This Decree details regulations on digital signatures and services for verifying digital signatures, applicable to management agencies, organizations providing services for verifying digital signatures, as well as individuals using digital signatures. It includes provisions on issuing, granting, extending, suspending, revoking digital certificates and conditions ensuring the security of digital signatures.
적용 범위
Management agencies, organizations providing services for verifying digital signatures; agencies, organizations, and individuals using digital signatures, digital certificates, and services for verifying digital signatures in electronic transactions.
핵심 사항
- Public service providers of digital signature verification must have a license from the Ministry of Information and Communications and must meet financial, human resources, and technical conditions.
- Digital certificates of agencies, organizations, and authorized persons shall be issued in accordance with Article 6 of this Decree.
- Conditions ensuring the security of digital signatures are specified in Article 9 of this Decree.
- Organizations providing specialized digital signature verification services for agencies and organizations need to have a certificate confirming their eligibility from the Ministry of Information and Communications.
- Foreign digital certificates used in Vietnam must comply with the conditions stipulated in Article 46 of this Decree.
🌐 이 문서의 사회적 영향
- Establishing a strict management system for digital signatures to enhance safety and efficiency in electronic transactions.
- Reducing legal risks for organizations and individuals using digital signatures.
- Improving the issuance and management procedures for digital certificates to facilitate business and work transactions.
❓ 자주 묻는 질문
What conditions must organizations providing digital signature verification services meet?
They must obtain a license from the Ministry of Information and Communications, meet financial conditions (minimum deposit of 5 billion VND), human resource conditions (university degree or higher in information security), technical conditions (security systems), and the license duration is 10 years.
How can foreign digital certificates be used in Vietnam?
They may only be used for electronic transactions of entities specified in Article 44 of this Decree and must comply with licensing conditions from the Ministry of Information and Communications.
What is the validity period of a digital certificate?
The validity period of a digital certificate is five years, depending on the type of digital certificate issued. Foreign digital certificates also have a similar validity period but not exceeding the validity period of the certificate.
What conditions must organizations providing specialized digital signature verification services meet?
They must have a registration certificate for operations, meet human resource conditions (university degree or higher), technical conditions (security systems), and the validity period is five years.
What procedures are required for organizations providing public digital signature verification services to obtain a license?
They must submit an application for a license, including a request form, confirmation of deposit, personnel files, and technical plans. The review period is 50 days.
전문
|
THE GOVERNMENT |
SOCIALIST REPUBLIC OF VIET NAM |
|
Number: 130/2018/NĐ-CP |
Hanoi, September 27, 2018 |
DECREE
DETAILING IMPLEMENTATION OF THE ELECTRONIC TRANSACTION LAW ON DIGITAL SIGNATURES AND SERVICES FOR VERIFYING DIGITAL SIGNATURES
Pursuant to the Law on Government Organization dated June 19, 2015;
Pursuant to the Law on Electronic Transactions dated November 29, 2005;
Pursuant to the Law on Information Technology dated June 29, 2006;
Pursuant to the Law on Fees and Charges dated November 25, 2015;
At the proposal of the Minister of Information and Communications;
The Government promulgates this Decree detailing implementation of the Law on Electronic Transactions regarding digital signatures and services for verifying digital signatures.
PART I
GENERAL PROVISIONS
Article 1. Scope of Regulation
This Decree specifies details on digital signatures and digital certificates; management, provision, and use of digital signatures, digital certificates, and services for verifying digital signatures.
Article 2. Applicability
This Decree applies to agencies, organizations managing and providing services for verifying digital signatures; agencies, organizations, and individuals using digital signatures, digital certificates, and services for verifying digital signatures in electronic transactions.
Article 3. Explanation of Terms
In this Decree, the following terms are understood as follows:
1. "Key" is a binary number sequence (0 and 1) used in cryptographic systems.
2. "Asymmetric cryptographic system" is a cryptographic system capable of generating a key pair consisting of a private key and a public key.
3. "Private key" is a key in a key pair belonging to an asymmetric cryptographic system, used to create a digital signature.
4. "Public key" is a key in a key pair belonging to an asymmetric cryptographic system, used to verify a digital signature created by the corresponding private key in the key pair.
5. "Signing" is the process of inserting a private key into a software program to automatically generate and attach a digital signature to a data message.
6. "Digital signature" is an electronic signature generated by transforming a data message using an asymmetric cryptographic system, whereby those who obtain the original data message and the signer's public key can accurately determine:
a) That the transformation was created using the correct private key corresponding to the public key in the same key pair;
b) The integrity of the content of the data message from the time of the transformation.
7. "Digital certificate" is an electronic certificate issued by an organization providing services for verifying digital signatures to provide identifying information for a public key of an agency, organization, or individual, thereby confirming that the agency, organization, or individual is the signer of the digital signature by using the corresponding private key.
8. "Valid digital certificate" is a digital certificate that has not expired, been suspended, or revoked.
9. "Public digital certificate" is a digital certificate issued by an organization providing public services for verifying digital signatures.
10. "Foreign digital certificate" is a digital certificate issued by an organization providing foreign services for verifying digital signatures.
11. "Subscriber" is an agency, organization, or individual granted a digital certificate, accepting the digital certificate, and holding the corresponding private key to the public key recorded on the issued digital certificate.
12. "Signer" is a subscriber using their own private key to sign a data message under their name.
13. "Recipient" is an organization or individual receiving a signed data message from the signer, using the signer's digital certificate to verify the digital signature in the received data message.
14. "Application using digital signature" is an information technology application allowing integration and use of digital signatures for authentication.
15. "Organization providing services for verifying digital signatures" is an organization providing services for verifying digital signatures that carries out activities of providing services for verifying digital signatures.
16. "Organization providing public services for verifying digital signatures" is an organization providing services for verifying digital signatures for agencies, organizations, and individuals using such services in public activities. The activity of providing public services for verifying digital signatures by organizations providing public services for verifying digital signatures is a conditional business activity regulated by law.
17. "Organization providing specialized services for verifying digital signatures" is an organization providing services for verifying digital signatures for agencies, organizations, and individuals using such services in specific professional or field activities with similar operational characteristics or purposes and linked through operational regulations or legal normative documents stipulating common organizational structures or forms of association and joint operations. The operation of an organization providing specialized services for verifying digital signatures does not aim at profit-making. An organization providing specialized services for verifying digital signatures includes:
a) An organization providing specialized government services for verifying digital signatures providing services for verifying digital signatures to Party and State agencies;
b) An organization providing specialized services for verifying digital signatures of agencies and organizations. The activity of providing specialized services for verifying digital signatures by agencies and organizations must be registered with the competent state management agency for services for verifying digital signatures in accordance with the law.
18. "Agent for public services for verifying digital signatures" is a trader assisting an organization providing public services for verifying digital signatures in supplying services for verifying digital signatures to subscribers according to an agency agreement to earn remuneration.
19. "Verification regulation" is the regulation of organizations providing services for verifying digital signatures concerning procedures and formalities for issuing, managing digital certificates, and using digital certificates by subscribers, and the relationship between the organization providing services for verifying digital signatures and its agents and subscribers.
20. "Service fee for maintaining the online database for checking the status of digital certificates" is the amount of money that organizations providing services for verifying digital signatures must pay when the National Organization Providing Services for Verifying Digital Signatures (as stipulated in Chapter VI of this Decree) maintains an online database about digital certificates and other information serving the purpose of checking the status of digital certificates and the validity of digital signatures of organizations providing services for verifying digital signatures.
21. "Device storing private keys" is a physical device containing the digital certificate and the private key of the subscriber.
Article 4. Digital Signature Certification Service
The digital signature certification service is a type of electronic signature certification service provided by a digital signature certification service organization to subscribers to verify that the subscriber is the person who signed the data message digitally. The digital signature certification service includes:
1. Creating a key pair or assisting in creating a key pair including a public key and a private key for the subscriber.
2. Issuing, renewing, suspending, restoring, and revoking the subscriber's digital certificate.
3. Maintaining an online database of digital certificates.
4. Providing necessary information to help certify the digital signature of the subscriber on the data message.
Chapter II
DIGITAL SIGNATURE AND DIGITAL CERTIFICATE
Article 5. Content of Digital Certificate
The digital certificate issued by a national digital signature certification service organization, a public digital signature certification service organization, a government-specific digital signature certification service organization, or a specific digital signature certification service organization of an agency or organization must include the following contents:
1. Name of the digital signature certification service organization.
2. Name of the subscriber.
3. Serial number of the digital certificate.
4. Validity period of the digital certificate.
5. Public key of the subscriber.
6. Digital signature of the digital signature certification service organization.
7. Restrictions on purpose and scope of use of the digital certificate.
8. Legal liability limitations of the digital signature certification service organization.
9. Cryptographic algorithm.
10. Other necessary contents as prescribed by the Ministry of Information and Communications.
Article 6. Digital Certificate of Agencies, Organizations, and Authorized Persons of Agencies, Organizations
1. All agencies, organizations, state positions, and authorized persons of agencies, organizations as stipulated by laws on seal management and use have the right to be issued a digital certificate with the value as prescribed in Clause 2, Article 8 of this Decree.
2. The digital certificate issued to state positions and authorized persons of agencies, organizations must clearly state the position and name of the agency or organization of such person.
3. The issuance of digital certificates to agencies, organizations, state positions, and authorized persons of agencies, organizations must be based on the following documents:
a) A document from the agency or organization requesting the issuance of a digital certificate for the agency, organization, authorized person, or state position.
b) A valid copy of the decision establishing the agency or organization, the decision defining functions, tasks, powers, or a document confirming the position of the authorized person of the agency or organization or the state position.
