Circular No. 28/2015/TT-NHNN on the management and use of digital signatures, certificates, and digital signature verification services of the State Bank of Vietnam

Circular No. 28/2015/TT-NHNN stipulates the management and use of digital signatures and certificates of the State Bank of Vietnam. The document applies to units under the State Bank, credit organizations, foreign bank branches, National Treasury, and other organizations using the State Bank's digital signature verification service in electronic transactions organized by the State Bank.

文号28/2015/TT-NHNN
文件类型Circular
发布机关State Bank of Vietnam
签署人Nguyễn Toàn Thắng — Phó Thống đốc
更新24/06/2026
行业Banking
领域Banking Information Technology
发布日期18/12/2015
生效日期01/02/2016
失效日期01/03/2026
状态Expired
✦ 智能摘要

Circular No. 28/2015/TT-NHNN stipulates the management and use of digital signatures and certificates of the State Bank of Vietnam. The document applies to units under the State Bank, credit organizations, foreign bank branches, National Treasury, and other organizations using the State Bank's digital signature verification service in electronic transactions organized by the State Bank.

适用范围

Units under the State Bank; credit organizations; foreign bank branches; National Treasury; and other organizations using the State Bank's digital signature verification service in electronic transactions organized by the State Bank.

要点

  • Management and use of digital signatures, certificates, and digital signature verification services must submit applications for issuance, extension, suspension, restoration, and revocation of certificates through the network or postal service.
  • Processing time for applications: 5 working days from the date of receipt of complete and valid documents.
  • Certificates have a maximum validity period of 5 years and must be renewed at least 10 days before expiration.
  • In case the secret key is disclosed or suspected to be disclosed, the certificate will be immediately suspended.
  • Users of certificates must store and use the secret key according to the 'Confidential' regime; they may not share or lend out the secret key code.

🌐 本文件的社会影响

  • Positive impact: Saving time and costs in the process of managing and using digital signatures and certificates.
  • Negative impact: It may cause difficulties for organizations when complying with regulations on managing and using secret keys.

❓ 常见问题

What documents are required to obtain a certificate?

Submit one set of documents including a request for issuance of a certificate and a personal application form from the organization managing the user.

How long does it take to process an application for certificate renewal?

Within 5 working days from the date of receipt of complete and valid documents.

For how long is a certificate valid?

Maximum validity of 5 years, must be renewed at least 10 days before expiration.

If the secret key is disclosed or suspected to be disclosed, what should be done?

The user must submit a request for suspension of the certificate through the network, deliver directly, or send via postal service to the organization providing the digital signature service.

What are the responsibilities of users when using certificates?

Use for the purpose granted; store and use the secret key according to the 'Confidential' regime; do not share or lend out the secret key code.

全文

STATE BANK OF VIETNAM

STATE BANK OF VIETNAM



SOCIALIST REPUBLIC OF VIET NAM
Independence – Freedom – Happiness

NUMBER: 28/2015/TT-NHNN
HA NOI, December 18, 2015

CIRCULAR

REGULATING THE MANAGEMENT AND USE OF DIGITAL SIGNATURES, CERTIFICATES, AND DIGITAL SIGNATURE VERIFICATION SERVICES OF THE STATE BANK OF VIETNAM

 OF DIGITAL SIGNATURES OF THE STATE BANK OF VIETNAMspecialized agency under the People's Committee of the province/city.

__________________

 

Pursuant to the Law on the State Bank of Vietnam No.No. Pursuant to Law No. 46/2010/QH12 dated June 16, 2010;

No. 06/2013/UBTVQH13 dated March 18, 2013;

Pursuant to Law on Information Technology No. 67/2006/QH11 dated June 29, 2006;

Pursuant to the Law on Electronic Transactions;No. Law No. 51/2005/QH11 dated November 29, 2005;

Pursuant to Decree No. 26/2007/NĐ-CP dated February 15, 2007 of the Government detailing the implementation of the Law on Electronic Transactions regarding digital signatures;No. AND DIGITAL SIGNATURE VERIFICATION SERVICES;No.;

