This Circular details the technical audit for organizations providing trust services in the field of electronic signatures and digital signature certification. This Circular takes effect from January 1, 2026.
适用范围
Public key infrastructure certificate service providers and technical audit organizations designated by the Ministry of Science and Technology.
要点
- Provisions on preparing and unifying the technical audit plan
- Evaluating collected information and conducting actual assessments
- Issuing a certificate after completing the technical audit
- The duration of the technical audit shall not exceed six months
- Responsibilities of relevant agencies and organizations in managing and implementing technical audits
🌐 本文件的社会影响
- Strengthening state management over trust service provision activities
- Ensuring the safety and effectiveness of the electronic certification system
- Improving the quality of services and reputation of public key infrastructure certificate service providers
❓ 常见问题
When does this Circular take effect?
This Circular takes effect from January 1, 2026.
What is the duration of the technical audit?
Each technical audit shall not exceed six months.
What must public key infrastructure certificate service providers do in the near future?
Within three years from the date Decree No. 23/2025/NĐ-CP takes effect, these organizations must develop and complete their first technical audit.
全文
CIRCULAR
Article 24regulating technical audit for electronic signatures and trust services
On the basis of Law on Electronic Transactions No. 20/2023/QH15 dated June 22, 2023;
BASED ON Decree No. 23/2025/NĐ-CP dated February 21, 2025 of the Government on electronic signatures and trusted services;
Pursuant to Decree No. 127/2007/NĐ-CP dated August 1, 2007 of the Government detailing implementation of certain provisions of the Law on Technical Standards and Regulations; Decree No. 78/2018/NĐ-CP dated May 16, 2018 of the Government amending and supplementing certain provisions of Decree No. 127/2007/NĐ-CP;
Pursuant to Decree No. 132/2008/NĐ-CP dated December 31, 2008 of the Government detailing implementation of certain provisions of the Law on Product Quality; Decree No. 74/2018/NĐ-CP dated May 15, 2018 of the Government amending and supplementing certain provisions of Decree No. 132/2008/NĐ-CP;
Pursuant to Decree No. 55/2025/NĐ-CP dated March 2, 2025 of the Government stipulating the functions, tasks, powers, and organizational structure of the Ministry of Science and Technology;
AT THE SUGGESTION OF THE DIRECTOR OF THE NATIONAL ELECTRONIC CERTIFICATION CENTER;
The Minister of Science and Technology issues this Circular to regulate technical audit for electronic signature systems and trust services.
PART I
GENERAL PROVISIONS
Article 1. Scope of Regulation
This Circular provides detailed regulations on technical audit activities as stipulated in Clause 2, Article 27 of Decree No. 23/2025/NĐ-CP dated February 21, 2025 of the Government on electronic signatures and trust services.
Article 2. Applicability
1. This Circular applies to organizations and individuals participating in or related to technical audit activities for information systems and service provision processes ensuring the security of electronic signatures, secure electronic signature certificates, digital signatures, secure digital signature certificates, and trust services.
2. Organizations and entities creating and using secure electronic signatures and secure electronic signature certificates shall proactively conduct technical audits as prescribed in this Circular to evaluate their information systems and service provision processes.
Article 3. Explanation of Terms
In this Circular, the following terms are understood as follows:
1. "Technical audit" refers to an independent and objective assessment of information systems and service provision processes aimed at determining compliance with mandatory technical standards, technical regulations, and technical requirements applicable to secure electronic signatures, secure electronic signature certificates, digital signatures, secure digital signature certificates, and trust services. Mandatory technical standards are applied when referenced in technical regulations or legal normative documents.
2. "Technical audit organization" is a certification body designated according to laws on technical standards and regulations, product quality, and goods quality.
3. "Representative location sample" means one or several locations selected from among the registered operating locations of the audited organization for evaluation purposes, ensuring efficiency, resource conservation, and still reflecting objectively the level of compliance across the entire system.
Article 4. Basis for Evaluation and Cycle of Technical Audit
1. The basis for technical audit evaluation includes specific requirements for information systems and service provision processes as stipulated in technical regulations, technical standards, and technical requirements applicable to secure electronic signatures, secure electronic signature certificates, digital signatures, secure digital signature certificates, and trust services.
2. Technical audit shall be conducted periodically every two years.
3. Within a maximum period of one year from the date of issuance of the digital signature certificate, the trust service provider must complete the initial technical audit, except as provided for in Clause 2, Article 15 of this Circular.