Article 7. Use of Digital Signatures and Digital Certificates of Agencies, Organizations, and Authorized Persons of Agencies, Organizations
1. The digital signature of the entity receiving a digital certificate as prescribed in Article 6 of this Decree may only be used to perform transactions within the authority of the agency, organization, and the state position holding the digital certificate.
2. The act of signing on behalf of or at the request of another person as prescribed by law shall be carried out by the authorized person using their own digital signature, understood based on the position of the signer recorded on the digital certificate.
Article 8. Legal Value of Digital Signature
1. In cases where the law requires a document to bear a signature, the requirement for a data message is considered met if the data message is signed with a digital signature and the digital signature is secured according to the provisions of Article 9 of this Decree.
2. In cases where the law requires a document to bear the stamp of an agency or organization, the requirement for a data message is considered met if the data message is signed with a digital signature of the agency or organization and the digital signature is secured according to the provisions of Article 9 of this Decree.
3. Foreign digital signatures and digital certificates licensed for use in Vietnam according to Chapter V of this Decree have the same legal value and effect as those issued by public digital signature certification service organizations in Vietnam.
Article 9. Conditions to ensure the security of digital signatures
A digital signature shall be considered a secure electronic signature when it meets the following conditions:
1. The digital signature is created during the period when the digital certificate is valid and can be verified using the public key recorded on that digital certificate.
2. The digital signature is created using the private key corresponding to the public key recorded on the digital certificate issued by one of the following organizations:
a) National digital signature certification service provider organization;
b) Government-specific digital signature certification service provider organization;
c) Public digital signature certification service provider organization;
d) Digital signature certification service provider organization for agencies and organizations granted certificates confirming their qualifications to provide secure specific digital signatures as stipulated in Article 40 of this Decree.
3. The private key must be under the control of the signer at the time of signing.
Article 10. Provisions on the format of digital certificates
When issuing digital certificates, public digital signature certification service providers and specific digital signature certification service providers for agencies and organizations granted certificates confirming their qualifications to provide secure specific digital signatures must comply with the provisions on the format of digital certificates according to the certification regulation of the national digital signature certification service provider organization.
Chapter III
PUBLIC DIGITAL SIGNATURE CERTIFICATION SERVICE
Section 1
LICENSE TO PROVIDE PUBLIC DIGITAL SIGNATURE CERTIFICATION SERVICE
Article 11. Operating Conditions
A public digital signature certification service provider may provide services if it meets the following conditions:
1. It has a license to provide public digital signature certification services issued by the Ministry of Information and Communications.
2. It holds a digital certificate issued by the national digital signature certification service provider organization.
Article 12. Term of License
The license granted to a public digital signature certification service provider has a term of 10 years.
Article 13. Conditions for Issuing a License
1. Subject Conditions:
It is a business established under Vietnamese law.
2. Financial conditions:
a) Deposit a guarantee fund of not less than five billion (5) Vietnamese dong at a commercial bank operating in Vietnam to address risks and compensation that may arise during the provision of services due to errors of the public digital signature certification service provider and to cover costs for receiving and maintaining the company's database in case the license is revoked;
b) Pay maintenance fees for the system checking the status of digital certificates (in the case of reissuing the license).
3. Personnel conditions:
a) The enterprise must have personnel responsible for: System management, system operation, issuance of digital certificates, and ensuring the security of the system information;
b) Personnel specified in point a of this clause must hold a bachelor’s degree or higher in information security, information technology, or electronics and telecommunications.
4. Technical conditions:
a) Establish technical equipment systems to meet the following requirements:
- Fully, accurately, and timely store subscriber information for the issuance of digital certificates throughout the validity period of the digital certificate;
- Fully, accurately, and timely maintain a list of active, suspended, and expired digital certificates, and allow and guide Internet users to access online 24 hours a day, seven days a week;
- Ensure the creation of key pairs only once randomly and uniquely; have features to prevent the discovery of the private key when the corresponding public key is known;
- Have features to warn, block, and detect unauthorized network access;
- Be designed to minimize direct contact with the Internet environment as much as possible;
- The key distribution system for subscribers must ensure the integrity and confidentiality of the key pair. In cases where keys are distributed through a computer network, the key distribution system must use secure protocols to prevent information from being exposed during transmission.
b) Have technical solutions to meet the requirements for ensuring the security of information systems and technical standards and mandatory standards applicable to digital signatures and digital signature certification services currently in effect;
c) Have measures to control entry and exit from the headquarters, system access rights, and entry and exit from locations housing equipment used to provide digital signature certification services;
d) Have backup plans to ensure continuous safe operation and recovery in case of incidents;
đ) Have measures to provide online subscriber information to the national digital signature certification service provider organization to support state management of digital signature certification services;
e) All equipment systems used to provide services must be located in Vietnam;
g) Have headquarters and facilities suitable for fire and explosion prevention requirements under the law, capable of resisting floods, earthquakes, electromagnetic interference, and illegal human intrusion;
h) Have a certification regulation according to the model prescribed in the certification regulation of the national digital signature certification service provider organization.
Article 14. Application Documents for Permit Issuance
1. An application form requesting issuance of a public digital signature authentication service permit according to Model No. 01 attached to this Decree.
2. A bank guarantee certificate issued by a commercial bank operating in Vietnam. This certificate must include, but not be limited to, an unconditional and irrevocable commitment to pay any amount within the guarantee limit to the beneficiary to address risks and potential compensation during the provision of services due to errors by the public digital signature authentication service provider, and to cover costs for receiving and maintaining the enterprise's database in case the permit is revoked.
3. Human resources file including: Curriculum vitae, diplomas, certificates of the technical staff participating in the provision of digital signature authentication services by the enterprise, complying with the provisions of Clause 3, Article 13 of this Decree.
4. Technical plan ensuring compliance with the provisions of Clause 4, Article 13 of this Decree.
5. Authentication regulations according to the model prescribed in the Authentication Regulations of the National Digital Signature Authentication Organization.
Article 15. Review of Application Documents and Permit Issuance
Within 50 days from the date of receipt of valid application documents, the Ministry of Information and Communications shall take the lead and coordinate with the Ministry of Public Security, the Government Cryptographic Agency, and relevant ministries and sectors to review the application documents and issue permits to enterprises that meet the conditions stipulated in Article 13 of this Decree. The format of the public digital signature authentication service permit is specified in Model No. 05 attached to this Decree.
In cases of refusal, the Ministry of Information and Communications shall notify in writing and specify the reasons.
Article 16. Amendment of Permit Content and Reissuance of Permit
1. Amendment of permit content shall be carried out when the enterprise changes any of the following information: legal representative, head office address, trading name.
The enterprise submits an application for amendment of permit content to the Ministry of Information and Communications. The application for amendment of permit content includes: An application form for amendment of permit content according to Model No. 02 attached to this Decree, a detailed report describing the proposed changes, and related documents.
Within 15 working days from the date of receipt of complete and valid application documents, the Ministry of Information and Communications shall review and reissue the permit to the enterprise with the amended contents; if refused, it must notify in writing and specify the reasons.
The validity period of the amended permit is the remaining period of the previously issued permit.
2. In cases where the permit is lost or damaged, the enterprise submits an application for reissuance of the permit according to Model No. 03 attached to this Decree, specifying the reason to the Ministry of Information and Communications. Within 7 working days from the date of receipt of the application, the Ministry of Information and Communications shall examine and reissue the permit to the enterprise.
The validity period of the reissued permit due to loss or damage is the remaining period of the previously issued permit.
3. To ensure the continuity of service provision, enterprises wishing to continue providing services must submit an application for reissuance of the permit at least 90 days before the permit expires. The application for reissuance of the permit due to expiration includes:
a) An application for reissuance of a public digital signature authentication service permit of the enterprise due to the expiration of the old permit according to Model No. 03 attached to this Decree;
b) A bank guarantee certificate issued by a commercial bank operating in Vietnam according to Clause 2, Article 14 of this Decree;
c) Information on personnel and technical changes of the enterprise related to the permit issuance conditions as stipulated in Clauses 3 and 4, Article 13 of this Decree (if applicable).
Within 30 days from the date of receipt of complete and valid application documents, the Ministry of Information and Communications shall take the lead and coordinate with the Ministry of Public Security, the Government Cryptographic Agency, and relevant ministries and sectors to review the application documents and inspect whether the enterprise meets the permit issuance conditions in reality, and reissue the permit to the enterprise if it meets all the conditions. If refused, the Ministry of Information and Communications shall notify in writing and specify the reasons.
The validity period of the reissued permit due to expiration is 10 years.
Article 17. Suspension of license and cessation of issuance of digital certificate
1. A public key infrastructure service provider shall have its license suspended for no more than six months if it falls under any of the following circumstances:
a) Providing services contrary to the content stated on the license;
b) Failing to meet any of the licensing conditions stipulated in Article 13 of this Decree during the provision of services;
c) Failing to pay the full service fee for maintaining the system to check the status of digital certificates for six months.
2. A public key infrastructure service provider must cease issuing new digital certificates to subscribers if it falls under any of the following circumstances:
a) The license for providing public key infrastructure services has been suspended according to Clause 1 of this Article;
b) Upon discovering errors in its service system that may affect the interests of subscribers and recipients.
3. During the period of license suspension, if the public key infrastructure service provider remedies the cause of suspension, the Ministry of Information and Communications will permit the public key infrastructure service provider to continue providing services.
Article 18. Revocation of License
1. A public key infrastructure service provider shall have its license revoked if it occurs any of the following circumstances:
a) Failing to commence service provision within twelve months from the date of issuance without a valid reason;
b) Being dissolved or declared bankrupt in accordance with relevant laws;
c) The license for providing public key infrastructure services has expired;
d) Failing to pay the full service fee for maintaining the system to check the status of digital certificates for twelve months;
đ) Failing to remedy the conditions for suspension as prescribed in Clause 1 of Article 17 after the suspension period set by the competent authority;
e) The enterprise does not wish to continue providing services.
