safety nationwide, except for cases specified in points b and c of this clause;

b) The Ministry of National Defense shall take the lead and coordinate with relevant ministries and sectors to carry out preventive work, detect, and handle acts specified in Clause 1 of this Article concerning military information systems;

c) The Government Cryptographic Agency shall take the lead and coordinate with relevant ministries and sectors to carry out preventive work, detect, and handle acts specified in Clause 1 of this Article concerning cryptographic information systems under the Government Cryptographic Agency.

Article 19. Prevention and Combating Cyber Terrorism

1. The competent state agencies shall be responsible for applying measures as prescribed in this Law and laws on prevention and combating terrorism to handle cyber terrorism.

2. The managers of information systems shall regularly review and inspect the information systems under their management to eliminate the risk of cyber terrorism.

3. When signs or acts of cyber terrorism are detected, organizations, individuals must promptly report to the cyber security protection forces. The agency receiving the report shall be responsible for fully receiving reports on cyber terrorism and promptly informing the specialized cyber security protection forces.

4. The Ministry of Public Security shall take the lead and coordinate with relevant ministries and sectors to implement work on preventing and combating cyber terrorism, apply measures to render terrorist sources ineffective, handle cyber terrorism, and minimize the consequences for information systems to the lowest extent possible, except in cases provided for in Clause 5 and Clause 6 of this Article.5. The Ministry of National Defense shall take the lead and coordinate with relevant ministries and sectors to implement work on preventing and combating cyber terrorism, apply measures to render terrorist sources ineffective, handle cyber terrorism, and minimize the consequences for military information systems to the lowest extent possible.

6. The Government Cryptographic Office shall take the lead and coordinate with relevant ministries and sectors to implement work on preventing and combating cyber terrorism, apply measures to render terrorist sources ineffective, handle cyber terrorism, and minimize the consequences for cryptographic information systems under the Government Cryptographic Office to the lowest extent possible.

Article 20. Prevention and Handling of Dangerous Situations Concerning Cyber Security

1. Dangerous situations concerning cyber security include:

a) The appearance of inciting information on cyberspace that poses a risk of riots, disruption of public security, and terrorism;

b) Attacks on important national security information systems;

c) Large-scale, high-intensity attacks on multiple information systems;

d) Cyber attacks aimed at destroying important national security facilities and targets;

đ) Cyber attacks seriously infringing upon sovereignty, interests, and national security; causing particularly serious harm to social order and safety, and the legitimate rights and interests of agencies, organizations, and individuals.

2. Responsibilities for preventing dangerous situations concerning cyber security are stipulated as follows:

a) Specialized cyber security protection forces shall cooperate with the managers of important national security information systems to implement technical and operational solutions to prevent, detect, and handle dangerous situations concerning cyber security;

b) Telecommunications, Internet, information technology enterprises, service providers on telecommunications networks, the Internet, and additional services on cyberspace, and related agencies, organizations, and individuals shall be responsible for cooperating with the specialized cyber security protection forces under the Ministry of Public Security in preventing, detecting, and handling dangerous situations concerning cyber security.

3. Measures for handling dangerous situations concerning cyber security include:

a) Immediately implementing emergency plans for cyber security prevention and response, blocking, eliminating, or mitigating losses caused by dangerous situations concerning cyber security;

b) Notifying related agencies, organizations, and individuals;

c) Collecting relevant information; continuously monitoring dangerous situations concerning cyber security;

d) Analyzing and evaluating information, forecasting the potential impact range and severity of losses caused by dangerous situations concerning cyber security;

đ) Ceasing to provide network information in specific areas or disconnecting international network gateways;

e) Deploying personnel and means to block and eliminate dangerous situations concerning cyber security;

g) Other measures as prescribed by the National Security Law.

4. Handling dangerous situations concerning cyber security is stipulated as follows:

a) Upon discovering dangerous situations concerning cyber security, agencies, organizations, and individuals shall promptly inform the specialized cyber security protection forces and immediately apply the measures prescribed in point a and point b of Clause 3 of this Article;

b) The Prime Minister shall consider and decide, or delegate the Minister of Public Security to consider and decide, to handle dangerous situations concerning cyber security nationwide, in specific localities, or for a specific target;

c) The Prime Minister shall consider and decide, or delegate the Minister of National Defense to consider and decide, to handle dangerous situations concerning cyber security for military information systems and cryptographic information systems under the Government Cryptographic Office;d) Specialized cyber security protection forces shall take the lead and coordinate with related agencies, organizations, and individuals to apply the measures prescribed in Clause 3 of this Article to handle dangerous situations concerning cyber security;

e) Agencies, organizations, and individuals related shall be responsible for cooperating with the specialized cyber security protection forces to implement measures to prevent and handle dangerous situations concerning cyber security.

c) The specialized force for cybersecurity shall take the lead and coordinate with relevant agencies, organizations, and individuals to apply the measures prescribed in Clause 3 of this Article to address cybersecurity emergencies;

d) Relevant agencies, organizations, and individuals shall be responsible for coordinating with the specialized force for cybersecurity to implement measures aimed at preventing and addressing cybersecurity emergencies.

Article 21. Struggle to Protect Cybersecurity

1. The struggle to protect cybersecurity is an organized activity carried out by specialized forces responsible for cybersecurity on cyberspace with the aim of protecting national security and ensuring social order and safety.

