This Decree stipulates electronic signatures and trusted services, applicable to agencies, organizations, and individuals directly involved or related. It provides detailed regulations on digital certificate issuance, trusted service business operations, and responsibilities of relevant parties.
适用范围
Agencies, organizations, and individuals directly involved or related to electronic signatures and trusted services.
要点
- which → must/are allowed/not allowed to do what → accompanied by SPECIFIC AMOUNT/PENALTY/RATE/THRESHOLD/DURATION/CONDITIONS (if applicable in the text):
- 1. Organizations and individuals directly involved or related to electronic signatures and trusted services → are entitled to be issued public key certificates, must comply with regulations on duration, content, and method of issuance.
- 2. Enterprises engaged in trusted service business → must meet financial conditions, management and technical personnel requirements, and technical plans serving service provision activities.
- 3. Organizations providing public key certification services → establish and manage national electronic certification infrastructure, self-issue public key certificates for themselves, generate key pairs for organizations and individuals.
- 4. Individuals and organizations requesting issuance of public key certificates → must submit complete application documents as prescribed, be issued certificates if they meet the required conditions.
- 5. Organizations providing trusted services that have been temporarily suspended or had their licenses revoked → are responsible for rectifying the situation and implementing measures to continue operations.
🌐 本文件的社会影响
- Positive impact: Enhance information security, improve efficiency of electronic transactions.
- Negative impact: Increased costs for enterprises when implementing conditions for trusted service business.
- Benefits: Citizens and businesses can use secure and convenient electronic signatures.
- Costs: Enterprises must invest in technical systems and personnel to meet legal requirements.
❓ 常见问题
What conditions must enterprises meet to engage in trusted service business?
Meet financial conditions (bonding or insurance), management and technical personnel requirements, and technical plans serving service provision activities.
What documents do individuals need to prepare to issue public key certificates?
Personal identification documents (ID card, passport) and establishment decision or business registration certificate of the organization.
What is the validity period of a digital certificate?
The original digital certificate of the organization providing national electronic certification services has a validity period of 25 years, while digital certificates for time stamping services have a maximum validity period of 5 years.
What should enterprises engaged in trusted service business do if they are temporarily suspended?
They must rectify the reasons for temporary suspension and implement measures to continue operations according to regulations.
What responsibilities do organizations providing public key certification services have when issuing certificates?
Must establish and promulgate procedures and processes for issuing electronic certificates; verify and cross-check information identifying organizations and individuals; retain full information about the certificate issuance and service usage process.
全文
THE GOVERNMENT
____________
Number: 23/2025/NĐ-CP
SOCIALIST REPUBLIC OF VIET NAM
Independence - Freedom - Happiness
______________
Hanoi, February 21, 2025
DECREE
Regulations on electronic signatures and trusted services
_____________
Pursuant to the Law on Organization of the Government dated June 19, 2015; the Law Amending and Supplementing Certain Provisions of the Law on Organization of the Government and the Law on Organization of Local Administration dated November 22, 2019;
Pursuant to the Law on Electronic Transactions dated June 22, 2023;
Pursuant to the Law on Fees and Charges dated November 25, 2015;
At the proposal of the Minister of Information and Communications;
The Government promulgates this Decree to regulate electronic signatures and trusted services.
PART I
GENERAL PROVISIONS
Article 1. Scope of Regulation
This Decree regulates electronic signatures and trusted services, except for specialized electronic signatures for official duties and trusted services for verifying specialized electronic signatures for official duties.
Article 2. Applicability
This Decree applies to agencies, organizations, and individuals directly involved or related to electronic signatures and trusted services.
Article 3. Explanation of Terms
In this Decree, the following terms are understood as follows:
1. "Key" is a binary string (0 and 1) used in cryptographic systems.
2. "Sign with a key" is the process of incorporating a secret key into a software program to automatically generate and attach a digital signature to a data message.
3. "Valid digital certificate" is a digital certificate that has not expired, been suspended, or revoked.
4. "Data message integrity code" is a sequence of characters used to verify the integrity of a data message.
5. "Subscriber" is an agency, organization, or individual that enters into a contract for the provision and use of trusted services with a service provider.
6. "National Electronic Authentication Service Provider Organization" is the National Electronic Authentication Center under the Ministry of Information and Communications.
7. "Authentication policy" is a document containing policies and procedures for issuing, managing digital certificates or digital certificates for specialized secure electronic signatures, using specialized secure electronic signatures, or providing trusted services by the National Electronic Authentication Service Provider Organization, trusted service providers, or specialized secure electronic signature issuers.
8. "Service maintenance fee for status checking system of digital certificates" is the amount of money paid to maintain information systems for checking the status of digital certificates for public key authentication services, time stamping services, and data message authentication services.
9. "Secret key storage medium" is a device containing the subscriber's secret key.
Chapter II
ELECTRONIC SIGNATURES
Section 1
DIGITAL CERTIFICATES FOR ELECTRONIC SIGNATURES
Article 4. Digital Certificates for Electronic Signatures
Digital certificates for electronic signatures are classified as follows:
1. Original digital certificate of the National Electronic Authentication Service Provider Organization is a digital certificate issued by the National Electronic Authentication Service Provider Organization to itself corresponding to each type of trusted service.
2. Digital certificate of a trusted service provider is a digital certificate issued by the National Electronic Authentication Service Provider Organization to a trusted service provider corresponding to each type of trusted service, including: digital certificate for time stamping service, digital certificate for data message authentication service, digital certificate for public key authentication service.
3. Public digital certificate is a digital certificate issued by a public key authentication service provider to a subscriber.
4. Specialized digital certificate is a digital certificate issued by an agency or organization creating a specialized electronic signature.
Article 5. Content of Digital Certificates for Electronic Signatures
The content of digital certificates for electronic signatures includes:
1. Information about the agency or organization issuing the digital certificate for electronic signatures.
2. Information about the agency, organization, or individual receiving the digital certificate for electronic signatures, including the name of the agency, organization, or individual; identification code or number of the agency, organization, or individual or their electronic identity, and other necessary information (if applicable).
3. Serial number of the digital certificate for electronic signatures.
4. Validity period of the digital certificate for electronic signatures.
5. Data for verifying the electronic signature of the agency, organization, or individual receiving the digital certificate for electronic signatures.
6. Electronic signature of the agency or organization issuing the digital certificate for electronic signatures.
7. Purpose and scope of use of the digital certificate for electronic signatures.
8. Legal responsibility of the agency or organization issuing the digital certificate for electronic signatures.
Article 6. Content of Digital Signature Certificate
1. The content of the original digital signature certificate issued by the national electronic authentication service provider includes:
a) Name of the national electronic authentication service provider;
b) Serial number of the digital signature certificate;
c) Validity period of the digital signature certificate;
d) Public key of the national electronic authentication service provider;
đ) Digital signature of the national electronic authentication service provider;
e) Purpose and scope of use of the digital signature certificate;
g) Legal responsibility of the national electronic authentication service provider;
h) Asymmetric key algorithm.
2. The content of the digital signature certificate issued by the trusted service provider corresponding to each type of service includes:
a) Name of the organization issuing the digital signature certificate;
b) Name of the trusted service provider;
c) Serial number of the digital signature certificate;
d) Validity period of the digital signature certificate;
đ) Public key of the trusted service provider;
e) Digital signature of the organization issuing the digital signature certificate;
g) Purpose and scope of use of the digital signature certificate;
h) Legal responsibility of the trusted service provider;
i) Asymmetric key algorithm.
3. The content of the public digital signature certificate includes:
a) Name of the organization issuing the digital signature certificate;
b) Name of the subscriber;
c) Serial number of the digital signature certificate;
d) Validity period of the digital signature certificate;
đ) Public key of the subscriber;
e) Digital signature of the organization issuing the digital signature certificate;
g) Purpose and scope of use of the digital signature certificate;
h) Legal responsibility of the organization providing public digital signature certification services;
i) Asymmetric key algorithm.
Article 7. Validity Period of Electronic Signature Certificate, Digital Signature Certificate
1. The validity period of the original digital signature certificate issued by the national electronic authentication service provider is 25 years.
2. The validity period of the digital signature certificate issued by the trusted service provider:
a) For time stamping services, the maximum validity period is 05 years;
b) For data message authentication services, the maximum validity period is 05 years;
c) For public digital signature authentication services, the maximum validity period is 10 years.
3. The maximum validity period for public digital signature certificates is 03 years.
4. The validity period of the dedicated electronic signature certificate when it is guaranteed by a dedicated electronic signature certificate is 10 years.
Article 8. Format of Electronic Signature Certificate, Digital Signature Certificate
When issuing and distributing electronic signature certificates and digital signature certificates, the agencies and organizations creating dedicated electronic signatures, and the trusted service providers must comply with the format regulations for electronic signature certificates and digital signature certificates as prescribed by the Minister of Information and Communications.
Section 2
SECURE DEDICATED ELECTRONIC SIGNATURE
Article 9. Secure Dedicated Electronic Signature
1. A secure dedicated electronic signature must meet all requirements stipulated in Clause 2, Article 22 of the Law on Electronic Transactions.
A secure dedicated electronic signature guaranteed by an electronic signature certificate of the agency or organization that creates it is deemed to meet all requirements stipulated in Clause 2, Article 22 of the Law on Electronic Transactions.
2. A secure dedicated electronic signature created and used exclusively by the agency or organization for its own activities, consistent with its functions and tasks, includes:
a) Internal activities of the agency or organization creating the secure dedicated electronic signature;
b) Specialized or sectoral activities, having similar nature or purpose of work and interconnected through operational regulations or organizational structure documents, forms of association, and joint activities;
c) Activities representing the agency or organization creating the secure dedicated electronic signature in transactions with other organizations or individuals.
3. The agency or organization creating the secure dedicated electronic signature bears legal responsibility for the use of the secure dedicated electronic signature according to the provisions of Clause 2 of this Article.
Article 10. Documents for requesting issuance and reissuance of specialized electronic signature certification ensuring security.
1. Documents for issuing specialized electronic signature certification ensuring security:
a) Application form for requesting issuance of specialized electronic signature certification ensuring security according to Model No. 01 attached as Appendix to this Decree;
b) A valid copy, including a copy issued from the original book or a certified copy or a copy compared with the original of one of the following documents: business registration certificate, investment registration certificate for foreign investors, decision on establishment or document stipulating organizational structure or other valid certificates/licenses according to laws on investment and laws on enterprises;
c) Regulations on operation, document stipulating organizational structure; forms of association and joint activities to prove the use of specialized electronic signatures ensuring security as provided in Clause 2, Article 9 of this Decree;
d) Document proving the creation of specialized electronic signatures ensuring security meeting all requirements as provided in Clause 1, Article 9 of this Decree according to Model No. 03 attached as Appendix to this Decree;
đ) Regulation on authentication as prescribed in Article 29 of this Decree.