2. A public key infrastructure service provider whose license is revoked shall be responsible for negotiating and transferring all related databases and files concerning service provision and ensuring the continued use of services by subscribers to another active public key infrastructure service provider within thirty days from the date of receipt of the notice of license revocation.
3. The Ministry of Information and Communications supervises and guides the transfer between public key infrastructure service providers to ensure uninterrupted service use by subscribers.
In case of failure to reach an agreement with other organizations regarding the transfer of related databases and files concerning service provision and ensuring the continued use of services by subscribers, the Ministry of Information and Communications shall designate one or more public key infrastructure service providers to carry out this task. The receiving organization shall assume the rights and obligations towards subscribers and recipients according to the contract signed between the subscriber and the organization whose license was revoked.
4. Costs associated with accepting, maintaining databases and files, and ensuring the continued use of services by subscribers shall be taken from the deposit account at the bank of the public key infrastructure service provider whose license was revoked.
5. After three years from the date of license revocation except for the revocation specified in point c of Clause 1 of this Article, a public key infrastructure service provider may request the reissuance of a license. Conditions and procedures for reissuance shall be carried out in accordance with the provisions for new issuance.
Article 19. Validity period of digital certificates issued to organizations providing public key infrastructure (PKI) certification services
Digital certificates issued to organizations providing PKI certification services shall have a validity period of five years.
Article 20. Conditions for issuing digital certificates to organizations providing public key infrastructure (PKI) certification services
1. Possess a valid license for providing PKI certification services issued by the Ministry of Information and Communications.
2. The actual technical system must comply with the licensing application file.
3. The public key on the digital certificate will be unique and paired with the private key of the organization applying for the digital certificate.
Article 21. Documents for issuing digital certificates to organizations providing public key infrastructure (PKI) certification services
The documents for issuing digital certificates to organizations providing PKI certification services include:
1. A request form for issuing a digital certificate according to Model No. 04 attached to this Decree.
2. A copy of the license for providing PKI certification services.
3. Other documents as prescribed in the certification regulations of the organization providing PKI certification services.
Article 22. Examination and issuance of digital certificates to organizations providing public key infrastructure (PKI) certification services
Within thirty working days from the date of receipt of a complete and valid application for a digital certificate, the organization providing PKI certification services shall examine the application:
1. The organization providing PKI certification services shall conduct the following examinations:
a) Inspect the actual technical system of the organization providing PKI certification services to ensure that it complies with the licensing application file;
b) Witness the creation of the private key and public key pair of the organization providing PKI certification services to ensure that the key pair is created securely as prescribed.
2. If the conditions for issuing a digital certificate are met, the organization providing PKI certification services shall issue the digital certificate. If the conditions are not met, the organization providing PKI certification services shall issue a written refusal to issue the digital certificate and specify the reasons.
3. The issuance of digital certificates by the organization providing PKI certification services to organizations providing PKI certification services must ensure the continuity of the service provided to subscribers.
Section 2
ACTIVITIES OF PROVIDING SERVICES BY ORGANIZATIONS PROVIDING PUBLIC KEY INFRASTRUCTURE (PKI) CERTIFICATION SERVICES
1. A digital certificate issuance application form according to the model of the organization providing PKI certification services.
2. Supporting documents including:
a) For individuals: Identity card or citizen identification card or passport;
b) For organizations: Decision on establishment or decision on functions, tasks, powers, organizational structure or business registration certificate or investment certificate; identity card, citizen identification card or passport of the legal representative of the organization.
3. Individuals and organizations have the right to choose to submit certified copies, photocopies with certification, or photocopies presented together with original documents for verification.
Article 24. Creation and Distribution of Keys for Subscribers
1. Organizations and individuals requesting issuance of digital certificates may create their own key pairs or request in writing that public key service providers create key pairs for them.
2. In cases where organizations and individuals requesting issuance of digital certificates create their own key pairs, public key service providers must ensure that such organizations and individuals use equipment in accordance with prescribed standards to generate and store the key pairs.
3. In cases where public key service providers create key pairs, such organizations must ensure secure methods are used to transfer secret keys to organizations and individuals requesting issuance of digital certificates and may only retain copies of secret keys upon written request from such organizations and individuals.
Article 25. Issuance of Digital Certificates for Subscribers
1. Public key service providers issue digital certificates to subscribers after verifying the following contents:
a) The information in the application for issuance of digital certificates submitted by the subscriber is accurate;
b) The public key on the digital certificate to be issued will be unique and paired with the secret key of the organization or individual requesting issuance of the digital certificate.
2. A digital certificate can only be issued to the applicant and must contain all the information specified in Article 5 of this Decree.
3. Public key service providers may only publish the issued digital certificate of the subscriber in their database based on confirmation of the accuracy of the information on the digital certificate from the subscriber; the publication period shall not exceed 24 hours after receipt of such confirmation, except in cases of agreement otherwise.
4. Public key service providers shall not refuse to issue digital certificates to organizations and individuals requesting issuance of digital certificates without justifiable reasons.
5. Public key service providers must ensure security throughout the entire process of creating and transferring digital certificates to subscribers.
Article 26. Extension of Digital Certificates for Subscribers
1. At least 30 days before the expiration date of the digital certificate, the subscriber has the right to request an extension of the digital certificate.
2. Upon receiving a request for extension from the subscriber, the public key service provider has the obligation to complete the extension procedures before the certificate expires.
3. In cases where there is a change in the public key on the extended digital certificate, the subscriber must clearly request it; the creation, distribution, and publication of the extended digital certificate shall be carried out in accordance with the provisions of Articles 24 and 25 of this Decree.
Article 27. Change of Key Pairs for Subscribers
In cases where the subscriber requests a change in the key pair, the subscriber must submit a request for changing the key pair. The creation, distribution, and publication of the digital certificate with the new public key shall be carried out in accordance with the provisions of Articles 24 and 25 of this Decree.
Article 28. Suspension and Restoration of Digital Certificates for Subscribers
1. The digital certificate of the subscriber shall be suspended in the following cases:
a) When the subscriber requests in writing and such request has been verified as accurate by the public key service provider;
b) When the public key service provider has grounds to confirm that the issued digital certificate does not comply with the provisions of Articles 24 and 25 of this Decree or when any errors affecting the rights of the subscriber and recipient are discovered;
c) When requested by judicial authorities, police agencies, or the Ministry of Information and Communications;
d) According to the suspension conditions stipulated in the contract between the subscriber and the public key service provider.
2. Upon having grounds for suspending the digital certificate, the public key service provider must suspend it immediately and notify the subscriber and publish on the database of digital certificates the suspension, start time, and end time of the suspension.
3. Public key service providers must restore the digital certificate when there are no longer grounds for suspension or when the suspension period according to the request has expired.
Article 29. Revocation of Digital Certificates for Subscribers
1. The digital certificate of a subscriber shall be revoked in the following cases:
a) When the subscriber requests in writing and such request has been verified by the service provider organization to be accurate;
b) When the subscriber, being an individual, dies or is declared missing by a court, or when the subscriber, being an organization, is dissolved or declared bankrupt under the provisions of the law;
c) When requested by judicial authorities, police agencies, or the Ministry of Information and Communications;
d) In accordance with the conditions for revoking digital certificates that have been stipulated in the contract between the subscriber and the public key certification service provider organization.
2. When there is a basis for revoking the digital certificate, the public key certification service provider organization must revoke the digital certificate, simultaneously notify the subscriber, and publish on the database of digital certificates the revocation thereof.
Article 30. Time Stamp Service
1. The time stamp service is an added-value service to attach information about date, month, year, and time to data messages.
2. The time stamp service is provided by the public key certification service provider organization. The provision of the time stamp service must comply with technical standards and mandatory standards applicable to the time stamp service.
3. The date, month, year, and time attached to the data message are the date, month, year, and time when the time stamp service provider organization receives the data message and is certified by the time stamp service provider organization.
4. The source of time of the time stamp service provider organizations must comply with the provisions of the law regarding national standard time sources.
Article 31. Certification Rules of Public Key Certification Service Provider Organizations
1. The certification rules of public key certification service provider organizations are established according to the model prescribed in the certification rules of the National Public Key Certification Service Provider Organization.
2. The certification rules of public key certification service provider organizations must be made public in accordance with Clause 2 of Article 33 of this Decree.
3. When there is a change in information in the certification rules, the public key certification service provider organization must notify in writing to the National Public Key Certification Service Provider Organization and must obtain written consent from the National Public Key Certification Service Provider Organization for the changed contents.
Section 3
OBLIGATIONS OF PUBLIC KEY CERTIFICATION SERVICE PROVIDER ORGANIZATIONS
Article 32. Obligations of Public Key Certification Service Provider Organizations towards Subscribers
1. Ensuring continuous and uninterrupted use of services by subscribers throughout the validity period of the digital certificate and continuously checking the status of the subscriber's digital certificate.
2. Resolving risks and compensation amounts occurring for subscribers and recipients in cases where errors are determined to be caused by the public key certification service provider organization.
3. Ensuring the security of personal information, private information, and storage devices for digital certificates for subscribers in accordance with the laws on information security and other related laws.
4. Receiving Information:
Ensuring that the information reception channel operates 24 hours a day and 7 days a week from subscribers related to the use of digital certificates.
5. Related to key management activities:
a) Immediately notifying the subscriber and applying preventive measures and timely remediation actions upon discovering signs that the subscriber's secret key has been exposed, is no longer intact, or any other error that may adversely affect the subscriber's interests;
b) Advising the subscriber to change the key pair when necessary to ensure the highest reliability and security of the key pair.