2. The contents of the struggle to protect cybersecurity include:

a) Monitoring online information and preventing, combating, and handling organizations and individuals engaging in activities that use cyberspace to infringe upon national security and social order and safety;

b) Using technical solutions to block illegal information;

c) Preventing and protecting the stable operation of important information systems related to national security;

d) Paralyzing or limiting the use of cyberspace aimed at harming national security or causing particularly serious harm to social order and safety;

đ) Proactively attacking and neutralizing targets on cyberspace to protect national security and ensure social order and safety.

3. The Ministry of Public Security shall take the lead and coordinate with relevant ministries and sectors to implement the struggle to protect cybersecurity; the Ministry of National Defense shall take the lead and coordinate with relevant ministries and sectors to implement the struggle to protect cybersecurity concerning military information systems.

Article 22. Prevention of Information Conflicts on Cyberspace

1. An information conflict occurs when two or more domestic and foreign organizations use technological and informational measures to cause damage to information and information systems on cyberspace, affecting national security and social order and safety.

2. Prevention of information conflicts on cyberspace involves implementing technical and informational measures to monitor, detect, warn, identify sources, filter, remove, refute, shape public opinion, rectify, penalize, and other measures to eliminate information conflicts on cyberspace.

3. Organizations and individuals within their scope of duties and powers have the following responsibilities:

a) Preventing information conflicts on cyberspace from their own information systems; cooperating to determine sources, push back, and mitigate consequences of cyber attacks carried out through domestic and foreign organizations' information systems;

b) Preventing the activities of domestic and foreign organizations and individuals with the purpose of creating information conflicts on cyberspace;

c) Eliminating the organization's implementation of posting and disseminating information on cyberspace that significantly impacts national defense, national security, and social order and safety of domestic and foreign organizations and individuals.

4. The Government shall provide detailed regulations on this matter.

Chapter IV

CYBERSECURITY PROTECTION ACTIVITIES

Article 23. Implementation of Cybersecurity Protection Activities in State Agencies, Political Organizations, and Social-Political Organizations at Central and Local Levels

1. The contents of implementing cybersecurity protection activities include:

a) Establishing and perfecting regulations and rules for using internal computer networks and Internet-connected computer networks; plans to ensure cybersecurity for information systems; contingency plans to respond to and mitigate cybersecurity incidents;

b) Applying and implementing plans, measures, and technologies to protect cybersecurity for information systems and information and documents stored, drafted, and transmitted on information systems under their management;

c) Organizing training on cybersecurity knowledge for civil servants, employees, and workers; enhancing the capacity of cybersecurity protection forces;

d) Protecting cybersecurity in the provision of public services on cyberspace, exchange, collection of information with agencies, organizations, and individuals, sharing information internally and with other agencies or in other activities as prescribed by the Government;

đ) Investing in and building physical infrastructure suitable for conditions to ensure the implementation of cybersecurity protection activities for information systems;

e) Conducting cybersecurity inspections of information systems; preventing and combating violations of cybersecurity laws; responding to and mitigating cybersecurity incidents.

2. Heads of agencies and organizations are responsible for implementing cybersecurity protection activities within their jurisdiction.

Article 24. Protection of cyber security for national internet infrastructure and international network gateways

1. The protection of cyber security for national internet infrastructure and international network gateways must ensure a close integration between cyber security requirements and socio-economic development requirements; encourage the establishment of international gateways on Vietnamese territory; encourage organizations and individuals to participate in investment in building national internet infrastructure.

2. Organizations and individuals managing and operating national internet infrastructure and international network gateways shall have the following responsibilities:

a) Protecting cyber security within their management authority; being subject to management, inspection, and supervision by competent state agencies and implementing cyber security requirements set forth by such agencies;

b) Creating conditions and implementing necessary technical and operational measures to enable competent state agencies to perform cyber security tasks when requested.

Article 25. Ensuring information security on networks

1. Websites, electronic portals, or specialized pages on social networks of organizations and individuals may not provide, post, or transmit information containing content as stipulated in Clauses 1, 2, and 3 of Article 13 and Clause 1 of Article 15 of this Law and other information with content that infringes upon national security.

2. Domestic and foreign enterprises providing services on telecommunications networks, the Internet, and additional services in Vietnam's cyberspace shall have the following responsibilities:

a) Verify user information when users register for account numbers; secure user information and accounts; provide user information to specialized forces responsible for cyber security under the Ministry of Public Security no later than 24 hours from the time of receiving a written request, email, telephone call, or other confirmed communication method for the purpose of verification, investigation, and handling of violations of laws on cyber security; in cases of emergency threatening national security or human lives, the provision of information shall be no later than three hours;

b) Prevent the sharing of information, remove information, and disable services or applications with content violating the provisions of this Law no later than 24 hours from the time of receiving a request from specialized forces responsible for cyber security under the Ministry of Public Security and retain system logs to serve verification, investigation, and handling of violations of laws on cyber security as prescribed by law; in cases of emergency threatening national security, the prevention and removal of information shall be no later than six hours;

c) Not provide or cease providing services on telecommunications networks, the Internet, and additional services to organizations and individuals posting information on cyberspace containing content as stipulated in Clause 1, Clause and 2 Article 13, Clause 1 and Clause 2 Article 14 of of this Law when requested by specialized forces responsible for cyber security under the Ministry of Public Security;

d) Store personal information of service users, data created by service users, including: account name, service usage time, payment information for service usage fees, IP address accessed, and related data for a period as prescribed by law after the user has ended the use of the service.