2. Documents for reissuing specialized electronic signature certification ensuring security:
a) Application form for requesting issuance of specialized electronic signature certification ensuring security due to expiration according to Model No. 01 attached as Appendix to this Decree;
b) Document proving the creation of specialized electronic signatures ensuring security meeting all requirements as provided in Clause 1, Article 9 of this Decree according to Model No. 03 attached as Appendix to this Decree;
c) Information changes in the application documents as stipulated in points b, c, đ of Clause 1 of this Article;
d) Report on the implementation of the certification from the date of issuance to the date of reissue request according to Model No. 08 attached as Appendix to this Decree.
Article 11. Procedures for receiving and processing applications for issuance and reissuance of specialized electronic signature certification ensuring security.
1. Agencies and organizations prepare one set of documents corresponding to the issuance and reissuance requests as stipulated in Article 10 of this Decree.
2. The application documents shall be submitted directly to the Ministry of Information and Communications or sent through postal service or via online public service system (National Public Service Portal, https://dichvucong.gov.vn or the Ministry of Information and Communications Public Service Portal, https://dichvucong.mic.gov.vn).
3. The validity check of the documents will be based on the following criteria:
a) The documents must be prepared in accordance with the provisions of Clause 1 of this Article;
b) The documents must be in Vietnamese. The documents must have the confirmation seal of the agency or organization, the certified copy seal; printed documents established by agencies or organizations with two pages or more must be stamped across the fold.
4. Within seven working days from the date of receipt of the application for issuance and reissuance of specialized electronic signature certification ensuring security, the Ministry of Information and Communications will check the validity of the documents according to the provisions of Clause 3 of this Article.
a) In case of non-compliance, the Ministry of Information and Communications will notify and specify the reasons;
b) In case of compliance, the Ministry of Information and Communications will request cooperation in reviewing the documents with the Ministry of Public Security, the Government Cryptographic Agency, and related agencies or organizations. Within fifteen days from the date of receipt of the request for cooperative review, the Ministry of Public Security, the Government Cryptographic Agency, and related agencies or organizations must respond in writing;
c) Within twenty days from the date of receipt of full cooperative review opinions as stipulated in point b of Clause 4 of this Article, the Ministry of Information and Communications will review and evaluate the actual information system for creating and issuing specialized electronic signature certification ensuring security for agencies and organizations. The model of specialized electronic signature certification ensuring security is prescribed according to Model No. 02 attached as Appendix to this Decree. In case of rejection, the Ministry of Information and Communications will issue a notification and specify the reasons. The specialized electronic signature certification ensuring security of agencies and organizations has a maximum validity period of ten years.
5. In case agencies and organizations choose to implement the procedures for issuing and reissuing specialized electronic signature certification ensuring security in an electronic environment, the reception and processing of documents will be carried out in accordance with the Government's regulations on implementing administrative procedures in an electronic environment, providing online public services of state agencies on the internet, and laws on electronic transactions, except for the actual evaluation as stipulated in point c of Clause 4 of this Article.
6. In case specialized electronic signatures ensuring security do not meet one of the requirements stipulated in Clause 2, Article 22 of the Law on Electronic Transactions, the Ministry of Information and Communications will revoke the specialized electronic signature certification ensuring security and announce on its website (https://rootca.gov.vn/) that the specialized electronic signature does not ensure security.
Section 3
MINISTRY SIGNATURE
Article 12. Public Digital Signature
A public digital signature is a digital signature used in public activities, guaranteed by a public digital signature certificate and meeting all requirements stipulated in Clause 3, Article 22 of the Law on Electronic Transactions.
Article 13. Digital Signature Certificate for Agencies, Organizations and Authorized Persons of Agencies, Organizations
1. All agencies, organizations, and authorized persons of agencies, organizations established and operating legally in accordance with the law have the right to be issued a digital signature certificate.
2. The digital signature certificate issued to authorized persons of agencies, organizations must clearly state their position and the name of the agency or organization they belong to.
Article 14. Use of Digital Signatures and Digital Signature Certificates of Agencies, Organizations and Authorized Persons of Agencies, Organizations
1. The digital signatures of agencies, organizations and authorized persons of agencies, organizations issued and distributed digital signature certificates in accordance with Article 13 of this Decree shall only be used to perform transactions and activities within the scope of authority of the agency, organization and the position specified in the digital signature certificate.
2. The act of signing on behalf of another person or signing under delegated authority as prescribed by law shall be carried out by the person assigned or authorized to use their own digital signature, understood based on the position of the signatory recorded on the digital signature certificate.
Article 15. Obligations of the Signatory Before Signing Digitally
1. Prior to signing digitally, the signatory must carry out the procedure to check the status of their digital signature certificate as follows:
a) Check the status of their own digital signature certificate on the information system of the agency or organization issuing and distributing the digital signature certificate;
b) Check the status of the digital signature certificate of the organization issuing and distributing the digital signature certificate for themselves on the trusted service certification system of the national electronic certification service provider;
c) In case the results of checks at points a and b of this clause are simultaneously valid, the signatory may proceed with digital signing. If the result of the check at point a or point b of this clause is not valid, the signatory shall not proceed with digital signing.
2. Use software for digital signing that meets the requirements set forth in Article 17 of this Decree.
Article 16. Obligations of the Recipient When Receiving Digitally Signed Data Messages
1. Prior to accepting the digital signature of the signatory, the recipient must verify the following information:
a) The status of the digital signature certificate, scope of use, liability limits, and other information on the digital signature certificate of the signatory must ensure identification in accordance with the law on electronic identity verification and authentication;
b) The digital signature must be created using the private key corresponding to the public key on the signatory's digital signature certificate;
c) For digital signatures created using foreign digital signature certificates recognized in Vietnam, the recipient must verify the validity of the foreign digital signature certificate on both the trusted service certification system of the national electronic certification service provider and the foreign organization's electronic signature certification service system.
2. The recipient must carry out the procedure to check the status of the digital signature certificate as follows:
a) Check the status of the digital signature certificate at the time of signing, scope of use, liability limits, and other information on the certificate according to Article 6 of this Decree on the information system of the agency or organization issuing and distributing the digital signature certificate;
b) In cases where the signatory uses a public digital signature certificate issued by a public digital signature certification service provider organization: check the status of the public digital signature certificate of the public digital signature certification service provider organization that has issued the public digital signature certificate at the time of signing on the trusted service certification system of the national electronic certification service provider;
c) The digital signature on the data message is only valid if the results of checks at points a and b of this clause are simultaneously valid.
3. The recipient is responsible for accepting the digital signature certificate in the following cases:
a) Failure to comply with the provisions of Clauses 1 and 2 of this Article;
b) Knowing or being informed about the temporary suspension, revocation, or expiration of the digital signature certificate of the subscriber.
4. Use software for verifying digital signatures that meets the requirements set forth in Article 17 of this Decree.
Article 17. Requirements for digital signature software and digital signature verification software
1. Digital signature software and digital signature verification software must comply with technical standards for digital signatures on data messages; shall not use technical barriers or technology to limit the verification of the validity of digital signatures.
2. For digital signature software, it must have the following functions:
a) Function to authenticate the signatory subject and perform digital signing;
b) Function to verify the validity of the digital signature certificate where the information in the digital signature certificate has been adequately identified in accordance with the law on electronic identification and authentication; function to connect with the Public Digital Signature Certification Service Gateway;
c) Function to store and delete information accompanying signed data messages;
d) Function to change (add, remove) digital signature certificates of agencies or organizations issuing digital signature certificates;
đ) Function to notify (in writing/or symbolically) the signer whether the digital signing of the data message was successful or not.
3. For digital signature verification software, it must have the following functions:
a) Function to verify the legality of digital signatures on data messages;
b) Function to store and delete information accompanying signed data messages;
c) Function to change (add, remove) digital signature certificates of agencies or organizations issuing digital signature certificates;
d) Function to notify (in writing/or symbolically) whether the verification of the legality of the digital signature is valid or invalid.
4. The Minister of Information and Communications shall stipulate technical requirements for the functions of digital signature software and digital signature verification software.
CHAPTER III
RELIABLE SERVICES
Section 1
OPERATING RELIABLE SERVICES
Article 18. Conditions for Operating
Enterprises are entitled to register one or more reliable services. When registering any reliable service, enterprises must meet all conditions prescribed in Clause 1 of Article 29 of the Law on Electronic Transactions. Among these conditions, the conditions at points b, c, d, đ of Clause 1 of Article 29 of the Law on Electronic Transactions are detailed as follows:
1. Regarding financial conditions to address risks and possible compensation during the provision of services and cost recovery for maintaining related information databases, enterprises may choose to implement one of the following forms:
a) Deposit funds at a commercial bank in Vietnam applicable to one or more reliable services. The deposit amount is 10 billion Vietnamese dong for every 300 thousand subscribers and not less than 10 billion Vietnamese dong, provided that the enterprise does not collect prepaid fees from subscribers exceeding one year;
b) Purchase liability insurance for damage arising from the provision of reliable services to ensure subscriber benefits throughout the service period.
2. Human resource management and technical conditions:
a) Operational system personnel including: management, operation, information security, access control, monitoring and inspection, lifecycle management of digital signature certificates, key lifecycle management;
b) Service delivery personnel including: technical audit, security, issuance, suspension, revocation, installation and warranty; verification of subscriber identity (for public digital signature certification services and message data certification services);
c) Personnel responsible for information security and confidentiality must have a bachelor's degree or higher in information security and at least two years of relevant experience corresponding to their field of study;
d) Personnel responsible for management, operation, technical audit, issuance, suspension, revocation, installation and warranty, monitoring and inspection, key lifecycle management must have a bachelor's degree or higher in information technology or closely related fields and at least two years of relevant experience corresponding to their field of study.
3. Technical solutions serving the operation of service provision must apply uniformly to all types of reliable services and must include the following contents:
a) Compliance with technical standards, norms, technical requirements for digital signatures, digital signature certificates; reliable services; network information security; cybersecurity;
b) Full, accurate, and timely storage of subscriber information; updating lists of active, suspended, and revoked digital signature certificates; subscribers can access and use the Internet for online access 24 hours a day, 7 days a week;
c) Ensuring each key pair is generated randomly and uniquely once; having features to ensure the secret key is not revealed when the corresponding public key is available;
d) Warning, preventing, and detecting unauthorized access in the electronic environment;
đ) Lifecycle management components of digital signature certificates designed to minimize direct contact with the electronic environment and be independent of systems not serving reliable services;
e) Information systems must ensure minimum level 3 network information security and protect personal data in accordance with laws on network information security and cybersecurity;
g) Access control, system entry rights, physical access rights to equipment;
h) Backup measures to ensure continuous safe operation and recovery in case of incidents, procedures for data backup, online data backup, data restoration, with the ability to restore data within the shortest time of eight working hours from the time of system failure; the backup center must be at least 20 kilometers away from the main data center and ready to operate when the main system fails;
i) Information systems providing services must be located in Vietnam;
k) Certification regulations as prescribed in Article 29 of this Decree.