6. In case of temporarily suspending issuance of new digital certificates:
During the suspension period, the public key certification service provider organization is responsible for maintaining the relevant database system for issued digital certificates.
7. Upon revocation of the license, the public key certification service provider organization must immediately notify the subscriber about the cessation of its services and provide information about the organization receiving its database to ensure the subscriber's service usage rights.
8. Drafting a model contract with subscribers including the following contents:
a) Scope, limitations of use, level of security, costs related to the issuance and use of digital certificates, and other information that may affect the subscriber's interests;
b) Requirements for ensuring safety in storing and using secret keys;
c) Complaint procedures and dispute resolution.
9. Implementing the rights and obligations of the principal party according to the provisions of the commercial law.
Article 33. Obligations of organizations providing public digital signature certification services towards state management agencies for digital signatures and certification services
1. Disclosure of information:
Organizations providing public digital signature certification services must publicly disclose and maintain the following information on their electronic bulletin boards 24 hours a day, 7 days a week:
a) Their certification regulations and digital certificates;
b) The list of active, suspended, and revoked digital certificates of subscribers;
c) Other necessary information as prescribed by law.
2. Updating information:
Organizations providing public digital signature certification services must update the information specified in Clause 1 of this Article within 24 hours when there is a change.
3. Providing information:
Organizations providing public digital signature certification services must provide online in real-time to the organization providing national digital signature certification services information about the number of active, suspended, and revoked digital certificates to serve state management work related to certification services.
4. Storing information:
All information related to the temporary suspension or revocation of licenses and subscriber databases, digital certificates must be stored for at least five years from the date of license suspension or revocation.
5. Paying service fees for maintaining the system to check the status of digital certificates as prescribed.
6. Reporting periodically and urgently as prescribed by the Ministry of Information and Communications and the requirements of competent state agencies.
Section 4
PUBLIC DIGITAL SIGNATURE CERTIFICATION SERVICE AGENTS
Article 34. Conditions for operation of public digital signature certification service agents
1. Being a trader including legally established economic organizations, individuals engaged in independent and regular commercial activities and registered for business.
2. Having a specific address for the trading office.
3. Having an agency contract with the organization providing public digital signature certification services.
Article 35. Rights and obligations of public digital signature certification service agents
1. Implementing the rights and obligations of agents as prescribed by law on commerce.
2. Fully guiding the application forms and procedures for issuing digital certificates to subscribers.
3. Publicly posting the process of issuing digital certificates at the agent's office.
4. Ensuring a 24-hour-a-day, 7-day-a-week information channel to receive requests from subscribers.
5. Bearing responsibility to report when required by competent authorities to serve state management work related to certification services.
Chapter IV
SPECIALIZED DIGITAL SIGNATURE CERTIFICATION SERVICES OF ORGANIZATIONS
Section 1
ISSUING LICENSES FOR THE REGISTRATION OF ACTIVITIES OF ORGANIZATIONS PROVIDING SPECIALIZED DIGITAL SIGNATURE CERTIFICATION SERVICES FOR ORGANIZATIONS
Article 36. Conditions for operation and registration of activities
1. Conditions for operation
Organizations can operate to provide specialized digital signature certification services when they have an activity registration certificate issued by the Ministry of Information and Communications.
2. Conditions for registration of activities
a) Organizations must have personnel responsible for: System administration; system operation and issuance of digital certificates; ensuring the security of the system. These personnel must hold a bachelor's degree or higher in information security, computer science, or electronics and telecommunications;
b) Establishing technical equipment systems that meet the following requirements:
- Fully, accurately, and timely store subscriber information for the issuance of digital certificates throughout the validity period of the digital certificate;
- Ensure the creation of key pairs only once randomly and uniquely; have features to prevent the discovery of the private key when the corresponding public key is known;
- Have features to warn, block, and detect unauthorized network access;
- Designed to minimize direct contact with the Internet environment as much as possible.
c) Having a plan to provide online subscriber information to the organization providing national digital signature certification services to serve state management work related to certification services;
d) The entire system of equipment used to provide services must be located in Vietnam;
đ) Having an office and location for machinery and equipment that comply with fire prevention and explosion protection laws; capable of resisting floods, earthquakes, electromagnetic interference, and illegal human intrusion.
Article 37. Registration Documents
1. Application for issuance of registration certificate for operation of organizations providing specialized digital signature verification services according to Model No. 06 attached hereto.
2. Documents proving compliance with the conditions for registration of operation as stipulated in Clause 2, Article 36 of this Decree.
3. Documents proving that the service users have the same nature of activities or purpose of work and are linked through the charter of operation or legal regulations on organizational structure or forms of cooperation and joint operations.
Article 38. Procedures for Issuance, Temporary Suspension, Revocation, Modification, and Reissuance of Registration Certificates for Operation
1. Issuance of Registration Certificate for Operation
a) Within thirty working days from the date of receipt of a valid registration application, the Ministry of Information and Communications shall examine the application and issue the registration certificate for operation if the application meets the conditions for registration of operation as stipulated in Clause 2, Article 36 of this Decree. The model of the registration certificate for organizations providing specialized digital signature verification services is specified in Model No. 09 attached hereto.
In case of refusal, the Ministry of Information and Communications shall notify in writing and specify the reasons.
b) The registration certificate for operation of organizations providing specialized digital signature verification services for agencies and organizations has a validity period of five years.
2. Temporary Suspension of Registration Certificate for Operation
Organizations providing specialized digital signature verification services for agencies and organizations may be temporarily suspended from operating for no more than six months in the following cases:
a) Providing services contrary to the content recorded on the registration certificate for operation;
b) Failing to meet one of the conditions for issuance of the registration certificate for operation as stipulated in Clause 2, Article 36 of this Decree during the provision of services.
3. Restoration of Registration Certificate for Operation
During the period of temporary suspension of the registration certificate for operation, if the organization providing specialized digital signature verification services for agencies and organizations remedies the cause of temporary suspension, the Ministry of Information and Communications will allow the organization to continue providing services.
4. Revocation of Registration Certificate for Operation
Organizations providing specialized digital signature verification services for agencies and organizations will have their registration certificates for operation revoked in the following cases:
a) Not implementing the provision of services within twelve months from the date of issuance of the registration certificate for operation without a legitimate reason;
b) Being dissolved or declared bankrupt in accordance with relevant laws;
c) Failing to remedy the conditions for temporary suspension as stipulated in Clause 2, Article 38 of this Decree after the suspension period set by the competent authority;
d) Agencies and organizations do not wish to continue providing services.
5. Modification of Content of Registration Certificate for Operation
Modification of the content of the registration certificate for operation shall be carried out when the organization issued the certificate changes one of the following information: headquarters address, legal representative, scope and target of service provision, technical standards applied.
To modify the content of the registration certificate for operation, the organization providing specialized digital signature verification services for agencies and organizations must submit an application for modification of the content of the registration certificate for operation to the Ministry of Information and Communications, which includes: an application for modification of the content of the registration certificate for operation according to Model No. 07 attached hereto and related documents and materials serving as the basis for the request for modification.
Within fifteen working days from the date of receipt of a complete and valid application, the Ministry of Information and Communications shall examine and reissue the registration certificate for operation with the modified contents; in case of refusal to reissue, it must notify in writing and specify the reasons.
The validity period of the reissued registration certificate for operation is the remaining period of the previously issued certificate.
6. Reissuance of Registration Certificate for Operation Upon Expiry
At least thirty days before the expiry of the registration certificate for operation, the organization providing specialized digital signature verification services for agencies and organizations must submit an application for reissuance of the registration certificate for operation upon expiry. The application for reissuance of the registration certificate for operation upon expiry includes:
a) An application for reissuance of the registration certificate for operation upon expiry according to Model No. 08 attached hereto;
b) Any changes in personnel and technical information of the organization related to the conditions for issuance of the certificate as stipulated in Clause 2, Article 36 of this Decree (if applicable).
Within fifteen working days from the date of receipt of a valid application for reissuance of the registration certificate for operation upon expiry, the Ministry of Information and Communications shall examine the application.
If the application meets all conditions, the Ministry of Information and Communications shall reissue the registration certificate for operation for the organization. In case of refusal, the Ministry of Information and Communications shall notify in writing and specify the reasons.
The validity period of the reissued registration certificate for operation upon expiry is five years.
Article 39. Rights and Obligations of Organizations Providing Special-Purpose Digital Signature Certification Services
1. Provide special-purpose digital signature certification services within the scope and objects of operation registered in the business registration certificate issued by the Ministry of Information and Communications.
2. Specify the provision and use of special-purpose digital signature certification services within agencies and organizations within the scope and objects of operation registered.
3. Report periodically and urgently in accordance with the regulations of the Ministry of Information and Communications and the requirements of competent state agencies.
4. In cases where organizations providing special-purpose digital signature certification services for agencies and organizations have the need to use special-purpose digital signatures to transact with organizations and individuals serving specialized activities under their functions and tasks, they must have a certificate of qualification conditions ensuring safety for special-purpose digital signatures issued by the Ministry of Information and Communications in accordance with Articles 9, 40, and 41 of this Decree.
Section 2
ISSUANCE OF CERTIFICATE OF QUALIFICATION CONDITIONS ENSURING SAFETY FOR SPECIAL-PURPOSE DIGITAL SIGNATURES OF AGENCIES AND ORGANIZATIONS
Article 40. Conditions for Issuing Certificate of Qualification Conditions Ensuring Safety for Special-Purpose Digital Signatures
1. Have a business registration certificate of the organization providing special-purpose digital signature certification services.