3. Domestic and foreign enterprises providing services on telecommunications networks, the Internet, and additional services in Vietnam's cyberspace that engage in collecting, exploiting, analyzing, and processing data on personal information, data on relationships of service users, and data created by service users in Vietnam must apply data protection measures as prescribed by law and store this data in Vietnam for a period as prescribed by the Government.

Foreign enterprises as stipulated in this clause must establish a branch or representative office in Vietnam.

4. The Government shall specify details of Clause 2 and Clause 3 of this Article.

Article 26. Data Security Assurance

1. Data security assurance is a comprehensive set of technical, organizational, and legal measures aimed at protecting data and preventing data security breaches.

2. Contents of data security assurance including:

a) Establishing policies and procedures for data security assurance;

b) Applying measures, standards, and technical regulations as prescribed by laws on cybersecurity;

c) Using fundamental cryptographic methods and civil cryptography to ensure data security;

d) Implementing strict personnel control mechanisms directly involved in data processing;

đ) Conducting regular risk assessments to detect, prevent, and promptly address threats to data security;

e) Inspecting and evaluating cross-border data transfers; conditions for ensuringdata security in critical information systems concerning national security, databases, data centers, and data storage systems;

g) Other contents as prescribed by law.

3. The Government shall provide detailed regulations for Clause 2 of this Article and define responsibilities for data security assurance.

Chapter V

TECHNICAL STANDARDS, PRODUCTS AND SERVICES FOR CYBERSECURITY TECHNICAL,

CYBERSECURITY PRODUCTS AND SERVICES

Article 27. Technical Standards and Regulations for Cybersecurity

1. Cybersecurity standards and technical regulations apply to information systems, hardware, software, cybersecurity management and operation systems, cybersecurity products and services, information technology, and network-connected devices.

2. Certification and declaration of conformity for cybersecurity, certification and declaration of compliance with cybersecurity standards shall be carried out in accordance with the provisions of laws on standards and technical regulations.

3. Assessment of compliance with cybersecurity standards and regulations for critical information systems concerning national security and for state management activities related to cybersecurity shall be conducted by organizations designated by the Minister of Public Security.

4. Responsibilities of the Ministry of Public Security include: herein:

a) Drafting proposals for national cybersecurity standards;

b) Managing the quality of cybersecurity products and services, except for civil cryptography products and services;

c) Registering, designating, and managing the activities of organizations certifying compliance with cybersecurity standards, except as provided for in Clause 6 of this Article.

5. The Minister of Public Security shall issue national technical standards for cybersecurity.

6. The Ministry of National Defense shall register, designate, and manage the activities of organizations certifying compliance with cybersecurity standards in the military field.

The Government Cryptographic Office assists the Minister of National Defense in managing the quality of civil cryptography products and services; registering, designating, and managing the activities of organizations certifying compliance with cybersecurity standards for civil cryptography products and services.

Article 28. Cybersecurity Products and Services

1. Cybersecurity products include:

a) Civil cryptography products;

b) Cybersecurity testing and evaluation products;

c) Cybersecurity monitoring products;

d) Anti-attack and intrusion products;

đ) Other cybersecurity products.

2. Cybersecurity services include:

a) Cybersecurity testing and evaluation services;

b) Information security services not using civil cryptography;

c) Civil cryptography services;

d) Cybersecurity consulting services;

đ) Cybersecurity monitoring services;

e) Cybersecurity incident response services;

g) Data recovery services;

h) Network attack prevention and countermeasures services;

i) Other cybersecurity services.

3. The Government shall provide detailed regulations on this Article.

Article 29. Business of network security products and services

1. Enterprises conducting business in network security products and services must have a business license for network security products and services.

2. Enterprises conducting business in network security products and services shall be responsible for the following:

a) Implementing the business license for network security products and services accurately; complying with legal provisions on network security and other relevant legal provisions;

b) Ensuring the quality of network security products and services according to published standards and corresponding technical regulations as stipulated by laws on product and commodity quality, laws on standards and technical regulations before entering the market;

c) Establishing, retaining, and securing customer information, managing files and documents related to technical solutions and technologies of products, service provision activities in accordance with legal provisions;

d) Refusing to provide network security products and services when discovering organizations or individuals violating laws on the use of network security products and services, breaching commitments agreed upon regarding the use of products and services provided by the enterprise;

đ) Cooperating, creating conditions, and implementing requests of specialized forces protecting network security to implement measures to protect network security.

3. The Government shall specify matters concerning the issuance, temporary suspension, and revocation of business licenses for network security products and services; specify matters concerning the import and export of network security products; and specify matters concerning the business of network security products and services.

Chapter VI

FORCES AND CONDITIONS TO ENSURE NETWORK SECURITY

Article 30. Forces Protecting Network Security

1. Forces protecting network security include:

a) Specialized forces protecting network security deployed at the Ministry of Public Security and the Ministry of National Defense;

b) Forces protecting network security deployed at ministries, sectors, provincial People's Committees, and agencies directly managing important information systems concerning national security;

c) Organizations and individuals mobilized to participate in protecting network security.