4. For public digital signature certification services, technical solutions must comply with the provisions of Clause 3 of this Article and supplement the following contents:
a) The key distribution system for subscribers must ensure the integrity and security of the key pair. In cases where keys are distributed through computer networks, the key distribution system must use secure protocols to prevent information leakage over the transmission path;
b) Solutions for providing information (digital signature certificates, periodic and ad hoc reports as required) electronically to national electronic certification service providers to support state management tasks.
5. For time stamping services and data message authentication services, the technical solution must comply with the provisions of Clause 3 of this Article and supplement the following contents:
a) Time source in accordance with the law on national standard time sources;
b) Solution for providing information (data message integrity code, transaction event log, periodic and extraordinary reports as prescribed) electronically to the organization providing national electronic authentication services, serving state management work.
Article 19. Documents for applying for issuance, reissuance, change of content, and extension of business licenses for trust services
1. Documents for applying for issuance of a business license for trust services:
a) Application form for issuance of a business license for trust services according to Form No. 04 attached to this Decree, specifying the type of trust service to be operated;
b) A valid copy including a copy issued from the original book or a certified copy or a copy compared with the original of one of the following documents: business registration certificate, investment registration certificate for foreign investors, establishment decision or other valid certificates and permits in accordance with the laws on investment and business;
c) Documentation proving compliance with financial conditions stipulated in Clause 1 of Article 18 of this Decree;
d) Human resources management and technical file including criminal record, certified copies of university degrees or higher of the management and technical human resource team as stipulated in Clause 2 of Article 18 of this Decree, description of job duties and relevant experience corresponding to management and technical positions, labor contracts and assignment decisions;
đ) Technical plan serving the provision of services suitable for each type of trust service to ensure the provisions of Clauses 3, 4, and 5 of Article 18 of this Decree;
e) Authentication regulations as prescribed in Article 29 of this Decree.
2. Documents for applying for reissuance of a business license for trust services;
a) Application for reissue of a business license due to expiration of the old license according to Form No. 05 attached to this Decree;
b) Documentation proving compliance with financial conditions stipulated in Clause 1 of Article 18 of this Decree;
c) Information about changes in the enterprise related to business conditions as prescribed in Article 29 of the Law on Electronic Transactions (if applicable);
d) Report on the implementation of the license from the date of issuance to the date of application for reissue according to Form No. 08 attached to this Decree.
3. Documents for applying for change of content of a business license for trust services
a) Application for change of content of the business license according to Form No. 05 attached to this Decree;
b) Detailed report describing the proposed changes and related documents.
4. Documents for applying for extension of a business license for trust services
a) Application for extension of a business license for trust services of the enterprise due to expiration of the old license according to Form No. 05 attached to this Decree;
b) Documentation proving compliance with financial conditions stipulated in Clause 1 of Article 18 of this Decree;
c) Report on the implementation of the license from the date of issuance to the date of application for extension according to Form No. 08 attached to this Decree.
Article 20. Procedure for accepting applications for issuance, reissuance, change of content, and extension of business licenses for reliable services
1. The enterprise prepares one set of application files corresponding to the request for issuance, reissuance, change of content, and extension of the business license for reliable services as stipulated in Article 19 of this Decree.
2. The application documents shall be submitted directly to the Ministry of Information and Communications or sent through postal service or via online public service system (National Public Service Portal, https://dichvucong.gov.vn or the Ministry of Information and Communications Public Service Portal, https://dichvucong.mic.gov.vn).
3. The validity check of the documents will be based on the following criteria:
a) The documents must be prepared in accordance with the provisions of Clause 1 of this Article;
b) The documents must be in Vietnamese. The documents must have the confirmation seal of the agency or organization, the certified copy seal; printed documents established by agencies or organizations with two pages or more must be stamped across the fold.
4. Within seven working days from the date of receipt of the application file for issuance, reissuance, change of content, and extension of the business license for reliable services, the Ministry of Information and Communications shall check the validity of the file in accordance with Clause 3 of this Article.
a) In case of non-compliance, the Ministry of Information and Communications will notify and specify the reasons;
b) In case the file is valid, the Ministry of Information and Communications shall examine and process the file in accordance with the provisions of Article 21 of this Decree.
5. In case the enterprise chooses to implement the procedure for issuance, reissuance, change of content, and extension of the business license for reliable services through an electronic environment, the acceptance and processing of the file shall be carried out in accordance with the Government's regulations on administrative procedures in an electronic environment, online public service provision by state agencies on the internet, and laws on electronic transactions, except for the actual assessment cases specified in Clause 1 and Clause 2 of Article 21 of this Decree.
Article 21. Procedure for handling applications for issuance, reissuance, change of content, and extension of business licenses for reliable services
1. For applications for issuance of a business license for reliable services
a) Within seven working days from the date of receipt of a valid file, the Ministry of Information and Communications shall request cooperation in reviewing the file from the Ministry of Public Security, the General Office for Official Reception of the Government, and relevant agencies and organizations. Within twenty days from the date of receipt of the request for cooperation in reviewing the file, the Ministry of Public Security, the General Office for Official Reception of the Government, and relevant agencies and organizations shall have the responsibility to reply in writing;
b) Within twenty days from the date of receipt of all opinions on cooperative review as stipulated in point a of this clause, the Ministry of Information and Communications shall review and issue the license according to Model No. 06 attached to this Decree. In case of refusal, the Ministry of Information and Communications shall notify in writing and specify the reasons;
c) Within one year from the date of issuance, the organization providing reliable services must implement in practice the conditions stipulated in Article 18 of this Decree; report on the implementation of activities providing reliable services according to Model No. 07 attached to this Decree;
d) The digital signature certificate shall be issued or reissued to the organization providing reliable services within thirty days from the date of receipt of the report as stipulated in point c of this clause and based on the actual evaluation of the system operation process and certification rules; the suitability of the information system providing reliable services with the license issuance file and witnessing the creation of the key pair (secret key and public key) of the organization providing reliable services. In case of refusal, the national electronic certification organization must notify in writing and specify the reasons.
2. For applications for reissuance of a business license for reliable services
a) In case the enterprise wishes to continue providing services, it must apply for reissuance of the license at least ninety days before the expiration date of the current license;
b) Within ten days from the date of receipt of a valid file, the Ministry of Information and Communications shall request cooperation in reviewing the file from the Ministry of Public Security, the General Office for Official Reception of the Government, and relevant agencies and organizations. Within twenty days from the date of receipt of the request for cooperation in reviewing the file, the Ministry of Public Security, the General Office for Official Reception of the Government, and relevant agencies and organizations shall have the responsibility to reply in writing;
c) Within fifteen days from the date of receipt of all opinions on cooperative review as stipulated in point a of this clause, the Ministry of Information and Communications shall review the file and reissue the license based on compliance with the business conditions stipulated in Article 18 of this Decree and the actual evaluation of the results of business operations in reliable services. In case of refusal, the Ministry of Information and Communications shall notify in writing and specify the reasons.
3. For applications for change of content of a business license for reliable services
a) In case there is a change in any of the information about the headquarters address or trading name, the enterprise must apply for a change in the content of the license;
b) Within seven working days from the date of receipt of a complete and valid file, the Ministry of Information and Communications shall review and issue the license to the enterprise with the changed contents. In case of refusal to issue, the Ministry of Information and Communications shall notify in writing and specify the reasons. The validity period of the changed license is the remaining period of the previously issued license.
4. For applications for extension of a business license for reliable services
a) In case the business license for reliable services still has at least sixty days before its expiration date but is currently undergoing division, merger, or consolidation and has not been subject to administrative penalties in the operation of reliable services within twelve months from the date of submission of the application for extension, the enterprise wishing to extend the business license for reliable services must submit an application for extension;
b) Within thirty days from the date of receipt of a complete and valid file, the Ministry of Information and Communications shall issue the extended license according to Model No. 06 attached to this Decree. In case of refusal, the Ministry of Information and Communications shall notify in writing and specify the reasons. The validity period of the extended license shall not exceed one year from the expiration date of the original license:
Article 22. Suspension of License
1. An organization providing reliable services shall be suspended from its license for no more than six months if it falls under any of the following circumstances:
a) Providing services contrary to the content recorded on the license;
b) Failing to meet one of the business conditions stipulated in Article 18 of this Decree since the commencement of service provision;
c) Failing to properly fulfill the obligation to declare and pay fees for maintaining the system to check the status of digital signature certificates as prescribed by laws on fees and charges for over six months.
2. Procedures for suspending licenses and pausing digital signature certificates
a) The Ministry of Information and Communications shall organize meetings and prepare minutes of work with organizations providing reliable services falling under any of the circumstances specified in Clause 1 of this Article. Within seven working days from the date of issuance of the minutes, the Ministry of Information and Communications shall review and issue a decision to suspend the license;
b) Within five working days, the national electronic authentication service provider shall pause the digital signature certificates of organizations providing reliable services and publish such information on the electronic information website (https://rootca.gov.vn/) in cases where the business license for reliable services is suspended or the information system for providing reliable services does not comply with technical audit regulations.
3. During the period of suspension of the license, if the organization providing reliable services has remedied the reasons for suspension, the Ministry of Information and Communications will allow the organization providing reliable services to continue providing services; restore the digital signature certificates within seven working days from the date of remedying the reasons for suspension.
Article 23. Revocation of License
1. An organization providing reliable services shall have its license revoked in the following cases:
a) Not wishing to continue providing services;
b) Dissolution or cessation of operations;
c) Being declared bankrupt by a court;
d) Being merged or consolidated;
đ) Within one year from the date of licensing, the organization providing reliable services does not implement in practice the conditions stipulated in Article 18 of this Decree, except for force majeure or objective obstacles as prescribed by law that the organization providing reliable services has reported in writing to the Ministry of Information and Communications;
e) Engaging in acts of forging documents in the application for issuance, extension, or reissuance of licenses or tampering with the content of issued licenses;
g) Failing to remedy the reasons for suspension as stipulated in Clause 1 of Article 22 of this Decree after the suspension period set by the competent authority;
h) Committing prohibited acts as prescribed in Article 6 of the Law on Electronic Transactions.
2. The procedure for revoking the business license of an organization providing reliable services shall be carried out as follows:
a) The Ministry of Information and Communications shall organize meetings and prepare minutes of work with organizations providing reliable services falling under any of the circumstances specified in Clause 1 of this Article. Within thirty days from the date of issuance of the minutes, the Ministry of Information and Communications shall review and issue a decision to revoke the license, and at the same time require the organization providing reliable services to immediately cease entering into contracts for the provision of reliable services; hand over files and databases related to service provision to another organization providing reliable services according to agreement or designation by the Ministry of Information and Communications:
For public key certification services: subscriber information, subscriber files, digital signature certificate data (list of published digital signature certificates, the entire list of revoked digital signature certificates during the service provision period);
For message data authentication services: subscriber information, subscriber files, confirmation information for recipients and senders (based on registered subscriber information); information about the time of sending and receiving message data; message data; message data integrity assurance code;
For time stamping services: subscriber information, subscriber files, message data integrity assurance code for verification purposes.
b) Within five working days, the national electronic authentication service provider shall revoke the digital signature certificates of organizations providing reliable services and publish such information on the electronic information website (https://rootca.gov.vn/) in cases where the business license for reliable services is revoked; the digital signature certificates have expired; there is a written request from the competent authority; or there is a written request from the organization providing reliable services specifying the reasons for revocation.