2. Meet the human resources and technical conditions prescribed in Clauses 3 and 4 of Article 13 of this Decree.
Article 41. Documents for Requesting Issuance of Certificate of Qualification Conditions Ensuring Safety for Special-Purpose Digital Signatures
1. Application for issuance of certificate of qualification conditions ensuring safety for special-purpose digital signatures according to Model No. 10 attached to this Decree.
2. Copy of the business registration certificate of the organization providing special-purpose digital signature certification services.
3. Decision on establishment and charter of the organization.
4. Human resources dossier including curriculum vitae, certificates of the team of personnel participating in the provision of special-purpose digital signature certification services meeting the provisions of Clause 3 of Article 13 of this Decree.
5. Technical plan to ensure the provisions of Clause 4 of Article 13 of this Decree.
6. Certification regulation according to the model prescribed in the certification regulation of the National Digital Signature Certification Organization.
Article 42. Procedures and Formalities for Issuing, Temporarily Suspending, Revoking, Amending Content, and Reissuing Certificate of Qualification Conditions Ensuring Safety for Special-Purpose Digital Signatures
1. Issuance of Certificate of Qualification Conditions Ensuring Safety for Special-Purpose Digital Signatures
a) Within sixty working days from the date of receipt of a valid application for issuance of certificate of qualification conditions ensuring safety for special-purpose digital signatures, the Ministry of Information and Communications shall take the lead and coordinate with the Ministry of Public Security, the Government Cryptographic Office, and relevant ministries and sectors to examine the documents, conduct on-site inspections, and issue the certificate of qualification conditions ensuring safety for special-purpose digital signatures to the organization if it meets all the conditions stipulated in Article 40 of this Decree. The format of the certificate of qualification conditions ensuring safety for special-purpose digital signatures is specified in Model No. 13 attached to this Decree.
If the organization does not meet the required conditions, the Ministry of Information and Communications will notify in writing and specify the reasons.
b) The certificate of qualification conditions ensuring safety for special-purpose digital signatures has a validity period corresponding to the business registration certificate of the organization providing special-purpose digital signature certification services but not exceeding five years.
2. Temporary Suspension of Certificate of Qualification Conditions Ensuring Safety for Special-Purpose Digital Signatures
An organization providing special-purpose digital signature certification services for agencies and organizations may be temporarily suspended from holding the certificate of qualification conditions ensuring safety for special-purpose digital signatures for no more than six months in any of the following cases:
a) Being temporarily suspended from holding the business registration certificate of the organization providing special-purpose digital signature certification services;
b) Not meeting one of the conditions for issuing the certificate of qualification conditions ensuring safety for special-purpose digital signatures stipulated in Clause 2 of Article 40 of this Decree during the provision of services.
3. Restoration of Certificate of Qualification Conditions Ensuring Safety for Special-Purpose Digital Signatures
During the temporary suspension of the certificate of qualification conditions ensuring safety for special-purpose digital signatures, if the organization providing special-purpose digital signature certification services for agencies and organizations remedies the cause of the temporary suspension, the Ministry of Information and Communications will revoke the decision to temporarily suspend the certificate of qualification conditions ensuring safety for special-purpose digital signatures of the agency or organization.
4. Revocation of Certificate of Qualification Conditions Ensuring Safety for Special-Purpose Digital Signatures
An organization providing special-purpose digital signature certification services for agencies and organizations will have its certificate of qualification conditions ensuring safety for special-purpose digital signatures revoked in any of the following cases:
a) Being revoked from holding the business registration certificate of the organization providing special-purpose digital signature certification services;
b) Not remedying the conditions for temporary suspension stipulated in Clause 2 of Article 42 of this Decree after the suspension period set by the state agency.
5. Amendment of Content of Certificate of Qualification Conditions Ensuring Safety for Special-Purpose Digital Signatures
The amendment of content of the certificate of qualification conditions ensuring safety for special-purpose digital signatures is carried out when the organization holding the certificate of qualification conditions ensuring safety for special-purpose digital signatures changes one of the following information: headquarters address, legal representative, scope and objects of service provision, technical standards applied.
To change the content of the certificate proving eligibility for ensuring the safety of specialized digital signatures, the service provider organization of specialized digital signature authentication of agencies and organizations shall submit a request to change the content of the certificate proving eligibility for ensuring the safety of specialized digital signatures to the Ministry of Information and Communications. The application file includes: Form No. 11 attached to this Decree and related documents that serve as the basis for requesting changes.
Within fifteen working days from the date of receiving a valid application file, the Ministry of Information and Communications shall review and reissue the certificate proving eligibility for ensuring the safety of specialized digital signatures with the changed contents; in case of refusal to issue, it must notify in writing and specify the reasons.
The validity period of the reissued certificate proving eligibility for ensuring the safety of specialized digital signatures is the remaining validity period of the previously issued certificate.
6. Reissuing the certificate proving eligibility for ensuring the safety of specialized digital signatures upon expiration
At least forty-five days before the certificate proving eligibility for ensuring the safety of specialized digital signatures expires, the service provider organization of specialized digital signature authentication shall submit an application to reissue the certificate proving eligibility for ensuring the safety of specialized digital signatures due to expiration. The application file for reissuing the certificate proving eligibility for ensuring the safety of specialized digital signatures due to expiration includes:
a) An application for reissuing the certificate proving eligibility for ensuring the safety of specialized digital signatures due to expiration, according to Form No. 12 attached to this Decree;
b) A copy of the registration certificate for the operation of the service provider organization of specialized digital signature authentication;
c) Information on personnel and technical changes of the relevant organization related to the conditions for issuing the certificate proving eligibility for ensuring the safety of specialized digital signatures as stipulated in Clause 2, Article 40 of this Decree.
Within thirty days from the date of receiving a valid application file, the Ministry of Information and Communications shall lead and coordinate with relevant ministries and sectors to review the application file and inspect the actual fulfillment of the conditions for issuing the certificate.
If the organization meets all the conditions for issuing the certificate, the Ministry of Information and Communications shall reissue the certificate proving eligibility for ensuring the safety of specialized digital signatures to the organization. In case of refusal, the Ministry of Information and Communications shall issue a written notification specifying the reasons.
The validity period of the reissued certificate proving eligibility for ensuring the safety of specialized digital signatures due to expiration is five years.
Chapter V
DIGITAL CERTIFICATES AND FOREIGN DIGITAL SIGNATURES IN VIETNAM
Article 43. Conditions for using foreign digital certificates
1. The digital certificate is still valid for use.
2. It has been granted permission to use in Vietnam by the Ministry of Information and Communications or accepted in international transactions. In cases where foreign digital certificates are used for servers and software without requiring a permit.
Article 44. Subjects using foreign digital certificates
1. Foreign organizations and individuals in Vietnam.
2. Vietnamese organizations and individuals who need to conduct electronic transactions with foreign partners where the digital certificates provided by domestic digital signature authentication service organizations have not been recognized in that country.
Article 45. Scope of Activities and Validity Period of Permits for Using Foreign Digital Certificates in Vietnam
1. The scope of activities shall be electronic transactions of entities using foreign digital certificates as prescribed in Article 44 of this Decree.
2. The validity period of permits for using foreign digital certificates in Vietnam shall be five years but not exceeding the validity period of the digital certificate.
Article 46. Conditions for Issuing Permits for Use
1. For subscribers using foreign digital certificates in Vietnam:
a) Belonging to the category prescribed in Article 44 of this Decree;
- Business registration certificate or investment certificate or establishment decision or decision specifying functions, tasks, and authorities for organizations; identity card or citizen identification card or passport for individuals;
- A document from the competent authority allowing foreign organizations and individuals to operate legally in Vietnam for subscribers who are foreign organizations and individuals;
- In cases where authorization to use a digital certificate is granted, there must be a lawful authorization for the use of the digital certificate, and the subscriber's information must match the information in the authorization document.
2. For foreign service providers of digital signature certification with recognized digital certificates in Vietnam:
a) Established and operating legally in the country where the foreign digital signature certification service provider has registered to operate;
b) Meeting the mandatory standard list applicable to digital signatures and digital signature certification services issued by the Ministry of Information and Communications or international standards on digital signatures determined by the Ministry of Information and Communications to have equivalent levels of information security;
c) Certified by an auditing firm that their business operations comply with reputable international standards on digital signature certification services.
Article 47. Documents for Issuing Permits for Using Foreign Digital Certificates in Vietnam
1. An application form for issuing a permit for using foreign digital certificates in Vietnam by the subscriber according to Model No. 14 attached to this Decree.
2. Explanatory and supporting documents demonstrating compliance with the conditions stipulated in Article 46 of this Decree.
3. A certified true copy of the contract (or agreement) for using foreign digital certificates between the subscriber and the foreign digital certificate provider or a document proving that the subscriber is a legitimate user of the foreign digital certificate.
4. A commitment statement regarding the use of foreign digital certificates in Vietnam in accordance with Vietnamese laws on digital signatures and digital signature certification services.
Article 48. Examination of Application Documents and Issuance of Permits for Using Foreign Digital Certificates in Vietnam
1. Within thirty working days from the date of receipt of valid application documents from organizations and individuals requesting issuance of permits for using foreign digital certificates in Vietnam, the Ministry of Information and Communications shall examine the application documents.
2. If the application documents meet the stipulated conditions, the Ministry of Information and Communications shall issue a permit for using foreign digital certificates in Vietnam. The model for the permit for using foreign digital certificates in Vietnam is specified in Model No. 15 attached to this Decree.
In cases where the conditions are not met, the Ministry of Information and Communications shall notify in writing and specify the reasons.
Article 49. Amendment and Reissue of Foreign Digital Certificate Usage Permit in Vietnam
1. The amendment of the content of foreign digital certificate usage permit in Vietnam shall be carried out in cases where the permit recipient changes their trading name, changes the legal representative for organizations, or changes the type of digital certificate they use.