2. The Government shall detail Clause 1 of this Article; specify matters concerning cooperation among forces protecting network security.

Article 31. Ensuring Human Resources for Protecting Network Security

1. The State shall train and develop human resources for protecting network security to ensure quantity and quality, meeting the requirements of national network security capability.

2. Specialized forces protecting network security shall be prioritized in personnel allocation based on job positions and qualification criteria, applying recruitment, examination, employment, training, development, remuneration, and talent attraction mechanisms according to special policies prescribed by the Government.

3. The management body of important information systems concerning national security shall be responsible for the following:

a) Allocating appropriate departments or personnel specialized in accordance with the level of protection of the system;

b) Ensuring that personnel performing network security tasks meet professional and vocational standards;

c) Regularly updating and enhancing skills for staff involved in operation, monitoring, emergency response, and handling network incidents.

Article 32. Recruitment, Training, and Development of Forces Protecting Network Security

1. Vietnamese citizens who meet the standards of moral character, health, qualifications, and knowledge in network security and information technology, and express willingness may be recruited into forces protecting network security.

2. Priority shall be given to training and developing high-quality forces protecting network security; identifying young talents in network security and information technology to guide their education, recruitment, attraction, and utilization in the field of network security.

3. Priority shall be given to developing cybersecurity training institutions meeting international standards; encouraging collaboration and creating opportunities for cooperation in cybersecurity between the public and private sectors, domestically and internationally.

Article 33. Education and Training on Cybersecurity Knowledge and Skills

1. The content of cybersecurity education shall be included in national defense and security education courses at schools and in the program for training national defense and security knowledge as prescribed by the Law on National Defense and Security Education.

2. The Ministry of Public Security shall take the lead and coordinate with relevant ministries and sectors to organize training on cybersecurity skills for cybersecurity protection forces and civil servants, officers, and workers participating in cybersecurity protection.

The Ministry of National Defense and the Government Cryptographic Office shall organize training on cybersecurity skills for individuals under their management.

Article 34. Advanced Training on Cybersecurity Knowledge and Skills

1. The cybersecurity protection forces specified in points a and b of Clause 1, Article 30 of this Law must meet the requirements for advanced cybersecurity knowledge and skills.

2. Individuals directly managing and operating information systems at Levels 3, 4, and 5 within state agencies, organizations, and enterprises must undergo advanced training on cybersecurity knowledge and skills and obtain certification, except those who have been trained in cybersecurity majors.

3. The Ministry of Public Security shall take the lead and coordinate with relevant ministries and sectors to organize advanced training on cybersecurity knowledge and skills, except as provided for in Clause 4 of this Article.

4. The Ministry of National Defense and the Government Cryptographic Office shall organize advanced training on cybersecurity knowledge and skills for individuals under their management.

5. The Government shall stipulate standards for advanced cybersecurity knowledge and skills; programs, contents, and certification procedures for advanced training on cybersecurity knowledge and skills.

Article 35. Dissemination of Cybersecurity Knowledge

1. The State shall implement policies to disseminate cybersecurity knowledge nationwide, encourage state agencies to cooperate with private organizations and individuals to carry out educational programs and raise awareness about cybersecurity; prioritize dissemination and guidance for children, elderly people, and those with difficulties in understanding to enhance their ability to protect their legitimate rights and interests online.

2. Ministries, sectors, agencies, and organizations shall be responsible for building and implementing activities to disseminate cybersecurity knowledge and raise awareness among cadres, civil servants, officers, and workers within their ministries, sectors, agencies, and organizations.

3. Provincial People's Committees shall be responsible for building and implementing activities to disseminate cybersecurity knowledge and raise awareness among local agencies, organizations, and individuals.

Article 36. Research and Development of Cybersecurity

1. The content of research and development of cybersecurity includes:

a) Building software and equipment for cybersecurity protection;

b) Methods for assessing software and equipment for cybersecurity protection to meet standards and minimize vulnerabilities and security gaps, harmful software;

c) Methods for checking hardware and software provided to ensure proper functionality;

d) Methods for protecting state secrets, work-related secrets, business secrets, personal secrets, family secrets, and privacy; security capabilities when transmitting information over cyberspace;

đ) Determining the origin of information transmitted over cyberspace;

e) Addressing cyber threats;

g) Building cyber ranges and testing environments for cybersecurity;

h) Technical initiatives to enhance awareness and skills in cybersecurity;

i) Cybersecurity forecasting;

k) Researching practical applications and developing cybersecurity theory.

2. Relevant agencies, organizations, and individuals have the right to conduct research and development in cybersecurity.

Article 37. Enhancing Self-reliance Capacity in Cybersecurity 

1. The State encourages and creates conditions for agencies, organizations, and individuals to enhance their self-reliance capacity in cybersecurity and improve their ability to produce, inspect, evaluate, and certify digital equipment, network services, and applications.