Pursuant to Decree No. 106/2011/NĐ-CP dated November 23, 2011 of the Government amending and supplementing Decree No. 26/2007/NĐ-CP of the Government dated February 15, 2007 detailing the implementation of the Law on Electronic Transactions regarding digital signatures and digital signature verification services;, amended and supplemented by Decree No. 109/2025/NĐ-CP and Decree No. 193/2025/NĐ-CP ,No. Điều của Luật Giao thông đường thủy nội địa ngày 17 tháng 6 năm 2014;u Pursuant to Decree No. 106/2011/NĐ-CP of the Government dated November 23, 2011 amending and supplementing some articles of Decree No. 26/2007/NĐ-CP of the Government dated February 15, 2007 detailing the implementation of the Law on Electronic Transactions regarding digital signatures and digital signature verification services;ənAND DIGITAL SIGNATURE VERIFICATION SERVICES;intention "7. A flexible power plant is a thermal power plant using reciprocating internal combustion engines (RICE) or aeroderivative gas turbines (Aero-GT) with fast start-up capabilities, designed in modular form to generate electricity for balancing capacity and maintaining power system stability."No.;

Pursuant to Decree No. 170/2013/NĐ-CP dated November 13, 2013 amending and supplementing some articles of Decree No. 26/2007/NĐ-CP of the Government dated February 15, 2007 detailing the implementation of the Law on Electronic Transactions regarding digital signatures and digital signature verification services;intention "7. A flexible power plant is a thermal power plant using reciprocating internal combustion engines (RICE) or aeroderivative gas turbines (Aero-GT) with fast start-up capabilities, designed in modular form to generate electricity for balancing capacity and maintaining power system stability."No. and verification servicesənAND DIGITAL SIGNATURE VERIFICATION SERVICES;No. Pursuant to Decree No. 106/2011/NĐ-CP of the Government dated November 23, 2011 amending and supplementing some articles of Decree No. 26/2007/NĐ-CP of the Government dated February 15, 2007;

Pursuant to Decree No. 156/2013/NĐ-CP dated November 11, 2013 regulating functions, tasks, and regulations;onThis Circular provides detailed guidance on the issuance of treasury bills in accordance with Clause 1, Article 11 of Decree No. 01/2011/NĐ-CP dated January 5, 2011 of the Government on the issuance of government bonds, bonds guaranteed by the Government, and local government bonds (hereinafter referred to as Decree No. 01/2011/NĐ-CP), including:

At the proposal of the Director of the Information Technology Department;

THENo.THE GOVERNOR OF THE STATE BANK OF VIETNAM ISSUES THIS CIRCULAR REGULATING THE MANAGEMENT AND USE OF DIGITAL SIGNATURES, CERTIFICATES, AND DIGITAL SIGNATURE VERIFICATION SERVICES OF THE STATE BANK OF VIETNAM.on THE MANAGEMENT AND USE OF DIGITAL SIGNATURES, CERTIFICATES,AND DIGITAL SIGNATURE VERIFICATION SERVICESNo. and verification servicesOF THE STATE BANK OF VIETNAM.intention "7. A flexible power plant is a thermal power plant using reciprocating internal combustion engines (RICE) or aeroderivative gas turbines (Aero-GT) with fast start-up capabilities, designed in modular form to generate electricity for balancing capacity and maintaining power system stability."No. OF THE STATE BANK OF VIETNAM.

PART I

GENERAL PROVISIONS

Article 1. Scope of Regulation

This Circular regulates the management and use of digital signatures, certificates, and digital signature verification services in electronic transactions of the State Bank of Vietnam (the State Bank).

Article 2. Applicability

1. Units under the State Bank; credit organizations; foreign bank branches; National Treasury.

2. Other organizations using the digital signature verification service of the State Bank in electronic transactions organized by the State Bank.

Article 3. Explanation of Terms

In this Circular, the following terms are understood as follows:

1. "Certificate" is a type of electronic certificate issued by the organization providing the State Bank's digital signature verification service.

2. "Digital signature verification service" is a type of service provided by the organization providing the State Bank's digital signature verification service. The digital signature verification service includes:

a) Creating a key pair including public and private keys for subscribers;

b) Issuing, renewing, suspending, restoring, and revoking subscriber certificates;

c) Maintaining an online database of certificates;

d) Other related services as prescribed.