3. The enterprise shall not be granted a license for three years from the date of license revocation due to violations of the contents stipulated in points đ, e, and g of Clause 1 of this Article.
4. The Ministry of Information and Communications shall supervise and guide the transfer between organizations providing reliable services to ensure uninterrupted service usage by subscribers; require organizations providing reliable services whose licenses have been revoked to complete insurance or deposit procedures to address risks and compensation payments and settle costs for receiving and maintaining relevant information databases related to service provision.
Section 2
RELIABLE SERVICES ACTIVITY
Article 24. Time stamping service
The time stamping service provided by a reliable service provider includes the following activities:
1. Embedding time into data messages; the time embedded into the data message is the date and time when the time stamping service provider receives the data message.
2. Providing necessary information to help verify the data message that has been stamped with date, month, year, and time.
3. Implementing storage and management of user information.
4. Issuing, renewing, suspending, restoring, and revoking subscriber accounts.
5. Maintaining online data on user information and issued time stamps.
Article 25. Data message authentication service
1. The data message authentication service includes:
a) Service for storing and confirming the integrity of data messages;
b) Service for sending and receiving secure data messages.
2. The service for storing and confirming the integrity of data messages includes the following activities:
a) Implementing storage and management of user information (service usage identification data, service usage authentication data);
b) Storing data on verified sender identity evidence;
c) Storing logs of secure send/receive service operations, verifying the identities of the sender and recipient, and exchanges of information or data between the sender or recipient;
d) Storing evidence of verified recipient identity before sending;
đ) Proving that the information in the data message remains intact during transmission;
e) Providing reference information or a complete list of the entire process, content of sending and receiving data messages, and any modifications (if any) accompanied by a timestamp.
3. The service for sending and receiving secure data messages includes the following activities:
a) Authenticating the sender;
b) Being authenticated by the recipient before sending data;
c) Ensuring secure data transmission and receipt through digital signatures from qualified service providers;
d) Notifying the sender and recipient of any necessary changes to the data for the purpose of sending or receiving data;
đ) Embedding timestamps for sending and receiving data messages.
Article 26. Public key digital signature verification service
1. The public key digital signature verification service is a service provided by a public key digital signature verification service provider to authenticate the signatory on the data message, ensuring the non-repudiation of the signatory with the data message and the integrity of the signed data message. The public key digital signature verification service includes:
a) Public key digital signature verification service using hardware devices for private key storage;
b) Public key digital signature verification service using mobile devices;
c) Remote public key digital signature verification service.
2. The public key digital signature verification service provided by a reliable service provider includes the activities stipulated in Articles 35, 36, 37, 38, 39, 40, 41, 42, 43, and 44 of this Decree.
Article 27. Technical Audit
1. A technical audit is an independent and objective evaluation of information systems and service provision processes to determine compliance with mandatory technical standards, technical regulations, and technical requirements for secure electronic signatures, secure electronic certificates, digital signatures, secure digital certificates, and reliable services.
2. The Ministry of Information and Communications shall specify technical audits in accordance with Clause 1 of this Article in compliance with laws on technical standards and regulations.
Article 28. Device Management Code
1. The device management code is a series of numbers, letters, or symbols used to identify devices within the reliable service information system as prescribed in Clause 2 of this Article for state management purposes.
The management code includes fields of information: name, configuration, serial number of the device; location where the device is placed and function of the device.
2. Devices in the information system providing reliable services must be assigned a code including: servers; devices belonging to the lifecycle management component of digital signature certificates; key storage devices; storage devices; network and security devices.
3. Issuance of management codes
a) Implementation methods are guided and registered automatically through the online public service system (National Public Service Portal, https://dichvucong.gov.vn or Ministry of Information and Communications Public Service Portal, https://dichvucong.mic.gov.vn or National Electronic Authentication Center Public Service Portal, https://neac.gov.vn);
b) Registration and assignment of management codes must be completed before the system begins to provide reliable services and immediately upon any change in coded devices.
c) Time limit for issuance of management codes: within eight working hours from receipt of automatic notification of completed registration.
4. Organizations providing reliable services are responsible for registering and automatically assigning the codes issued according to the provisions of Clauses 2 and 3 of this Article to devices.
Article 29. Model Certification Rules
1. The model certification rules include at least the following contents: policies on electronic signature certificates, scope, purpose of use, recipients eligible for issuance, requirements for the lifecycle operation of electronic signature certificates/digital signature certificates.
2. The Ministry of Information and Communications promulgates the model certification rules as prescribed in Clause 1 of this Article.
3. National electronic authentication service organizations, organizations providing reliable services, and organizations creating specialized secure electronic signatures are responsible for developing, publicly disclosing, and implementing certification rules based on the model certification rules. Any changes in the certification rules must be reported in writing to the Ministry of Information and Communications (National Electronic Authentication Center).
Article 30. Interconnection with National Electronic Authentication Service Providers
The interconnection of national electronic authentication service providers with public digital signature authentication service providers, with specialized digital signature authentication service providers for official duties; updating the status of foreign electronic signature certificates into the reliable service authentication system must meet the following requirements as stipulated by the Ministry of Information and Communications:
1. The information system must ensure the ability to check the status of electronic signature certificates, digital signature certificates, and verify the validity of digital signatures.
2. The information system must have tools and measures to protect data and authenticate data during the interconnection process.
3. Technical conditions serving interconnection, provision of information for checking the status of electronic signature certificates, digital signature certificates, and verifying the validity of digital signatures.
Article 31. Responsibilities of Reliable Service Providers
1. Fulfill responsibilities as prescribed in Article 30 of the Law on Electronic Transactions, laws on cybersecurity, personal data protection.
2. Conduct technical audits every two years.
3. In cases of temporary suspension, reliable service providers are responsible for maintaining databases related to public digital signature certificates issued until such certificates are restored.
4. In cases of temporary suspension, reliable service providers are responsible for maintaining databases of information related to service provision activities until such digital signature certificates are restored.
Article 32. Responsibilities of organizations and individuals when applying time stamps, checking time stamps on data messages, and developing time stamp application software
1. In cases where it is necessary to verify the signing time of data messages, the recipient shall check the time stamp attached to the data message and related information about the time stamp must be provided by a reliable time stamp service provider that has been licensed.
2. The recipient shall use software tools and verification processes that meet technical standards and norms for time stamps or verify time stamps within the entire system of reliable electronic service certification of the national electronic service certification organization and the information system of the reliable service provider.
3. The recipient shall bear responsibility for accepting time stamps in the following cases:
a) Failure to comply with the provisions of Clauses 1 and 2 of this Article;
b) Knowing or being informed about the temporary suspension, revocation, or expiration of the digital signature certificate of the reliable time stamp service provider on the website https://rootca.gov.vn/.
Article 33. Responsibilities of the National Electronic Service Certification Organization
1. Building, managing, operating, and developing the national electronic certification infrastructure; managing and providing services to reliable service providers, agencies, and organizations granted specialized electronic signature certificates ensuring security, individuals and organizations using digital signatures and digital signature certificates, foreign electronic certification service providers, and agencies, organizations, and individuals using recognized electronic signatures and digital signature certificates in Vietnam.
2. Announcing and updating on the website https://rootca.gov.vn/ the following information: list of reliable service providers, agencies, and organizations granted specialized electronic signature certificates ensuring security, foreign electronic certification service providers, foreign electronic signatures, and foreign digital signature certificates recognized in Vietnam; certification regulations; list of valid, expired, suspended, revoked digital signature certificates, and other necessary information.
3. Coordinating activities to handle incidents related to electronic signature certification services and electronic authentication, time stamping services, and other services as prescribed by e-commerce laws; updating and storing complete and accurate certification request information as prescribed by law.
4. Evaluating the actual operation procedures of the information system providing reliable services, certification regulations, the suitability of the information system providing reliable services with licensing documentation, the creation of specialized secure electronic signatures, and witnessing the generation of secret keys and public keys of reliable service providers.
5. Issuing its own digital certificates, creating key pairs, and issuing, suspending, and revoking digital certificates for reliable service providers specified in Chapter III of this Decree: the national electronic service certification organization plays a role and has rights and obligations as a reliable service provider according to Chapter III of this Decree. Reliable service providers play a role and have rights and obligations as subscribers according to Chapter III of this Decree.
6. Organizing the collection, management, and use of fees for maintaining the status check system of digital signature certificates according to laws on fees and charges.
7. Researching, building, managing, and operating testing, inspection, evaluation, calibration, and standard quality measurement systems for products and services related to electronic signatures and reliable services according to e-commerce laws.
8. Checking compliance with requirements for secure specialized electronic signatures and adherence to business conditions for reliable services.
9. Implementing international cooperation activities on electronic signatures and reliable services; coordinating and supporting relevant agencies and organizations to integrate reliable services into information technology applications to ensure authentication and security.
Section 3
ACTIVITIES OF PROVIDING ELECTRONIC CERTIFICATION SERVICES
DIGITAL SIGNATURE GATEWAY
Article 34. Documents for Requesting Issuance of Public Digital Signature Certificates
1. A request form for issuing public digital signature certificates in paper or electronic format according to the model provided by the service provider organization.
2. Supporting documents include:
a) For individuals: identity documents including citizen identification card, identification card, electronic identification card, certificate of identification, level 2 electronic identity account, passport with validity period; entry visa with validity period or proof of visa exemption (for foreign individuals).
b) For organizations: establishment decision, decision on functions, tasks, powers, organizational structure, business registration certificate, investment certificate, business household registration certificate, and identity documents of the legal representative of the organization, including citizen identification card, identification card, certificate of identification, level 2 electronic identity account, passport; or the organization's level 2 electronic identity account.
3. Individuals and organizations have the right to choose to submit certified copies from original books, notarized copies, electronic copies, or submit copies along with originals for verification or use level 2 electronic identity accounts in accordance with the law on electronic identification and authentication.
In cases where originals are presented for verification, the public digital signature certification service provider organization must confirm on the copy and be responsible for the accuracy of the copy compared to the original. The legalization of consular documents for papers issued by foreign competent authorities shall be carried out in accordance with the provisions of the law. In cases where the documents in the file are electronic copies, the public digital signature certification service provider organization must have solutions and technology to collect, check, and compare, ensuring that the electronic copy has complete, accurate content matching the original in accordance with the law.
4. In cases where individuals or the legal representatives of organizations provide or use information in the citizen identification card, identification card, electronic identification card, certificate of identification, or information in the individual's level 2 electronic identity account or information in the organization's electronic identity account, the public digital signature certification service provider organization (which has approval documents allowing connection to the electronic identification and authentication system in accordance with the law on electronic identification and authentication or having sufficient means to read data in the electronic chip, data in the level 2 electronic identity account) extracts data from the electronic chip, data from the individual's level 2 electronic identity account, and the organization's electronic identity account; does not require individuals or the legal representatives of organizations to submit documents and supporting materials as stipulated in Clause 2 of this Article.