2. The Government shall implement the following measures to enhance the self-reliance capacity in cybersecurity for agencies, organizations, and individuals:

a) Directing the development of policies, strategies, and planning for the development of the cybersecurity industry; technical standards and norms for hardware and software products to proactively eliminate cybersecurity risks from the product formation stage;

b) Promoting technology transfer, research, mastery, and development of cybersecurity industry technologies, products, and services;

c) Promoting the application of new and advanced technologies related to cybersecurity;

d) Organizing training, developing, and optimizing the utilization of high-quality cybersecurity human resources;

đ) Strengthening the business environment, improving competitive conditions, and supporting enterprises in researching, producing products, services, and applications to protect cybersecurity;

3. Investment activities and resource mobilization for the development of cybersecurity industry infrastructure include:

a) Investment activities in building cybersecurity industry infrastructure are special preferential investment sectors, entitled to incentives and support under laws on investment, taxation, land, and other relevant laws;

b) The State prioritizes allocating budget funds for the construction of cybersecurity industry infrastructure including: Research, design, production, and testing facilities for cybersecurity products and services; National key laboratories for cybersecurity; Testing, evaluation facilities for cybersecurity products and services; Large data centers; Concentrated cybersecurity industrial parks; Cybersecurity industrial complexes;

c) The cybersecurity industry infrastructure invested in as stipulated in point b of this clause is a type of public asset infrastructure and is managed, operated, and utilized according to laws on management and use of public assets;

d) Organizations and enterprises are permitted to import technology chains, equipment, machinery, and tools serving training, research, and development of cybersecurity products and services;

đ) State-owned agencies, organizations, and enterprises prioritize using domestically produced cybersecurity products and services;

4. The Ministry of Public Security advises and assists the Government in building and developing cybersecurity industry infrastructure to enhance self-reliance capacity in cybersecurity.

Article 38. Funding for Cybersecurity Protection

1. Agencies, organizations, state-owned enterprises, political organizations, socio-political organizations, and public service units funded by the state budget must allocate funding for cybersecurity protection in their annual budget estimates for implementing tasks of digital transformation and information technology application; at least 15% of the total funding for implementing programs, projects, and investment initiatives for digital transformation and information technology application should be allocated for cybersecurity protection.

2. Agencies, organizations, and units not covered by the provisions of Clause 1 of this Article shall ensure their own funding for cybersecurity protection.

Chapter VII

RESPONSIBILITIES OF AGENCIES, ORGANIZATIONS, AND INDIVIDUALS IN THE IMPLEMENTATION OF INSPECTION CONCLUSIONS REGARDING CYBERSECURITY

Article 39. State Management Responsibilities for Cybersecurity

1. The Government shall uniformly manage state affairs concerning cybersecurity.

2. The Ministry of Public Security shall be the lead agency assisting the Government in managing state affairs concerning cybersecurity; it shall be responsible before the Government for implementing the following state management contents on cybersecurity, except for the contents stipulated inClause 3 and Clause 4 of this Article:

a) Issuing or submitting to competent state agencies for issuance normative legal documents on cybersecurity;

b) Developing, proposing strategies, policies, plans, and solutions for cybersecurity protection; researching, developing, utilizing cryptographic means for protecting data within the scope of management of the Ministry of Public Security;

c) Coordinating with relevant agencies to organize propaganda and refute information containing anti-state content as prescribed in Clause 1, Article 13 of this Law;

d) Requesting enterprises providing telecommunications services, internet services, and additional services in cyberspace, and managers of information systems to remove information violating laws on cybersecurity from services and information systems directly managed by such enterprises, agencies, and organizations;

đ) Preventing and combating activities using cyberspace to infringe upon national sovereignty, interests, national security, public order, and safety, and preventing and combating cybercrime;

e) Ensuring information security in cyberspace and data security; establishing mechanisms for managing IP address identification; verifying account registration information; warning and sharing cybersecurity information and threats;

g) Advising and proposing to the Government and the Prime Minister to consider and decide on the division of responsibilities and coordination in implementing measures to protect cybersecurity, prevent, and handle acts of infringing upon cybersecurity when the content of state management involves multiple Ministries and sectors;

h) Mobilizing experts, scientists, specialized staff, and utilizing systems, means, and equipment in emergency situations to protect national security and ensure public order and safety in cyberspace;

i) Organizing drills to prevent and combat cyber attacks; drills to respond to and mitigate cybersecurity incidents for critical information systems related to national security;

k) Inspecting, auditing, resolving complaints and grievances, and handling violations of laws on cybersecurity;

3. The Ministry of National Defense shall be responsible before the Government for managing state affairs concerning cybersecurity within its scope of management as follows:

a) Issuing or submitting to competent state agencies for issuance normative legal documents on cybersecurity within its scope of management;

b) Developing, proposing strategies, policies, plans, and solutions for cybersecurity protection within its scope of management;

c) Preventing and combating activities using cyberspace to infringe upon national security within its scope of management;

d) Coordinating with the Ministry of Public Security to organize drills to prevent and combat cyber attacks, drills to respond to and mitigate cybersecurity incidents for critical information systems related to national security, and implementing cybersecurity protection work;

đ) Inspecting, auditing, resolving complaints and grievances, and handling violations of laws on cybersecurity within its scope of management;

4. The Government Cryptographic Office shall assist the Minister of National Defense in managing state affairs concerning civilian cryptography and cybersecurity within its scope of management as prescribed by law;

5. Ministries, ministerial-level agencies, and agencies under the Government, within their functions, tasks, and authorities, shall implement cybersecurity protection work; coordinate with the Ministry of Public Security in managing state affairs concerning cybersecurity;

6. Provincial People's Committees shall implement cybersecurity protection work at the local level; coordinate with the Ministry of Public Security in managing state affairs concerning cybersecurity.