3. "Service provider" is the organization providing the State Bank's dedicated digital signature verification service (CA-NHNN) managed and operated by the Information Technology Department.

4. "Subscriber" is an organization or individual belonging to a unit or organization as stipulated in Article 2 of this Circular, who is issued a certificate by the service provider; accepts the certificate and retains the corresponding private key recorded on the issued certificate.

5. "Subscriber manager" is units under the State Bank, credit organizations, foreign bank branches, National Treasury, or other organizations requesting issuance of certificates for individuals within their own units or organizations.

6. "State Bank electronic transaction" is activities and operations conducted electronically by the State Bank.

7. "Private key" is a key in a key pair in an asymmetric cryptographic system used to create digital signatures.

8. "Public key" is a key in a key pair in an asymmetric cryptographic system used to verify digital signatures created by the corresponding private key in the pair.

9. "Signer" is a subscriber who uses their own private key to sign a data message under their name.

10. "Recipient" is an organization or individual receiving a digitally signed data message from the signer, using the signer's certificate to verify the digital signature in the received message and proceeding with related activities and transactions.

Article 4. Contents of the digital certificate

1. The name of the organization providing digital signature services.

2. Name of the subscriber.

3. Name of the subscriber manager.

4. Serial number of the certificate.

5. Validity period of the certificate.

6. Public key of the subscriber.

7. Digital signature of the digital signature service provider.

8. Restrictions on the purpose and scope of use of the certificate.

9. Restrictions on the legal liability of the digital signature service provider.

10. Other necessary contents as prescribed by the Ministry of Information and Communications.

Chapter II

DIGITAL SIGNATURE VERIFICATION SERVICES

Article 5. Issuance of Digital Certificates

1. Digital Certificate for Individuals under Subscriber Management Organizations

When there is a need to issue a digital certificate for an individual under a subscriber management organization, the subscriber management organization shall submit one (1) set of application documents for issuance of a digital certificate through the network, directly or via postal service to the headquarters of the digital signature service provider. The application package includes:

a) A request for issuance of a digital certificate from the subscriber management organization according to Form 01 attached to this Circular;

b) An individual's request for issuance of a digital certificate under the subscriber management organization according to Form 02 attached to this Circular.

2. Digital Certificate for Authorized Persons (Legal Representatives)

When there is a need to issue a digital certificate for an authorized person (legal representative) of a subscriber management organization, the subscriber management organization shall submit one (1) set of application documents for issuance of a digital certificate directly or via postal service to the headquarters of the digital signature service provider. The application package includes:

a) Documents as stipulated in Clause 1 of this Article;

b) A copy of the certificate confirming the registration of the seal model issued to the agency or organization according to the regulations on seal management and use;

c) A copy of the document confirming the position of the authorized person of the agency or organization;

d) For copies as stipulated in points b and c of this Clause, the organization has the right to choose copies issued from the original book or certified copies or copies accompanied by presentation of the original for comparison.

3. Within five working days from the date of receipt of complete and valid application documents for issuance of a digital certificate, the digital signature service provider shall issue a digital certificate for the subscriber and notify the result through the network or via postal service. In case of refusal, the reasons must be clearly stated.

4. The validity period of the digital certificate of the subscriber proposed by the subscriber management organization but not exceeding five years from the date the digital certificate becomes effective.

Article 6. Extension of Digital Certificates

1. The digital certificate requested for extension must still be valid.

2. The subscriber management organization shall send the Application for Extension of Digital Certificate according to Form 03 attached to this Circular through the network, directly or via postal service to the digital signature service provider.

3. The Application for Extension of Digital Certificate must be sent to the digital signature service provider at least ten days before the expiration date of the digital certificate.

4. Within five working days from the date of receipt of a valid Application for Extension of Digital Certificate, the digital signature service provider shall extend the digital certificate for the subscriber and notify the result through the network or via postal service. In case of refusal, the reasons must be clearly stated.