Article 35. Request for Issuing Public Digital Signature Certificates
1. When there is a need to request issuance of public digital signature certificates, organizations and individuals prepare one set of documents in accordance with Article 34 of this Decree and submit directly or send via postal services or electronic means to the public digital signature certification service provider organization.
2. Upon receiving the request documents from organizations and individuals, the public digital signature certification service provider organization must verify and compare the documents in the request for issuance and process:
a) If the documents in the request for issuance of public digital signature certificates are complete, legal, and valid, and all factors declared in the issuance request form match completely with the documents in the request for issuance of public digital signature certificates, the public digital signature certification service provider organization shall issue public digital signature certificates for organizations and individuals in accordance with Clause 3 of this Article;
b) If the documents in the request for issuance of public digital signature certificates are incomplete, illegal, or invalid, or if the factors declared in the request for issuance of public digital signature certificates do not match the documents in the request for issuance of public digital signature certificates, the public digital signature certification service provider organization shall notify organizations and individuals to complete the documents;
c) In cases where the public digital signature certification service provider organization refuses to issue public digital signature certificates, it must notify organizations and individuals.
3. After completing the verification, comparison, and confirmation of information about organizations and individuals, the public digital signature certification service provider organization proceeds to conclude contracts and issue public digital signature certificates for subscribers in accordance with Article 38 of this Decree.
4. Issuance of public digital signature certificates through electronic methods is carried out in accordance with Article 36 of this Decree.
5. The issuance of public digital signature certificates for organizations and individuals by the public digital signature certification service provider organization that has established relationships and completed the recognition and verification of information about organizations and individuals is decided by that service provider organization but must ensure that all information and documents in the request for issuance of public digital signature certificates as stipulated in Article 34 of this Decree are available or collected.
Article 36. Issuance of Public Digital Signature Certificates via Electronic Means
1. Organizations providing public digital signature authentication services that issue public digital signature certificates via electronic means must establish, promulgate, and publicly disclose procedures and processes for issuing public digital signature certificates via electronic means in accordance with this Article, laws on electronic transactions, relevant laws on information security, cyber security, personal data protection, and the issuance of public digital signature certificates, including at least the following steps:
a) Collecting information about the application for issuing public digital signature certificates in accordance with Article 34 of this Decree;
b) Conducting verification and cross-checking of information to identify organizations and individuals;
c) Warning organizations and individuals about actions that should not be carried out during the issuance and use of public digital signature certificates via electronic means;
d) Providing organizations and individuals with the content of the contract and concluding the contract with them.
2. Organizations providing public digital signature authentication services shall decide on measures, forms, and technologies to identify and verify organizations and individuals for the purpose of issuing public digital signature certificates via electronic means; they shall bear responsibility for any risks arising (if any) and must meet the following minimum requirements:
a) Having solutions and technologies to collect, check, cross-check, and ensure the accuracy of information to identify organizations and individuals, biometric data of the legal representative of organizations and individuals (which are biological factors closely linked to the legal representative of organizations and individuals performing identification, difficult to forge, with low matching rates such as fingerprints, facial features, iris patterns, voiceprints, and other biometric factors), ensuring accurate identification of the subject and implementing identity verification according to the provisions of laws on electronic identification and authentication;
b) Having technical measures to confirm that organizations and individuals who have been identified agree with the contents of the contract;
c) Establishing management, control, and risk assessment procedures, including measures to prevent impersonation, interference, modification, and distortion of information to identify organizations and individuals before, during, and after the issuance of public digital signature certificates for subscribers; in case of discovering risks, discrepancies, or suspicious signs between information to identify organizations and individuals and biometric factors of organizations and individuals, or detecting suspicious transactions during the signing process, organizations providing public digital signature authentication services must promptly refuse or temporarily suspend public digital signature certificates and re-verify information to identify organizations and individuals. The management and control procedures for risks must be regularly reviewed and improved based on updated information and data during service provision;
d) Storing and preserving all detailed information and data to identify organizations and individuals during the issuance of public digital signature certificates and the use of public digital signature authentication services, such as: information to identify organizations and individuals; biometric factors of the legal representative of organizations and individuals; audio and video recordings; transaction phone numbers; transaction logs. All information and data must be stored securely and confidentially, backed up, and ensured to be complete and intact to serve inspection, cross-checking, dispute resolution, complaints handling, and information provision when requested by competent state management agencies. The storage period shall be implemented in accordance with the provisions of laws on record keeping and personal data protection.
Article 37. Creation, Distribution, and Management of Subscriber Keys
1. Organizations and individuals requesting issuance of public digital signature certificates may create their own key pair or request in writing that the service provider of public digital signature certification create a key pair for them.
2. In cases where organizations and individuals requesting issuance of public digital signature certificates create their own key pair, the service provider of public digital signature certification must ensure that such organizations and individuals use key generation devices in accordance with mandatory technical standards and specifications to generate and store the key pair.
3. In cases where the service provider of public digital signature certification creates the key pair, the organization must ensure secure methods are used to transfer the private key to the requesting organization or individual and may only retain a copy of the private key upon written request from the requesting organization or individual.
4. In cases where the service provider of public digital signature certification operates under a remote signing model, the organization may retain the private key of the requesting organization or individual and must ensure secure methods are used to store it.
5. Regarding key management activities, the service provider of public digital signature certification has the following responsibilities:
a) Immediately notify the subscriber and take preventive and corrective measures promptly upon discovering signs that the subscriber's private key has been exposed, is no longer intact, or any other errors that could adversely affect the subscriber's interests;
b) Advise the subscriber to change the key pair when necessary to ensure the highest level of reliability and security for the key pair;
c) Restore key storage means at the subscriber's request.
Article 38. Issuance of Public Digital Signature Certificates to Subscribers
1. The service provider of public digital signature certification issues a public digital signature certificate to the subscriber after verifying the following contents:
a) Information in the application for issuance of a public digital signature certificate submitted by the subscriber is accurate;
b) The public key on the public digital signature certificate to be issued will be unique and paired with the private key of the requesting organization or individual.
2. A public digital signature certificate can only be issued to the requesting organization or individual and must contain all information prescribed in Article 6 of this Decree.
3. The service provider of public digital signature certification may publish the public digital signature certificate issued to the subscriber in its database of public digital signature certificates only after receiving confirmation from the subscriber regarding the accuracy of the information on the certificate; the publication deadline shall not exceed 24 hours after receipt of the subscriber's confirmation, except in cases of agreement otherwise.
4. The service provider of public digital signature certification must ensure security throughout the process of creating and transferring public digital signature certificates to subscribers.
Article 39. Renewal of Public Digital Signature Certificates for Subscribers
1. Before the expiration date of the public digital signature certificate, the subscriber has the right to request renewal of the certificate.
2. Upon receiving a renewal request from the subscriber, the service provider of public digital signature certification has the obligation to complete the renewal procedures before the certificate expires and must ensure that the subscriber is properly identified and verified according to the legal provisions on electronic identification and verification.
3. In cases where renewal of the public digital signature certificate involves changing the public key, the subscriber must make a request and specify the reasons; the creation, distribution, and publication of the renewed certificate shall comply with the provisions of Articles 37 and 38 of this Decree.
Article 40. Changing Key Pairs for Subscriber Accounts
In cases where subscribers require changing key pairs, subscribers must submit a written request for changing key pairs. The creation, distribution of keys, and publication of public digital signature certificates with new public keys shall be carried out in accordance with the provisions of Articles 37 and 38 of this Decree.
Article 41. Suspension and Restoration of Public Digital Signature Certificates for Subscribers
1. Public digital signature certificates of subscribers shall be suspended in the following circumstances:
a) When the subscriber requests in writing and such request has been verified by the service provider to be accurate;
b) When risks, discrepancies, or unusual signs are detected between the identification information of organizations or individuals and their biometric factors, or when suspicious transactions are identified during the signing process, or when any errors affecting the interests of the subscriber and the recipient are discovered;
c) When the subscriber, being an organization, ceases all business operations;
d) Upon receipt of a written request from judicial authorities, police agencies, or the Ministry of Information and Communications;
đ) In accordance with the conditions for suspending public digital signature certificates as stipulated in the contract between the subscriber and the service provider.
2. When there is a basis for suspending public digital signature certificates as provided in Clause 1 of this Article, the service provider must suspend them immediately and notify the subscriber, while publishing on the database of public digital signature certificates the suspension, start time, and end time of the suspension.
3. The service provider must restore public digital signature certificates when there is no longer a basis for suspension or when the suspension period requested has expired, or upon request from competent state authorities.
Article 42. Revocation of Public Digital Signature Certificates for Subscribers
1. Public digital signature certificates of subscribers shall be revoked in the following circumstances:
a) When the subscriber requests in writing and such request has been verified by the service provider to be accurate;
b) When the subscriber, being an individual, has died or disappeared according to court declarations, or when the subscriber, being an organization, has been dissolved or declared bankrupt under the law;
c) Upon receipt of a written request from judicial authorities, police agencies, or the Ministry of Information and Communications;
d) In accordance with the conditions for revoking public digital signature certificates as stipulated in the contract between the subscriber and the service provider.
2. When there is a basis for revocation as provided in Clause 1 of this Article, the service provider must revoke the public digital signature certificates, and simultaneously notify the subscriber and publish on the database of public digital signature certificates the revocation.
Article 43. Provision of Information
1. Publication of Information:
Service providers of public digital signature certification services must publicly disclose and maintain the following information on their electronic websites 24 hours a day, seven days a week:
a) Their certification rules and digital signature certificates;
b) Lists of active, suspended, and revoked public digital signature certificates of subscribers;
c) Necessary information as prescribed by law.
2. Updating Information:
Service providers of public digital signature certification services must update the information specified in Clause 1 of this Article within 24 hours of any changes.
3. Provision of Information:
Service providers of public digital signature certification services must provide real-time online information to national electronic certification service providers about the number of active, suspended, and revoked public digital signature certificates to support state management of public digital signature certification services.
4. Storage of Information:
a) Service providers of public digital signature certification services are responsible for ensuring that points of acceptance, software, and applications for issuing public digital signature certificates comply fully with regulations on verification and storage of subscriber information; they are entirely liable under the law for the verification, storage, and management of subscriber information at points of acceptance, software, and applications for issuing public digital signature certificates;
b) Service providers of public digital signature certification services are responsible for building reliable information systems and centralized databases to enter, store, and manage subscriber information throughout the duration of service usage, including: information on applications for issuing public digital signature certificates as stipulated in Article 34 of this Decree, the start date of service usage, and the end date of service usage for terminated subscribers; for terminated subscribers, information must continue to be stored in the database according to legal retention requirements and for a minimum of two years;
Service providers of public digital signature certification services are responsible for storing all information related to the temporary suspension or revocation of licenses and subscriber information databases, public digital signature certificates according to legal retention requirements and for a minimum of five years, starting from the date of license suspension, revocation, or non-renewal;
c) Service providers of public digital signature certification services are responsible for connecting their centralized subscriber information databases to the Ministry of Information and Communications' database to support state management of electronic transactions; connecting to the National Population Database for reference and verification of subscriber information to ensure correct identification of subjects and implementation of identity verification according to laws on electronic identification and authentication;
d) Service providers of public digital signature certification services are responsible for providing complete information; proving that subscriber information in the centralized database of the organization has been compared, verified, entered, stored, and managed in accordance with the law.