The application dossier for amending the content of the permit includes an application form for amending the permit content, a detailed report describing the proposed amendments, and related documents (if any).
Within ten working days from the date of receiving all necessary documents, the Ministry of Information and Communications shall review and amend the permit content for the applicant; if the issuance is refused, it must notify in writing and specify the reasons.
2. In case the permit is lost or damaged, the foreign digital certificate user shall submit an application for reissuing the permit to the Ministry of Information and Communications, clearly stating the reason. Within seven working days from the date of receipt of the application, the Ministry of Information and Communications shall examine and reissue the permit for the applicant.
3. The validity period of the amended and reissued permits shall be the remaining period of the previously issued permit.
Article 50. Obligations of Organizations and Individuals Using Foreign Digital Certificates with Permits Issued in Vietnam
1. To use foreign digital certificates within the scope specified in the foreign digital certificate usage permit in Vietnam.
2. To report incidents or provide information on the situation of using foreign digital certificates in Vietnam upon request of the Ministry of Information and Communications.
Article 51. Acceptance of Foreign Digital Certificates in International Transactions
1. Foreign digital certificates accepted in international transactions are those foreign digital certificates whose users are not present in Vietnam and are valid for data messages sent to Vietnamese authorities and organizations.
2. Authorities, organizations, and individuals select and are responsible for accepting foreign digital certificates in international transactions.
Chapter VI
NATIONAL DIGITAL SIGNATURE VERIFICATION SERVICE PROVIDER ORGANIZATION
Article 52. Position, Functions, Tasks, and Powers of the National Digital Signature Verification Service Provider Organization
1. The national digital signature verification service provider organization is a public service unit under the Ministry of Information and Communications, providing verification services for digital signatures to public digital signature verification service providers, specialized digital signature verification service providers of agencies and organizations certified to ensure the security conditions for specialized digital signatures, and agencies, organizations, and individuals using foreign digital certificates permitted for use in Vietnam. The national digital signature verification service provider organization is unique.
2. The national digital signature verification service provider organization has the following tasks and powers:
a) Building, managing, maintaining, and operating technical systems to perform functions as stipulated in Clause 1 of this Article;
b) Self-issuing digital certificates for itself;
c) Researching and submitting to competent authorities for the establishment and issuance of regulations on the management and provision of digital signature verification services for specialized digital signature verification service providers of agencies and organizations certified to ensure the security conditions for specialized digital signatures and agencies, organizations, and individuals using foreign digital certificates permitted for use in Vietnam;
d) Announcing and updating on its electronic information website lists of public digital signature verification service providers, specialized digital signature verification service providers certified to operate, foreign digital certificates permitted for use in Vietnam, and foreign digital certificates accepted in international transactions;
đ) Implementing activities to enable Vietnamese digital signature verification services to be recognized in other countries and international organizations.
Article 53. Activities of Organizations Providing Digital Signature Certification Services
The issuance of digital certificates and digital signature certification services for organizations providing digital signature certification services shall be regulated in Chapters III and IV of this Decree:
1. National digital signature certification service organizations play roles and have rights and obligations as public digital signature certification service organizations according to Chapter III of this Decree. Organizations providing digital signature certification services play roles and have rights and obligations as subscribers according to Chapter III of this Decree.
2. In addition to complying with the provisions of Clause 1 of this Article, national digital signature certification service organizations and organizations providing digital signature certification services must comply with the following provisions:
a) The key pair prescribed in Article 24 of this Decree shall be created by the organization providing digital signature certification services on their own system;
b) The content required to be checked before issuing a digital certificate as prescribed in Clause 1 of Article 25 of this Decree shall include additional checks on compliance with operational conditions as prescribed in Clauses 3 and 4 of Article 13 of this Decree;
c) Public information prescribed in Clause 2 of Article 33 of this Decree shall be published on the electronic news website of the national digital signature certification service organization or public digital signature certification service organizations;
d) Organizations providing digital signature certification services that use digital certificates issued by the national digital signature certification service organization must pay service fees for maintaining the system to check the status of digital certificates according to the Law on Fees and Charges.
Article 54. Regulations on Certification of National Digital Signature Certification Service Organizations
1. The certification regulations of national digital signature certification service organizations shall be promulgated by the Ministry of Information and Communications to guide procedures and processes for providing digital signature certification services, including the following contents:
a) A model contract between public digital signature certification service organizations and agents;
b) A model contract between public digital signature certification service organizations and subscribers;
c) Model certification regulations of public digital signature certification service organizations and specialized digital signature certification service organizations with a certificate ensuring security for specialized digital signatures.
2. Organizations providing digital signature certification services, agents of public digital signature certification services, and subscribers using foreign digital certificates permitted for use in Vietnam are responsible for implementing the provisions of the certification regulations of national digital signature certification service organizations.
Chapter VII
SPECIALIZED DIGITAL SIGNATURE CERTIFICATION SERVICES FOR THE GOVERNMENT
Article 55. Position, Functions, Tasks, Powers of Organizations Providing Specialized Digital Signature Certification Services for the Government
1. Organizations providing specialized digital signature certification services for the government are subordinate organizations under the Government Cryptographic Bureau, providing specialized digital signature certification services for the government to Party and State agencies.
2. Organizations providing specialized digital signature certification services for the government have the following tasks and powers:
a) Managing, maintaining, and operating technical systems to provide specialized digital signature certification services for the government to Party and State agencies;
b) Self-issuing digital certificates for itself;
c) Drafting, submitting to competent authorities for promulgation, and organizing guidance on business procedures regarding the provision, management, and use of specialized digital signature certification services for the government;
d) Annually guiding agencies, organizations, and individuals to report and organize summaries of work on managing and deploying the use of digital certificates and digital signature certification services within Party and State agencies;
đ) Being allocated and guaranteed personnel, funding, and office space by the State to implement tasks, manage, maintain operations, ensure the provision of digital certificates and digital signature certification services according to the actual needs of Party and State agencies and security and safety standards based on the scale of operations.
Article 56. Government Dedicated Digital Signature Certification Services
The organization providing government dedicated digital signature certification services shall provide the following services:
1. Creation and distribution of key pairs.
2. Issuance of digital certificates.
3. Renewal of digital certificates.
4. Modification of information content in digital certificates.
5. Revocation of digital certificates.
6. Restoration of secret key storage devices.
7. Service for publishing and maintaining online databases on digital certificates.
8. Online verification service for digital certificates.
9. Time stamp issuance.
Article 57. Use of Government Dedicated Digital Signature Certification Services
For electronic transactions of Party and State agencies, if digital signatures are applied, they must use digital signature certification services provided by organizations offering government dedicated digital signature certification services.
Article 58. Creation and Distribution of Key Pairs
1. Organizations providing government dedicated digital signature certification services create key pairs (public keys and private keys) for subscribers.
2. Public keys are linked to digital certificates and published online on the website of the organization providing government dedicated digital signature certification services.
3. Private keys corresponding to each subscriber's digital certificate are stored on secret key storage devices and transferred to subscribers through secure methods.
Article 59. Validity Period of Digital Certificates
1. The validity period of digital certificates issued by organizations providing government dedicated digital signature certification services is twenty years.
2. The validity period of newly issued digital certificates for subscribers is a maximum of five years.
3. For renewed digital certificates, the validity period can be extended up to three years.
Article 60. Conditions for Issuing New Digital Certificates
1. Conditions for issuing new digital certificates to individuals:
a) Must be civil servants, public officials, or employees of Party and State agencies with a need for electronic transactions;
b) Must have a written request and confirmation from the head of the agency or directly managing organization.
2. Conditions for issuing new digital certificates to persons authorized by agencies and organizations according to laws on seal management and use, and state officials:
a) Must be persons authorized by agencies and organizations under Party and State agencies according to laws on seal management and use, and state officials with a need for electronic transactions;
b) Must have a written request and confirmation from the head of the agency or directly managing organization.
3. Conditions for issuing digital certificates to agencies and organizations:
a) Must be agencies or organizations with legal personality;
b) Must have a decision establishing the agency or organization or confirmation from the head of the directly managing superior agency or organization;
c) Must have a written request from the person assigned by the agency or organization to manage its digital certificate and confirmation from the head of the directly managing agency or organization.
4. Conditions for issuing new digital certificates to equipment, services, and software:
a) Equipment, services, and software must be owned or managed by agencies or organizations with legal personality;
b) The person managing the digital certificate for the equipment, service, or software must be an authorized person of the agency or organization according to laws on seal management and use;
c) Must have a written request from the person assigned by the agency or organization to manage the digital certificate for the equipment, service, or software and confirmation from the head of the directly managing agency or organization.
Article 61. Documents for Issuing Digital Certificates
1. Documents for issuing digital certificates to individuals: A request for issuance of a digital certificate from the individual, confirmed by the directly managing agency or organization.
2. Issuance of digital certificates to persons authorized by agencies and organizations under laws on seal management and use, and those with state positions: A request for issuance of a digital certificate from the authorized person of the agency or organization under laws on seal management and use, and those with state positions, confirmed by the directly managing agency or organization.
3. Issuance of digital certificates to agencies and organizations: A request for issuance of a digital certificate from the person assigned by the agency or organization to manage the digital certificate, confirmed by the head of the directly managing agency or organization.
4. Issuance of digital certificates to devices, services, software: A request for issuance of a digital certificate from the person assigned by the agency or organization to manage the digital certificate for the device, service, or software, a copyright ownership confirmation document from the agency or organization managing the software, and confirmed by the head of the directly managing agency or organization.