Article 7. Suspension of digital certificates

1. A subscriber's digital certificate is suspended when one of the following situations occurs:

a) Secret key leakage or suspected leakage; loss of secret key storage device, unauthorized copying or other security breaches, the subscriber sends the Application for Temporary Suspension of Digital Certificate according to Form 04 attached to this Circular through the network, directly or via postal service to the digital signature service provider;

b) At the written request of the prosecution agency, security agency, or Ministry of Information and Communications;

c) At the written request of the subscriber management organization;

d) The digital signature service provider discovers any errors or incidents that may affect the subscriber's rights or the security of the digital signature certification service system;

đ) The temporary suspension period of the digital certificate as stipulated in point a and c of this Clause according to the request of the subscriber or the subscriber management organization. The temporary suspension period of the digital certificate as stipulated in point b of this Clause according to the request of the prosecution agency, security agency, or Ministry of Information and Communications.

2. Upon receiving information or requests as stipulated in Clause 1 of this Article, the digital signature service provider shall immediately suspend the digital certificate, notify the result through the network or via postal service within five working days, and update the information on the State Bank's electronic information website.

Article 8. Restoration of Digital Certificates

1. The digital certificate to be restored must ensure that it is within the suspension period.

2. A subscriber's digital certificate shall be restored in the following cases:

a) At the request in writing from the prosecution agency, security agency, or the Ministry of Information and Communications;

b) At the request for restoration of the digital certificate from the management organization;

c) The suspension period of the digital certificate according to the suspension request has expired;

d) The digital certificate was suspended under point d, Clause 1, Article 7 of this Circular, and the errors or incidents have been resolved.

3. The management organization sends the Application for Restoration of Digital Certificate Form 05 attached to this Circular through the network, submits directly, or sends via postal service to the service provider.

4. Within five working days from the date of receipt of a valid Application for Restoration of Digital Certificate, the service provider shall restore the digital certificate for the subscriber and notify the result through the network or via postal service. In case of refusal, the reason must be clearly stated.

Article 9. Revocation of digital certificates

1. A subscriber's digital certificate shall be revoked in the following cases:

a) At the request in writing from the prosecution agency, security agency, or the Ministry of Information and Communications;

b) At the request in writing from the management organization;

c) The management organization is dissolved or declared bankrupt in accordance with the law;

d) There is sufficient evidence to determine that the subscriber violates the regulations on managing and using secret keys and key storage devices as stipulated in Clause 1 and Clause 2, Article 15 of this Circular.

2. The management organization sends the Application for Revocation of Digital Certificate Form 06 attached to this Circular through the network, submits directly, or sends via postal service to the service provider.

3. Upon receiving the information or requests as stipulated in Clause 1 of this Article, the service provider immediately proceeds to revoke the digital certificate, notifies the result through the network or via postal service within five working days, and updates the information on the State Bank's electronic website.

Article 10. Key Generation and Distribution

1. A subscriber's key pair is generated by the subscriber or the service provider.

2. In the case of self-generation of the key pair, the subscriber must generate the key pair before the activation expiration date specified in the digital certificate issuance notice. If the subscriber fails to generate the key pair before the activation expiration date, the management organization sends the Application for Change of Activation Code Form 08 to the service provider requesting an extension of the key generation time for the subscriber before the activation expiration date specified in the digital certificate issuance notice. If beyond the activation expiration date specified in the digital certificate issuance notice, the subscriber wishes to continue using the digital certificate, they must follow the procedures stipulated in Article 11 of this Circular.

3. In the case where the service provider generates the key pair for the subscriber, the subscriber must visit the service provider to request the generation of the key pair. The service provider shall generate the key pair and hand it over to the subscriber.

4. The subscriber must use the key storage device according to the instructions of the service provider.

Article 11. Key Pair Change

1. A subscriber requesting a change in the key pair must ensure that the digital certificate remains valid. If the digital certificate has expired, the subscriber wishing to continue using the digital certificate must follow the procedures stipulated in Article 5 of this Circular.

2. The management organization sends the Application for Change of Key Pair Form 07 attached to this Circular through the network, submits directly, or sends via postal service to the service provider.

3. Within five working days from the date of receipt of a valid Application for Change of Key Pair, the service provider shall change the key pair for the subscriber and notify the result through the network or via postal service. In case of refusal, the reason must be clearly stated.