Article 44. Connection to the Public Digital Signature Certification Service Gateway
1. Organizations providing public digital signature certification services shall be responsible for connecting to the Public Digital Signature Certification Service Gateway.
2. Information systems serving electronic transactions using digital signatures shall be responsible for integrating with the Public Digital Signature Certification Service Gateway to ensure the authenticity, integrity, and non-repudiation of data messages.
3. The Ministry of Information and Communications shall provide detailed guidance on implementing the connection as prescribed in Clause 1 and Clause 2 of this Article.
Article 45. Rights and Responsibilities of Users Utilizing Public Digital Signature Certification Services
1. Have the right to request organizations providing public digital signature certification services to provide in writing information according to the contract concluded.
2. Have the right to request organizations providing public digital signature certification services to temporarily suspend, revoke issued digital signature certificates and bear responsibility for such requests.
3. Provide information truthfully and accurately as required by regulations to organizations providing public digital signature certification services. In case of changes to any provided information, users must notify the organization providing public digital signature certification services to implement changes to the content of the public digital signature certificate.
4. If self-generating key pairs, users must ensure that the key pair generation device meets technical standards and mandatory requirements.
5. Control and use their secret keys securely throughout the validity period of the public digital signature certificate and during suspension periods.
6. Notify the organization providing public digital signature certification services within 24 hours if signs of leakage, theft, or unauthorized use of their secret key are discovered so that appropriate measures can be taken.
7. When agreeing to have the organization providing public digital signature certification services publish the public digital signature certificate according to Clause 3, Article 38 of this Decree or when issuing the public digital signature certificate to others for transaction purposes, the user is deemed to have committed to the recipient that the user is the lawful holder of the secret key corresponding to the public key on the public digital signature certificate and that the information on the public digital signature certificate related to the user is true, while also fulfilling obligations arising from the public digital signature certificate.
8. Shall be held liable under the law if violating the provisions of Clauses 3, 4, 5, 6, and 7 of this Article and other relevant laws.
PART IV
IMPLEMENTING PROVISIONS
Article 46. Effective Date
1. This Decree takes effect from April 10, 2025.
2. Decree No. 130/2018/NĐ-CP dated September 27, 2018 of the Government detailing the implementation of the Law on Electronic Transactions regarding digital signatures and digital signature certification services, and Decree No. 48/2024/NĐ-CP dated May 9, 2024 of the Government amending and supplementing certain articles of Decree No. 130/2018/NĐ-CP dated September 27, 2018 of the Government detailing the implementation of the Law on Electronic Transactions regarding digital signatures and digital signature certification services shall cease to be effective from the date this Decree takes effect, except for the provisions stipulated in Article 47 of this Decree.
Article 47. Transitional Provisions
1. In cases where organizations are granted licenses to provide public digital signature certification services according to detailed legal documents implementing the Law on Electronic Transactions No. 51/2005/QH11 which remain valid, the payment of service fees for maintaining the status check system for digital certificates according to the current legal provisions on fees and charges shall continue until the competent authority issues replacement documents.
2. Organizations granted licenses to provide trusted services that have been providing public digital signature certification services since the Law on Electronic Transactions No. 20/2023/QH15 took effect, shall pay service fees for maintaining the status check system for digital signature certificates as fees for maintaining the status check system for digital certificates according to the current legal provisions on fees and charges until the competent authority issues replacement documents.
3. For new services arising from the provisions of the Law on Electronic Transactions No. 20/2023/QH15 without fee collection provisions, no fees shall be collected until the competent authority issues regulations on fee collection.
4. Except in cases where organizations providing public digital signature certification services choose to apply the provisions of the Law on Electronic Transactions No. 20/2023/QH15, organizations providing public digital signature certification services currently operating legally shall have the responsibility to review and upgrade their information systems and management and technical staff to meet the provisions of this Decree within two years from the date this Decree takes effect.
5. Issuing digital certificates according to licenses for providing public digital signature certification services granted before the Law on Electronic Transactions No. 20/2023/QH15 took effect and still valid on the date the Law on Electronic Transactions No. 20/2023/QH15 takes effect shall be carried out once. The maximum validity period of the issued digital certificate shall not exceed five years and shall not exceed the remaining validity period of the license.
6. Software applications incorporating digital signature software and digital signature verification software within two years from the date this Decree takes effect shall be reviewed and upgraded to comply with the provisions of Article 17 of this Decree.
7. In cases where the system administrator of information systems serving electronic transactions using digital signatures in transactions, the system administrator shall be responsible for reviewing and upgrading the information system and software applications to incorporate digital signature software and digital signature verification software in compliance with the provisions of Article 17 of this Decree.
Article 48. Responsibility for Implementation
The Minister, Heads of ministerial-level agencies, Heads of government-affiliated agencies, Chairpersons of People's Committees at all levels, and relevant agencies, organizations, and individuals shall be responsible for implementing this Decree.
(Attached to Decree No. 23/2025/NĐ-CP dated February 21, 2025 ofthe Government)
|
Model No. 01 |
A Notary Office must have its own specific address, with rooms for notaries and staff to work, a room to receive clients requesting notarization, and a storage room for notarization files.Request for issuance/reissuance of specialized electronic signature certification ensuring security |
|
Form No. 02 |
Article 1. SubjectsAcceptance of specialized electronic signature certification ensuring security |
|
Implementation Report of Production Projects of Supporting Industry Products Confirmed with Incentives |
Documents of the Standing Committee of the National Assembly, the President, the Chairman of the Central Committee of the Vietnam Fatherland Front,Certificate of establishment of specialized electronic signature certification ensuring security |
|
Form number 04 |
A Notary Office must have its own specific address, with rooms for notaries and staff to work, a room to receive clients requesting notarization, and a storage room for notarization files.Request for issuance of a business license for trust services |
|
Form number 05 |
A Notary Office must have its own specific address, with rooms for notaries and staff to work, a room to receive clients requesting notarization, and a storage room for notarization files.Request to change content/reissue/extend the business license for trust services |
|
Form number 06 |
The application and procedures for requesting confirmation are Form 1 - HĐ/HTQT and the provisions in Section D.III of Circular No. 133/2004/TT-BTC, supplemented with the following specific information:Business license for trust services |
|
Form No. 07 |
Report onImplementation of trust service provision activities |
|
Form No. 08 |
Report on the situation ofImplementation of certificate/license |
Model No. 01
|
NAME OF AUTHORITY, ORGANIZATIONADDRESS: |
CSOCIALIST REPUBLIC OF VIET NAM |
|
Provincial People's Committees set specific prices... |
..., day .... month .... year .... |
PETITION FOR APPLICATION ISSUE/REISSUE CERTIFICATE FOR SPECIALIZED ELECTRONIC SIGNATURE TO ENSURE SECURITY
Respectfully submit to:Ministry of Information and Communications.
WHEREAS,ứ Law on Electronic Transactions June 22, 2023;
WHEREAS,Pursuant to Decree No. .../.../ND-CP dated ... month ... year ... of the Government on electronic signatures and trust services;
(Name of authority, organization) requests the Ministry of Information and Communications to issue/reissue the certificate for specialized electronic signature to ensure security with the following contents:1. General information about the authority, organization
Part 1. Trade name:
2. International trade name:3. Decision
establishing/Decision stipulating functions and tasks No. ... issued by ... on ... month ... year ... (if applicable) or Enterprise Registration Certificate No. ... issued by ... on ... month ... year ... (if applicable).4. Legal representative's name:
5. Personal identification number of the legal representative: 6. Main office address:
7. Telephone:2. Attached documents (specify type and quantity of files)
Name of documentQuantity
3. Commitment(Organization) commits to be responsible for the accuracy and legality of the provided information above and attached documents, and commits to comply with laws on electronic signatures and related laws.
LEGAL REPRESENTATIVEOF THE AUTHORITY, ORGANIZATION
Part (Signature, full name, position, and stamp)
|
Serial number |
Contact person for the file (name, position, telephone, email address):Part IV: Results of Event-Based Surveillance Monitoring |
Provincial People's Committees set specific pricesNumber 02 |
Remarks |
|
1 |
|
|
|
|
2 |
|
|
|
|
3 |
|
|
|
|
… |
|
|
|
Part INFORMATION AND
(Name of authority, organization) requests the Ministry of Information and Communications to issue/reissue the certificate for specialized electronic signature to ensure security with the following contents:number: .../CN-BTTTT
|
|
The method for determining the collection rate is calculated based on the following formula:date: ... month ... year ... |
- Office of the President of the StateUpon examination of the application for issuance/reissuance of the certificate for specialized electronic signature to ensure security dated ... month ... year ... of ...(1);
Model The recommendation of ...(2).
|
BNOW APPROVES |
CSOCIALIST REPUBLIC OF VIET NAM |
|
Provincial People's Committees set specific pricesThe specialized electronic signature created by |
Hà Nội(NAME OF AUTHORITY/ORGANIZATION), |
English trade name:
(ENGLISH NAME),headquartered at ..., established by Decision No. ... issued by ... on ... month ... year ... (if applicable) or registered with Business Registration Certificate No.: ... issued by ... on ... month ... year ... (if applicable), meets all requirements as stipulated in Clause 2, Article 22
MINISTER OF INFORMATION AND COMMUNICATIONS
WHEREAS,ứ Law on Electronic Transactions June 22, 2023;
WHEREAS,Pursuant to Decree No. .../.../ND-CP dated ... month ... year ... of the Government on electronic signatures and trust services;
WHEREAS,Law on Electronic Transactions.
The specialized electronic signature to ensure security is used exclusively for activities consistent with its functions and tasks as follows:1. Internal activities of (name of authority/organization);
Pursuant to the proposal of the Director of the Department of Ethnic Affairs and Religion Propaganda;2. Specialized or sectoral activities, having the same nature or purpose of work and interconnected through ...;
3. To sign with other organizations or individuals in transactions consistent with its functions and tasks;4. Not for commercial purposes.
Article 1. Technical standards applied:... ...(1) must comply with the provisions of June 22, 2023, Decree No. .../.../ND-CP dated ... month ... year ... of the Government on electronic signatures and trust services and relevant laws. This certificate for specialized electronic signature to ensure security takes effect from the date of signing and remains valid until ... month ... year ...; (3) replaces Certificate No. .../CN-BTTTT issued by the Minister of Information and Communications on ... month ... year ... (1) Name of the authority, organization granted the certificate. (2) Director of the unit submitting the application for certification.