Article 5. Method of representative site sampling technical audit
For organizations subject to technical audit with multiple operating sites, the technical audit must be conducted at the headquarters of the organization being audited and may select representative samples for the remaining sites to ensure the comprehensiveness, independence, objectivity, and effectiveness of the technical audit.
When using the method of representative site sampling technical audit, the technical audit organization must ensure the following contents:
1. The number of representative site samples is specified in the service provision contract for technical audit.
2. The selection of representative site samples is based on the following factors:
a) The results of reviewing information security policies;
b) Differences in the scale of information systems at different sites;
c) Differences in the purposes of operation at different sites;
d) The complexity level of information systems at different sites;
đ) Differences in management policies and working methods between sites;
e) Potential risks to the safety of information systems and service delivery processes between sites;
g) Information systems operated by different parties.
3. The selection process must combine purposeful selection methods (based on criteria set out in Clause 2 of this Article) and random selection methods;
4. In cases where non-compliance is discovered at one of the representative sites, corrective actions must be applied to all operational sites of the organization being technically audited;
5. The technical audit organization must establish records and retain documentation regarding the selection of representative sites for evaluation.
Article 6. Review of Corrective Actions
Implementation, review of corrective actions (if any), and issuance of certification shall be carried out as follows:
1. Step 1: Prepare an initial assessment report and request for corrective action
The technical audit organization prepares an initial assessment report after conducting the technical audit activities stipulated in Articles 9, 10, and 11 of this Circular, specifying issues that need to be addressed and sends it to the organization being technically audited to request a corrective plan.
2. Step 2: Develop a corrective action plan
The organization being technically audited must develop and notify the technical audit organization of a corrective action plan based on the initial assessment report from Step 1, including corresponding corrective actions.
3. Step 3: Submit corrective action results and evidence
After completing the corrective action plan, the organization being technically audited must submit a written report on the results of corrective actions along with supporting evidence to the technical audit organization.
4. Step 4: Evaluate corrective action results
The technical audit organization evaluates the results of corrective actions based on the provided evidence. If necessary, additional clarification, verification, or confirmation may be required.
5. Step 5: Issue certification
The technical audit organization reviews the issuance of certification according to the provisions of Clause 2 of Article 12 of this Circular.
Article 7. Technical Audit Report
The technical audit report must include the following basic contents:
1. General information about the technical audit:
a) Description of general information about the organization being technically audited;
b) Objectives, scope, and location of the technical audit;
c) Evaluation bases as prescribed in Clause 1 of Article 4 of this Circular;
d) Relevant legal bases.
2. Assessment of the organization being technically audited's information security risks;
3. Time spent on technical audit activities and total time for the technical audit;
4. Methods of technical audit used during the evaluation process;
5. Information for certification decision-making, including:
a) Contents, scope, locations audited, and collected evidence;
b) Evaluation findings;
c) Detailed information on non-conformities (if any);
d) Conclusions on the conformity of the organization being technically audited with the evaluation bases prescribed in Clause 1 of Article 4 of this Circular;
đ) Expert assessor's evaluation report on the technical audit process;
e) Information on representative sites audited.
6. The technical audit report must be signed by the head of the technical audit team and stamped by the technical audit organization. In cases where the technical audit report is established in the form of a data message, it must be digitally signed by the head of the technical audit team and the technical audit organization.
Article 8. Designation of Technical Audit Organizations
1. The Ministry of Science and Technology shall designate technical audit organizations in accordance with the provisions of laws on technical standards, technical regulations, product quality, and goods.
2. The list of technical audit organizations designated by the Ministry of Science and Technology shall be publicly posted on the Ministry's electronic portal.
Chapter II
TECHNICAL AUDIT
Article 9. Preparation and Unification of the Technical Audit Plan
1. Technical audit organizations shall be responsible for collecting information to serve as a basis for proposing a suitable technical audit plan in accordance with the scale and actual situation of the audited organization. Such information includes:
a) Detailed information about the audited organization;
b) Regulations on certification and policies on electronic signature certificates;
c) Operation procedures and control processes;
d) Technical documentation on information systems;
đ) Terms of agreements with customers;
e) Contracts and agreements with third parties (if any);
g) Documentation and records proving compliance with activities such as system logs, operation logs;
h) Other relevant reports to support the technical audit.