Article 12. Updating and Publishing Information

The organization providing digital signature services shall publish, update, and maintain 24 hours a day, 7 days a week on the electronic news page of the State Bank of Vietnam the following information:

1. Circulars governing the management and use of digital signatures, digital certificates, and digital signature verification services.

2. Lists of active, suspended, and revoked digital certificates of subscribers.

3. Other necessary information.

Chapter III

RESPONSIBILITIES OF THE PARTIES INVOLVED IN PROVIDING AND USING DIGITAL SIGNATURE VERIFICATION SERVICES

Article 13. Responsibilities of the organization providing digital signature services

1. Issue, renew, suspend, revoke, restore digital certificates, and change key pairs for subscribers upon request.

2. Manage and operate technical equipment systems providing digital signature verification services for the State Bank of Vietnam.

3. Have contingency plans to ensure the safe and continuous operation of digital signature verification services provided by the State Bank of Vietnam.

4. Fully, accurately, and timely update subscriber information for the management of digital certificates throughout their validity period.

5. Distribute keys and digital certificates to subscribers.

6. Provide subscribers with information about the scope and limitations of digital certificate usage, security requirements, and other information that may affect the rights of subscribers.

7. Ensure that the channel for receiving requests to suspend or revoke digital certificates operates 24 hours a day, 7 days a week.

8. Retain information related to the suspension, revocation of digital certificates, or changes to key pairs for at least five years from the date of suspension, revocation, or change of key pairs.

9. Publish lists of active, suspended, or revoked digital certificates.

10. Provide information about software and guidance materials regarding the management and use of digital signatures, digital certificates, and digital signature verification services.

Article 14. Responsibilities of the organization managing subscribers

1. Register digital certificates of authorized persons (legal representatives) on behalf of the managing organization to sign digital signatures on relevant documents and files related to digital certificates.

2. Manage, compile, and update subscriber lists within the organization. Review the subscriber list at least once every three months to ensure: (i) the subscriber list and assigned tasks are appropriate to job positions and work requirements; (ii) employees who leave or transfer must have their digital certificates promptly revoked; (iii) digital certificates nearing expiration must be renewed in time to ensure uninterrupted business operations.

3. Report periodically and ad hoc as stipulated in Article 17 of this Circular.

4. Be responsible for the accuracy of the information in the subscriber's digital certificate file managed and submitted to the organization providing digital signature services.

5. Submit digital certificate files through the internet via the State Bank of Vietnam’s electronic portal or by postal service or directly to the organization providing digital signature services; digital certificate files submitted online must be signed by an authorized person using a digital signature issued by the organization providing digital signature services.

6. Guide, inspect, and facilitate conditions for subscribers under their management to use digital certificates and secret keys in accordance with the provisions of this Circular.

7. Promptly notify the organization providing digital signature services to suspend or revoke the digital certificate of the authorized person in cases where the authorized person temporarily ceases work, leaves, changes position, or transfers to another organization.

8. Promptly notify the organization providing digital signature services to suspend or revoke the digital certificate of the subscriber in cases where the subscriber temporarily ceases work, leaves, or transfers to another organization; the subscriber changes jobs and does not use the previously issued digital certificate, and other cases arising from the needs of the managing organization.

Article 15. Obligations of the Subscriber

1. Use digital certificates for the intended purpose as granted.

2. Safeguard and use secret keys and data stored in devices holding secret keys under the "Confidential" regime; do not share or lend secret key codes or devices holding secret keys of digital certificates.

3. Promptly notify the service provider of digital signatures and the subscriber management organization upon discovering or suspecting that the digital certificate or secret key is no longer secure.

4. Comply with other regulations regarding issuance, management, and use of digital certificates.

Article 16. Obligations of Signers and Recipients

1. Before accepting a digital signature from the signer, the recipient must verify the following information:

a) The validity, scope of use, and liability limits of the digital certificate and digital signature of the signer and the service provider of digital signatures;

b) The digital signature must be created using the secret key corresponding to the public key on the digital certificate of the signer.

2. The recipient shall bear all losses arising in the following cases:

a) Failure to comply with the provisions of Clause 1 of this Article;

b) Knowing or having been informed about the untrustworthiness of the digital certificate and secret key of the signer but still accepting the digital certificate.