Article 2. (3) Used in case of reissue.
Number 03DOCUMENTS PROVING COMPLIANCE WITH REQUIREMENTS FOR SPECIALIZED ELECTRONIC SIGNATURE TO ENSURE SECURITY
Establishment/Decision stipulating functions and tasks No. ... issued by ... on ... month ... year ... (if applicable) or Enterprise Registration Certificate No. ... issued by ... on ... month ... year ... (if applicable).2. Attached documents (specify type and quantity of documents)
Detailed description and operation procedures of the information system creating specialized electronic signatureList of personnel managing and technical staff participating in the actual operation of the information system along with assigned positions
Description of compliance with all requirements as stipulated in Clause 2, Article 22Compliance with legal regulations of the authority/organization (in case of reissue)
Article 3. Certification procedure (in case of specialized electronic signature to ensure security guaranteed by digital certificate)
Article 4. Changes to the information system during operation (in case of reissue) Law on Electronic Transactions Results of the most recent technical audit (if available)
Article 5. Other documents (if available)
|
|
BPRIME MINISTER |
Note:
Number 04NAME OF ENTERPRISE
APPLICATIONREQUEST FOR BUSINESS LICENSE FOR TRUST SERVICES
(Name of enterprise) requests the Ministry of Information and Communications to issue a business license for trust services with the following contents:1. General information about the enterprise
Model 3. Enterprise Registration Certificate No. ... issued by ... on ... month ... year ...
|
NAME OF AUTHORITY, ORGANIZATIONADDRESS: |
CSOCIALIST REPUBLIC OF VIET NAM |
|
Provincial People's Committees set specific prices... |
…, day … month … year … |
8. Fax number:
Respectfully submit to:Ministry of Information and Communications.
WHEREAS,ứ Law on Electronic Transactions June 22, 2023;
WHEREAS,Pursuant to Decree No. .../.../ND-CP dated ... month ... year ... of the Government on electronic signatures and trust services;
Part 1. Trade name:
2. International trade name:3. Decision
establishing/Decision stipulating functions and tasks No. ... issued by ... on ... month ... year ... (if applicable) or Enterprise Registration Certificate No. ... issued by ... on ... month ... year ... (if applicable).4. Legal representative's name:
5. Personal identification number of the legal representative: 9. Website:
7. Telephone:2. Attached documents (specify type and quantity of files)
Name of documentQuantity
3. Commitment(Organization) commits to be responsible for the accuracy and legality of the provided information above and attached documents, and commits to comply with laws on electronic signatures and related laws.
LEGAL REPRESENTATIVEOF THE AUTHORITY, ORGANIZATION
Part 10. Tax code:
|
Serial number |
Contact person for the file (name, position, telephone, email address):Part IV: Results of Event-Based Surveillance Monitoring |
Provincial People's Committees set specific pricesNumber 02 |
Remarks |
|
1 |
2. Summary description of the request for business licenseType of business license requested |
|
|
|
2 |
1. Business license for trust services ...Duration of the requested license: ... years ... months... |
|
|
|
3 |
2. Summary description of the request for business license2. Business license for ... Law on Electronic Transactions |
|
|
|
4 |
3. Attached documents (specify type and quantity of files)4. Commitment |
|
|
|
5 |
(Enterprise) commits to be responsible for the accuracy and legality of the provided information above and attached documents, and commits to comply with laws on trust services and related laws.ENTERPRISE SEAL |
|
|
|
6 |
Number 05APPLICATION FOR CHANGE OF CONTENT/REISSUE/EXTENSION OF BUSINESS LICENSE FOR TRUST SERVICES |
|
|
|
7 |
signing and implementing Agreements(Enterprise) requests the Ministry of Information and Communications to change the content of the business license for trust services No. ... issued by the Minister of Information and Communications on ... month ... year ..., specifically as follows: |
|
|
|
8 |
2. Summary description of the request to change content/reissue/extend the business licenseBusiness license for trust services requested to change content/reissue/extend: |
|
|
|
... |
|
|
|
Part INFORMATION AND
(Name of authority, organization) requests the Ministry of Information and Communications to issue/reissue the certificate for specialized electronic signature to ensure security with the following contents:number: .../CN-BTTTT
|
|
The method for determining the collection rate is calculated based on the following formula:date: ... month ... year ... |
- Office of the President of the StateUpon examination of the application for issuance/reissuance of the certificate for specialized electronic signature to ensure security dated ... month ... year ... of ...(1);
Model License No. ... issued by the Minister of Information and Communications on ... month ... year ...
|
3. Reason for change/reissue/extension:4. Content requested to change/reissue/extend: |
CSOCIALIST REPUBLIC OF VIET NAM |
|
Provincial People's Committees set specific prices... |
…, day … month … year … |
APPLICATION FORCONSIDERATION OF BUSINESS LICENSE FOR RELIABLE SERVICES (Company name) requests the Ministry of Information and Communications to issue a business license for reliable services with the following contents:
Respectfully submit to:Ministry of Information and Communications.
WHEREAS,ứ Law on Electronic Transactions June 22, 2023;
WHEREAS,Pursuant to Decree No. .../.../ND-CP dated ... month ... year ... of the Government on electronic signatures and trust services;
1. General information about the company3. Business registration certificate number ... issued by ... on ... month ... year ...
Part 8. Fax Number:
2. International trade name:3. Decision
establishing/Decision stipulating functions and tasks No. ... issued by ... on ... month ... year ... (if applicable) or Enterprise Registration Certificate No. ... issued by ... on ... month ... year ... (if applicable).4. Legal representative's name:
9. Website:10. Tax Code:
7. Telephone:2. Attached documents (specify type and quantity of files)
Name of documentQuantity
3. Commitment(Organization) commits to be responsible for the accuracy and legality of the provided information above and attached documents, and commits to comply with laws on electronic signatures and related laws.
LEGAL REPRESENTATIVEOF THE AUTHORITY, ORGANIZATION
2. Summary of the application for the business licenseat License requested to be issued
1. Business license for service ...
Duration of the license requested to be issued: ... years ... months...2.
Part 3. Attached documents (specify type and quantity of files)
Lo4. Commitment
(Company) commits to be responsible for the accuracy and legality of the provided information above and attached documents, and commits to comply with the laws on reliable services and related laws.COMPANY SEAL 1
The issuance of work permits is governed by the following legal documents as prescribed by current laws: i) Decree No. 34/2008/NĐ-CP dated March 25, 2008, on the recruitment and management of foreign workers in Vietnam; ii) Decree No. 46/2011/NĐ-CP dated June 17, 2011, amending certain provisions of Decree No. 34/2008/NĐ-CP; and iii) Circular No. 31/2011/TT-BLDTBXH dated November 3, 2011, issued by the Ministry of Labor, Invalids, and Social Affairs guiding the implementation of Decrees No. 34 and No. 46.Service name as prescribed in this Decree.
number 05COMPANY SEAL2
The issuance of work permits is governed by the following legal documents as prescribed by current laws: i) Decree No. 34/2008/NĐ-CP dated March 25, 2008, on the recruitment and management of foreign workers in Vietnam; ii) Decree No. 46/2011/NĐ-CP dated June 17, 2011, amending certain provisions of Decree No. 34/2008/NĐ-CP; and iii) Circular No. 31/2011/TT-BLDTBXH dated November 3, 2011, issued by the Ministry of Labor, Invalids, and Social Affairs guiding the implementation of Decrees No. 34 and No. 46.Service name as prescribed in this Decree.
Part APPLICATION FOR CHANGE OF CONTENT/REISSUE/EXTENSION OF BUSINESS LICENSE FOR RELIABLE SERVICES
|
Serial number |
Contact person for the file (name, position, telephone, email address):Part IV: Results of Event-Based Surveillance Monitoring |
Provincial People's Committees set specific pricesNumber 02 |
Remarks |
|
1 |
|
|
|
|
2 |
|
|
|
|
3 |
|
|
|
|
… |
|
|
|
Part (Company) requests the Ministry of Information and Communications to change the content of the business license for reliable services number... issued by the Minister of Information and Communications on... month... year..., specifically as follows:
1. General information about the company2. Summary of the request to change the content of the license/reissue/extend
|
|
The method for determining the collection rate is calculated based on the following formula:date: ... month ... year ... |
- Office of the President of the StateUpon examination of the application for issuance/reissuance of the certificate for specialized electronic signature to ensure security dated ... month ... year ... of ...(1);
___________________
1 ArticleLicense number ... issued by the Minister of Information and Communications on ... month... year ...
2 ArticleLicense number ... issued by the Minister of Information and Communications on ... month... year ...
Model 2. Reason for change/reissue/extension:
|
3. Reason for change/reissue/extension:4. Content requested to change/reissue/extend: |
CSOCIALIST REPUBLIC OF VIET NAM |
|
Provincial People's Committees set specific prices... |
…, day … month … year … |
3. Content of the request to change/reissue/extend:
Respectfully submit to:Ministry of Information and Communications.
WHEREAS,ứ Law on Electronic Transactions June 22, 2023;
WHEREAS,Pursuant to Decree No. .../.../ND-CP dated ... month ... year ... of the Government on electronic signatures and trust services;
1. General information about the companyEND.
Part 8. Fax Number:
2. International trade name:3. Decision
establishing/Decision stipulating functions and tasks No. ... issued by ... on ... month ... year ... (if applicable) or Enterprise Registration Certificate No. ... issued by ... on ... month ... year ... (if applicable).4. Legal representative's name:
9. Website:10. Tax Code:
7. Telephone:2. Attached documents (specify type and quantity of files)
Name of documentQuantity
3. Commitment(Organization) commits to be responsible for the accuracy and legality of the provided information above and attached documents, and commits to comply with laws on electronic signatures and related laws.
LEGAL REPRESENTATIVEOF THE AUTHORITY, ORGANIZATION
2. Summary of the application for the business licenseat License requested to be issued
1. Business license for service ...
Duration of the license requested to be issued: ... years ... months...2.