Article 40. Responsibilities of the System Administrator in Cybersecurity Protection 

1. The system administrator shall have the following responsibilities:

a) Implement cybersecurity protection for the information system in accordance with this Law;

b) Connect the cybersecurity monitoring system and anti-malware system to the National Cybersecurity Center of the Ministry of Public Security or the provincial Cybersecurity Center to support cybersecurity monitoring; concentrate at the National Cybersecurity Center of the Ministry of Public Security or the provincial cybersecurity center to support cybersecurity monitoring;

c) Report cybersecurity incidents to the specialized agencies of the Ministry of Public Security or the Ministry of Defense.

2. In addition to the responsibilities stipulated in Clause 1 of this Article, the system administrator who uses state budget funds shall have the following responsibilities:

a) Develop a cybersecurity assurance plan that has been reviewed by the competent state agency when establishing, expanding, or upgrading the information system;

b) Designate individuals or units responsible for cybersecurity.

Article 41. Responsibilities of Service Providers on Cyberspace

1. Comply with legal regulations on cybersecurity.

2. Warn users about potential cybersecurity risks when using services provided on cyberspace and guide preventive measures; develop emergency response plans to ensure cybersecurity to proactively address vulnerabilities, risks, and cybersecurity incidents.

3. Immediately implement emergency response plans to ensure cybersecurity upon occurrence of a cybersecurity incident, while simultaneously reporting to the specialized cybersecurity protection forces as prescribed by this Law.

4. Apply technical measures to ensure cybersecurity for data processing activities, including personal data processing, in accordance with this Law, data laws, personal data protection laws, and other relevant legal provisions.

5. Have the responsibility to identify the IP addresses of organizations and individuals using internet services; provide IP identification information to the specialized cybersecurity protection forces to implement cybersecurity protection measures.

6. Cooperate with the specialized cybersecurity protection forces under the Ministry of Public Security to establish connection systems, interconnect technical lines, transmit data, and meet other necessary conditions to implement cybersecurity protection measures when requested for investigation, verification, and handling of violations of cybersecurity laws.

7. Telecommunication network service providers, Internet service providers, and additional services on cyberspace in Vietnam shall comply with the provisions of this Article and Clauses 2 and 3 of Article 25 of this Law.

Article 42. Responsibilities of Agencies, Organizations, and Individuals Using Cyberspace

1. Comply with legal regulations on cybersecurity.

2. Have the responsibility to secure information related to registration, opening, management, and use of their digital accounts. If a digital account is used to commit a violation of the law, depending on the nature and severity of the violation, the account holder or user may be subject to disciplinary action, administrative penalties, or criminal prosecution; if damage is caused to the interests of the State, the rights and legitimate interests of organizations and individuals, compensation must be made according to the law.

3. Timely provide information related to cybersecurity protection, cybersecurity threats, and cybercrime to authorized agencies and cybersecurity protection forces.

4. Fulfill requests and guidelines from authorized agencies in cybersecurity protection; assist and create conditions for agencies, organizations, and responsible persons to carry out cybersecurity protection measures.

Chapter VIII

IMPLEMENTING PROVISIONS

Article 43. Amending and supplementing some articles of related laws

1. Replacing some phrases and abolishing some clauses of the Law on Archives No. 33/2024/QH15 as follows:

a) Replacing the phrase "information security" at Point b Clause 1 Article 35, the phrase "network information security" at Point b Clause 2 Article 36, and the phrase "information security, information security" at Clause 3 Article 60 with the phrase "cybersecurity";

b) Abolishing Clause 4 Article 58.

2. Replacing and abolishing some phrases of the Consumer Protection Law No. 19/2023/QH15 as follows:

a) Replacing the phrase "information security" with the phrase "information security" at Point d Clause 1 Article 16, the phrase "information security, information security" with the phrase "cybersecurity" at Clause 1 Article 15, Title 19, Clause 1 and Clause 3 Article 19;

b) Abolishing the phrase "network information security" at Clause 3 Article 19.

3. Replacing some phrases of the Law on Fees and Charges No. 97/2015/QH13 which has been amended and supplemented by Laws No. 09/2017/QH14, No. 23/2018/QH14, No. 72/2020/QH14, No. 16/2023/QH15, No. 20/2023/QH15, No. 24/2023/QH15, No. 33/2024/QH15, No. 35/2024/QH15, No. 47/2024/QH15, No. 60/2024/QH15, No. 74/2025/QH15, No. 89/2025/QH15, No. 94/2025/QH15, No. 95/2025/QH15, and No. 118/2025/QH15 as follows:

a) Replacing the phrase "information security" with the phrase "cybersecurity" at Subitem 10 Item VI Part A and Subitem 16 Item III Part B Appendix No. 01 - List of Fees and Charges;

b) Replacing the phrase "network information security" with the phrase "cybersecurity" at Subitem 11 Item VI Part A Appendix No. 01 - List of Fees and Charges.