Chapter IV

IMPLEMENTING PROVISIONS

Article 17. Reporting System

The subscriber management organization has the responsibility to submit reports to the State Bank of Vietnam (Department of Information Technology) as follows:

1. Periodic reports on the management and use of digital certificates:

a) Reporting period: Once every six months, at the latest on January 15 and July 15 each year;

b) Method of submitting reports: Submitting reports in writing and Excel files of Microsoft via the network according to Form 09 to the State Bank of Vietnam (Department of Information Technology).

2. Ad hoc reports when requested by the service provider of digital signatures.

Article 18. Violations, Handling of Violations, Complaints, and Dispute Resolution

Determination of violations and handling of violations, complaints, and dispute resolution concerning digital signatures and digital signature verification services provided by the service provider of digital signatures, subscribers, and subscriber management organizations shall be carried out in accordance with the laws on digital signatures and other relevant laws.

Article 19. Effective Date

This Circular takes effect from February 1, 2016, and replaces Circular No. 12/2011/TT-NHNN dated May 17, 2011, on the management and use of digital signatures, digital certificates, and digital signature verification services of the State Bank of Vietnam.

Article 20. Implementation

1. The Department of Information Technology is responsible for:

a) Guide the management and use of digital signatures, digital certificates, and digital signature verification services;

b) Monitor and inspect the implementation of this Circular.

2. Banking inspection agencies have the responsibility to cooperate with the Department of Information Technology to inspect the compliance with this Circular by credit institutions and foreign bank branches.

3. Heads of units under the State Bank of Vietnam; Governors of the State Bank of Vietnam branch in provinces and centrally-administered cities; Chairmen of the Board of Directors, Chairmen of the Board of Members, General Directors (Directors) of credit institutions and foreign bank branches, and National Treasury have the responsibility to organize the implementation of this Circular.

DIRECTOR
DEPUTY DIRECTOR

Nguyen Toan Thang

原始文件(PDF)

在新标签页打开PDF ↗

关系图

↑ 依据及影响本文件的文件
依据 8
47/2010/QH12 Luật Các tổ chức tín dụng số 47/2010/QH12 已失效 46/2010/QH12 Luật Ngân hàng Nhà nước Việt Nam số 46/2010/QH12 生效中 67/2006/QH11 Luật Công nghệ thông tin số 67/2006/QH11 生效中 51/2005/QH11 Nghị quyết số 51/2005/QH11 Về nhiệm vụ năm 2006 生效中 170/2013/NĐ-CP Nghị định số 170/2013/NĐ-CP Sửa đổi, bổ sung một số điều của Nghị định số 26/2007/NĐ-CP ngày 15 tháng 02 năm 2007 của Chính phủ quy định chi tiết thi hành Luật Giao dịch điện tử về chữ ký số và dịch vụ chứng thực chữ ký số và Nghị định số 106/2011/NĐ-CP ngày 23 tháng 11 năm 2011 của Chính phủ sửa đổi, bổ sung một số điều của Nghị định số 26/2007/NĐ-CP ngày 15 tháng 02 năm 2007 已失效 106/2011/NĐ-CP Nghị định số 106/2011/NĐ-CP Sửa đổi, bổ sung một số điều của Nghị định số 26/2007/NĐ-CP của Chính phủ ngày 15 tháng 02 năm 2007 quy định chi tiết thi hành Luật Giao dịch điện tử về chữ ký số và dịch vụ chứng thực chữ ký số 已失效 26/2007/NĐ-CP Nghị định số 26/2007/NĐ-CP Quy định chi tiết thi hành Luật Giao dịch điện tử về chữ ký số và dịch vụ chứng thực chữ ký số 已失效 156/2013/NĐ-CP Nghị định số 156/2013/NĐ-CP Quy định chức năng, nhiệm vụ, quyền hạn và cơ cấu tổ chức của Ngân hàng Nhà nước Việt Nam 生效中
28/2015/TT-NHNN
Circular No. 28/2015/TT-NHNN on the management and use of digital signatures, certificates, and digital signature verification services of the State Bank of Vietnam
Expired

点击文件即可打开。红色边框=改变效力的关系。