Part LEGAL REPRESENTATIVE OF
(Company) commits to be responsible for the accuracy and legality of the provided information above and attached documents, and commits to comply with the laws on reliable services and related laws.COMPANY/ORGANIZATION
The application and procedures for requesting confirmation are Form 1 - HĐ/HTQT and the provisions in Section D.III of Circular No. 133/2004/TT-BTC, supplemented with the following specific information:Contact person for documents (name, position, phone, email address):
2. Reasons for replacement/reissue/extension:ổi/cấp lại/gia hạn:
3. Content of the request for replacement/reissue/extension:ội dung đề nghị thay đổi/cấp lại/gia hạn:
Part APPLICATION FOR CHANGE OF CONTENT/REISSUE/EXTENSION OF BUSINESS LICENSE FOR RELIABLE SERVICES
|
Serial number |
Contact person for the file (name, position, telephone, email address):Part IV: Results of Event-Based Surveillance Monitoring |
Provincial People's Committees set specific pricesNumber 02 |
Remarks |
|
1 |
|
|
|
|
2 |
|
|
|
|
3 |
|
|
|
|
… |
|
|
|
Part (Company) requests the Ministry of Information and Communications to change the content of the business license for reliable services number... issued by the Minister of Information and Communications on... month... year..., specifically as follows:
1. General information about the companyhereby commits to being responsible for the accuracy and legality of the provided information and accompanying documents, and commits to complying with the laws on reliable services and related laws./.
|
|
The method for determining the collection rate is calculated based on the following formula:date: ... month ... year ... |
- Office of the President of the StateUpon examination of the application for issuance/reissuance of the certificate for specialized electronic signature to ensure security dated ... month ... year ... of ...(1);
Model number 06
|
BNOW APPROVES |
CSOCIALIST REPUBLIC OF VIET NAM |
|
Provincial People's Committees set specific prices: /GP-BTTTT |
Hà Nộiissued on the... day of the... month of the... year |
LICENSE FOR OPERATING RELIABLE SERVICES
MINISTER OF INFORMATION AND COMMUNICATIONS
WHEREAS,ứ Law on Electronic Transactions June 22, 2023;
WHEREAS,Pursuant to Decree No. .../.../ND-CP dated ... month ... year ... of the Government on electronic signatures and trust services;
WHEREAS,Law on Electronic Transactions.
The specialized electronic signature to ensure security is used exclusively for activities consistent with its functions and tasks as follows:dossier for applying for/renewing/extending/changing the contents of the License for Operating Reliable Services dated... month... year... of ...(1);
Pursuant to the proposal of the Director of the Department of Ethnic Affairs and Religion Propaganda;2. Specialized or sectoral activities, having the same nature or purpose of work and interconnected through ...;
NOW PERMITS
Article 1. (NAME OF ENTERPRISE), June 22, 2023, Decree No. .../.../ND-CP dated ... month ... year ... of the Government on electronic signatures and trust services and relevant laws. This certificate for specialized electronic signature to ensure security takes effect from the date of signing and remains valid until ... month ... year ...; (3) replaces Certificate No. .../CN-BTTTT issued by the Minister of Information and Communications on ... month ... year ... headquartered at..., holding Business Registration Certificate number: ... issued by... on the... day of the... month of the... year..., to operate reliable services with the specific contents as follows:
2. International trade name:ervice: ...(1)
2. Typeof reliable service permitted to operate:
a) Providingservice ...(3)
The issuance of work permits is governed by the following legal documents as prescribed by current laws: i) Decree No. 34/2008/NĐ-CP dated March 25, 2008, on the recruitment and management of foreign workers in Vietnam; ii) Decree No. 46/2011/NĐ-CP dated June 17, 2011, amending certain provisions of Decree No. 34/2008/NĐ-CP; and iii) Circular No. 31/2011/TT-BLDTBXH dated November 3, 2011, issued by the Ministry of Labor, Invalids, and Social Affairs guiding the implementation of Decrees No. 34 and No. 46.期限提供服务至...月...日...年...
b) License for operating ...(3) service
The issuance of work permits is governed by the following legal documents as prescribed by current laws: i) Decree No. 34/2008/NĐ-CP dated March 25, 2008, on the recruitment and management of foreign workers in Vietnam; ii) Decree No. 46/2011/NĐ-CP dated June 17, 2011, amending certain provisions of Decree No. 34/2008/NĐ-CP; and iii) Circular No. 31/2011/TT-BLDTBXH dated November 3, 2011, issued by the Ministry of Labor, Invalids, and Social Affairs guiding the implementation of Decrees No. 34 and No. 46.期限提供服务至...月...日...年...
3. Scopeof service provision
d.1. Amount of taxable income in Vietnam:The organization providing reliable services (1) shall carry out activities in accordance with the provisions of Article... of Decree No.../.../ND-CP dated... month... year... of the Government on electronic signatures and reliable services.
4. Typeof digital signature certificates and Method of storing subscriber secret keys (For public digital signature certification services)
a) IThe organization providing reliable services (1) shall provide the following types of digital signature certificates:
….
b) Methodof storing subscriber secret keys as follows:
….
Article 2. Changes to the information system during operation (in case of reissue) Law on Electronic Transactions On June 22, 2023, Decree No.../.../ND-CP dated... month... year... of the Government on electronic signatures and reliable services and other relevant laws.
Article 3. This License for Operating Reliable Services shall take effect from the date of signing and shall be valid until the... day of the... month of the... year;(4) replacing License No.../GP-BTTTT issued by the Minister of Information and Communications on the... day of the... month of the... year...
|
|
BPRIME MINISTER |
Note:
(1) Name of enterprisegranted the license.
APPLICATIONDirector of the unit submitting the application for the license.
(3) Reliable service permitted to operate.
(4) Used in cases of changing the content/reissuing the license.
Model number 07
|
3. Reason for change/reissue/extension:4. Content requested to change/reissue/extend: |
CSOCIALIST REPUBLIC OF VIET NAM |
|
Provincial People's Committees set specific prices... |
..., on the... day of the... month of the... year |
REPORT ON IMPLEMENTATION OF RELIABLE SERVICE PROVIDING ACTIVITIES
Respectfully submit to:To: Ministry of Information and Communications
(TNational Electronic Certification Service Provider Organization)
WHEREAS,ứ Law on Electronic Transactions June 22, 2023;
WHEREAS,Pursuant to Decree No. .../.../ND-CP dated ... month ... year ... of the Government on electronic signatures and trust services;
Part 8. Fax Number:
2. International trade name:3. Decision
establishing/Decision stipulating functions and tasks No. ... issued by ... on ... month ... year ... (if applicable) or Enterprise Registration Certificate No. ... issued by ... on ... month ... year ... (if applicable).4. Legal representative's name:
9. Website:10. Tax Code:
7. Telephone:2. Attached documents (specify type and quantity of files)
Name of documentQuantity
3. Commitment(Organization) commits to be responsible for the accuracy and legality of the provided information above and attached documents, and commits to comply with laws on electronic signatures and related laws.
LEGAL REPRESENTATIVEOF THE AUTHORITY, ORGANIZATION
2. Summary of the application for the business licenseat License requested to be issued
1. Business license for service ...
Duration of the license requested to be issued: ... years ... months...2.
Part 2. Summary description of the license
(Company) commits to be responsible for the accuracy and legality of the provided information above and attached documents, and commits to comply with the laws on reliable services and related laws.License for Operating Reliable Services issued:
The application and procedures for requesting confirmation are Form 1 - HĐ/HTQT and the provisions in Section D.III of Circular No. 133/2004/TT-BTC, supplemented with the following specific information:License No... issued by the Minister of Information and Communications on the... day of the... month of the... year...
2. Name ofreliable service requesting issuance of digital signature certificate:
3. Name ofthe organization providing reliable services requesting to be recorded on the digital signature certificate:
Part 3. Attached documents (specify type and quantity of documents)
|
Serial number |
Contact person for the file (name, position, telephone, email address):Part IV: Results of Event-Based Surveillance Monitoring |
Provincial People's Committees set specific pricesNumber 02 |
Remarks |
|
1 |
signing and implementing AgreementsActual implementation results of the information system |
|
|
|
2 |
HHuman resources management and technical dossier, contracts (copies) |
|
|
|
3 |
List and allocation of humanresources for management and technology |
|
|
|
4 |
Draft key generation ceremony script |
|
|
|
5 |
List ofequipment in the information system with management codes |
|
|
|
6 |
signing and implementing AgreementsLatest technical audit result (for cases where there are already digital signature certificates and services are being provided) |
|
|
|
7 |
3. Attached documents (specify type and quantity of files)Legal regulations of the enterprise (for reissue cases) |
|
|
|
8 |
Operational proceduresof the actual information system |
|
|
|
9 |
(Enterprise) commits to be responsible for the accuracy and legality of the provided information above and attached documents, and commits to comply with laws on trust services and related laws.Authentication |
|
|
|
10 |
Number 05changes to the information system during actual implementation (if any) |
|
|
|
11 |
2. Summary description of the request to change content/reissue/extend the business licenseBusiness license for trust services requested to change content/reissue/extend: |
|
|
|
… |
|
|
|
Part (Company) requests the Ministry of Information and Communications to change the content of the business license for reliable services number... issued by the Minister of Information and Communications on... month... year..., specifically as follows:
1. General information about the companyhereby commits to being responsible for the accuracy and legality of the provided information and accompanying documents, and commits to complying with the laws on digital signatures, reliable services, and related laws.
|
|
The method for determining the collection rate is calculated based on the following formula:date: ... month ... year ... |
- Office of the President of the StateUpon examination of the application for issuance/reissuance of the certificate for specialized electronic signature to ensure security dated ... month ... year ... of ...(1);
Model number 08
|
3. Reason for change/reissue/extension:/EP/ |
CSOCIALIST REPUBLIC OF VIET NAM |
|
Provincial People's Committees set specific prices... |
…, day … month … year … |
Respectfully submit to:Ministry of Information and Communications.
I. INFORMATION ON CERTIFICATE/LICENSE
The application and procedures for requesting confirmation are Form 1 - HĐ/HTQT and the provisions in Section D.III of Circular No. 133/2004/TT-BTC, supplemented with the following specific information:License for Operating Reliable Services/Certificate of Special-Purpose Electronic Signature for Security No... issued by... on the... day of the... month of the... year...
II. REPORT ON IMPLEMENTATION OF THE CERTIFICATE/LICENSEFor the Certificate of Special-Purpose Electronic Signature for Security
- Office of the President of the State1. Scope
of special-purpose electronic signatures for security provided2. Statistics on the number of special-purpose electronic signatures for security created
3. Technology,standards, and specifications for special-purpose electronic signatures for security
4. Humanresources, capacity, and technical experience of personnel within the agency or organization
For the License for Operating Reliable Servicessignature on paper vouchers in accordance with the law on electronic transactions;
Condition of container/special vehicle/goods...1. Types
- Office of the President of the Stateof services provided, scope of services provided
Statistics on the number of service users, market share, revenue3. Service
3. Technology,usage contracts
4. Pricing5. Technology,
standards, specifications, and service qualityImplementation Provisions
6. Financial reportThe financial report has been audited at the most recent year prior to the submission of this Report.
7. Human
resources, capacity, and technical experience of personnel within the enterpriseRespectfully,
LEGAL REPRESENTATIVE OFsignature on paper vouchers in accordance with the law on electronic transactions;
Condition of container/special vehicle/goods...THE ENTERPRISE/ORGANIZATION
Contact person for documentation (name, position, phone, email address):ọng.
|
|
The method for determining the collection rate is calculated based on the following formula:LEGAL REPRESENTATIVE OF |
- Office of the President of the Stateầu mối liên hệ về tài liệu (họ tên, chức vụ, điện thoại, địa chỉ thư điện tử):
原始文件(PDF)
关系图
点击文件即可打开。红色边框=改变效力的关系。