4. Replacing and abolishing some phrases of the Law on Digital Industry No. 71/2025/QH15 as follows:

a) Replacing the phrase "information security" with the phrase "cybersecurity" at Point a Clause 1 Article 25;

b) Abolishing the phrase "network information security" at Article 10.

5. Replacing and abolishing some phrases of the Data Law No. 60/2024/QH15 as follows:

a) Replacing the phrase "data security, data security" with the phrase "data security" at Clause 4 Article 25;

b) Replacing the phrase "information security, information security" with the phrase "cybersecurity" at Clause 2 Article 33;

c) Abolishing the phrase ", information security" at Clause 4 Article 25;

d) Abolishing the phrase "network information security" at Clause 4 Article 39;

đ) Abolishing the phrase "laws on network information security" at Clause 4 Article 43.

6. Replacing and abolishing some phrases of the Cultural Heritage Law No. 45/2024/QH15 which has been amended and supplemented by Law No. 84/2025/QH15 as follows:

a) Replacing the phrase "network information security" with the phrase "cybersecurity" at Clause 4 Article 59;

b) Abolishing the phrase "network information security" at Point c Clause 2 Article 86.

7. Replacing and abolishing some phrases of the Telecommunications Law No. 24/2023/QH15 which has been amended and supplemented by Law No. 47/2024/QH15 as follows:

a) Replacing the phrase "network information security" with the phrase "information security" at Clause 8 Article 5;

b) Abolishing the phrase ", network information security" at Title 5 and Clause 1 Article 5, Point c Clause 2 Article 38;

c) Abolishing the phrase "network information security" at Clause 2 Article 21 and Point b Clause 2 Article 29.

8. Replacing and abolishing some phrases of the Electronic Transactions Law No. 20/2023/QH15 which has been amended and supplemented by Law No. 60/2024/QH15 as follows:

a) Abolishing the phrase "network information security and" at Title 5;

b) Abolishing the phrase "laws on network information security" at Clause 1 Article 5;

cc) Replacing the phrase "network information security" with the phrase "cybersecurity" at Point c Clause 1 Article 20, Clause 2 Article 21, Point c Clause 1 Article 29, Clause 6 Article 30, Clause 4 Article 44, Point a Clause 4 Article 46, and Point c Clause 1 Article 47;

For coal-fired thermal power plants where the enterprise holds 100% of the registered capital and uses 100% of its own capital to invest in the project approved by the competent authority, E is determined as 100%;d) Abolishing the phrase "network information security" at Point d Clause 1 Article 42 and Point a Clause 1 Article 47..

9. Replacing the phrase "network information security" with the phrase "cybersecurity" at Point b Clause 2 Article 12 of the Corporate Income Tax Law No. 67/2025/QH15; at Clause 1 Article 169 of the Land Law No. 31/2024/QH15 which has been amended and supplemented by Laws No. 43/2024/QH15, No. 47/2024/QH15, No. 58/2024/QH15, No. 71/2025/QH15, No. 84/2025/QH15, No. 93/2025/QH15, and No. 95/2025/QH15.

10. Replacing the phrase "information security, information security" with the phrase "cybersecurity" at Point a Clause 3 Article 7 of the Water Resources Law No. 28/2023/QH15 which has been amended and supplemented by Law No. 84/2025/QH15.

11. Abolishing the phrase "network information security" at Point đ Clause 1 Article 24 of the Administrative Violations Handling Law No. 15/2012/QH13 which has been amended and supplemented by Laws No. 54/2014/QH13, No. 18/2017/QH14, No. 67/2020/QH14, No. 09/2022/QH15, No. 11/2022/QH15, No. 56/2024/QH15, and No. 88/2025/QH15.

12. Abolishing the phrase "network information security" at Clause 6 Article 16 ofthe People's Public Security Law No. 37/2018/QH14 which has been amended and supplemented by LawsNo. 21/2023/QH15, Law No. No. 30/2023/QH15, Law No. No. 38/2024/QH15, Law No. No. 52/2024/QH15 and No. 86/2025/QH15; at Clause 1 Article 66 of the Election of National Assembly Deputies and People's Council Deputies Law No. 85/2015/QH13 which has been amended and supplemented by Law No. 83/2025/QH15.

13. Abolishing the phrase ", information security" at Clause 3 Article 136 of theCourt LIMITATION People's Court Law No. 34/2024/QH15 which has been amended and supplemented by Law No. 81/2025/QH15; at Clause 1 Article 26 of the Electricity Law No. 61/2024/QH15 which has been amended and supplemented by Law No. 94/2025/QH15.

14. Abolishing the phrase "information security" at Clause 8 Article 29; the phrase "and information security" at Clause 2 and Clause 7 Article 29 of the Chemicals Law No. 69/2025/QH15.

15. Abolishing the phrase "information security" at Clause 3 Article 51, Clause 1 and Clause 5 Article 52 of the Bidding Law No. 22/2023/QH15 which has been amended and supplemented by Laws No. 57/2024/QH15 and No. 90/2025/QH15; at Point e Clause 1 Article 23 of the Civil Defense Law No. 18/2023/QH15 which has been amended and supplemented by Law No. 98/2025/QH15.

16. Abolishing the phrase ", laws on ensuring information security" at Clause 4 Article 7 of the Atomic Energy Law No. 94/2025/QH15.