Article 62. Procedures for Issuing Digital Certificates
1. Request for Issuance of Digital Certificates:
a) Digital Certificate for Individuals:
The individual must submit a request for issuance of a digital certificate in accordance with Clause 1 of Article 61 of this Decree to the organization providing specialized government digital signature verification services.
b) Digital Certificate for Persons Authorized by Agencies and Organizations Under Laws on Seal Management and Use, and Those With State Positions:
The person authorized by the agency or organization under laws on seal management and use, and those with state positions must submit a request for issuance of a digital certificate confirmed by the directly managing agency or organization, along with documents as specified in Clause 2 of Article 61 of this Decree, to the organization providing specialized government digital signature verification services.
c) Digital Certificate for Agencies and Organizations:
The person authorized by the agency or organization under laws on seal management and use, who is assigned by the agency or organization to manage the digital certificate for the agency or organization, must submit a request for issuance of a digital certificate confirmed by the directly managing agency or organization, along with documents as specified in Clause 3 of Article 61 of this Decree, to the organization providing specialized government digital signature verification services.
d) Digital Certificate for Devices, Services, Software:
The person authorized by the agency or organization under laws on seal management and use, who is assigned by the agency or organization to manage the digital certificate for the device, service, or software, must submit a request for issuance of a digital certificate confirmed by the directly managing agency or organization to the organization providing specialized government digital signature verification services.
2. Within three working days from the date of receipt of valid documents, the organization providing specialized government digital signature verification services shall be responsible for reviewing the documents, organizing the creation of key pairs, creating digital certificates, and ensuring the secure storage device for the private key for the subscriber. It shall notify the time and place for receiving the secure storage device for the private key to the directly managing agency or organization.
3. The directly managing agency or organization shall be responsible for receiving the secure storage device for the private key from the organization providing specialized government digital signature verification services. After transferring the secure storage device for the private key to the subscriber, the directly managing agency or organization shall submit a request for the effective date of the digital certificate to the organization providing specialized government digital signature verification services.
4. Within one working day from the date of receipt of the request for the effective date of the digital certificate, the organization providing specialized government digital signature verification services shall be responsible for publishing the digital certificate of the subscriber on its electronic information website. The digital certificate of the subscriber becomes effective from the date it is published by the organization providing specialized government digital signature verification services.
Article 63. Conditions for Extending Digital Certificates
1. A digital certificate can only be extended once and must have at least 60 days remaining before its expiration date.
2. Agencies, organizations, and individuals must submit a written request, which must be approved by the direct supervisory agency, to extend the digital certificate.
Article 64. Procedures and Formalities for Extending Digital Certificates
1. Requesting Extension of Digital Certificates
a) Extension of digital certificates for individuals:
Individuals must submit a written request for extension of the digital certificate, confirmed by the directly supervising agency, to the organization providing specialized government digital signature authentication services.
b) Extension of digital certificates for persons authorized by agencies and organizations under the law on management and use of seals, and persons holding state positions:
Individuals authorized by agencies and organizations under the law on management and use of seals, and persons holding state positions must submit a written request for extension of the digital certificate (without attaching the documents specified in point b, Clause 2, Article 61 of this Decree) confirmed by the directly supervising agency, to the organization providing specialized government digital signature authentication services.
c) Extension of digital certificates for agencies and organizations:
The individual authorized by agencies and organizations under the law on management and use of seals, who is assigned by the agency or organization to manage the digital certificate, must submit a written request for extension of the digital certificate (without attaching the documents specified in points b and c, Clause 3, Article 61 of this Decree), confirmed by the directly supervising agency, to the organization providing specialized government digital signature authentication services.
d) Extension of digital certificates for devices, services, and software:
The individual authorized by agencies and organizations under the law on management and use of seals, who is assigned by the agency or organization to manage the digital certificate for devices, services, and software, must submit a written request for extension of the digital certificate, confirmed by the directly supervising agency, to the organization providing specialized government digital signature authentication services.
2. Within three working days from the date of receiving the request for extension of the digital certificate, the organization providing specialized government digital signature authentication services shall be responsible for extending the digital certificate for the subscriber and notify the directly supervising agency.
In case the request for extension of the digital certificate is not accepted, the organization providing specialized government digital signature authentication services shall notify in writing the reasons to the directly supervising agency.
Article 65. Conditions for Changing Information Content in Digital Certificates
1. The digital certificate requiring changes in information content must have at least 60 days remaining before its expiration date, and the validity period of the digital certificate after changing the information content will remain unchanged from the validity period before the change.
2. Agencies, organizations, and individuals must submit a written request, which must be confirmed by the directly supervising agency, to change the information content of the digital certificate.
Article 66. Cases for Changing Information Content in Digital Certificates
1. For individual digital certificates:
a) Change of the agency or organization where the individual works if the information does not match the information in the digital certificate;
b) Change of email address information.
2. For individual digital certificates of persons authorized by agencies and organizations under the law on management and use of seals, and persons holding state positions:
Individuals change their authority of the agency or organization under the law on management and use of seals, or change their state position.
3. For agency or organizational digital certificates:
Agencies or organizations change their name or place of operation if the information does not match the information in the digital certificate.
4. For device, service, or software digital certificates:
Devices, services, or software change their name or upgrade their version, adding new features if the information does not match the information in the digital certificate.
Article 67. Procedures and formalities for changing the content of information in a digital certificate
1. Request to change the content of information in a digital certificate
a) Changing the content of information in a digital certificate for individuals:
Individuals must submit a written request to change the content of information in a digital certificate, confirmed by the directly managing agency or organization, to the service provider of specialized government digital signature certification services;
b) Changing the content of information in a digital certificate for persons authorized by agencies or organizations under the law on management and use of seals, and persons holding state positions:
Individuals authorized by agencies or organizations under the law on management and use of seals, and persons holding state positions must submit a written request to change the content of information in a digital certificate and relevant documents as stipulated in Clause 2, Article 61 of this Decree to the service provider of specialized government digital signature certification services;
c) Changing the content of information in a digital certificate for agencies or organizations:
The person authorized by agencies or organizations under the law on management and use of seals, who is assigned by the agency or organization to manage the digital certificate of the agency or organization, must submit a written request to change the content of information in a digital certificate, confirmed by the directly managing agency or organization, to the service provider of specialized government digital signature certification services;
d) Changing the content of information in a digital certificate for devices, services, software:
The person authorized by agencies or organizations under the law on management and use of seals, who is assigned by the agency or organization to manage the digital certificate for devices, services, software, must submit a written request to change the content of information in a digital certificate, confirmed by the directly managing agency or organization, to the service provider of specialized government digital signature certification services.
2. Within three working days from the date of receiving the request to change the content of information in a digital certificate, the service provider of specialized government digital signature certification services shall be responsible for changing the content of information in the digital certificate for the subscriber and notify the directly managing agency or organization thereof.
In case of refusal to accept the request to change the content of information in a digital certificate, the service provider of specialized government digital signature certification services shall notify in writing with detailed reasons to the directly managing agency or organization.
Article 68. Cases of revoking a digital certificate
1. For all types of digital certificates:
a) The digital certificate has expired;
b) At the written request of the subscriber, confirmed by the directly managing agency or organization, in cases where the secret key is disclosed or suspected to be disclosed; the device storing the secret key is lost or other security breaches occur; the device storing the secret key is damaged;
c) At the written request of the prosecution agency or police agency;
d) At the written request of the agency or organization managing the subscriber;
đ) The subscriber violates the regulations on managing and using the device storing the secret key as stipulated in Article 74 of this Decree.
2. For individual digital certificates:
a) The cases stipulated in Clause 1 of this Article;
b) The individual changes their job position and the new job position information does not match the information in the digital certificate;
c) The individual retires, resigns, or passes away.
3. For digital certificates of individuals authorized by agencies or organizations under the law on management and use of seals, and persons holding state positions:
a) The cases stipulated in Clauses 1 and 2 of this Article;
b) The individual changes the authority of the agency or organization under the law on management and use of seals, or changes the state position.
4. For digital certificates of agencies or organizations:
a) The cases stipulated in Clause 1 of this Article;
b) The agency or organization is dissolved.
5. For digital certificates of devices, services, software:
a) The cases stipulated in Clause 1 of this Article;
b) The device, service, or software ceases operation.
Article 69. Authority to Propose Revocation of Digital Certificates
1. Organizations providing government-specific digital signature authentication services automatically revoke digital certificates when they expire, and simultaneously notify the direct management agency or organization about the revocation of the secret key storage device.
2. In all cases where digital certificates are revoked other than expiration, a written request for revocation must be promptly sent to the direct management agency or organization.
3. When the subscriber is an individual who has retired, resigned, transferred to another agency, or passed away, the direct management agency or organization of the subscriber has the authority to send a written request for revocation of the digital certificate to the organization providing government-specific digital signature authentication services.
4. When the subscriber is an organization that has been dissolved, the direct management agency or organization of that organization has the authority to send a written request for revocation of the digital certificate to the organization providing government-specific digital signature authentication services.
5. Requests for revocation of digital certificates sent to the organization providing government-specific digital signature authentication services must be executed as quickly as possible in writing.
Article 70. Documentation, Procedure, and Process for Revoking Digital Certificates
1. The documentation for revoking digital certificates includes one of the following documents:
a) A written request for revocation of the digital certificate from an individual with confirmation from the direct management agency or organization;
b) A written request for revocation of the digital certificate from a judicial agency or public security agency.
2. Procedure and process for revoking digital certificates:
Within twelve hours from receiving the request for revocation of the digital certificate, the organization providing government-specific digital signature authentication services must render the digital certificate ineffective and announce the revocation of the digital certificate on its electronic information website; simultaneously notify the direct management agency or organization about the revocation of the secret key storage device.