2. The technical audit plan must clearly reflect the following requirements:
a) Evaluation criteria according to Clause 1, Article 4 of this Circular;
b) The duration of the technical audit as stipulated in Article 13 of this Circular;
c) Locations for technical audits. In cases where the technical audit organization needs to apply representative location auditing methods as prescribed in Article 5 of this Circular, the technical audit organization must list representative locations and selection criteria in the technical audit plan.
3. The technical audit organization shall convene meetings and unify in writing with the audited organization regarding the contents planned for implementation in the technical audit plan.
Article 10. Evaluation of Collected Information
The technical audit organization shall evaluate the information provided by the audited organization as stipulated in Clause 1, Article 9 of this Circular. The evaluation results shall serve as the basis for implementing the practical evaluation plan.
Article 11. Practical Evaluation
The technical audit organization shall conduct direct evaluations at the audited organization according to the agreed-upon plan and evaluation content.
Article 12. Issuance of Certification
1. In cases requiring corrective actions, the audited organization shall implement corrective actions as prescribed in Article 6 of this Circular.
2. Based on the results of the technical audit and the results of corrective actions (if any), the technical audit organization shall consider and decide to issue a certificate accompanied by a technical audit report to the audited organization; if not issuing a certificate, the technical audit organization shall notify in writing, specifying the reasons accompanied by the technical audit report to the audited organization.
Article 13. Duration of Technical Audits
1. The duration of a technical audit is calculated from the date of initiating the evaluation of collected information to the date of issuing the technical audit report.
2. The duration of each technical audit shall not exceed six months.
3. In cases requiring corrective actions, if the time required to complete the corrective action plan proposed by the audited organization exceeds the audit duration specified in Clause 2 of this Article, the technical audit organization and the audited organization shall agree in writing to extend the audit duration but not more than forty-five days.
Chapter III
TRÁCH NHIỆM CỦA CÁC CƠ QUAN, TỔ CHỨC LIÊN QUAN VÀ
IMPLEMENTING PROVISIONS
Article 14. Responsibilities of relevant agencies and organizations
1. Technical audit organizations shall be responsible for:
a) Fulfilling the rights and obligations of certification organizations as prescribed by laws on technical standards and technical regulations;
b) Conducting technical audit activities fully, objectively, and independently in accordance with laws on technical standards and technical regulations, product quality, goods quality, and provisions of this Circular;
c) Ensuring that the technical audit process complies with the provisions of this Circular.
2. Organizations subject to technical audit shall be responsible for:
a) Within a maximum period of five (5) working days from the date of receipt of the technical audit results, submitting the technical audit results to the Ministry of Science and Technology (National Electronic Authentication Center) for management purposes;
b) Ensuring the continuous validity of the certificate during the provision of reliable services.
3. The National Standardization, Metrology and Quality Control Committee (Ministry of Science and Technology) shall be responsible for:
a) Being the focal point for receiving and processing applications for designation of technical audit organizations and proposing the Minister of Science and Technology to issue decisions on designating technical audit organizations in compliance with laws on technical standards and technical regulations, product quality, and goods quality;
b) Leading and coordinating with the National Electronic Authentication Center (Ministry of Science and Technology) and related units in reviewing, updating, and perfecting the system of technical regulations and technical standards in the field of reliable services.
4. The National Electronic Authentication Center (Ministry of Science and Technology) shall be responsible for receiving technical audit reports from organizations subject to technical audit; compiling and reporting to the Minister of Science and Technology for state management purposes regarding the provision of reliable services.
Article 15. Implementation and Effectiveness
1. This Circular shall take effect from January 1, 2026.
2. Within three (3) years from the date of effectiveness of Decree No. 23/2025/NĐ-CP dated February 21, 2025 of the Government on electronic signatures and reliable services, public key infrastructure service providers already licensed under Decree No. 130/2018/NĐ-CP dated September 27, 2018 of the Government detailing the implementation of the Law on E-commerce on digital signatures and digital signature verification services must develop plans and complete their initial technical audits.
3. During the implementation process, if there are difficulties or obstacles, relevant organizations and individuals shall report to the Ministry of Science and Technology (National Electronic Authentication Center) for prompt resolution./.
原始文件(PDF)
关系图
点击文件即可打开。红色边框=改变效力的关系。