17. Abolishing Clause 3 Article 49 of the Library Law No. 46/2019/QH14.

Article 44. Effective date of implementation

1. This Law takes effect from July 1, 2026.

2. The Cybersecurity Law number 86/2015/QH13 has been amended and supplemented with some articles according to Law number 35/2018/QH14; the Cybersecurity Law number 24/2018/QH14 ceases to be effective from the date this Law comes into force.

Article 45. Transitional Provisions

1. Information systems that have been classified according to the provisions of the Cybersecurity Law number 86/2015/QH13, which has been amended and supplemented with some articles according to Law number 35/2018/QH14, shall continue to maintain their classification level from the date this Law comes into force; within twelve months from the date this Law comes into force, they must ensure the conditions, standards, and security measures corresponding to their classification level as stipulated by this Law.

2. Types of business licenses for cybersecurity products and services, civil cryptography as prescribed by the Cybersecurity Law number 86/2015/QH13, which has been amended and supplemented with some articles according to Law number 35/2018/QH14 issued before the date this Law comes into force remain valid until the expiration date indicated on the license.

3. Cybersecurity products, services, solutions, technical means for ensuring cybersecurity as prescribed by the Cybersecurity Law number86/2015/QH13, which has been amended and supplemented with some articles according to Law number 35/2018/QH14 put into use before the date this Law comes into force may continue to be used; within twelve months from the date this Law comes into force, they must meet the cybersecurity conditions as stipulated by this Law.

This Law was adopted by the National Assembly of the Socialist Republic of Vietnam, the fifteenth session, Adopted at the tenth session on December 10, 2025.

SPEAKER OF THE NATIONAL ASSEMBLY

Tran Thanh Man

 

Văn bản này đang được cập nhật văn bản gốc, vui lòng xem nội dung toàn văn và kiểm tra lại sau.

Bản đồ quan hệ

↑ Cơ sở & văn bản tác động lên văn bản này
Căn cứ 16
47/2026/TT-BCA Thông tư 47/2026/TT-BCA Ban hành Quy chuẩn kỹ thuật quốc gia về an ninh mạng cho hệ thống thông tin lưu trữ tài liệu điện tử trong các cơ quan Đảng, Nhà nước Còn hiệu lực 27/2026/NĐ-CP Nghị định số 27/2026/NĐ-CP Quy định về Cơ sở dữ liệu quốc gia về cán bộ, công chức, viên chức Còn hiệu lực 48/2026/TT-BCA Thông tư 48/2026/TT-BCA Ban hành Quy chuẩn kỹ thuật quốc gia về thiết bị camera giám sát sử dụng giao thức Internet - Các yêu cầu an ninh mạng cơ bản Còn hiệu lực 212/2026/NĐ-CP Nghị định quy định về điều kiện năng lực hoạt động xây dựng, Hệ thống thông tin, Cơ sở dữ liệu quốc gia về hoạt động xây dựng Còn hiệu lực 72/2026/QĐ-UBND Quyết định phân cấp thẩm quyền thực hiện một số nhiệm vụ trong lĩnh vực đất đai trên địa bàn tỉnh Đồng Tháp Còn hiệu lực 84/2026/QĐ-UBND Quyết định Ban hành Quy chế bảo vệ dữ liệu cá nhân trong hoạt động của cơ quan nhà nước trên địa bàn tỉnh Thái Nguyên Còn hiệu lực 85/2026/QĐ-UBND Quyết định số 85/2026/QĐ-UBND Ban hành Quy chế Quản lý, vận hành, khai thác và sử dụng Hệ thống Camera giám sát tỉnh Thái Nguyên Còn hiệu lực 50/2026/QĐ-UBND Quyết định số 50/2026/QĐ-UBND Ban hành Quy chế xây dựng, cập nhật, quản lý, vận hành và khai thác cơ sở dữ liệu đất đai trên địa bàn thành phố Hải Phòng Còn hiệu lực 215/2026/NĐ-CP Nghị định số 215/2026/NĐ-CP Về an ninh hàng không Còn hiệu lực 216/2026/NĐ-CP Nghị định số 216/2026/NĐ-CP Quy định chi tiết và hướng dẫn thi hành một số điều của Luật Lý lịch tư pháp Còn hiệu lực 35/2026/QĐ-TTg Quyết định 35/2026/QĐ-TTg của Bộ Tư pháp Chưa hiệu lực 59/2026/QĐ-UBND Quyết định 59/2026/QĐ-UBND của Hải Phòng Chưa hiệu lực 32/2026/NQ-HĐND Nghị quyết 32/2026/NQ-HĐND của Vĩnh Long Còn hiệu lực 56/2026/QĐ-UBND Quyết định 56/2026/QĐ-UBND của Đồng Nai Còn hiệu lực 39/2026/NQ-HĐND Nghị quyết 39/2026/NQ-HĐND của Đồng Tháp Chưa hiệu lực 40/2026/NQ-HĐND Nghị quyết 40/2026/NQ-HĐND của Đồng Tháp Còn hiệu lực
116/2025/QH15
LAW ON CYBER SECURITY NUMBER 116/2025/QH15
In effect
↓ Văn bản chịu tác động từ văn bản này
Sửa đổi, bổ sung 1

Bấm vào một văn bản để mở. Viền đỏ = quan hệ làm thay đổi hiệu lực.