Article 71. Recovery of Secret Key Storage Devices After Expiration of Digital Certificates or Revocation of Digital Certificates
1. Subscribers must be responsible for returning the secret key storage device to the direct management agency or organization when the digital certificate expires or is revoked.
2. The direct management agency or organization of the subscriber is responsible for recovering the secret key storage device in cases where the subscriber is an individual who has retired, resigned, or passed away, or where the subscriber is an organization that has been dissolved and handed over to the organization providing government-specific digital signature authentication services.
3. Process for recovering the secret key storage device:
a) Within five working days from the date of revocation of the digital certificate, the direct management agency or organization is responsible for recovering the secret key storage device of the expired digital certificate or the revoked digital certificate, and handing it over to the organization providing government-specific digital signature authentication services;
b) The handover process of the secret key storage device must be documented in a record.
Article 72. Issuance of New Digital Certificates After Expiration or Revocation of Old Digital Certificates
1. If a subscriber needs to obtain a new digital certificate after the old one has expired or been revoked and meets the conditions set forth in Article 63 of this Decree, they may be considered for issuance of a new digital certificate.
2. The documentation, procedure, and process shall be the same as for the initial issuance of digital certificates.
Article 73. Restoration of Secret Key Storage Devices
1. In cases where secret key storage devices need to be restored:
a) The secret key storage device will be locked when the wrong password is entered more than the number of times specified by the organization providing government-specific digital signature certification services;
b) To reactivate the secret key storage device, the restoration procedure for the secret key storage device must be carried out;
c) Only the organization providing government-specific digital signature certification services and organizations authorized by that organization have the right to restore the secret key storage device;
d) The list of organizations authorized by the organization providing government-specific digital signature certification services to restore the secret key storage device shall be published on the website of the organization providing government-specific digital signature certification services.
2. Documents for restoring secret key storage devices:
A request for restoration of the secret key storage device from the subscriber, confirmed by the directly managing authority or organization.
3. Procedure for restoring secret key storage devices:
a) The subscriber requesting restoration of the secret key storage device, with confirmation from the directly managing authority, sends the request to the organization providing government-specific digital signature certification services;
b) Within 24 hours from receiving the request for restoration of the secret key storage device, the organization providing government-specific digital signature certification services or the authorized organization restores the secret key storage device and informs the subscriber requesting restoration of the secret key storage device and the directly managing authority.
Article 74. Management of Secret Key Storage Devices
1. Secret key storage devices must be managed in accordance with current laws.
2. It is not allowed to use tools, programs, or any other means to alter data or damage secret key storage devices.
Chapter VIII
RIGHTS AND OBLIGATIONS OF SUBSCRIBERS, SIGNERS, RECIPIENTS, ORGANIZATIONS, AND INDIVIDUALS DEVELOPING APPLICATIONS AND PROVIDING DIGITAL SIGNATURE SOLUTIONS
Article 75. Rights and Obligations of Subscribers Using Public Digital Signature Certification Services
1. Has the right to request the organization providing public digital signature certification services to provide in writing the information stipulated in Clause 8, Article 32 of this Decree.
2. Has the right to request the organization providing their digital signature certification service to temporarily suspend or revoke the issued digital certificate and bear responsibility for such requests.
3. Provide information truthfully and accurately as required to the organization providing public digital signature certification services.
4. If creating a key pair themselves, the subscriber must ensure that the key pair generation device complies with technical standards and mandatory standards. This provision does not apply if the subscriber rents the key pair generation device from the organization providing public digital signature certification services.
5. Safely and confidentially store and use their secret key throughout the period during which their digital certificate is valid and suspended.
6. Notify the organization providing their digital signature certification service within 24 hours if they discover signs that their secret key has been disclosed, stolen, or used improperly so that appropriate measures can be taken.
7. When agreeing to allow the organization providing public digital signature certification services to publicly disclose their digital certificate as stipulated in Clause 3, Article 25 of this Decree or when providing that digital certificate to others for transaction purposes, the subscriber is deemed to have committed to the recipient that the subscriber is the lawful holder of the secret key corresponding to the public key on the digital certificate and that the information related to the subscriber on the digital certificate is true, and must fulfill obligations arising from the digital certificate.
8. Shall be held responsible under the law if violating the provisions of Clauses 3, 4, 5, 6, and 7 of this Article and other relevant legal provisions.
Article 76. Rights and Obligations of the Subscriber Using Specialized Digital Signature Certification Services for Agencies and Organizations
1. Use the service within the scope prescribed in the certification regulation of the organization providing digital signature certification services.
2. Safeguard and use their secret key securely and confidentially throughout the period during which their digital certificate is valid and suspended.
3. Notify the organization providing digital signature certification services within twenty-four hours if they discover signs that their secret key has been disclosed, stolen, or used improperly to take timely measures.
Article 77. Rights and Obligations of the Subscriber Using Foreign Digital Certificates Licensed for Use in Vietnam
1. Have rights and obligations similar to those of subscribers using public digital signature certification services within the scope and purposes specified in the license for foreign digital certificates issued in Vietnam.
2. Notify the organization providing digital signature certification services and the Ministry of Information and Communications within twenty-four hours if they discover signs that their secret key has been disclosed, stolen, or used improperly to take timely measures.
Article 78. Obligations of the Signatory Before Executing a Digital Signature
Prior to executing a digital signature, the signatory must perform the following procedures to check the status of their digital certificate:
1. Check the status of their digital certificate on the technical system of the organization providing digital signature certification services that issued the digital certificate.
2. In cases where the signatory uses a digital certificate provided by an organization offering public digital signature certification services: Check the status of the digital certificate of the organization providing digital signature certification services on the technical system of the National Organization Providing Digital Signature Certification Services.
3. If the results of checks under Clauses 1 and 2 of this Article are simultaneously effective, the signatory may execute the digital signature. If the result of the check under Clause 1 or Clause 2 of this Article is not effective, the signatory shall not execute the digital signature.
Article 79. Obligation to Verify the Validity of Digital Certificates and Digital Signatures When Receiving Digitally Signed Data Messages
1. Before accepting a digital signature from the signatory, the recipient must verify the following information:
a) The status of the digital certificate, the scope of use, liability limits, and other information on the digital certificate of the signatory;
b) The digital signature must be created by the secret key corresponding to the public key on the signatory's digital certificate;
c) For digital signatures created by foreign digital certificates licensed for use in Vietnam, the recipient must verify the validity of the digital certificate on both the system of the National Organization Providing Digital Signature Certification Services and the system of the foreign organization providing digital signature certification services issuing the digital certificate.
2. The recipient must follow the verification procedure as follows:
a) Check the status of the digital certificate at the time of signing, the scope of use, liability limits, and other information on the digital certificate according to Article 5 of this Decree on the technical system of the organization providing digital signature certification services that issued the digital certificate;
b) In cases where the signatory uses a digital certificate provided by an organization offering public digital signature certification services: Check the status of the digital certificate of the organization providing digital signature certification services at the time of signing on the technical system of the National Organization Providing Digital Signature Certification Services;
c) A digital signature on a data message is only effective when the results of checks under Clauses 1 and 2 of this Article are simultaneously effective.
3. The recipient shall be responsible in the following cases:
a) Failure to comply with the provisions of Clauses 1 and 2 of this Article;
b) Knowing or being informed about the untrustworthiness of the signatory's digital certificate and secret key.
Article 80. Responsibilities of organizations and individuals developing applications using digital signatures
1. Comply with technical standards and mandatory standards applicable to digital signatures and digital signature certification services that are currently in effect.
2. Ensure technological neutrality and not use technical barriers to limit the use of digital signatures by one or several service providers of digital signature certification services.
3. Update digital certificates of digital signature certification service providers in applications upon request from such organization or upon request from competent authorities as prescribed by law to ensure accurate verification results.
4. Comply with the procedures for checking the status of digital certificates as stipulated in Article 78 and Clause 2 of Article 79 of this Decree.
Article 81. Responsibilities of organizations and individuals providing digital signature solutions
1. Provide solutions that comply with technical standards and mandatory standards applicable to digital signatures and digital signature certification services that are currently in effect.
2. Encourage the provision of solutions that follow widely recognized and advanced digital signature standards worldwide.
Chapter IX
IMPLEMENTING PROVISIONS
Article 82. Transitional Provisions
For digital signature certification service providers currently operating legally, within two years from the date this Decree takes effect, they must meet the conditions for providing services as prescribed in this Decree.
Article 83. Effective Date
1. This Decree shall take effect from November 15, 2018.
2. This Decree replaces Decree No. 26/2007/NĐ-CP dated February 15, 2007 of the Government detailing the implementation of the Law on Electronic Transactions regarding digital signatures and digital signature certification services, Decree No. 106/2011/NĐ-CP dated November 23, 2011 of the Government amending and supplementing certain articles of Decree No. 26/2007/NĐ-CP, and Decree No. 170/2013/NĐ-CP dated November 13, 2013 of the Government amending and supplementing certain articles of Decree No. 26/2007/NĐ-CP and Decree No. 106/2011/NĐ-CP.
Article 84. Implementation Organization and Responsibility for Enforcement
1. Ministries, agencies at the ministerial level, government agencies, provinces, centrally governed cities, and related agencies and organizations involved in applying information technology in state administrative activities and providing online public services to citizens and businesses have the responsibility to promote the application and use of digital signatures and digital signature certification services in accordance with the provisions of this Decree to ensure the security of electronic transactions between state agencies and citizens and businesses.
2. Ministers, heads of agencies at the ministerial level, heads of government agencies, Chairpersons of People's Committees of provinces and centrally governed cities, and related organizations and individuals are responsible for enforcing this Decree./.
|
|
PRIME MINISTER |
원본 문서(PDF)
관계도
문서를 클릭하면 열립니다. 빨간 테두리=효력을 변경하는 관계.